01/08/2019
G.R. No. 203335
r. Section 19 on Restricting or Blocking Access to Computer Data;
s. Section 20 on Obstruction of Justice;
t. Section 24 on Cybercrime Investigation and Coordinating Center (CICC); and
u. Section 26(a) on CICC’s Powers and Functions.
Some petitioners also raise the constitutionality of related Articles 353, 354, 361, and 362 of the RPC on the crime
of libel.
The Rulings of the Court
Section 4(a)(1)
Section 4(a)(1) provides:
Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act:
(a) Offenses against the confidentiality, integrity and availability of computer data and systems:
(1) Illegal Access. – The access to the whole or any part of a computer system without right.
Petitioners contend that Section 4(a)(1) fails to meet the strict scrutiny standard required of laws that interfere with
the fundamental rights of the people and should thus be struck down.
The Court has in a way found the strict scrutiny standard, an American constitutional construct,1 useful in
determining the constitutionality of laws that tend to target a class of things or persons. According to this standard, a
legislative classification that impermissibly interferes with the exercise of fundamental right or operates to the
peculiar class disadvantage of a suspect class is presumed unconstitutional. The burden is on the government to
prove that the classification is necessary to achieve a compelling state interest and that it is the least restrictive
means to protect such interest.2 Later, the strict scrutiny standard was used to assess the validity of laws dealing
with the regulation of speech, gender, or race as well as other fundamental rights, as expansion from its earlier
applications to equal protection.3
In the cases before it, the Court finds nothing in Section 4(a)(1) that calls for the application of the strict scrutiny
standard since no fundamental freedom, like speech, is involved in punishing what is essentially a condemnable act
– accessing the computer system of another without right. It is a universally condemned conduct.4
Petitioners of course fear that this section will jeopardize the work of ethical hackers, professionals who employ
tools and techniques used by criminal hackers but would neither damage the target systems nor steal information.
Ethical hackers evaluate the target system’s security and report back to the owners the vulnerabilities they found in
it and give instructions for how these can be remedied. Ethical hackers are the equivalent of independent auditors
who come into an organization to verify its bookkeeping records.5
Besides, a client’s engagement of an ethical hacker requires an agreement between them as to the extent of the
search, the methods to be used, and the systems to be tested. This is referred to as the "get out of jail free card."6
Since the ethical hacker does his job with prior permission from the client, such permission would insulate him from
the coverage of Section 4(a)(1).
Section 4(a)(3) of the Cybercrime Law
Section 4(a)(3) provides:
Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act:
(a) Offenses against the confidentiality, integrity and availability of computer data and systems:
x x x x
(3) Data Interference. – The intentional or reckless alteration, damaging, deletion or deterioration of computer data,
electronic document, or electronic data message, without right, including the introduction or transmission of viruses.
Petitioners claim that Section 4(a)(3) suffers from overbreadth in that, while it seeks to discourage data interference,
it intrudes into the area of protected speech and expression, creating a chilling and deterrent effect on these
guaranteed freedoms.
Under the overbreadth doctrine, a proper governmental purpose, constitutionally subject to state regulation, may not
be achieved by means that unnecessarily sweep its subject broadly, thereby invading the area of protected
freedoms.7 But Section 4(a)(3) does not encroach on these freedoms at all. It simply punishes what essentially is a
form of vandalism,8 the act of willfully destroying without right the things that belong to others, in this case their
computer data, electronic document, or electronic data message. Such act has no connection to guaranteed
freedoms. There is no freedom to destroy other people’s computer systems and private documents.
All penal laws, like the cybercrime law, have of course an inherent chilling effect, an in terrorem effect9 or the fear of
possible prosecution that hangs on the heads of citizens who are minded to step beyond the boundaries of what is
proper. But to prevent the State from legislating criminal laws because they instill such kind of fear is to render the
state powerless in addressing and penalizing socially harmful conduct.10 Here, the chilling effect that results in
paralysis is an illusion since Section 4(a)(3) clearly describes the evil that it seeks to punish and creates no
tendency to intimidate the free exercise of one’s constitutional rights.
Besides, the overbreadth challenge places on petitioners the heavy burden of proving that under no set of
circumstances will Section 4(a)(3) be valid.11 Petitioner has failed to discharge this burden.
Section 4(a)(6) of the Cybercrime Law
Section 4(a)(6) provides:
Section 4. Cybercrime Offenses. – The following acts constitute the offense of cybercrime punishable under this Act:
(a) Offenses against the confidentiality, integrity and availability of computer data and systems:
x x x x
(6) Cybersquatting. – The acquisition of domain name over the internet in bad faith to profit, mislead, destroy the
reputation, and deprive others from registering the same, if such a domain name is:
(i) Similar, identical, or confusingly similar to an existing trademark registered with the appropriate
government agency at the time of the domain name registration;
(ii) Identical or in any way similar with the name of a person other than the registrant, in case of a personal
name; and
https://lawphil.net/judjuris/juri2014/feb2014/gr_203335_2014.html
4/19