BillBuddy
Back to bill feed
HealthJusticeLocal Government
BillSBN-213920th Congress

Strengthening the Cybercrime Prevention Measures

In committee Filed May 20, 2026
◷ Where it standsIn Committee
FiledCommittee2nd Reading3rd ReadingBicamEnacted

Filed on May 20, 2026, and referred to the Committees on Science and Technology and Justice and Human Rights; it has been pending in committee since May 25, 2026, with no recorded action since then.

Should you care?
Relevance to you
Broad

The bill addresses the increasing incidents of cybercrime affecting various sectors, particularly the IT-BPM industry.

Business Process Outsourcing (BPO) companiesIT service providersCybersecurity professionalsGeneral public
Timeliness
Timely

The bill responds to a growing need for stronger cybercrime prevention measures due to increasing incidents.

Affects you ifIT-BPM companiesCybercrime victimsLaw enforcement agenciesService providersData privacy advocates
Impact assessment
AI read — verify with source
Overall impact
6.1/ 10
Long title

Strengthening the Cybercrime Prevention Measures

Plain-language summary
AI Summary

This bill aims to strengthen the Cybercrime Prevention Act of 2012 by amending various sections to enhance legal measures against cybercrime, particularly by empowering service providers to file complaints and ensuring stricter penalties for cyber offenses.

What this bill actually requires
RequiresService providers can file criminal complaints for cyber offenses affecting their data and systems.
RequiresLaw enforcement can collect traffic data in real-time with a court warrant.
PenalizesPenalties for cybercrime offenses will be one degree higher than those provided by the Revised Penal Code.
DeadlineThe Department of Information and Communications Technology (DICT) must issue implementing rules and regulations within 90 days of the Act's effectivity.
ⓘ AI-generated — verify with the source.↗ Official Senate PDF
What changes from current law

Compared with current law:

Today

Service providers have limited ability to act against cybercrime.

This bill

Service providers are empowered to file complaints for cyber offenses.

Today

Cybercrime incidents often go unreported or uninvestigated.

This bill

Complaints can be filed without prior police reports, streamlining the process.

ⓘ AI-generated comparison — verify against the bill and the cited law.
Ask this bill

The bill aims to strengthen the Cybercrime Prevention Act of 2012 by amending various sections to enhance legal measures against cybercrime, particularly by empowering service providers to file complaints.

Source · full text
Issue areas
HealthJusticeLocal GovernmentLaw enforcementCybercrime preventionData PrivacyIT-BPM SectorService Providers

✦ Dashed tags are AI-suggested nuance; solid tags follow the committee taxonomy.

Legislative history
May 20, 2026Senate
Introduced by Senator BAM AQUINO;
May 25, 2026Senate
Read on First Reading and Referred to the Committees on SCIENCE AND TECHNOLOGY and JUSTICE AND HUMAN RIGHTS;
✦ AI insight

Stalled: the bill has sat in committee for over four months with no action since its referral on May 25, 2026.

Tap a term to decode it
Floor activity

No floor deliberations yet — this measure has not reached plenary. Its committee-stage actions appear under Legislative history above.

Full text
SBN-2139 — verbatim textAs filed

Office of tire € TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES ) First Regular Session 26 MAY 20 A11 :10 SENATE RECEIVED BY: S. No. 2139 Introduced by Senator Bam Aquino AN ACT STRENGTHENING THE CYBERCRIME PREVENTION MEASURES, AMENDING FOR THE PURPOSE REPUBLIC ACT NO. 10175, OTHERWISE KNOWN AS THE "CYBERCRIME PREVENTION ACT OF 2012" EXPLANATORY NOTE The Philippines is a global leader in the Information Technology-Business Process Management (IT-BPM) industry, a sector that has contributed 8% to the Philippine GDP and employs 1.9 million of Filipinos as of 2025. This industry's competitiveness rests fundamentally on the trust, security, and reliability of its digital infrastructure. In recent years, however, the Philippines has witnessed a troubling rise in cybersecurity breaches and cybercrime incidents. In 2025 alone, the PNP Anti- Cybercrime Group recorded 10,184 cybercrime incidents, yet only 14.18% were under investigation. These incidents have resulted financial losses ranging from P414-418 million (PNP/CICC) to P5.82 billion (BSP), largely from online scams and fraudulent digital transactions. These crimes result in heavy economic costs on individual victims and erode the country's hard-earned reputation as a secure and reliable destination for global business outsourcing. Most alarmingly, perpetrators of these crimes have, with increasing frequency, evaded justice due to structural gaps in the current legal framework. The existing Cybercrime Prevention Act of 2012 (Republic Act No. 10175), while landmark in its time, was not designed to anticipate the scale, complexity, and organizational nature of modern cybercrime, nor the unique operational realities of the IT-BPM sector. To remedy this, the proposed amendments expressly grant legal standing to service providers, including IT-BPM companies, to file criminal complaints for cyber offenses affecting the data and systems they manage or process in the course of their operations. By empowering these entities to act, the bill ensures more timely prosecution of offenders, enhances deterrence, and reinforces the protection of outsourced operations. In view of the foregoing, the passage of this bill is earnestly sought. Ban Oquirr

Sentate Office of the secretary TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES ) First Regular Session MAY 20 A11:11 SENATE RECEIVED BY S. No. 2139 Introduced by Senator Bam Aquino AN ACT STRENGTHENING THE CYBERCRIME PREVENTION MEASURES, AMENDING FOR THE PURPOSE REPUBLIC ACT 10175, OTHERWISE KNOWN AS THE "CYBERCRIME PREVENTION ACT OF 2012" Be it enacted by the Senate and House of Representatives of the Philippines in Congress assembled:

Section 1. Section 3 of Republic Act No. 10175 is amended to read as follows:

"SECTION 3. Definition of Terms - For the purposes of this Act, the following 3 terms are hereby defined as follows: XXX (n) Service provider refers to: (1) Any public or private entity that provides to users of its service the ability to communicate by means of a computer system; [and] (2) Any other entity that processes or stores computer data on behalf of such 9 communication service or users of such service[.]; AND (3) ANY ENTITY CONTRACTED BY ANOTHER ENTITY, WHETHER DOMESTIC OR FOREIGN, TO PROCESS ANY DATA OR INFORMATION OF ANY PERSON WHEREVER LOCATED, INCLUDING ENTITY PROVIDING BUSINESS PROCESS OUTSOURCING AND SIMILAR SERVICES. (o) Subscriber's information refers to any information contained in the form of computer data or any other form that is held OR ACCESSED by a service provider,

1 relating to subscribers, WHETHER LOCATED IN THE PHILIPPINES OR NOT, of 2 its services other than traffic or content data by which identity can be established: (Q) IDENTIFYING INFORMATION REFERS TO ANY NAME OR NUMBER 4 THAT MAY BE USED ALONE OR IN CONJUNCTION WITH ANY OTHER 5 INFORMATION TO IDENTIFY ANY SPECIFIC INDIVIDUAL, INCLUDING ANY 6 OF THE FOLLOWING: (1) NAME, DATE OF BIRTH, DRIVER'S LICENSE NUMBER, PASSPORT 8 NUMBER, TAX IDENTIFICATION NUMBER OR OTHER GOVERNMENT- 9 ISSUED IDENTIFICATION NUMBER; (2) UNIQUE BIOMETRIC DATA, SUCH AS FINGERPRINT OR OTHER 11 UNIQUE PHYSICAL REPRESENTATION; (3) UNIQUE ELECTRONIC IDENTIFICATION NUMBER, ADDRESS, OR 13 ROUTING CODE; AND (4) TELECOMMUNICATION IDENTIFYING INFORMATION OR ACCESS DEVICE."

Sec. 2. Section 4 of the same Act is amended to read as follows:

"SECTION 4. Cybercrime Offenses. - The following acts shall constitute the 18 offense of cybercrime punishable under this Act: (a) Offenses against the confidentiality, integrity [and], availability, NON- REPUDIATION, AUTHENTICATION, PRIVACY, AND SAFETY of computer data and systems: (1) Illegal Access. - The access to the whole or any part of computer system without right. THIS SHALL INCLUDE THE INFRINGEMENT OF SECURITY MEASURES WITH THE INTENT OF OBTAINING COMPUTER DATA WITHOUT RIGHT FROM THE OWNER OR OTHER DISHONEST OR CRIMINAL INTENT OR IN RELATION TO AN COMPUTER SYSTEM THAT IS CONNECTED TO 27 ANOTHER COMPUTER SYSTEM.

(2) Illegal Interception. - INTENTIONALLY AND WITHOUT RIGHT, [T]the 2 interception, made by technical means, without right of any non-public transmission 3 of computer data TO, from, or within a computer system carrying such computer data. (3) Data Interference. - The intentional or reckless alteration, INPUTTING, 5 damaging, deletion or deterioration of computer data, electronic document, or 6 electronic data message, without right, including the introduction or transmission of 7 [viruses] MALWARE, REGARDLESS OF WHO CONTROLS OR OWNS THE 8 COMPUTER DATA. (4) System Interference. - The intentional alteration, or reckless hindering or 10 interference IN WHOLE OR IN PART, [with] OF the functioning of a computer or computer network by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing [computer data or program, electronic document, or electronic data message,] without right or authority, including the introduction or transmission of [viruses] MALWARE TO THE COMPUTER SYSTEM. 7) MALICIOUS REFUSAL TO SURRENDER COMPUTER DATA OR COMPUTER SYSTEM. - ANY PERSON WHO MALICIOUSLY AND UNLAWFULLY POSSESSES, RETAINS OR REFUSES TO SURRENDER ANY COMPUTER OR COMPUTER SYSTEM THAT CONTAINS DATA IN THE FORM OF PERSONAL INFORMATION, SENSITIVE PERSONAL INFORMATION, OR PRIVILEGED INFORMATION UNDER RA 10173 OR THE "DATA PRIVACY ACT OF 2012," TO THE LAWFUL OR RIGHTFUL OWNER OR POSSESSOR OF THE COMPUTER OR COMPUTER SYSTEM OR PROCESSOR OF SUCH DATA." (b) Computer-related Offenses: xxx (2) Computer-related Fraud. - The unauthorized input, alteration, or deletion of computer data or program or interference in the functioning of a computer system, causing ANY FORM OF damage, WHETHER DIRECT, INDIRECT, LEGAL OR

1 CONTRACTUAL, thereby with fraudulent intent: Provided, That if no damage has been caused, the penalty imposable shall be one (1) degree lower. xxx"

Sec. 3. Section 5 of the same Act is amended to read as follows:

"SECTION 5. Other Offenses. - The following acts shall also constitute an offense: (a) Aiding or Abetting in the Commission of the Cybercrime. - Any person who 8 willfully abets or aids in the commission of, OR INFLUENCES OR DECEIVES 9 ANOTHER TO COMMIT, any of the offenses enumerated in this Act shall be held 10 liable. (b) Attempt in the Commission of Cybercrime. - Any person who willfully attempts to commit any of the offenses enumerated in this Act shall be held liable. (C) FAILURE TO SURRENDER COMPUTER DATA OR COMPUTER SYSTEM. - ANY PERSON WHO KNOWINGLY AND UNLAWFULLY POSSESSES OR FAILS TO SURRENDER ANY COMPUTER SYSTEM THAT CONTAINS COMPUTER DATA THAT ARE CONSIDERED PERSONAL INFORMATION, SENSITIVE PERSONAL INFORMATION OR PRIVILEGED INFORMATION UNDER REPUBLIC ACT NO. 10173, OR THE "DATA PRIVACY ACT OF 2012," 19 SHALL BE HELD LIABLE. (D) SOLICITATION TO COMMIT CYBERCRIME. - ANY PERSON WHO WILLFULLY PROPOSES, SOLICITS, DECEIVES OR INDUCES ANOTHER PERSON TO COMMIT ANY OF THE OFFENSES UNDER THIS ACT, SHALL BE HELD LIABLE."

Sec. 4. Section 6 of the same Act is amended to read as follows:

SECTION 6. All crimes defined and penalized by the Revised Penal Code, as

amended, and special laws, if committed by, through and with use of information and communication technologies shall be covered by the relevant provisions of this Act: Provided, That the penalty to be imposed shall be one (1) degree higher than that

1 provided for by the Revised Penal Code, as amended, and special laws, as the case 2 may be. THE PROSECUTION OF THE OFFENSES UNDER THIS ACT MAY BE 4 INITIATED BY ANY OFFENDED PARTY OR ANY AFFECTED SERVICE 5 PROVIDER.

Sec. 5. A new Section 11-A shall be inserted after Section 11 of the same Act

7 to read as follows: "SECTION 11-A. FILING A COMPLAINT. - NOTWITHSTANDING ANY 9 EXISTING LAWS AND PROCEDURES, IN VIEW OF THE NATURE OF 10 CYBERCRIME, COMPLAINTS ON ANY OFFENSE PUNISHABLE UNDER THIS 11 ACT MAY BE FILED BY THE FOLLOWING: (1) PRIVATE COMPLAINANT WHICH INCLUDES ALL THE SERVICE PROVIDERS AS DEFINED IN SECTION 3(N) AS AMENDED INCLUDING THOSE PROVIDING BUSINESS PROCESS OUTSOURCING AND SIMILAR SERVICES. FILING MADE UNDER THIS SUBSECTION SHALL NOT REQUIRE ANY PREREQUISITE ACTION INCLUDING THAT THE SAME BE PRECEDED BY 17 A REPORT OR COMPLAINT FILED WITH A LAW ENFORCEMENT AGENCY; OR (2) ANY LAW ENFORCEMENT OFFICER OR A DULY AUTHORIZED REPRESENTATIVE IN CASES WHERE THE PRIVATE COMPLAINANT IS LOCATED OUTSIDE THE PHILIPPINES AND IS UNABLE TO APPEAR BEFORE THE PROSECUTOR'S OFFICE OR THE COURT."

Sec. 6. Section 12 of the same Act is amended to read as follows:

"SECTION 12. Real-Time Collection of Traffic Data. - Law enforcement authorities, with due cause, AND UPON SECURING A COURT WARRANT, shall be authorized to collect or record by technical or electronic means traffic data in real-time associated with specified communications transmitted by means of a computer system.

Traffic data refer only to the communication's origin, destination, route, time, 2 date, size, duration, or type of underlying service, but not content, nor identities. All other data to be collected or seized or disclosed SHALL LIKEWISE require 4 a court warrant.

Sec. 7. Section 13 of the same Act is amended with an addition to be read as

7 follows: A new Section 13-A shall be inserted after Section 13 of the same Act to read as follows: "SECTION 13-A. CONFIDENTIALITY IN HANDLING THIRD-PARTY DATA OR INFORMATION DURING CYBERCRIME INVESTIGATIONS AND PROCEEDINGS. - AN ENTITY ENGAGED IN THE COLLECTION, PROCESSING, HANDLING, STORAGE, OR TRANSMISSION OF PERSONAL, SENSITIVE, AND PROPRIETARY INFORMATION BELONGING TO A THIRD PARTY, INCLUDING BUT NOT LIMITED TO BUSINESS PROCESS OUTSOURCING (BPO) COMPANIES AND INFORMATION TECHNOLOGY (IT) SERVICE PROVIDERS, SHALL OBSERVE STRICT CONFIDENTIALITY OVER SUCH 17 INFORMATION, EVEN IN THE EVENT THAT SUCH DATA BECOMES RELEVANT 18 TO A CYBERCRIME INVESTIGATION OR LEGAL PROCEEDING. IN CASES WHERE A COMPLAINT OR PROSECUTION AFFECTS, INVOLVES, OR ARISES FROM THIRD-PARTY DATA OR INFORMATION AS SPECIFIED IN THE ABOVE PARAGRAPH, THERE SHALL BE A LIMITED DISCLOSURE OBLIGATION ON THE ENTITY IN POSSESSION OF SUCH DATA OR INFORMATION. NO THIRD-PARTY DATA OR INFORMATION SHALL BE REQUIRED TO BE DISCLOSED, SUBMITTED, OR REFERENCED IN ANY DOCUMENT SUBMTTED TO ANY AGENCY OR COURT WITHOUT THE EXPRESS WRITTEN CONSENT OF THE OWNER OF THE DATA OR INFORMATION. ANY DATA OR INFORMATION SUBMITTED TO LAW ENFORCEMENT AUTHORITIES OR THE COURTS SHALL BE REDACTED, ANONYMIZED, OR

1 SEALED TO PROTECT THIRD-PARTY IDENTITIES, PROPRIETARY OR 2 SENSITIVE DATA OR INFORMATION."

Sec. 8. Section 14 of the same Act is amended to read as follows:

"SECTION 14. Disclosure of Computer Data - Law enforcement authorities, 5 THROUGH A SUBPOENA OR upon securing a warrant, shall issue an order requiring 6 any person [or], service provider, OR INTERNET INTERMEDIARIES, INCLUDING 7 BUT NOT LIMITED TO SOCIAL MEDIA PLATFORMS, MESSAGING CHANNELS, 8 OR WEBSITES, to disclose or submit subscriber's information, traffic data, 9 CONTENT DATA, or ANY relevant data in his/its possession or control within 10 seventy-two (72) hours from receipt of the order in relation to a valid complaint officially docketed and assigned for investigation BEFORE THE LAW ENFORCEMENT AGENCY and the disclosure is necessary and relevant for the purpose of investigation."

Sec. 9. Section 19 of the same Act is amended to read as follows:

"SECTION 19. Restricting or Blocking Access to Computer Data. - When a computer data is prima facie found to be in violation of the provisions of this Act, the DOJ shall issue an order to restrict or block access to such computer data WITHOUT 18 PREJUDICE TO THE PRESERVATION OF AND/OR CONTINUOUS ACCESS TO 19 THE SAME BY LAW ENFORCEMENT AGENCIES AND/OR SERVICE PROVIDERS IN THE INSTANCES THAT THERE IS AN ONGOING OR AN IMPENDING INVESTIGATION BY EITHER LAW ENFORCEMENT AGENCIES OR AFFECTED SERVICE PROVIDERS."

Sec. 10. A new Section 21-A shall be inserted after Section 21 of the same Act

to read as follows: "SECTION 26-A. INITIATING THE COMPLAINT. - NOTWITHSTANDING ANY EXISTING LAWS AND PROCEDURES, IN VIEW OF THE NATURE OF CYBERCRIME, COMPLAINTS ON ANY OFFENSE PUNISHABLE UNDER THIS ACT MAY BE FILED BY THE FOLLOWING:

(1) PRIVATE COMPLAINANT; OR (2) ANY LAW ENFORCEMENT OFFICER IN CASES WHERE THE PRIVATE COMPLAINANT IS LOCATED OUTSIDE OF THE PHILIPPINES AND IS UNABLE TO APPEAR BEFORE THE PROSECUTOR'S OFFICE OR THE COURT. PRIVATE COMPLAINANT INCLUDES ALL THE SERVICE PROVIDERS AS DEFINED IN SECTION 3(R), AS AMENDED, INCLUDING THOSE PROVIDING BUSINESS PROCESS OUTSOURCING AND SIMILAR SERVICES. FILING 9 MADE UNDER THIS SUBSECTION SHALL NOT REQUIRE ANY PREREQUISITE 10 ACTION INCLUDING THAT THE SAME BE PRECEDED BY A REPORT OR 11 COMPLAINT FILED WITH A LAW ENFORCEMENT AGENCY."

Sec. 11. Implementing Rules and Regulations. - Within ninety (90) days from

13 the effectivity of this Act, the DICT, in coordination with CICC shall promulgate the necessary rules and regulations for the effective implementation of this Act.

Sec. 12. Separability Clause. - If any provision of this Act is declared

16 unconstitutional, the remainder thereof not otherwise affected shall remain in full force 17 and effect.

Sec. 13. Repealing Clause. - All laws, decrees, orders, rules, and regulations or

19 parts thereof inconsistent with this Act are hereby repealed or modified accordingly.

Sec. 14. Effectivity. - This Act shall take effect fifteen (15) days after its

publication in the Official Gazette or in a newspaper of general circulation. Approved,

Reproduced from the Senate document. The official PDF is the authoritative version.