How Is Digital Traffic Data Preserved by Philippine Telcos?

How Is Digital Traffic Data Preserved by Philippine Telcos?

Introduction

Digital traffic data can help identify the origin, destination, route, timing, duration, size, and type of an online communication. In cybercrime investigations, this information may connect a device, subscriber, or account to a particular digital activity.

Philippine telecommunications companies and other service providers are subject to statutory data-preservation duties. The general rule requires the integrity of traffic data and subscriber information to be preserved for at least six months from the date of the transaction. However, preservation is different from disclosure: a telecommunications company may be required to retain data without being permitted to release it unless the legal requirements for disclosure are satisfied.

What Is Digital Traffic Data?

Under the Cybercrime Prevention Act of 2012, traffic data refers to computer data other than the content of a communication. It includes the communication’s origin, destination, route, time, date, size, duration, and type of underlying service.

Traffic data therefore concerns the circumstances or metadata of a communication rather than the substance of the message itself. For example, a record showing that a subscriber’s device connected to a particular internet address at a specified time may constitute traffic data, while the text of an email or the contents of a chat message constitutes content data.

The distinction is material because traffic data, subscriber information, and content data are subject to different preservation and disclosure rules. The Supreme Court recognized these categories in Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014.

What Does the Six-Month Preservation Rule Require?

Section 13 of the Cybercrime Prevention Act of 2012 requires the integrity of traffic data and subscriber information relating to communication services to be preserved for a minimum of six months from the date of the transaction.

Content data is preserved for six months from the date the service provider receives the order from law enforcement authorities requiring its preservation. The distinction means that the starting point for traffic data and subscriber information is generally the transaction date, while the starting point for content data is receipt of the preservation order.

The service provider must also keep the preservation order and its compliance confidential. The statutory rule is reproduced in the Cybercrime Prevention Act of 2012, Republic Act No. 10175.

Can the Six-Month Period Be Extended?

Yes. Law enforcement authorities may order a one-time extension for another six months. Thus, the ordinary statutory period may reach twelve months when the extension is properly issued.

A further preservation consequence applies when the preserved, transmitted, or stored computer data is used as evidence in a case. Once that occurs, furnishing the service provider with the transmittal document to the Office of the Prosecutor is deemed notice to preserve the computer data until the termination of the case.

The resulting period is not limited to the original six-month period or its one-time extension. Preservation continues until the case terminates, subject to any court order applicable to the evidence.

What Must Telecommunications Companies Preserve?

The statutory preservation duty generally covers:

  • subscriber information;
  • traffic data relating to communications services;
  • content data when a preservation order is received; and
  • the integrity of the preserved computer data.

Subscriber information may include information held by a service provider that identifies the subscriber, the communication service used, the period of service, the subscriber’s address, telephone or access number, assigned network address, and available billing or payment information, subject to the applicable legal definitions and limitations.

Preservation does not necessarily require a telecommunications company to monitor every user or inspect the content of every communication. The preservation obligation concerns data already in the provider’s possession or control and does not, by itself, authorize unrestricted surveillance.

Is Preservation the Same as Disclosure?

No. Preservation protects the existence and integrity of data; disclosure releases specified data to law enforcement or another authorized recipient.

Under Section 14 of the Cybercrime Prevention Act of 2012, law enforcement authorities must first secure a court warrant before issuing an order requiring a person or service provider to disclose or submit subscriber information, traffic data, or relevant data in its possession or control.

The disclosure order must relate to a valid complaint that has been officially docketed and assigned for investigation. The disclosure must also be necessary and relevant to the investigation. Upon receipt of the order, the person or service provider is generally required to disclose or submit the specified data within seventy-two hours.

The Supreme Court explained in Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014, that disclosure under Section 14 involves the enforcement of a duly issued court warrant. Judicial intervention is required before the specified computer data may be disclosed.

Is a Subpoena Sufficient to Obtain Traffic Data?

Ordinarily, a subpoena alone is not the proper substitute for the court warrant required by the Cybercrime Prevention Act. The statutory procedure requires a warrant to disclose computer data, commonly referred to as a WDCD, before law enforcement may issue the disclosure order to the telecommunications company.

In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court described the general rule as requiring a court-issued warrant for the collection, seizure, or disclosure of data in a cybercrime investigation. The warrant application must establish reasonable grounds to believe that a cybercrime has been committed, is being committed, or is about to be committed; that the evidence sought is essential to the investigation, solution, or prevention of the offense; and that no other readily available means can obtain the evidence.

Accordingly, a request for traffic data should not be treated as an ordinary discovery demand. The requesting authority must identify the legal basis, the investigation, the data sought, and the reasons the data is necessary and relevant.

What Procedural Safeguards Apply?

The Rules on Cybercrime Warrants, A.M. No. 17-11-3-SC, prescribe specialized procedures for warrants involving the disclosure, search, seizure, and examination of computer data.

For disclosure, the request should be tied to a valid and officially docketed complaint. The data sought must be identified with sufficient specificity, and the requesting authority must show its relevance and necessity to the investigation.

The order should not be used as a general demand for all information about a subscriber or all communications passing through a telecommunications system. The scope should correspond to the offense under investigation, the relevant account or device, and the applicable period.

What Happens When the Data Is Used as Evidence?

When preserved computer data is transmitted to the Office of the Prosecutor and used as evidence, the provider’s receipt of the transmittal document serves as notification to continue preserving the data until the case ends or the court orders otherwise.

This continuing duty is important in cybercrime litigation because digital evidence may be challenged on grounds of authenticity, completeness, chain of custody, or alteration. The provider should maintain records showing when the data was preserved, how it was stored, who accessed it, and when it was transmitted.

The Rules on Cybercrime Warrants, A.M. No. 17-11-3-SC, also recognize the importance of protecting the integrity of electronic evidence and permit the court, upon motion and due hearing and for justifiable reasons, to order the complete or partial destruction or return of computer data and related items in the court’s custody.

How Is Traffic Data Used in a Cybercrime Trial?

Traffic data may help establish a connection between a subscriber, device, account, network address, and relevant time period. It may corroborate testimony, authenticate digital activity, identify a possible route of communication, or assist investigators in narrowing the source of an online transaction.

Traffic data does not automatically prove who personally operated a device or account. A subscriber may share an internet connection, use a public network, operate through a virtual private network, or have an account compromised by another person. The prosecution must therefore connect the traffic records with other competent evidence.

Typical corroborating evidence may include device examination results, account records, platform logs, payment records, witness testimony, admissions, security-camera footage, and proof that the accused exercised control over the relevant device or account.

What Should a Law Enforcement Request Identify?

A proper request should, at minimum, clearly identify:

  • the cybercrime or suspected offense under investigation;
  • the officially docketed complaint or investigation reference;
  • the subscriber, account, device, telephone number, or network address involved;
  • the specific traffic data or subscriber information sought;
  • the relevant date and time range;
  • why the data is necessary and relevant; and
  • the applicable warrant and preservation authority.

Overbroad requests create risks of privacy violations, evidentiary objections, and challenges to the validity of the disclosure. The request should be limited to what is reasonably connected to the investigation.

What Should Telecommunications Companies Do Upon Receiving a Request?

A telecommunications company should verify the issuing authority, the legal process served, the covered account or data, the period involved, and the response deadline. It should preserve the requested data without altering the original records and should document its internal handling of the request.

The company should also maintain confidentiality as required by the Cybercrime Prevention Act of 2012. Disclosure should be limited to the data specified in the valid process and should be made through a documented and secure procedure.

If the request is defective, excessively broad, unclear, or unsupported by the required court process, the provider should seek clarification or appropriate legal relief rather than voluntarily disclose unrelated subscriber or traffic information.

Are There Special Preservation Rules for Certain Offenses?

Yes. The general six-month rule under Republic Act No. 10175 is not the only preservation period that may apply. Special statutes may prescribe different periods for particular offenses or categories of data.

For cases involving online sexual abuse or exploitation of children, Republic Act No. 11930 requires internet intermediaries to preserve subscriber or registration information and traffic data for six months, extendible for another six months or during the pendency of the case. Content data is subject to a one-year preservation period, with a possible additional six-month extension upon notice by the competent authority.

For trafficking-related investigations, Republic Act No. 11862 requires the preservation and protection of the integrity of subscriber or registrant information and traffic data for one year from the date of the transaction. Upon notice from the Department of Justice, the Philippine National Police, the National Bureau of Investigation, or the DICT-Cybercrime Investigation and Coordinating Council, preservation may be extended for another year when necessary.

When more than one law may apply, counsel should identify the offense charged, the type of data involved, the provider’s legal classification, and the applicable special statute. The specific law governing the investigation may prescribe a longer period or additional duties.

What Are the Main Legal Risks?

The first risk is confusing preservation with disclosure. A provider may have a duty to retain data but still require a valid court warrant before releasing it.

The second risk is treating subscriber identity as conclusive proof of authorship. Subscriber or traffic records must be assessed together with other evidence showing control, access, and actual use.

The third risk is failing to preserve the original data and its integrity. Altered, incomplete, or poorly documented records may face objections concerning authenticity and reliability.

The fourth risk is overlooking special statutes. OSAEC, CSAEM, trafficking, and terrorism investigations may involve different preservation periods, procedures, or duties.

Practical Checklist for Counsel

  • Determine whether the request concerns subscriber information, traffic data, or content data.
  • Identify the applicable statute and preservation period.
  • Check whether a valid court warrant is required for disclosure.
  • Confirm that the complaint is officially docketed and assigned for investigation.
  • Review whether the request states why the data is necessary and relevant.
  • Preserve records concerning integrity, access, transmission, and chain of custody.
  • Test whether the records establish actual user identity, not merely subscriber registration.

Conclusion

Philippine telecommunications companies generally must preserve the integrity of traffic data and subscriber information for at least six months from the date of the transaction under Republic Act No. 10175. A one-time six-month extension may be ordered, and preservation may continue until the end of the case when the data is used as evidence and the provider receives the required transmittal notice.

That duty does not authorize automatic disclosure. Law enforcement must ordinarily obtain a court warrant, relate the request to a valid officially docketed complaint, establish necessity and relevance, and follow the procedures governing cybercrime warrants. Counsel should also examine special statutes that impose longer or different preservation periods.

For litigation purposes, traffic data is valuable corroborating evidence, but it should not be treated as conclusive proof that a particular subscriber personally committed the online act. Its evidentiary weight depends on authentication, integrity, chain of custody, lawful acquisition, and corroboration by other evidence.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH