How Should Companies Revoke Access During Layoffs?
Introduction
Corporate layoffs create an immediate risk to company-owned social media accounts, advertising platforms, cloud storage, email systems, customer databases, and other digital assets. A departing employee may still possess passwords, active sessions, recovery credentials, administrator privileges, or access through a personal device.
The company should therefore treat access revocation as both an employment-transition measure and an information-security control. The objective is to prevent unauthorized posting, deletion, account takeover, disclosure of personal information, or disruption of business operations while preserving evidence and respecting the employee’s legal rights.
Access should be removed through a documented, coordinated process involving human resources, management, information technology, information security, and, where appropriate, legal counsel.
Who Owns the Social Media Account?
The first step is to identify whether the account is a company asset or an employee’s personal account. A corporate social media page, advertising account, business manager, branded email address, customer database, and company-issued credential will generally be treated as business resources when created, maintained, or used for the employer’s operations.
The National Privacy Commission has recognized that company-issued credentials used for regulated business activities may be treated as company assets rather than as the former employee’s personal information. Continued use may also be justified by the company’s legitimate interests, subject to the requirements of the Data Privacy Act and its implementing rules. This does not, however, authorize unlimited access to personal accounts or unrelated private information.
In [NPC 19-278 (2022)](#I2.1), the Commission addressed the treatment of company-issued credentials and recognized that legitimate interest may support continued use of business credentials in appropriate circumstances.
What Should the Company Do Immediately?
Before informing the employee of the separation, the company should prepare an access-revocation checklist and identify every system connected to the employee’s work. The process should be coordinated so that disabling one account does not leave another account exposed.
The company should immediately consider the following measures:
- Disable the employee’s corporate email and identity-provider account.
- Revoke administrator, editor, moderator, advertising, billing, and developer privileges.
- Terminate active sessions and invalidate authentication tokens.
- Reset passwords for shared accounts and remove the employee’s recovery email and telephone number.
- Revoke access to social media management platforms, cloud storage, customer relationship systems, and messaging tools.
- Remove personal devices from approved-device lists and revoke application access.
Password changes alone may be insufficient. A departing user may remain logged in through an active browser session, mobile application, API token, single sign-on session, password manager, or recovery mechanism.
How Should Social Media Administrator Access Be Revoked?
The company should first ensure that at least two authorized officers or employees retain full administrative control. It should then remove the departing employee from the following roles, where applicable:
- Full administrator and page owner;
- Content editor, moderator, analyst, or advertiser;
- Business manager and payment administrator;
- Developer, API, or automation user;
- Account recovery contact; and
- External agency or social media management account.
After revocation, the company should review scheduled posts, automated replies, connected applications, active advertisements, payment instruments, domain verification settings, and linked pages. Unknown applications and unused administrator accounts should be removed.
The company should also confirm that the account’s recovery email address, telephone number, two-factor authentication device, backup codes, and password-reset contacts are controlled by the company rather than by an individual employee.
What Evidence Should Be Preserved?
Companies should preserve an access-revocation record showing the date and time of each action, the person who approved it, the system affected, the access removed, and any suspicious activity observed. Relevant logs may include login history, administrator changes, deleted content, scheduled posts, direct messages, file downloads, and changes to recovery credentials.
Evidence should be preserved before accounts are deleted or systems are reconfigured. The company should avoid altering, opening, or examining personal accounts and devices beyond the authority granted by law, company policy, consent, or a valid court order.
For criminal investigations, the preservation, disclosure, search, seizure, examination, custody, and destruction of computer data are subject to the applicable requirements of the Cybercrime Prevention Act and the Rule on Cybercrime Warrants. The rule includes procedures for preserving computer data and restricts the opening or use of deposited computer data as evidence unless the court grants the appropriate motion.
The Supreme Court in [Disini, Jr., et al. v. The Secretary of Justice, et al. (2014)](#J1.68) upheld several provisions concerning the preservation, disclosure, search, examination, and destruction of computer data while invalidating provisions that failed constitutional safeguards. The Court’s ruling confirms that cyber-investigation powers must be exercised consistently with due process, privacy, and other protected rights.
Under Section 17 of the Cybercrime Prevention Act, computer data subject to preservation and examination must be destroyed after the periods prescribed by law. A company should therefore seek legal advice promptly if it believes that relevant data may be needed for litigation or investigation.
Can the Company Inspect a Former Employee’s Device?
Inspection depends on ownership, company policy, consent, the nature of the device, and the scope of the investigation. A company-issued device may be subject to company security controls and monitoring policies, but this does not mean that every file or communication may be examined without limitation.
The Supreme Court has recognized, in the context of a government-issued computer and an administrative proceeding, that a government employee may have no reasonable expectation of privacy in files or communications stored on government property when applicable computer-use policies authorize monitoring. In [Office of the Court Administrator v. Reyes (2023)](#J2.59), the Court also recognized the relevance of the government’s computer-use policy and the admissibility of evidence obtained from government property in the circumstances presented.
That ruling should not be treated as blanket authority to inspect a departing employee’s personal telephone, personal email, private social media account, or unrelated cloud storage. The company should limit any inspection to company property, company data, and the purpose authorized by policy or law.
How Does Data Privacy Law Apply?
Social media accounts may contain personal information involving employees, customers, suppliers, and other individuals. The company must therefore ensure that access revocation, investigation, preservation, and disclosure are carried out for a legitimate purpose and only to the extent necessary.
Processing should observe transparency, legitimate purpose, and proportionality. A company should not collect or circulate an employee’s personal information merely because the employee is leaving. It should also avoid publishing allegations of misconduct or personal details unless there is a lawful basis and a justified business or legal purpose.
In [JBA v. FNT and NNT, NPC 20-026 (2022)](#I1.38), the National Privacy Commission ruled that continued posting of a former agent’s personal information in online advertisements after the withdrawal of consent constituted unauthorized processing. The Commission further stated that the responsible party could not avoid responsibility merely by blaming a deceased staff member and should have taken steps to stop further processing.
The decision illustrates an important operational rule: responsibility for an account or publication may continue even when the employee who originally created or managed it is no longer available. The company should maintain control over its accounts and act promptly when the purpose or authority for processing ends.
What If the Departing Employee Uses a Personal Account?
The company should distinguish between a personal account and a company account used through a personal device. An employee’s personal device does not automatically convert the employee’s private account into company property, but the use of a personal device does not necessarily make company accounts private.
If a company page is accessed through the employee’s personal telephone, the company should revoke the page role, terminate sessions, reset corporate credentials, and remove the device from company systems. It should not demand access to unrelated personal messages, photographs, contacts, or private accounts unless a lawful and clearly defined basis exists.
Where ownership is disputed, the company should preserve relevant records, review employment agreements and social media policies, and obtain legal advice before taking coercive action or making public accusations.
What If the Employee Creates a False or Anonymous Account?
The company should document the account, preserve publicly available evidence, and avoid retaliatory conduct. It should not attempt unauthorized access, impersonation, password guessing, or covert surveillance.
For lawyers, the Code of Professional Responsibility and Accountability prohibits the creation, maintenance, or operation of a social media account designed to hide identity for the purpose of circumventing the law or the Code. Section 39 of the [Code of Professional Responsibility and Accountability (2023)](#L2.45) is particularly relevant when the departing person is a lawyer or when counsel is advising a lawyer’s professional social media activity.
For court officials and personnel, the 2025 Code of Conduct and Accountability for Court Officials and Personnel contains a similar prohibition against fraudulent social media accounts. This rule applies specifically to court officials and personnel and should not be extended indiscriminately to private-sector employees.
What Preventive Controls Should Companies Adopt?
Companies should not rely on one employee’s personal credentials for control of an important business account. A better system assigns access through role-based accounts, maintains at least two authorized administrators, and requires approval for high-risk changes.
| Control | Purpose |
|---|---|
| Role-based access | Limits each user to the functions required for the job. |
| Multi-factor authentication | Reduces the risk that a stolen password will be sufficient for access. |
| Centralized password management | Allows the company to change shared credentials without relying on one employee. |
| Access reviews | Identifies former employees, inactive users, and unnecessary privileges. |
| Activity logging | Supports investigation and accountability when unauthorized changes occur. |
| Separation checklist | Ensures that HR, IT, security, and management complete coordinated actions. |
Employment contracts, confidentiality agreements, acceptable-use policies, and social media policies should state that company accounts, content, credentials, customer information, and business records remain subject to company control. Policies should also explain monitoring practices, permitted use of company systems, return of company property, and the consequences of unauthorized access.
What Should Happen When Sabotage Is Suspected?
If the company observes unauthorized posts, deletion of content, alteration of recovery credentials, suspicious downloads, or attempts to lock out administrators, it should first contain the incident. This may include disabling the suspected account, preserving logs, securing payment and advertising accounts, and preventing further publication.
The company should designate one person to coordinate communications and one person to preserve evidence. Screenshots alone may be insufficient; the company should preserve timestamps, account identifiers, audit logs, emails, platform notices, and relevant system records in a manner that supports authentication.
Where the facts indicate possible cybercrime, unauthorized access, data theft, fraud, or disclosure of personal information, the company should consult counsel before making a criminal complaint or contacting the platform. The Rule on Cybercrime Warrants provides specialized procedures for cybercrime-related preservation, disclosure, interception, search, seizure, examination, and custody of computer data.
Companies should not use self-help measures that could themselves constitute unauthorized access, data alteration, unlawful interception, or improper disclosure. The fact that an employee is under investigation does not eliminate the need for lawful procedure.
Can the Company Block or Remove Online Content?
A company may request removal of content from a platform when it owns the account or when the content violates the platform’s rules, contractual rights, intellectual property rights, confidentiality obligations, or applicable law. It should preserve the content and relevant account information before requesting deletion when litigation or investigation is reasonably foreseeable.
Section 19 of the Cybercrime Prevention Act authorizes the Department of Justice to issue an order restricting or blocking access to computer data that is prima facie found to violate the Act. In [Disini, Jr., et al. v. The Secretary of Justice, et al. (2014)](#J1.75), the Supreme Court declared the provision unconstitutional because it granted the executive branch power to restrict access without adequate judicial safeguards.
Accordingly, a private company should not assume that it may compel the blocking of online content through its own unilateral order. It should use platform procedures, seek appropriate judicial relief, or coordinate with the proper government authority when the facts justify official intervention.
Recommended Layoff-Day Procedure
A company can use the following sequence for a controlled separation:
- Confirm the effective date and time of separation.
- Identify every account, device, credential, application, and physical asset assigned to the employee.
- Preserve relevant logs and records before making major changes.
- Disable identity-provider, email, VPN, cloud, messaging, and business-system access.
- Remove social media roles and terminate active sessions.
- Change shared passwords and recovery credentials.
- Review scheduled content, advertisements, connected applications, billing details, and administrator changes.
- Collect company devices and secure company data.
- Document each action, including the responsible person and completion time.
- Escalate suspected unauthorized access, data exposure, or sabotage to counsel and the appropriate authorities.
Final Observations
Revoking administrator access during a corporate layoff is not limited to changing a password. It requires coordinated action over identities, sessions, recovery methods, devices, applications, scheduled content, payment systems, and evidence.
The company should act quickly but within lawful limits. It should protect corporate assets, preserve potentially relevant data, respect privacy, avoid unauthorized access to personal information, and use court or government processes when formal cyber-investigation measures are required.
A written access-control policy, periodic administrator review, multi-factor authentication, centralized credential management, and a tested separation checklist can substantially reduce the risk of account takeover and digital sabotage.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

