Back to all articles
Advisories

Your driver’s license data may be at risk: What Filipino drivers need to know

Sep 1, 2026 · 3 min readBy KasKasan Buddies

A complaint involving the LTO’s foreign contractor Dermalog has raised concerns about the security and control of Filipino drivers’ personal and biometric data.

  • If you have a Philippine driver's license, your personal data — your full name, birthday, address, and biometric information — may be sitting in a foreign-operated server right now, outside the Philippine government's control.
  • A civic group called Flag Maharlika filed a formal complaint with the NBI on May 19, 2026, urging an investigation into Dermalog — the German company contracted by the LTO to digitize and print Filipino driver's licenses under a ₱3.14 billion government contract awarded in 2018.
  • The LTO's own technical experts explicitly warned that Dermalog has full "access and control" over the five-year Driver's License Inventory and Printing Application Modules — and that this arrangement poses a national security threat because the foreign contractor can secretly print Philippine driver's license cards outside the country at any given time without LTO's knowledge.

A complaint involving the LTO’s foreign contractor Dermalog has raised concerns about the security and control of Filipino drivers’ personal and biometric data.

  • If you have a Philippine driver's license, your personal data — your full name, birthday, address, and biometric information — may be sitting in a foreign-operated server right now, outside the Philippine government's control.
  • A civic group called Flag Maharlika filed a formal complaint with the NBI on May 19, 2026, urging an investigation into Dermalog — the German company contracted by the LTO to digitize and print Filipino driver's licenses under a ₱3.14 billion government contract awarded in 2018.
  • The LTO's own technical experts explicitly warned that Dermalog has full "access and control" over the five-year Driver's License Inventory and Printing Application Modules — and that this arrangement poses a national security threat because the foreign contractor can secretly print Philippine driver's license cards outside the country at any given time without LTO's knowledge.

If you have a Philippine driver's license, your personal data — your full name, birthday, address, and biometric information — may be sitting in a foreign-operated server right now, outside the Philippine government's control.

This is not a drill.

A civic group called Flag Maharlika filed a formal complaint with the NBI on May 19, 2026, urging an investigation into Dermalog — the German company contracted by the LTO to digitize and print Filipino driver's licenses under a ₱3.14 billion government contract awarded in 2018.

The LTO's own technical experts explicitly warned that Dermalog has full "access and control" over the five-year Driver's License Inventory and Printing Application Modules — and that this arrangement poses a national security threat because the foreign contractor can secretly print Philippine driver's license cards outside the country at any given time without LTO's knowledge.

Making it worse: local LTO employees cannot even transfer physical card inventory from one district to another within the Philippines without asking a Dermalog employee based in Malaysia to do it remotely.

The LTO demanded Dermalog surrender the source code thirteen times. Thirteen times, Dermalog refused to comply. The government owns this system — but control remains in private hands.

Why this matters to you financially:

Your driver's license contains the exact data that scammers use to steal your identity — your full name, birthday, address, and biometric identifiers. That is the same information used to:

- Apply for credit cards and loans in your name

- Open bank accounts or e-wallets fraudulently

- Pass identity verification on financial platforms

- Commit SIM swap fraud to take over your accounts

Flag Maharlika is urging the NBI's Cybercrime and Counter-Intelligence divisions to look into potential violations of RA 10175 (Cybercrime Prevention Act), specifically Illegal Access and System Interference, and to check if public officials' administrative failures facilitated this under RA 3019 (Anti-Graft Law). A parallel complaint has also been filed with the National Privacy Commission.

The Solicitor General has separately petitioned the Supreme Court to nullify the Dermalog contract, with a temporary restraining order request pending.

What you can do right now:

- Monitor your bank accounts and credit card statements closely for any unauthorized transactions

- Check your credit report via the Credit Information Corporation (CIC) at cic.gov.ph for any loans or credit lines you did not open

- Enable transaction alerts and two-factor authentication on all your financial apps

- Be extra cautious of calls, texts, or emails using your personal details — scammers use exposed data to sound legitimate

- If you suspect identity theft, report it immediately to your bank, the NPC at privacy.gov.ph, and the NBI Cybercrime Division

You cannot control what the government does with your data. But you can control how fast you detect and respond if someone tries to use it against you.

Stay on top of your financial health with the KKB App — your one-stop for verified credit cards and digital banking options with strong security features.

Download here: https://www.kaskasanbuddies.com.ph/download?source=web

Share this with every driver you know. 14 million Filipinos deserve to know this is happening.

*Sources: The Manila Times, Manila Bulletin, Philstar — May 20-22, 2026. Flag Maharlika Letter to NBI Director Melvin Matibag, May 19, 2026. Ombudsman Resolution OMB-C-C-22-0061.*