Can OMB Raids Stop Enterprise Software Piracy?
Introduction
Businesses using unlicensed enterprise software may face civil, administrative, and criminal consequences in the Philippines. Foreign software developers can support enforcement by documenting ownership, licensing restrictions, suspected unauthorized installations, and the facts showing that counterfeit software was reproduced, distributed, or used commercially.
However, an Optical Media Board (OMB) raid is not automatically the proper remedy for every software-license violation. The OMB’s authority is principally directed at the mastering, manufacture, replication, importation, exportation, possession, sale, and distribution of optical media and related equipment or materials. A business merely using unauthorized software on computers, without an optical-media component, may instead require enforcement through the Intellectual Property Code, the Cybercrime Prevention Act, civil proceedings, or a properly supported criminal complaint.
What the Optical Media Board Regulates
Republic Act No. 9239, or the Optical Media Act of 2003, authorizes the OMB to regulate and license persons and entities engaged in the mastering, manufacture, or replication of optical media. The OMB may also inspect covered establishments, apply for search warrants, place optical media and related equipment in preventive custody, and act as complainant in criminal prosecutions.
The OMB may conduct inspections, with or without prior notice, of establishments—including those in economic zones—that engage in activities covered by the law. Its agents are considered agents of persons in authority for purposes of inspection and enforcement. The OMB may employ reasonable force when an establishment’s responsible persons evade, obstruct, or refuse a lawful inspection. Republic Act No. 9239 [RA 9239 (2004)](#L1.11).
The OMB also has authority to hear administrative cases and impose sanctions, including fines, confiscation, suspension or cancellation of licenses, and closure of establishments. It may issue subpoenas and subpoenas duces tecum, require the production of records and samples, and require regulated entities to preserve complete business records for at least five years. Republic Act No. 9239 [RA 9239 (2004)](#L1.12).
When Software Piracy Falls Within an OMB Raid
An OMB operation is most directly justified when the alleged piracy involves physical optical media or optical-media production. Examples include counterfeit software CD-ROMs, unauthorized software installers reproduced on discs, equipment used to replicate discs, packaging and labels, source-identification-code violations, and records showing the commercial manufacture or distribution of unauthorized copies.
Under Republic Act No. 9239, a person may incur criminal liability for engaging in the mastering, manufacture, replication, importation, or exportation of optical media without the required OMB license. Liability may also arise from reproducing intellectual property on optical media for commercial gain without the copyright owner’s authority or from manufacturing optical media without the required Source Identification (SID) Code.
The absence of the required SID Code is prima facie evidence that the optical media violates the statute. The use of a false, unauthorized, or another person’s SID Code is separately punishable. The basic penalties include imprisonment of three to six years and a fine of P500,000 to P1,500,000 for several violations under Section 19(a), while other offenses carry lower penalty ranges. Subsequent offenses under the statute carry increased penalties, including six to nine years’ imprisonment and fines of P1,500,000 to P3,000,000 for offenses under Section 19(a). Republic Act No. 9239 [RA 9239 (2004)](#L1.22).
By contrast, an office that simply installs an unauthorized enterprise application on its computers may not be engaged in the optical-media activities regulated by the OMB. That conduct may still constitute copyright infringement or cybercrime, but the legal basis for an OMB raid must be established by facts connecting the suspected conduct to optical media or to an OMB-regulated activity.
Applicable Copyright and Cybercrime Laws
Republic Act No. 8293, or the Intellectual Property Code of the Philippines, as amended by Republic Act No. 10372, protects computer programs as copyrighted works and provides civil, administrative, and criminal remedies for infringement. Unauthorized reproduction, adaptation, distribution, or commercial use may be actionable depending on the license terms, the acts proved, and the applicable statutory provisions.
Republic Act No. 10175, or the Cybercrime Prevention Act of 2012, also addresses the unauthorized use, production, sale, procurement, importation, distribution, or making available of a computer program without the right to do so. The Department of Information and Communications Technology has reiterated these risks in its government software-compliance rules. Department Circular No. HRA-008, Series of 2025 [Department Circular No. HRA-008, Series of 2025](#I1.0).
The legal theory should therefore match the conduct. Physical counterfeit discs and replication equipment may support OMB action. Unauthorized installations, unauthorized network deployment, altered license controls, and unlawful distribution of digital installers may require copyright, cybercrime, civil, or other criminal remedies, with the OMB involved only when its statutory jurisdiction is factually established.
What Foreign Software Developers Must Establish
A foreign software developer should prepare evidence addressing five points:
- Ownership or authority: documents showing ownership of the copyright, trademark, or software rights, or authority to act for the rights holder;
- License restrictions: enterprise license agreements, subscription terms, user limits, device limits, geographic restrictions, and prohibitions against copying or redistribution;
- Unauthorized conduct: technical findings showing unlicensed installations, duplicate product identifiers, unauthorized installers, circumvention, or distribution;
- Commercial connection: evidence that the software was used, copied, sold, distributed, or reproduced for business or commercial purposes; and
- Location and preservation: reliable information identifying the premises, devices, servers, optical media, records, and persons connected with the suspected acts.
In NBI–Microsoft Corporation and Lotus Development Corporation v. Hwang, the Supreme Court recognized that counterfeit software installers may constitute infringement even if the alleged copier or distributor claims to be a licensee. The Court also held that contractual disputes do not necessarily prevent the filing or investigation of a criminal complaint where the facts independently show unauthorized copying or distribution. NBI–Microsoft Corporation and Lotus Development Corporation v. Hwang, G.R. No. 147043, 21 June 2005 [NBI–Microsoft Corporation and Lotus Development Corporation v. Hwang (2005)](#J2.16).
The same decision illustrates why investigators should distinguish genuine software acquired through an authorized channel from counterfeit installers that the rights holder could not have authorized. Evidence that a business purchased a genuine product does not authorize it to reproduce that product or distribute unauthorized installation media.
Coordinating With the OMB
Coordination should begin before any request for inspection or search-warrant assistance. The foreign developer or its Philippine representative should provide the OMB with a written referral containing the suspected premises, the identity of the business and responsible officers, the software titles involved, the alleged acts, the licensing terms, the source of the information, and the reason the matter falls within optical-media regulation.
The referral should clearly separate facts within OMB jurisdiction from facts that may require action by the National Bureau of Investigation, Philippine National Police, prosecutors, the Intellectual Property Office, or the courts. An allegation that “unlicensed software was found” is not by itself enough to establish that the establishment is manufacturing or distributing optical media.
Where physical media are involved, the rights holder should identify whether the discs are genuine, counterfeit, unauthorized installers, or copies containing software beyond the scope of the license. It should also explain the significance of packaging, labels, SID Codes, serial numbers, product identifiers, and other technical indicators.
Search Warrants and Probable Cause
An OMB inspection and a judicial search warrant are different procedures. A warrant requires probable cause personally determined by a judge after examination under oath of the applicant and witnesses. The warrant must particularly describe the place to be searched and the things to be seized.
In Microsoft Corporation v. Maxicorp, Inc., the Supreme Court held that a warrant must particularly describe the premises and property subject to seizure. A defect affecting some items does not necessarily invalidate the entire warrant; evidence seized under the properly described portions may remain admissible, while items covered only by an invalidly broad description may be excluded. Microsoft Corporation v. Maxicorp, Inc., G.R. No. 140946, 13 September 2004 [Microsoft Corporation v. Maxicorp, Inc. (2004)](#J3.12).
Similarly, Columbia Pictures, Inc. v. Flores emphasized that a warrant cannot authorize the indiscriminate seizure of equipment and business materials that may also be used for legitimate purposes. The application should identify the specific copyrighted works, media, equipment, documents, or other items connected to the suspected offense. Columbia Pictures, Inc. v. Flores, G.R. No. 78631, 18 June 1993 [Columbia Pictures, Inc. v. Flores (1993)](#J5.4).
Earlier decisions involving master tapes should not be mechanically applied to every software case. In Columbia Pictures, Inc. v. Court of Appeals, the Court recognized that later-developed evidentiary requirements could not be applied retroactively to invalidate a warrant issued under the law and jurisprudence existing at the time. The case also stressed that a Videogram Regulatory Board license did not immunize a business from copyright or criminal liability. Columbia Pictures, Inc. v. Court of Appeals, G.R. No. 110318, 14 September 1996 [Columbia Pictures, Inc. v. Court of Appeals (1996)](#J1.49).
Evidence From Enterprise Computer Systems
Enterprise piracy investigations commonly depend on technical evidence rather than physical discs. Investigators may examine product identifiers, installation counts, license servers, deployment records, activation logs, software inventories, purchase documents, and network-access data, subject to lawful access and applicable privacy and procedural requirements.
In Microsoft Corporation, et al. v. Farajallah, et al., investigators relied on repeated product-identification patterns across computers as an indication that one installer had been used on multiple devices. Such technical observations may support probable cause when explained by competent witnesses and corroborated by other facts. Microsoft Corporation, et al. v. Farajallah, et al., G.R. No. 205800, 18 November 2014 [Microsoft Corporation, et al. v. Farajallah, et al. (2014)](#J4.3).
Technical evidence should be preserved through a documented chain of custody. Investigators should record the date and time of acquisition, the device or account examined, the method used, the identity of the person who collected the data, and any hash values or forensic safeguards applied. A rights holder should avoid altering, deleting, or remotely disabling suspected installations in a manner that could compromise evidence or disrupt a lawful investigation.
Limits on Raids and Seizures
An enforcement operation should not become a general search for every computer, server, document, or device in a business. The objects sought must be tied to the offense under investigation, and the warrant or lawful inspection authority must support the seizure.
For example, a warrant directed at counterfeit software CD-ROMs may not automatically authorize the seizure of every workstation used by employees. A computer may be seizable if it is particularly described and supported by probable cause showing that it was used to reproduce, store, distribute, or otherwise facilitate the offense. The same principle applies to accounting records, network devices, and servers.
Businesses should be given no less protection merely because the investigation concerns intellectual property. Rights holders and enforcement agencies must comply with constitutional search-and-seizure requirements, procedural rules, and the limits of the authority invoked.
Common Enforcement Scenarios
Counterfeit installation discs. If a business sells or distributes unauthorized software discs, the matter may directly implicate the Optical Media Act and the Intellectual Property Code. The OMB may inspect, seize relevant media and equipment, and pursue administrative or criminal remedies when the statutory elements are supported.
Unauthorized office-wide deployment. If a company installed enterprise software beyond the number of authorized users or devices, the matter may primarily involve copyright infringement, breach of license, or cybercrime. An OMB raid would require additional facts showing optical-media manufacture, replication, or distribution.
Unauthorized software reseller. A reseller that supplies genuine software through an authorized channel may have a different legal position from one that creates counterfeit installers. Evidence of the reseller’s authority, the source of the copies, and the contents of the distributed media is essential.
Government software use. Executive-branch offices are prohibited from using unlicensed software under Department Circular No. HRA-008, Series of 2025, and must submit annual software-compliance reports to the DICT on or before 31 January, or on the succeeding working day when the deadline falls on a weekend. Violations may result in administrative and criminal liability under the Administrative Code, the Intellectual Property Code, the Cybercrime Prevention Act, civil-service rules, and other applicable laws. Department Circular No. HRA-008, Series of 2025 [Department Circular No. HRA-008, Series of 2025](#I1.10).
Recommended Enforcement Plan
- Confirm the rights holder’s authority. Prepare copyright ownership records, certificates, assignments, powers of attorney, and documents authorizing the Philippine representative to act.
- Audit the suspected conduct lawfully. Collect license records, technical findings, purchase documents, and witness statements without unauthorized access or evidence tampering.
- Classify the violation. Determine whether the conduct involves optical-media manufacture or distribution, unauthorized software use, copyright infringement, cybercrime, trademark infringement, or several offenses.
- Refer the matter to the proper agency. Coordinate with the OMB for optical-media violations and with the NBI, PNP, IPO, prosecutors, or courts for matters outside the OMB’s statutory reach.
- Prepare a particularized warrant application when necessary. Identify the premises, software, media, equipment, records, and devices sought, and explain the factual basis for probable cause as to each category.
- Preserve evidence and business continuity. Use forensic procedures, maintain chain-of-custody records, and avoid requesting seizure of items that are not reasonably connected to the suspected offense.
Conclusion
Foreign software developers can play an important role in shutting down businesses that reproduce or distribute unauthorized enterprise applications. The strongest cases combine clear licensing evidence, technically reliable findings, proof of commercial activity, and coordination with the agency that has jurisdiction over the specific conduct.
The OMB is particularly relevant when piracy involves optical media, replication equipment, counterfeit installers, or related manufacturing and distribution activities. When the alleged violation consists only of unauthorized digital installation or enterprise use, the developer should not assume that an OMB raid is the correct first remedy. A carefully classified complaint and a particularized, evidence-based enforcement request are more likely to withstand judicial and administrative scrutiny.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

