Can IT Staff Be Prosecuted for Hiding Evidence?

Can IT Staff Be Prosecuted for Hiding Evidence?

Introduction

Employees who delete server files, destroy logs, or remove digital records to protect a company owner, executive, or supervisor may face criminal liability separate from the offense under investigation. Their employment status does not automatically shield them from prosecution.

Under Philippine criminal law, an IT employee may be charged as an accessory when, after knowing that a crime has been committed, the employee conceals or destroys the body, effects, or instruments of the crime to prevent its discovery. The employee may also face liability under special laws when the conduct involves unauthorized access, obstruction of justice, or the destruction of computer data.

What Is an Accessory to a Crime?

Article 19 of the Revised Penal Code classifies as accessories persons who, with knowledge of the commission of a crime and without having participated in it as principals or accomplices, take part in the offense after its commission.

One form of accessory liability arises when a person conceals or destroys the body of the crime, or its effects or instruments, to prevent discovery. The conduct must occur after the principal offense and must be accompanied by knowledge that a crime was committed.

The accessory must not have participated in the original offense as a principal or accomplice. If the IT employee helped commit the original crime through prior or simultaneous acts, the employee may instead be prosecuted as a principal or accomplice, depending on the evidence.

When Can an IT Employee Be Liable?

An IT employee may be prosecuted as an accessory when the prosecution can establish the following circumstances:

  • A crime was committed. There must be a principal offense, such as fraud, qualified theft, corruption, falsification, or another punishable act.
  • The employee knew that the crime had been committed. Mere technical knowledge that files were deleted is not enough; the employee must have known, or the evidence must show that the employee acted with the required criminal awareness.
  • The employee did not participate in the original crime as principal or accomplice. If the employee helped plan or execute the offense, accessory liability may not be the proper classification.
  • The employee acted after the crime. The timing of the deletion, wiping, concealment, or destruction matters.
  • The act was intended to prevent discovery or assist the offender. Accidental deletion, routine maintenance, or an authorized retention policy does not by itself establish accessory liability.

These requirements must be considered together. A system administrator who deletes logs without knowing that they relate to a crime may not be liable as an accessory. Conversely, an employee who receives instructions to wipe particular servers after learning that investigators are examining the company may face prosecution if the other elements are proven.

Deleting Servers May Constitute Destruction of Evidence

Digital evidence may include server images, access logs, emails, database records, audit trails, chat messages, backups, metadata, authentication records, and security-camera files. Deleting or altering these materials may amount to concealing or destroying the effects or instruments of a crime.

The prosecution will generally examine the employee’s authority, the timing of the deletion, the nature of the files, the instructions received, and whether the employee took steps to ensure that the data could no longer be recovered.

For example, an employee may face serious exposure where the evidence shows that the employee:

  • received notice of a pending investigation and then wiped relevant servers;
  • disabled logging or deleted access records identifying the suspected offender;
  • removed backup copies after being told to preserve company data;
  • changed retention settings to cause relevant records to be automatically erased; or
  • used privileged administrator access to conceal the deletion from auditors or investigators.

Accessory Liability Is Separate from the Boss’s Criminal Case

The employee’s liability is not merely an extension of the employer’s or boss’s case. The prosecution must prove the employee’s own acts and criminal intent.

A supervisor’s conviction is not always required before an accessory may be charged, provided that the prosecution can establish that a crime was committed and that the employee knowingly performed a subsequent act intended to conceal it. However, if no underlying crime can be established, accessory liability generally cannot stand because accessory liability presupposes a principal offense.

The employee may also be prosecuted separately even if the principal offender is unknown, has fled, or has not yet been convicted, subject to the rules governing criminal proceedings and the evidence available in the particular case.

Possible Liability Under the Cybercrime Prevention Act

The deletion of digital records may also implicate the Cybercrime Prevention Act of 2012 when the conduct involves computer data or a computer system covered by the statute.

Republic Act No. 10175 and the Rule on Cybercrime Warrants recognize procedures concerning the preservation, disclosure, search, seizure, examination, and destruction of computer data. The Rule on Cybercrime Warrants also provides that, upon motion and due hearing, a court may order the complete or partial destruction, or the return to its lawful owner or possessor, of computer data or related items in the custody of the court.

This court-supervised process is materially different from an employee’s unilateral decision to wipe or destroy company data. An IT worker cannot rely on the existence of a general data-destruction policy to justify the destruction of records that are subject to an investigation, preservation request, subpoena, or court process.

Under Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 11 February 2014, criminal provisions involving cybercrime must be applied consistently with due process and the requirement that punishable conduct be knowingly or willfully committed where the law requires that mental state. Thus, the prosecution must establish more than a technical malfunction or an unexplained loss of data.

Possible Liability for Obstruction of Justice

Depending on the facts, an employee who deletes evidence may also be exposed to liability for obstruction of justice or a related offense. The precise charge will depend on the underlying crime, the employee’s acts, the applicable statute, and whether the conduct was knowingly or willfully undertaken to impede investigation or prosecution.

The Supreme Court has recognized the importance of the mental element in offenses involving interference with criminal investigations. In Disini, Jr. v. Secretary of Justice, the Court stated that punishable non-compliance under the relevant cybercrime provision must be committed knowingly or willfully.

This means that investigators should preserve evidence showing intent, such as messages directing the deletion, the employee’s awareness of the investigation, selective rather than routine deletion, concealment of the deletion, or instructions to bypass ordinary retention procedures.

When Deletion May Not Result in Criminal Liability

Not every deletion of computer data is criminal. A person may have a defense where the deletion was accidental, authorized, unrelated to the offense, or performed in the ordinary course of business before the employee knew of any investigation.

Potentially relevant circumstances include:

  • the employee followed a documented and regularly implemented retention policy;
  • the files were deleted automatically under an established system rule;
  • the employee lacked knowledge of the crime or investigation;
  • the employee had no authority to access or alter the relevant records;
  • the data was deleted because of a genuine system failure; or
  • the employee preserved or reported the incident upon discovering the problem.

These circumstances do not automatically defeat a criminal case. Their significance depends on documentary records, system logs, witness testimony, forensic findings, and the credibility of the explanation offered.

Destroying Evidence Under Other Philippine Laws

Several laws may become relevant depending on the underlying offense and the type of records destroyed. The Revised Penal Code recognizes accessory liability for concealing or destroying the body, effects, or instruments of a crime. Special statutes may impose separate duties concerning records, confidentiality, preservation, or cooperation with authorities.

The Data Privacy Act of 2012 should not be treated as a general license to delete data whenever privacy concerns are invoked. It regulates the processing and security of personal information, but deletion must still be consistent with lawful retention duties, legitimate purposes, regulatory requirements, litigation holds, and court orders.

Section 30 of Republic Act No. 10173 penalizes the intentional or negligent concealment of a security breach involving sensitive personal information when the person knew of the breach and of the obligation to notify the National Privacy Commission under Section 20(f). The offense carries imprisonment of one year and six months to five years and a fine of P500,000 to P1,000,000.

The elements identified in In re: Commission on Elections, Smartmatic Group of Companies, RVA, and Other John Does and Jane Does, NPC SS 22-001 and NPC SS 22-008, 2022, include: a personal data breach; a breach requiring notification to the Commission; and knowing concealment of the breach from the Commission.

Accordingly, an IT employee who deletes breach-related records to conceal a reportable security incident may face a different theory of liability from an employee who destroys evidence of theft, fraud, or corruption.

Corporate Officers and Responsible Employees

Section 34 of Republic Act No. 10173 provides that, when the offender is a corporation, partnership, or juridical person, the penalty may be imposed on responsible officers who participated in the offense or, through gross negligence, allowed its commission.

This provision does not make every employee automatically liable for a corporate data-privacy offense. In In re: Wefund Lending Corporation and its Responsible Officers, NPC SS 21-006, 2021, the National Privacy Commission emphasized the need for evidence of direct participation or gross negligence before corporate officers may be held criminally responsible.

Similarly, an employee’s job title alone does not prove accessory liability. The prosecution must connect the employee to the deletion, establish the employee’s knowledge, and prove that the conduct was intended to conceal the crime, assist the offender, or prevent discovery.

How Prosecutors May Build the Case

A prosecution involving deleted servers will usually depend on digital forensics and circumstantial evidence. Investigators may examine:

  • server and firewall logs;
  • administrator accounts and privilege assignments;
  • backup schedules and deletion records;
  • email, chat, and ticketing-system communications;
  • remote-access records and authentication histories;
  • forensic images of devices used by the employee; and
  • company policies, investigation notices, and preservation instructions.

The timing of the deletion may be especially significant. A wipe performed shortly after a complaint, audit notice, search, demand for records, or communication with investigators may support an inference of deliberate concealment.

However, circumstantial evidence must form a coherent chain leading to guilt beyond reasonable doubt. Suspicion based solely on the employee’s privileged access is insufficient. The fact that an employee was the only person capable of deleting a file does not, by itself, prove that the employee did so criminally or knew of the underlying offense.

Responsibilities of IT Personnel During an Investigation

Once an employee learns that data may be relevant to an investigation, the employee should stop routine deletion affecting the relevant systems and promptly notify the designated legal, compliance, security, or data-protection officer.

IT personnel should not independently decide which records are irrelevant, should not overwrite affected devices, and should not follow informal instructions to destroy data merely because the instruction came from a superior. The employee should request written instructions and confirm whether a legal hold, preservation order, subpoena, or court warrant exists.

If data has already been deleted, the employee should immediately report the incident, preserve available logs, avoid further alteration of the system, and document what occurred. Concealing an initial mistake may create greater criminal exposure than the original accidental deletion.

Recommendations for Employers

Employers should maintain written retention and destruction policies that identify who may authorize deletion, how investigations trigger preservation holds, and how emergency system maintenance must be documented.

Companies should also separate technical access from deletion authority where possible. High-risk actions such as wiping servers, disabling logs, changing retention periods, or destroying backups should require documented approval, multi-person authorization, and an auditable record.

Training should make clear that an employee must not destroy relevant records to protect a manager, client, business partner, or the company itself. A superior’s instruction is not a defense when the employee knowingly assists in concealing a crime.

Conclusion

IT staff may face their own criminal prosecution when they knowingly delete or conceal digital evidence after a crime has been committed. The central questions are whether a crime occurred, whether the employee knew of it, whether the employee acted after the offense, and whether the deletion was intended to prevent discovery or assist the offender.

At the same time, lawful system maintenance, accidental deletion, automated retention processes, and actions taken without knowledge of the crime do not automatically establish accessory liability. Prosecutors must prove the employee’s personal participation and required criminal intent through competent evidence.

Employees should preserve potentially relevant data, report deletion incidents immediately, and seek legal guidance before acting on instructions that may affect evidence. Employers should implement documented preservation procedures, restrict destructive system privileges, and ensure that investigations are handled through coordinated legal, compliance, and cybersecurity channels.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH