How Can Companies Obtain IP Disclosure Warrants?
Introduction
Corporate fraud investigations increasingly depend on identifying the person behind an IP address, online account, email address, or other digital trace. Internet service providers, however, generally cannot be compelled to disclose subscriber information or traffic data merely because a company or its counsel requests it.
In the Philippines, the usual procedure is to secure a Warrant to Disclose Computer Data (WDCD) through law enforcement authorities and an issuing court. This procedure is governed principally by the Cybercrime Prevention Act of 2012, Republic Act No. 10175, and the Supreme Court’s Rules on Cybercrime Warrants.
What Is a Warrant to Disclose Computer Data?
A WDCD is a written court order, issued in the name of the People of the Philippines and signed by a judge, authorizing law enforcement authorities to require a person or service provider to disclose or submit subscriber information, traffic data, or other relevant computer data in its possession or control.
The warrant is designed to obtain identifying or connection-related information. In a corporate fraud investigation, this may include the subscriber associated with a suspected IP address, account registration details, contact information, and other data that may identify the person who accessed or used a computer system.
The warrant does not automatically authorize a search of the provider’s systems for every type of information. The data sought must be particularly described, relevant, and necessary to the investigation.
What Philippine Laws Govern the Procedure?
Republic Act No. 10175, or the Cybercrime Prevention Act of 2012, permits law enforcement authorities, after securing a court warrant, to issue an order requiring a person or service provider to disclose subscriber information, traffic data, or relevant data. The disclosure must relate to a valid complaint officially docketed and assigned for investigation, and must be necessary and relevant to the investigation.
The Act also provides the statutory basis for the search, seizure, and examination of computer data. Those powers are distinct from a WDCD because they concern the acquisition and forensic examination of stored computer systems or data rather than the compelled disclosure of information held by a service provider.
The Supreme Court’s Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, prescribe the application requirements, warrant forms, implementation procedures, returns, and custody rules for cybercrime warrants.
Who May Apply for the Warrant?
A corporate lawyer cannot ordinarily apply for and serve a WDCD as a private litigant on the company’s own authority. The application must be made by an authorized law enforcement officer in connection with an investigation of a probable cybercrime or another offense committed through or involving information and communications technology.
Corporate counsel may assist the company in preserving evidence, preparing a complaint, identifying the relevant digital records, and coordinating with the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, or another competent law enforcement agency.
The company should provide law enforcement with a coherent evidentiary package rather than a general request for an investigation. This normally includes the incident timeline, affected systems, relevant logs, suspected IP addresses, account identifiers, screenshots, access records, internal investigation findings, and affidavits of persons with personal knowledge.
What Must the Application Establish?
The verified application and supporting affidavits for a WDCD must state the essential facts supporting the requested disclosure. Under the Rules on Cybercrime Warrants, the application should identify:
- The probable offense involved;
- The relevance and necessity of the requested computer data or subscriber information;
- The persons or entities whose data are sought, including those with possession, control, or access to the data, if known;
- A particular description of the computer data or subscriber information sought;
- The place where the disclosure will be enforced, if available;
- The manner or method of disclosure, if available; and
- Other facts persuading the court that probable cause exists to issue the warrant.
The application must do more than state that fraud occurred. It should explain the connection between the suspected offense, the IP address or online account, the provider holding the information, and the information expected to identify or help locate the suspect.
How Should Suspect IP Addresses Be Described?
An IP address should be described with as much precision as the available records permit. The application should identify the IP address, the relevant date and time, the time zone, the source of the record, the affected system or account, and the activity associated with the address.
Where available, counsel should include the applicable port number, protocol, server or application accessed, login identifier, transaction reference, and the precise time interval. These details are important because an IP address may be dynamically assigned, shared by several users, or associated with a network address translation system.
A request phrased simply as “all information about the user of the IP address” may be challenged as insufficiently particular. A more focused request may seek the subscriber information, registration records, contact details, and relevant connection or traffic data associated with a specified IP address during a defined period.
What Information May Be Requested?
Depending on the facts and the provider’s records, the application may request:
- Subscriber name and account registration information;
- Installation or billing address;
- Telephone number and email address;
- Verification or identification records submitted during registration;
- IP address allocation records;
- Connection dates and times;
- Port and session information, when maintained by the provider; and
- Other specifically identified data relevant to the investigation.
The requested material must remain within the court’s authority and the provider’s possession or control. A WDCD should not be used as a substitute for a general discovery demand or an unrestricted search for evidence.
What Are the Probable-Cause Requirements?
The court must determine whether there are reasonable grounds to believe that a cybercrime or another ICT-related offense has been committed, is being committed, or is about to be committed. The application must also show that the data sought is essential or materially relevant to the investigation and that the requested disclosure is supported by specific facts.
The application should identify the offense by its legal elements and relate those elements to the evidence. For example, in an alleged unauthorized-access incident, the application should explain the system affected, the access that was unauthorized, the date and time of the access, the relevant digital records, and why the provider’s information may identify the person responsible.
Evidence that merely shows that an IP address was connected to an incident may not, by itself, prove who personally committed the fraud. An IP address is an investigative lead, not necessarily conclusive proof of identity. The company should therefore request the disclosure as part of a broader investigation involving device, account, payment, access-control, and witness evidence.
What Is the Required Disclosure Process?
After obtaining the WDCD, law enforcement authorities issue an order to the person or service provider identified in the warrant. Under Section 14 of Republic Act No. 10175, the provider is required to disclose or submit the specified data within seventy-two hours from receipt of the order, provided that the request relates to a valid complaint officially docketed and assigned for investigation and that the disclosure is necessary and relevant.
The order should match the warrant. It should not expand the description of the information, persons, accounts, or period stated in the court-issued authority.
Corporate counsel should coordinate with law enforcement regarding service, proof of receipt, the provider’s response, and the preservation of the original records. The production should be documented carefully to support authenticity and admissibility in any later criminal, civil, administrative, or employment proceeding.
Should Preservation Be Requested Before Disclosure?
Yes. Digital records may be overwritten, deleted, or altered under ordinary retention practices. Law enforcement may request an internet service provider to preserve and maintain the integrity of computer data that is the subject of an investigation.
Under the 2022 Revised Rules and Regulations Implementing Republic Act No. 9208, subscriber information and traffic data must be preserved by an internet service provider for a minimum of six months from the date of the transaction. Content data must be preserved for six months from receipt of the preservation order. A law enforcement officer may order a one-time extension for another six months.
Where preserved data is used as evidence in a case, the provider’s receipt of the transmittal document to the Office of the Prosecutor is treated as notification to preserve the data further until final termination of the case or until otherwise ordered by the court. Although these preservation provisions arise in the anti-trafficking context, they illustrate the importance of issuing a prompt, documented preservation request in a digital investigation.
How Does a WDCD Differ From Other Cybercrime Warrants?
| Warrant | Primary purpose |
|---|---|
| Warrant to Disclose Computer Data | Compels disclosure of subscriber information, traffic data, or other specified data held by a person or service provider. |
| Warrant to Intercept Computer Data | Authorizes listening to, recording, monitoring, or surveillance of communications or computer data while the communication is occurring. |
| Warrant to Search, Seize, and Examine Computer Data | Authorizes the search, seizure, and examination of specified computer data or related items. |
| Warrant to Examine Computer Data | Authorizes examination of data in a computer device or system lawfully acquired through a warrantless arrest or another lawful method. |
The correct warrant depends on where the evidence is located and what investigators need to do with it. A WDCD is generally appropriate when the immediate objective is to identify the subscriber or account associated with an IP address or service account. A search-and-seizure warrant may be necessary when investigators need to acquire and examine a suspect’s device or stored data.
What If the Service Provider Is Outside the Philippines?
For a person or service provider located outside the Philippines, service of warrants and other court processes under the Rules on Cybercrime Warrants must be coursed through the Department of Justice Office of Cybercrime, subject to relevant international instruments and agreements.
Corporate counsel should identify the provider’s legal entity, principal place of business, Philippine representative, data location, and available law-enforcement or judicial cooperation channel at the earliest stage. A domestic service attempt may be ineffective if the provider is legally situated abroad.
Can a Bank Be Compelled to Disclose Account-Holder Information?
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court held that Republic Act No. 10175 did not expressly or impliedly repeal the Bank Secrecy Law. The decision nevertheless recognized that a bank may be treated as a service provider for purposes of disclosing basic identifying information under a valid WDCD in a cybercrime investigation.
The ruling distinguishes identifying information from the financial details of bank deposits. A valid warrant may support disclosure of information such as the account holder’s name, address, contact details, verification identification, and related identifying data, but it does not automatically authorize unrestricted disclosure of protected deposit information.
Corporate counsel should therefore state precisely what information is sought and avoid combining an identity request with a broad demand for transaction or deposit records unless a separate legal basis and appropriate court authority exist.
Common Errors in Corporate Applications
- Applying as a private party without law enforcement participation. A company’s counsel should coordinate with a competent investigative agency rather than attempt to serve a private demand as though it were a WDCD.
- Requesting data without a defined time period. The application should identify the relevant date and time range, including the applicable time zone.
- Failing to identify the probable offense. The application must connect the facts to a legally recognized offense.
- Using an IP address as conclusive proof of identity. Shared networks, dynamic assignments, proxies, virtual private networks, and compromised devices may affect attribution.
- Ignoring preservation. A disclosure request may fail if the provider no longer retains the relevant records.
Recommended Workflow for Corporate Counsel
- Contain the incident. Secure affected systems, disable compromised credentials where appropriate, and prevent further unauthorized access without destroying relevant evidence.
- Preserve original records. Collect server logs, authentication records, email headers, access-control records, endpoint images, and related materials using documented procedures.
- Prepare a technical timeline. Identify the IP address, account, device, transaction, system, date, time, and activity associated with the suspected fraud.
- Assess the probable offense. Determine whether the facts may involve unauthorized access, computer-related fraud, identity theft, offenses under special laws, or another crime committed through ICT.
- Coordinate with law enforcement. Submit a complaint and supporting affidavits to the appropriate cybercrime investigative agency.
- Request immediate preservation. Ask investigators to preserve the provider’s relevant records while the warrant application is prepared.
- Review the proposed application. Confirm that the data, provider, IP address, time period, offense, and investigative purpose are specifically and consistently described.
- Track service and production. Record when the provider receives the order, monitor the seventy-two-hour disclosure period, and preserve the production package and chain-of-custody documents.
Final Observations
A WDCD is a focused judicial tool for obtaining information held by an internet service provider. It is not a general corporate discovery mechanism, and a private company cannot ordinarily compel disclosure simply by sending a demand letter.
The strongest application combines a properly documented incident, a specific probable offense, a precise description of the requested data, a defined time period, and a clear explanation of why the provider’s records are necessary and relevant. Counsel should also address preservation, provider location, data integrity, and the distinction between subscriber identification and more protected categories of information.
Because digital evidence can disappear quickly, companies should preserve records immediately, coordinate promptly with law enforcement, and seek the appropriate cybercrime warrant before the relevant provider data becomes unavailable.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

