How Are Corporate Computer Data Warrants Obtained?

How Are Corporate Computer Data Warrants Obtained?

Introduction

When law enforcement investigates a cybercrime involving a company, the seizure of laptops, servers, mobile devices, and storage media can affect business operations, confidential records, personal data, and legally protected communications. A search of corporate equipment is therefore not automatically valid merely because the devices are owned by a company or are located in its office.

Philippine law requires law enforcement authorities to comply with constitutional search-and-seizure standards, the Cybercrime Prevention Act of 2012, and the Supreme Court’s Rules on Cybercrime Warrants. The warrant must be supported by probable cause, must particularly describe the place and computer data involved, and must be implemented according to prescribed procedures for forensic imaging, examination, returns, custody, and preservation.

Governing Philippine Laws and Rules

The principal statute is R.A. No. 10175, or the Cybercrime Prevention Act of 2012. Section 15 authorizes law enforcement authorities, after a valid search and seizure warrant has been issued, to secure a computer system or storage medium, copy and preserve computer data, conduct forensic examination, and render data inaccessible or remove it when authorized by law.

The procedure is principally governed by the Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, approved in 2018. The Rules provide specialized procedures for disclosure, interception, search, seizure, examination, custody, and destruction of computer data.

In Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014, the Supreme Court upheld the basic validity of Section 15 of R.A. No. 10175. The Court explained that the provision supplements, rather than replaces, existing search-and-seizure procedures and is intended to ensure the proper collection, preservation, and use of computer data obtained under a court warrant.

What Warrant Is Required?

The appropriate warrant depends on what law enforcement intends to obtain and how the computer data will be accessed.

WarrantPrimary purpose
Warrant to Disclose Computer DataRequires a person or service provider to disclose subscriber information, traffic data, or other computer data in its possession or control.
Warrant to Intercept Computer DataAuthorizes the listening to, recording, monitoring, or surveillance of communications or computer data while the communication is occurring.
Warrant to Search, Seize, and Examine Computer DataAuthorizes the search of a specified place and the seizure and examination of identified computer devices, systems, storage media, or related items.
Warrant to Examine Computer DataAuthorizes forensic examination of a computer device or system that law enforcement has already acquired through a lawful warrantless arrest or another lawful method.

A company laptop already lawfully seized is not thereby open to unlimited examination. Before searching the data contained in that device, law enforcement must generally obtain a Warrant to Examine Computer Data, unless another recognized legal basis authorizes the examination.

Probable Cause and Judicial Issuance

A cybercrime warrant must be issued by a judge upon a finding of probable cause. The application must identify the offense being investigated and must establish a sufficient connection between the alleged offense, the place or device to be searched, and the computer data or items sought.

The warrant cannot authorize a general search of all corporate information without meaningful limits. Its description should identify, as specifically as reasonably possible, the relevant company, office, server, account, device, storage medium, user, data category, date range, or other circumstances that define the permitted search.

Corporate ownership does not eliminate the requirement of particularity. A company may own the laptop or server, but the device may contain employee communications, customer records, trade secrets, privileged material, financial information, or personal data belonging to individuals who are not accused of any offense.

Scope of a Warrant for Corporate Devices

A Warrant to Search, Seize, and Examine Computer Data authorizes law enforcement to search the particular place described in the warrant and to seize or examine the items identified in the order. The warrant may also authorize related activities permitted under Section 6.5 of the Rules on Cybercrime Warrants.

During implementation, law enforcement may require a person who understands the computer system and its protective measures to provide information reasonably necessary to conduct the search, seizure, and examination. This authority must remain connected to the execution of the warrant and does not create an unlimited power to compel unrelated disclosures.

Section 15 of R.A. No. 10175 permits law enforcement, pursuant to a properly issued search-and-seizure warrant, to:

  • secure a computer system or storage medium;
  • make and retain a copy of secured computer data;
  • maintain the integrity of relevant stored computer data;
  • conduct forensic analysis or examination; and
  • render data inaccessible or remove it when legally authorized.

On-Site and Off-Site Searches

The Rules on Cybercrime Warrants instruct law enforcement, when circumstances permit, to make a forensic image of the computer data on-site and to limit the search to the location identified in the warrant.

An off-site search may be conducted when justified by the circumstances. In that event, law enforcement should still make a forensic image, and the reasons for conducting the search off-site must be stated in the initial return.

A person whose computer devices or system were seized off-site may move for their return after a forensic image has been made. The issuing court may order the return when no lawful ground exists to continue withholding the devices.

Interception During Search and Examination

Interception may be conducted during the implementation of a Warrant to Search, Seize, and Examine Computer Data when authorized by law. However, the intercepted communications or computer data must be reasonably related to the subject matter of the warrant.

The interception must also be fully disclosed in the initial return. Law enforcement must explain the relationship between the intercepted material and the computer data identified in the warrant. Interception cannot be used as a basis for expanding the search into unrelated communications or information.

Initial Return and Required Information

Within 10 days from the issuance of the Warrant to Search, Seize, and Examine Computer Data, the authorized law enforcement officers must submit an initial return containing prescribed information.

The initial return should include:

  • a detailed list of all seized items, including device names, makes, brands, serial numbers, or other identifying information;
  • the hash value of the computer data, device, or system, when available;
  • whether a forensic image was made on-site or off-site;
  • the reasons for conducting an off-site forensic imaging or search;
  • whether interception occurred during implementation;
  • the intercepted data’s hash values and its relation to the warrant’s subject matter;
  • all actions taken from arrival at the premises until the items were secured for examination; and
  • a reasonable estimate of the time required to complete the examination, together with its justification.

These requirements create an audit trail. They allow the issuing court to determine whether the warrant was implemented within its permitted scope and whether the seized data remained intact.

Time Limits for Examination

Section 15 of R.A. No. 10175 allows law enforcement to request an extension to complete the examination and make the return. The extension may not exceed 30 days from the date of court approval.

The applicable warrant and the Rules on Cybercrime Warrants also govern the submission of the final return and the turnover of custody. Law enforcement should not treat the initial seizure as authority to retain and examine devices indefinitely.

Custody and Deposit of Computer Data

Under Section 16 of R.A. No. 10175, computer data examined under a proper warrant must be deposited with the court in a sealed package within 48 hours after the expiration of the period fixed in the warrant.

The deposit must be accompanied by an affidavit stating, among other matters, the dates and times covered by the examination and the law enforcement authority who may access the deposit. The executing officer must also certify that no duplicates or copies of the whole or any part of the data were made, or that any copies made are included in the sealed package, subject to specific statutory rules.

The sealed package may not be opened, the recordings replayed, or the contents used or disclosed except upon court order. The order is issued only upon motion, with notice and an opportunity to be heard by the person or persons whose conversations or communications were recorded.

Forensic Imaging, Hash Values, and Integrity

A forensic image is a bit-for-bit copy of computer data made for examination while preserving the original evidence. Hash values help establish whether the data or device has been altered because a change in the underlying data ordinarily produces a different hash value.

The Rules on Cybercrime Warrants require the initial return to identify relevant hash values and to explain whether forensic imaging was performed on-site or off-site. These details are important in later challenges involving authenticity, alteration, chain of custody, and the reliability of the examination.

Corporate Privacy and Personal Data

Corporate devices may contain personal information of employees, customers, suppliers, applicants, and other individuals. The existence of a cybercrime warrant does not remove the obligation to observe the warrant’s limits and other applicable privacy safeguards.

The National Privacy Commission has emphasized the importance of reasonable and appropriate organizational, physical, and technical safeguards. In In re: Department of Trade and Industry and Department of Trade and Industry–Rizal Provincial Office, NPC BN 18-220 and NPC BN 18-231, the Commission considered measures such as password protection, encryption, secure storage of external drives, and cloud-based storage in assessing an organization’s security practices.

Accordingly, a company facing a search should identify potentially sensitive or privileged material, preserve relevant evidence, prevent unauthorized alteration or deletion, and promptly coordinate with counsel and its data protection officer. These measures should not obstruct a lawful search or conceal evidence.

When a Warrantless Seizure May Be Relevant

The Rules on Cybercrime Warrants recognize that a computer device or system may first come into law enforcement custody through a lawful warrantless arrest or another lawful method. In that situation, law enforcement must still obtain a Warrant to Examine Computer Data before searching the device for forensic purposes.

The legality of the initial acquisition of the device and the legality of the subsequent examination are separate questions. A lawful seizure does not automatically authorize a forensic search of every file, account, application, or communication stored in the device.

Special Rule for OSAEC and CSAEM Investigations

For cases involving online sexual abuse or exploitation of children and child sexual abuse or exploitation materials, R.A. No. 11930 contains a special rule. Section 17 authorizes law enforcement agencies, when a cybercrime warrant has been issued, to retain a copy of the result of digital forensic examinations for identifying additional victims and suspects, conducting further investigation and case build-up, and referring information to foreign law enforcement authorities when the crime has a nexus abroad.

The 2023 IRR of R.A. No. 11930 similarly provides that the application for cyber warrants is governed by A.M. No. 17-11-03-SC. It also requires law enforcement to certify, when depositing the digital forensic examination with the court, that a duplicate copy was made and retained under the special statutory authority.

This exception is limited to the statutory purposes and circumstances identified in the law. It should not be treated as a general exception applicable to every cybercrime investigation involving a company’s computer systems.

Typical Corporate Investigation Scenarios

Company laptop assigned to an employee. If investigators lawfully seize the laptop, they should obtain a Warrant to Examine Computer Data before conducting a forensic examination. The examination should be confined to data reasonably related to the offense identified in the warrant.

Server located in a company office. A search of the server should be supported by a warrant particularly identifying the place, server, accounts, or data sought. If the server contains unrelated business records, the search should not become a general review of the company’s entire operations.

Cloud-based corporate account. If the relevant data is controlled by a service provider, law enforcement may need a Warrant to Disclose Computer Data or another appropriate warrant, depending on whether the objective is disclosure, interception, or examination of data already acquired.

Device voluntarily surrendered by an employee. Voluntary surrender may affect the legality of the initial acquisition, but it does not necessarily authorize an unrestricted forensic examination. The applicable warrant and the circumstances of consent must still be examined.

What Companies Should Do During a Search

  • Request and review the warrant without physically resisting its implementation.
  • Record the identities of the officers, the devices taken, and the time and location of the search.
  • Designate a company representative and coordinate through counsel.
  • Ask that seized devices and storage media be specifically identified in the inventory or return.
  • Preserve relevant logs, backups, access records, and security footage.
  • Notify the data protection officer when personal data may have been accessed or compromised.
  • Document any apparent search beyond the warrant’s stated scope and raise the issue before the issuing court.

Company personnel should not delete files, disable systems, destroy devices, alter logs, or instruct employees to conceal information. Such conduct may create separate legal exposure and may undermine legitimate objections to an overbroad or irregular search.

Legal Remedies for an Improper Search

A party affected by the search may challenge the warrant, its implementation, the scope of the examination, the sufficiency of the returns, the chain of custody, or the admissibility and authenticity of the resulting evidence.

Possible issues include lack of probable cause, inadequate description of the data or place to be searched, examination beyond the warrant’s limits, failure to observe the 10-day initial-return period, failure to comply with the 48-hour deposit requirement after expiration of the warrant period, or failure to preserve the integrity of the evidence.

The proper remedy depends on the procedural posture of the case and the particular defect. Counsel should examine the warrant application, affidavits, issued warrant, inventory, initial and final returns, forensic reports, hash values, custody records, and court orders concerning extensions or access to deposited data.

Conclusion

Obtaining and implementing a warrant for corporate computer data requires more than a general allegation that a company device may contain evidence. Law enforcement must establish probable cause, secure the appropriate cybercrime warrant, identify the place and data with sufficient particularity, observe on-site or off-site forensic procedures, submit timely returns, preserve data integrity, and comply with the rules on custody and court deposit.

Companies should prepare for these situations through written incident-response procedures, access controls, encryption, secure backups, evidence-preservation protocols, and coordination among management, counsel, information-technology personnel, and the data protection officer. When a search occurs, the company should cooperate lawfully while documenting compliance with the warrant and promptly raising any objection through the issuing court.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH