01/08/2019
G.R. No. 203335
Indeed, courts are able to save vague provisions of law through statutory construction. But the cybercrime law,
dealing with a novel situation, fails to hint at the meaning it intends for the phrase "due cause." The Solicitor General
suggests that "due cause" should mean "just reason or motive" and "adherence to a lawful procedure." But the
Court cannot draw this meaning since Section 12 does not even bother to relate the collection of data to the
probable commission of a particular crime. It just says, "with due cause," thus justifying a general gathering of data.
It is akin to the use of a general search warrant that the Constitution prohibits.
Due cause is also not descriptive of the purpose for which data collection will be used. Will the law enforcement
agencies use the traffic data to identify the perpetrator of a cyber attack? Or will it be used to build up a case against
an identified suspect? Can the data be used to prevent cybercrimes from happening?
The authority that Section 12 gives law enforcement agencies is too sweeping and lacks restraint. While it says that
traffic data collection should not disclose identities or content data, such restraint is but an illusion. Admittedly,
nothing can prevent law enforcement agencies holding these data in their hands from looking into the identity of
their sender or receiver and what the data contains. This will unnecessarily expose the citizenry to leaked
information or, worse, to extortion from certain bad elements in these agencies.
Section 12, of course, limits the collection of traffic data to those "associated with specified communications." But
this supposed limitation is no limitation at all since, evidently, it is the law enforcement agencies that would specify
the target communications. The power is virtually limitless, enabling law enforcement authorities to engage in
"fishing expedition," choosing whatever specified communication they want. This evidently threatens the right of
individuals to privacy.
The Solicitor General points out that Section 12 needs to authorize collection of traffic data "in real time" because it
is not possible to get a court warrant that would authorize the search of what is akin to a "moving vehicle." But
warrantless search is associated with a police officer’s determination of probable cause that a crime has been
committed, that there is no opportunity for getting a warrant, and that unless the search is immediately carried out,
the thing to be searched stands to be removed. These preconditions are not provided in Section 12.
The Solicitor General is honest enough to admit that Section 12 provides minimal protection to internet users and
that the procedure envisioned by the law could be better served by providing for more robust safeguards. His bare
assurance that law enforcement authorities will not abuse the provisions of Section 12 is of course not enough. The
grant of the power to track cyberspace communications in real time and determine their sources and destinations
must be narrowly drawn to preclude abuses.95
Petitioners also ask that the Court strike down Section 12 for being violative of the voidforvagueness doctrine and
the overbreadth doctrine. These doctrines however, have been consistently held by this Court to apply only to free
speech cases. But Section 12 on its own neither regulates nor punishes any type of speech. Therefore, such
analysis is unnecessary.
This Court is mindful that advances in technology allow the government and kindred institutions to monitor
individuals and place them under surveillance in ways that have previously been impractical or even impossible. "All
the forces of a technological age x x x operate to narrow the area of privacy and facilitate intrusions into it. In
modern terms, the capacity to maintain and support this enclave of private life marks the difference between a
democratic and a totalitarian society."96 The Court must ensure that laws seeking to take advantage of these
technologies be written with specificity and definiteness as to ensure respect for the rights that the Constitution
guarantees.
Section 13 of the Cybercrime Law
Section 13 provides:
Sec. 13. Preservation of Computer Data. — The integrity of traffic data and subscriber information relating to
communication services provided by a service provider shall be preserved for a minimum period of six (6) months
from the date of the transaction. Content data shall be similarly preserved for six (6) months from the date of receipt
of the order from law enforcement authorities requiring its preservation.
Law enforcement authorities may order a onetime extension for another six (6) months: Provided, That once
computer data preserved, transmitted or stored by a service provider is used as evidence in a case, the mere
furnishing to such service provider of the transmittal document to the Office of the Prosecutor shall be deemed a
notification to preserve the computer data until the termination of the case.
The service provider ordered to preserve computer data shall keep confidential the order and its compliance.
Petitioners in G.R. 20339197 claim that Section 13 constitutes an undue deprivation of the right to property. They
liken the data preservation order that law enforcement authorities are to issue as a form of garnishment of personal
property in civil forfeiture proceedings. Such order prevents internet users from accessing and disposing of traffic
data that essentially belong to them.
No doubt, the contents of materials sent or received through the internet belong to their authors or recipients and
are to be considered private communications. But it is not clear that a service provider has an obligation to
indefinitely keep a copy of the same as they pass its system for the benefit of users. By virtue of Section 13,
however, the law now requires service providers to keep traffic data and subscriber information relating to
communication services for at least six months from the date of the transaction and those relating to content data for
at least six months from receipt of the order for their preservation.
Actually, the user ought to have kept a copy of that data when it crossed his computer if he was so minded. The
service provider has never assumed responsibility for their loss or deletion while in its keep.
At any rate, as the Solicitor General correctly points out, the data that service providers preserve on orders of law
enforcement authorities are not made inaccessible to users by reason of the issuance of such orders. The process
of preserving data will not unduly hamper the normal transmission or use of the same.
Section 14 of the Cybercrime Law
Section 14 provides:
Sec. 14. Disclosure of Computer Data. — Law enforcement authorities, upon securing a court warrant, shall issue
an order requiring any person or service provider to disclose or submit subscriber’s information, traffic data or
relevant data in his/its possession or control within seventytwo (72) hours from receipt of the order in relation to a
valid complaint officially docketed and assigned for investigation and the disclosure is necessary and relevant for the
purpose of investigation.
The process envisioned in Section 14 is being likened to the issuance of a subpoena. Petitioners’ objection is that
the issuance of subpoenas is a judicial function. But it is wellsettled that the power to issue subpoenas is not
exclusively a judicial function. Executive agencies have the power to issue subpoena as an adjunct of their
investigatory powers.98
Besides, what Section 14 envisions is merely the enforcement of a duly issued court warrant, a function usually
lodged in the hands of law enforcers to enable them to carry out their executive functions. The prescribed procedure
https://lawphil.net/judjuris/juri2014/feb2014/gr_203335_2014.html
13/19