Are Facebook Group Administrators Liable for Illegal Posts?

Are Facebook Group Administrators Liable for Illegal Posts?

Introduction

Facebook group administrators may face legal exposure when they knowingly permit members to publish unlawful material. The risk is greater when administrators actively approve, preserve, promote, or repeatedly ignore posts involving defamatory accusations, pirated movies, fraud, harassment, or other prohibited content.

However, Philippine law does not automatically treat every administrator as the author of every post made by a group member. Liability generally depends on the administrator’s participation, knowledge, intent, control over the content, and response after receiving notice of the alleged violation.

Are Group Administrators Automatically Liable for Members’ Posts?

Generally, no. Mere ownership or administration of a Facebook group does not, by itself, establish criminal liability for content posted by another person. The prosecution or complainant must connect the administrator to the unlawful publication or processing through evidence of authorship, participation, authorization, intentional assistance, or a legally recognized duty that was breached.

For cyber libel, the defamatory material must still satisfy the elements of libel under the Revised Penal Code. Section 6 of the Cybercrime Prevention Act may apply when an offense under the Revised Penal Code or a special law is committed through information and communications technology, subject to the statute and controlling jurisprudence. (R.A. No. 10175.)

The Supreme Court has distinguished the original author of an online defamatory statement from a person who merely reacts to, likes, or shares an existing post. In Disini, Jr. v. Secretary of Justice, the Court explained that treating ordinary reactions or sharing as aiding or abetting may create uncertainty and unconstitutional overbreadth. A comment that creates a new defamatory story, however, may constitute a separate publication. (Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 18, 2014.)

When Can an Administrator Become Secondarily Liable?

Secondary liability may become a serious issue when the administrator does more than passively maintain the group. Relevant circumstances may include the following:

  • the administrator personally created or edited the unlawful post;
  • the administrator directed or solicited the member to publish it;
  • the administrator knowingly approved or republished the material;
  • the administrator repeatedly allowed the same unlawful activity after receiving specific notice;
  • the administrator used pinned posts, announcements, paid promotions, or other tools to amplify the content; or
  • the administrator received a financial or other direct benefit from the unlawful publication.

These facts do not automatically establish liability, but they may support a finding of participation, authorization, conspiracy, or intentional assistance, depending on the offense charged and the evidence presented.

Liability for Defamatory Statements

Article 353 of the Revised Penal Code defines libel as a public and malicious imputation of a crime, vice or defect, or any act, omission, condition, status, or circumstance tending to cause dishonor, discredit, or contempt of another. The statement must be defamatory, published, directed against an identifiable person, and attended by malice unless a recognized exception applies. (Revised Penal Code, Article 353.)

Under Article 360, a person who publishes, exhibits, or causes the publication or exhibition of a defamation in writing or by similar means may be held responsible. The statute also identifies certain persons connected with newspapers and periodicals as responsible for defamatory material published in those media. (R.A. No. 4363.)

The Supreme Court has held that the statutory responsibility of editors and publishers of newspapers cannot be avoided merely by claiming lack of participation in preparing the article. That rule directly concerns the persons specifically covered by Article 360 and should not be mechanically extended to every social-media administrator. (Tulfo v. People of the Philippines, et al., G.R. No. 161032, September 16, 2008.)

In matters involving public officials or official conduct, the prosecution must establish actual malice beyond reasonable doubt. Actual malice means knowledge that the statement was false or reckless disregard of whether it was true or false. Mere offensiveness, negligence, or criticism is not enough. (Tulfo, et al. v. So, et al., G.R. Nos. 187113 and 187230, April 18, 2021; Tan v. People of the Philippines, G.R. No. 265929, 2026.)

Does Approving or Reposting a Defamatory Post Create Liability?

Approval or reposting may materially change the administrator’s position. An administrator who knowingly republishes a defamatory statement may be treated as a new publisher, particularly where the reposting is accompanied by an independent defamatory message, endorsement, or call for others to act against the subject.

By contrast, an administrator who merely fails to notice an isolated post is in a different position from one who personally selects the post, places it in an announcement, adds defamatory language, or keeps it prominently available after receiving a specific and credible complaint.

The context of the communication also matters. A private conversation or limited group may still become defamatory if the statement is communicated to third persons, and a post may reach a substantially larger audience when members share or repost it. The Supreme Court has recognized that social-media reposting can place a statement in a different context and expose it to a larger audience. (Badoy v. Magdoza-Malagar, et al., A.M. No. 22-09-16-SC and G.R. No. 263384, 2023.)

Potential Liability for Pirated Movies and Other Copyright Infringement

Administrators may face copyright-related exposure when they knowingly upload, distribute, authorize, or materially assist the unauthorized communication of copyrighted films. The risk increases where the group is created or operated specifically to exchange pirated movies, links, copies, or access credentials.

Passive administration alone does not necessarily prove direct infringement. The relevant inquiry is whether the administrator exercised meaningful control over the infringing activity, encouraged it, materially contributed to it, or intentionally continued the activity despite clear notice of infringement.

Administrators should avoid approving posts that provide unauthorized copies, download links, streaming links, screen recordings, or instructions designed to defeat copyright protection. They should also preserve evidence of takedown decisions, warnings, and notices received from copyright owners.

The available authorities do not establish a general rule that every Facebook group administrator is automatically liable for copyright violations committed by members. Liability should therefore be assessed under the specific provisions of the Intellectual Property Code, the evidence of participation, and the particular conduct attributed to the administrator.

Potential Liability Under the Data Privacy Act

Administrators may also incur liability when they collect, use, post, or disclose personal or sensitive personal information without consent or another lawful basis. Examples include publishing a member’s address, telephone number, identification document, medical information, criminal record, or private correspondence to expose or mobilize others against that person.

Section 25 of the Data Privacy Act penalizes unauthorized processing, while Section 32 addresses unauthorized disclosure. Section 33 may apply where multiple violations are committed in combination or series. (R.A. No. 10173.)

The National Privacy Commission has found that a private individual who posted another person’s personal and sensitive personal information on Facebook could be treated as a personal information controller where the individual controlled the collection, holding, processing, or use of the information. The Commission also found liability for unauthorized disclosure where the disclosure lacked consent and did not fall within the lawful-processing criteria. (NPC 20-287, 2024.)

Not every publication of personal information is unlawful. A legitimate interest may support processing in appropriate circumstances, but the processing must still satisfy the principles of transparency, legitimate purpose, proportionality, and fairness. A post that discloses more information than necessary, encourages mob action, or exposes a person to danger presents a substantial privacy risk.

Can an Administrator Be Liable for Illegal Content Despite Not Creating It?

Possibly, but not merely because the person holds an administrator title. The following factors may be relevant:

FactPossible legal significance
The administrator created the postMay establish direct authorship and publication.
The administrator approved or republished the postMay support a finding of participation or a new publication.
The administrator received a specific notice of illegalityMay show knowledge, particularly if the post remained available afterward.
The administrator pinned, promoted, or monetized the postMay support intentional assistance, control, or benefit.
The administrator promptly removed the postMay help demonstrate lack of intent and responsible response, although it does not erase an offense already completed.

These facts must be evaluated together. A single failure to remove content immediately is not equivalent to a deliberate policy of permitting unlawful material, especially where the administrator had no actual knowledge and exercised no meaningful control over the post.

What Should Administrators Do After Receiving Notice?

Administrators should adopt and consistently enforce written group rules prohibiting defamatory accusations presented as fact, copyright infringement, threats, harassment, doxxing, fraud, sexual exploitation material, and unlawful disclosure of personal information.

Upon receiving a credible complaint, the administrator should:

  1. record the date, identity of the complainant, post URL, screenshots, and relevant group activity;
  2. temporarily restrict or remove the disputed material where the complaint appears substantial;
  3. avoid editing the evidence in a way that may create uncertainty about its original form;
  4. notify the poster of the applicable rule and request an explanation when appropriate;
  5. preserve relevant records subject to privacy and lawful-disclosure requirements; and
  6. refer serious threats, child exploitation material, extortion, fraud, or imminent danger to the proper authorities.

Administrators should not encourage members to engage in vigilantism, publish private information, threaten the subject, or coordinate harassment. A group that becomes a platform for mob action may expose its administrators and active participants to separate criminal, civil, and administrative consequences.

Special Concern: Child Sexual Abuse Material

Content involving child sexual abuse or exploitation presents a distinct and substantially more serious category of risk. R.A. No. 11930 imposes duties on internet intermediaries and other private-sector entities concerning the prevention, reporting, blocking, and preservation of evidence involving online sexual abuse or exploitation of children and child sexual abuse or exploitation materials.

The implementing rules require internet intermediaries to prohibit streaming or live-streaming of covered material, preserve specified subscriber and traffic data within prescribed periods, and comply with lawful requests from competent authorities. For subscriber or traffic data, the ordinary preservation period is six months, extendible for another six months or during the pendency of the case; content data generally has a one-year period, subject to the conditions stated in the law and implementing rules. (R.A. No. 11930; IRR of R.A. No. 11930.)

An ordinary Facebook group administrator is not automatically an “internet intermediary” merely because the person manages a group. Nevertheless, knowingly storing, approving, forwarding, or promoting unlawful child-abuse material may expose the individual to liability under applicable criminal laws. Such material should never be downloaded, copied, forwarded, or retained except as lawfully required for reporting and investigation.

Possible Civil and Administrative Consequences

Even when criminal liability cannot be established, an affected person may pursue civil remedies for injury to reputation, privacy, property, or other protected interests. A person may also seek injunctive relief, damages, or other remedies depending on the cause of action and the evidence.

Lawyers who administer or use social-media groups may face professional discipline for abusive, malicious, obscene, deceptive, or privacy-violating conduct. The Code of Professional Responsibility and Accountability prohibits lawyers from creating or operating fraudulent social-media accounts to conceal identity or circumvent the law or the Code. (Code of Professional Responsibility and Accountability, A.M. No. 22-09-01-SC.)

Practical Risk Assessment

A group administrator’s legal risk is generally higher when the administrator has actual notice, exercises editorial control, personally participates in publication, benefits from the activity, or maintains a group whose principal purpose is unlawful distribution.

The risk is generally lower when the administrator has no participation in the post, applies neutral rules consistently, responds promptly to specific complaints, avoids republication, and maintains reasonable records of moderation decisions. These circumstances do not create immunity, but they may be important evidence concerning intent, participation, and diligence.

Conclusion

Facebook group administrators are not automatically liable for every unlawful post made by a member. Philippine law ordinarily requires proof connecting the administrator to the publication, processing, distribution, authorization, or intentional assistance involved in the alleged violation.

Administrators should therefore treat moderation as a legal-risk function rather than merely a technical privilege. Clear rules, consistent enforcement, prompt action after notice, careful handling of personal information, and immediate reporting of serious criminal content can reduce exposure while protecting members and affected persons.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH