01/08/2019 G.R. No. 203335 r. Section 19 on Restricting or Blocking Access to Computer Data; s. Section 20 on Obstruction of Justice; t. Section 24 on Cybercrime Investigation and Coordinating Center (CICC); and u. Section 26(a) on CICC’s Powers and Functions. Some petitioners also raise the constitutionality of related Articles 353, 354, 361, and 362 of the RPC on the crime of libel. The Rulings of the Court Section 4(a)(1) Section 4(a)(1) provides: Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act: (a) Offenses against the confidentiality, integrity and availability of computer data and systems: (1) Illegal Access. – The access to the whole or any part of a computer system without right. Petitioners contend that Section 4(a)(1) fails to meet the strict scrutiny standard required of laws that interfere with the fundamental rights of the people and should thus be struck down. The  Court  has  in  a  way  found  the  strict  scrutiny  standard,  an  American  constitutional  construct,1  useful  in determining the constitutionality of laws that tend to target a class of things or persons. According to this standard, a legislative  classification  that  impermissibly  interferes  with  the  exercise  of  fundamental  right  or  operates  to  the peculiar class disadvantage of a suspect class is presumed unconstitutional. The burden is on the government to prove  that  the  classification  is  necessary  to  achieve  a  compelling  state  interest  and  that  it  is  the  least  restrictive means to protect such interest.2 Later, the strict scrutiny standard was used to assess the validity of laws dealing with  the  regulation  of  speech,  gender,  or  race  as  well  as  other  fundamental  rights,  as  expansion  from  its  earlier applications to equal protection.3 In  the  cases  before  it,  the  Court  finds  nothing  in  Section  4(a)(1)  that  calls  for  the  application  of  the  strict  scrutiny standard since no fundamental freedom, like speech, is involved in punishing what is essentially a condemnable act – accessing the computer system of another without right. It is a universally condemned conduct.4 Petitioners  of  course  fear  that  this  section  will  jeopardize  the  work  of  ethical  hackers,  professionals  who  employ tools and techniques used by criminal hackers but would neither damage the target systems nor steal information. Ethical hackers evaluate the target system’s security and report back to the owners the vulnerabilities they found in it and give instructions for how these can be remedied. Ethical hackers are the equivalent of independent auditors who come into an organization to verify its bookkeeping records.5 Besides,  a  client’s  engagement  of  an  ethical  hacker  requires  an  agreement  between  them  as  to  the  extent  of  the search, the methods to be used, and the systems to be tested. This is referred to as the "get out of jail free card."6 Since the ethical hacker does his job with prior permission from the client, such permission would insulate him from the coverage of Section 4(a)(1). Section 4(a)(3) of the Cybercrime Law Section 4(a)(3) provides: Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act: (a) Offenses against the confidentiality, integrity and availability of computer data and systems: x x x x (3) Data Interference. – The intentional or reckless alteration, damaging, deletion or deterioration of computer data, electronic document, or electronic data message, without right, including the introduction or transmission of viruses. Petitioners claim that Section 4(a)(3) suffers from overbreadth in that, while it seeks to discourage data interference, it  intrudes  into  the  area  of  protected  speech  and  expression,  creating  a  chilling  and  deterrent  effect  on  these guaranteed freedoms. Under the overbreadth doctrine, a proper governmental purpose, constitutionally subject to state regulation, may not be  achieved  by  means  that  unnecessarily  sweep  its  subject  broadly,  thereby  invading  the  area  of  protected freedoms.7 But Section 4(a)(3) does not encroach on these freedoms at all. It simply punishes what essentially is a form  of  vandalism,8  the  act  of  willfully  destroying  without  right  the  things  that  belong  to  others,  in  this  case  their computer  data,  electronic  document,  or  electronic  data  message.  Such  act  has  no  connection  to  guaranteed freedoms. There is no freedom to destroy other people’s computer systems and private documents. All penal laws, like the cybercrime law, have of course an inherent chilling effect, an in terrorem effect9 or the fear of possible prosecution that hangs on the heads of citizens who are minded to step beyond the boundaries of what is proper. But to prevent the State from legislating criminal laws because they instill such kind of fear is to render the state  powerless  in  addressing  and  penalizing  socially  harmful  conduct.10  Here,  the  chilling  effect  that  results  in paralysis  is  an  illusion  since  Section  4(a)(3)  clearly  describes  the  evil  that  it  seeks  to  punish  and  creates  no tendency to intimidate the free exercise of one’s constitutional rights. Besides,  the  overbreadth  challenge  places  on  petitioners  the  heavy  burden  of  proving  that  under  no  set  of circumstances will Section 4(a)(3) be valid.11 Petitioner has failed to discharge this burden. Section 4(a)(6) of the Cybercrime Law Section 4(a)(6) provides: Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act: (a) Offenses against the confidentiality, integrity and availability of computer data and systems: x x x x (6) Cyber­squatting. – The acquisition of domain name over the internet in bad faith to profit, mislead, destroy the reputation, and deprive others from registering the same, if such a domain name is: (i)  Similar,  identical,  or  confusingly  similar  to  an  existing  trademark  registered  with  the  appropriate government agency at the time of the domain name registration; (ii) Identical or in any way similar with the name of a person other than the registrant, in case of a personal name; and https://lawphil.net/judjuris/juri2014/feb2014/gr_203335_2014.html 4/19

اختر الفقرة المستهدفة3