Section 9. Corporate Liability. — When any of the punishable acts herein defined are knowingly
committed on behalf of or for the benefit of a juridical person, by a natural person acting either
individually or as part of an organ of the juridical person, who has a leading position within, based on:
(a) a power of representation of the juridical person provided the act committed falls within the scope of
such authority; (b) an authority to take decisions on behalf of the juridical person: Provided, That the
act committed falls within the scope of such authority; or (c) an authority to exercise control within the
juridical person, the juridical person shall be held liable for a fine equivalent to at least double the fines
imposable in Section 7 up to a maximum of Ten million pesos (PhP10,000,000.00).
If the commission of any of the punishable acts herein defined was made possible due to the lack of
supervision or control by a natural person referred to and described in the preceding paragraph, for the
benefit of that juridical person by a natural person acting under its authority, the juridical person shall
be held liable for a fine equivalent to at least double the fines imposable in Section 7 up to a maximum
of Five million pesos (PhP5,000,000.00).
The liability imposed on the juridical person shall be without prejudice to the criminal liability of the
natural person who has committed the offense.
CHAPTER IV
ENFORCEMENT AND IMPLEMENTATION
Section 10. Law Enforcement Authorities. — The National Bureau of Investigation (NBI) and the
Philippine National Police (PNP) shall be responsible for the efficient and effective law enforcement of
the provisions of this Act. The NBI and the PNP shall organize a cybercrime unit or center manned by
special investigators to exclusively handle cases involving violations of this Act.
Section 11. Duties of Law Enforcement Authorities. — To ensure that the technical nature of
cybercrime and its prevention is given focus and considering the procedures involved for international
cooperation, law enforcement authorities specifically the computer or technology crime divisions or
units responsible for the investigation of cybercrimes are required to submit timely and regular reports
including pre-operation, post-operation and investigation results and such other documents as may be
required to the Department of Justice (DOJ) for review and monitoring.
Section 12. Real-Time Collection of Traffic Data. — Law enforcement authorities, with due cause, shall
be authorized to collect or record by technical or electronic means traffic data in real-time associated
with specified communications transmitted by means of a computer system.
Traffic data refer only to the communication’s origin, destination, route, time, date, size, duration, or
type of underlying service, but not content, nor identities.
All other data to be collected or seized or disclosed will require a court warrant.
Service providers are required to cooperate and assist law enforcement authorities in the collection or
recording of the above-stated information.
The court warrant required under this section shall only be issued or granted upon written application
and the examination under oath or affirmation of the applicant and the witnesses he may produce and
the showing: (1) that there are reasonable grounds to believe that any of the crimes enumerated
hereinabove has been committed, or is being committed, or is about to be committed: (2) that there are
reasonable grounds to believe that evidence that will be obtained is essential to the conviction of any