01/08/2019
G.R. No. 203335
prision correctional in its maximum period or a fine of One hundred thousand pesos (Php100,000.00) or both, for
each and every noncompliance with an order issued by law enforcement authorities.
Petitioners challenge Section 20, alleging that it is a bill of attainder. The argument is that the mere failure to comply
constitutes a legislative finding of guilt, without regard to situations where noncompliance would be reasonable or
valid.
But since the noncompliance would be punished as a violation of Presidential Decree (P.D.) 1829,102 Section 20
necessarily incorporates elements of the offense which are defined therein. If Congress had intended for Section 20
to constitute an offense in and of itself, it would not have had to make reference to any other statue or provision.
P.D. 1829 states:
Section 1. The penalty of prision correccional in its maximum period, or a fine ranging from 1,000 to 6,000 pesos, or
both, shall be imposed upon any person who knowingly or willfully obstructs, impedes, frustrates or delays the
apprehension of suspects and the investigation and prosecution of criminal cases by committing any of the following
acts:
x x x.
Thus, the act of noncompliance, for it to be punishable, must still be done "knowingly or willfully." There must still be
a judicial determination of guilt, during which, as the Solicitor General assumes, defense and justifications for non
compliance may be raised. Thus, Section 20 is valid insofar as it applies to the provisions of Chapter IV which are
not struck down by the Court.
Sections 24 and 26(a) of the Cybercrime Law
Sections 24 and 26(a) provide:
Sec. 24. Cybercrime Investigation and Coordinating Center.– There is hereby created, within thirty (30) days from
the effectivity of this Act, an interagency body to be known as the Cybercrime Investigation and Coordinating
Center (CICC), under the administrative supervision of the Office of the President, for policy coordination among
concerned agencies and for the formulation and enforcement of the national cybersecurity plan.
Sec. 26. Powers and Functions.– The CICC shall have the following powers and functions:
(a) To formulate a national cybersecurity plan and extend immediate assistance of real time commission of
cybercrime offenses through a computer emergency response team (CERT); x x x.
Petitioners mainly contend that Congress invalidly delegated its power when it gave the Cybercrime Investigation
and Coordinating Center (CICC) the power to formulate a national cybersecurity plan without any sufficient
standards or parameters for it to follow.
In order to determine whether there is undue delegation of legislative power, the Court has adopted two tests: the
completeness test and the sufficient standard test. Under the first test, the law must be complete in all its terms and
conditions when it leaves the legislature such that when it reaches the delegate, the only thing he will have to do is
to enforce it. The second test mandates adequate guidelines or limitations in the law to determine the boundaries of
the delegate’s authority and prevent the delegation from running riot.103
1avvphi1
Here, the cybercrime law is complete in itself when it directed the CICC to formulate and implement a national
cybersecurity plan. Also, contrary to the position of the petitioners, the law gave sufficient standards for the CICC to
follow when it provided a definition of cybersecurity.
Cybersecurity refers to the collection of tools, policies, risk management approaches, actions, training, best
practices, assurance and technologies that can be used to protect cyber environment and organization and user’s
assets.104 This definition serves as the parameters within which CICC should work in formulating the cybersecurity
plan.
Further, the formulation of the cybersecurity plan is consistent with the policy of the law to "prevent and combat such
[cyber] offenses by facilitating their detection, investigation, and prosecution at both the domestic and international
levels, and by providing arrangements for fast and reliable international cooperation."105 This policy is clearly
adopted in the interest of law and order, which has been considered as sufficient standard.106 Hence, Sections 24
and 26(a) are likewise valid.
WHEREFORE, the Court DECLARES:
1. VOID for being UNCONSTITUTIONAL:
a. Section 4(c)(3) of Republic Act 10175 that penalizes posting of unsolicited commercial
communications;
b. Section 12 that authorizes the collection or recording of traffic data in realtime; and
c. Section 19 of the same Act that authorizes the Department of Justice to restrict or block
access to suspected Computer Data.
2. VALID and CONSTITUTIONAL:
a. Section 4(a)(1) that penalizes accessing a computer system without right;
b. Section 4(a)(3) that penalizes data interference, including transmission of viruses;
c. Section 4(a)(6) that penalizes cybersquatting or acquiring domain name over the internet in
bad faith to the prejudice of others;
d. Section 4(b)(3) that penalizes identity theft or the use or misuse of identifying information
belonging to another;
e. Section 4(c)(1) that penalizes cybersex or the lascivious exhibition of sexual organs or sexual
activity for favor or consideration;
f. Section 4(c)(2) that penalizes the production of child pornography;
g. Section 6 that imposes penalties one degree higher when crimes defined under the Revised
Penal Code are committed with the use of information and communications technologies;
h. Section 8 that prescribes the penalties for cybercrimes;
i. Section 13 that permits law enforcement authorities to require service providers to preserve
traffic data and subscriber information as well as specified content data for six months;
j. Section 14 that authorizes the disclosure of computer data under a courtissued warrant;
https://lawphil.net/judjuris/juri2014/feb2014/gr_203335_2014.html
15/19