Republic Act 10175, the Cybercrime Prevention Act of 2012, is the foundation of Philippine cybercrime law. It defines offences, designates enforcement agencies, and sets penalties. This lesson summarises the parts an engineer or system owner must know.
Offences Defined In RA 10175
Section
Offence
Examples
Sec. 4(a)(1)
Illegal Access
Logging in without authority
Sec. 4(a)(2)
Illegal Interception
Sniffing private traffic
Sec. 4(a)(3)
Data Interference
Altering, deleting data without right
Sec. 4(a)(4)
System Interference
DoS, ransomware against a system
Sec. 4(a)(5)
Misuse of Devices
Producing, possessing tools to commit above
Sec. 4(a)(6)
Cyber-squatting
Bad-faith domain registration
Sec. 4(b)(1)
Computer-related Forgery
Forged digital documents
Sec. 4(b)(2)
Computer-related Fraud
Phishing, payment fraud
Sec. 4(b)(3)
Computer-related Identity Theft
Impersonation, account takeover
Sec. 4(c)(1)
Cybersex
Lascivious exhibition for favour or consideration
Sec. 4(c)(2)
Child Pornography
Aligned with RA 9775
Sec. 4(c)(3)
Unsolicited Commercial
Spam, with safe-harbour for opt-out
Sec. 4(c)(4)
Online Libel
Defamation online (constitutionally narrowed)
Enforcement Roles
Agency
Role
DOJ - Office of Cybercrime
Central authority, MLAT requests
NBI - Cybercrime Division
Investigation, digital forensics
PNP - Anti-Cybercrime Group
First response, public complaints
DICT - CICC
Cybercrime Investigation and Coordinating Center
BSP, NPC, SEC
Sector regulators for finance, privacy, securities
Penalty Snapshot
Offence Class
Penalty Range
Sec. 4(a) - Confidentiality, integrity, availability
Prision mayor or fine PHP 200K-500K
Sec. 4(b) - Computer-related
One degree higher than analog crime
Sec. 4(c) - Content
Per existing laws plus one degree higher when via ICT
Aiding, abetting
Same penalty as principal
What Engineers Should Do
Keep authentication logs and retain them as evidence (DPA-compliant).
Preserve volatile evidence (RAM, sessions) when an incident is suspected.
Coordinate with legal before contacting NBI or PNP-ACG.
Build chain-of-custody documentation into your incident playbook.
Discussion
Loading…