Direct answer: Under Philippine law, DICT leads national ICT and cybersecurity policy, while CICC coordinates cybercrime prevention and participating agencies. Neither has a general police power merely because an incident involves computers. Republic Act No. 10175 expressly makes the NBI and PNP responsible for cybercrime law enforcement. Republic Act No. 10844 later attached CICC to DICT, transferred national cybersecurity planning and CERT functions to DICT, and made the DICT Secretary CICC chair. A search, data disclosure, interception or blocking action needs its own valid legal basis. RA 10175 §§10, 24–26; RA 10844 §15(b).
Evidence and action
- Rule: NBI and PNP enforce RA 10175; DICT and CICC have distinct statutory policy and coordination roles.
- Qualification: A valid warrant or a separate, specific law can authorize a particular action. Check the exact authority and scope.
- Risk and evidence: Preserve the written request, issuing officer’s details, docket reference, warrant, requested data and your response record.
- Timing: No universal response period applies to every request. RA 10175 §14’s 72-hour period runs from receipt of a disclosure order that law enforcement issues after securing a court warrant; §13 separately requires service providers to preserve traffic data and subscriber information for at least six months from the transaction.
- Next step: Verify the requesting office independently. Route criminal complaints to NBI or PNP; assess NPC obligations separately for personal data. See what to do next.
Who has which role in a cybercrime case?
| Body | What the law assigns | What does not follow automatically |
|---|---|---|
| DICT | ICT policy, cybersecurity planning, government security functions and national CERT under RA 10844. | General arrest, criminal search or prosecution powers. |
| CICC | Coordinate prevention and suppression, monitor participating agencies’ cases, seek government assistance and develop capacity under RA 10175 §§24–26, read with RA 10844 §15(b). | Independent authority to search a device, compel private data or convict a suspect. |
| NBI and PNP | Law enforcement under RA 10175 §10 through dedicated cybercrime units. | Freedom from applicable warrants, court rules and constitutional safeguards. |
| DOJ and courts | DOJ receives law-enforcement reports for review and monitoring (§11); its Office of Cybercrime is the central authority for international mutual assistance (§23). Courts issue applicable warrants. | DOJ cannot invoke RA 10175 §19’s invalidated administrative blocking power. |
| NPC | Data Privacy Act oversight in its jurisdiction. | Transfer of its privacy mandate to DICT simply because it is attached for coordination. |
How did RA 10844 change CICC’s powers?
RA 10175 §26 originally gave CICC national cybersecurity planning, immediate CERT assistance, cybercrime coordination, case monitoring, international cooperation, public-private participation, recommendations and capacity building. The later DICT Act, RA 10844 §15(b) (approved May 23, 2016), attached CICC to DICT for policy and program coordination while retaining its functions under its own law so far as consistent. It specifically transferred all powers and functions related to cybersecurity, including the National Cybersecurity Plan, the National CERT and international cooperation on cybersecurity intelligence, to DICT. It also designated the DICT Secretary as CICC chair. Reading only the 2012 list without this 2016 change gives readers the wrong present-day division of responsibilities.
What are the legal limits of DICT and CICC?
Neither agency’s name creates an independent search or arrest power
RA 10175 §10 identifies NBI and PNP as the law-enforcement authorities. Sections 14–16 address disclosure, search, examination and court custody of computer data; these are not blanket permission for a coordinating body to take a device or obtain a person’s private messages. An agency may provide technical help, and an officer seconded from NBI or PNP may act under that officer’s actual legal authority. The request still needs the correct statutory and, where required, judicial basis. Read RA 10175 Chapter IV.
A preservation request is different from disclosure
Section 13 addresses preservation of traffic data and subscriber information by service providers. Section 14 lets law enforcement, upon securing a court warrant, order disclosure within 72 hours, in relation to a valid complaint officially docketed and assigned for investigation, among other requirements. The Supreme Court upheld both sections in Disini. If a platform receives a broad demand, it should check whether it is being asked to preserve, disclose or allow a search, and record the exact authority and data scope. Do not treat a coordination letter as a substitute for a warrant where one is required.
RA 10175 does not authorize warrantless live traffic collection under §12
The Supreme Court in Disini v. Secretary of Justice, G.R. No. 203335 (February 11, 2014) declared §12’s real-time traffic-data collection power unconstitutional. The printed statute still displays its original text; the decision controls. This does not decide every possible surveillance issue under other valid laws, which require separate analysis.
RA 10175 §19 cannot justify administrative website blocking
The same decision struck down §19, which would have let DOJ restrict or block access to computer data found prima facie in violation of the Act without a court warrant. DICT and CICC cannot revive that invalid provision through policy or coordination. A removal request might rest on another law, a court order, platform rules or a voluntary report; the legal basis and its limits should be identified before treating it as compulsory. Read the Supreme Court’s ruling.
Inter-agency coordination is not unrestricted data sharing
CICC may call on a government agency for help under RA 10175 §26(g). This does not automatically open every database, authorize bulk transfer of customer records or displace the Data Privacy Act. The purpose, lawful basis, scope and safeguards of a particular disclosure still matter. NPC remains the regulator for applicable data-privacy questions.
How do these boundaries work in practice?
Online scam: A victim may report a lead through a coordinating channel, but an NBI or PNP cybercrime unit handles criminal investigation. Preserve payment receipts, account identifiers, messages, URLs and timestamps. Use our reporting directory to find the appropriate route.
Platform data demand: A platform asked by CICC for all users’ private messages should authenticate the request, distinguish voluntary cooperation from compulsory disclosure, check the cited law and any warrant, and escalate a disputed demand to counsel.
Ransomware at a government office: DICT may coordinate technical response under its cybersecurity mandate. Law enforcement handles the criminal investigation, and the affected organization must separately assess privacy and other notification duties based on the actual data and incident.
What should a business do when contacted by DICT or CICC?
- Confirm the sender through an independently verified official channel.
- Save the original request and identify the case number, officer, legal basis and exact requested action.
- Separate technical assistance, preservation, disclosure, search and takedown; each has different conditions.
- Preserve relevant evidence safely, limit internal access and document any production.
- Ask the legal, security and privacy teams to assess a contested or sensitive request before release.
These steps are practical risk controls, not a claim that each is a separate statutory filing duty.
What to do next: options, forum and first action
| Your situation | Where to go and why | What to bring |
|---|---|---|
| You are a victim of hacking, online fraud or another RA 10175 offense | File a complaint with the PNP Anti-Cybercrime Group or the NBI cybercrime unit, the enforcement bodies named in RA 10175 §10. For a fast scam report, the government’s Inter-Agency Response Center hotline 1326, run with CICC, DICT, NTC, NPC, PNP and NBI, takes reports around the clock (PNA, August 14, 2023); a hotline report is not a sworn criminal complaint. | Valid ID, screenshots with visible dates and URLs, account names or numbers, transaction receipts, device details and a written timeline. See our evidence checklist. |
| Your personal data was mishandled or leaked | Raise it first with the organization’s data protection officer, then consider a complaint with the NPC, which administers the Data Privacy Act. A separate crime may also go to PNP or NBI. | Proof of the disclosure or breach notice, your correspondence with the organization and the harm suffered. |
| Your business received a DICT or CICC request for data, a search or a takedown | Follow the checklist above. Compelled disclosure of computer data normally needs a court warrant and a law-enforcement order under §14; a coordination letter alone is not one. | The request, envelope or email headers, any warrant or order, your data inventory and a log of what was preserved or produced. |
| You believe a request or warrant exceeds legal limits | Consult a lawyer promptly; a warrant or order can be questioned before the issuing court. If you cannot afford counsel, ask the Public Attorney’s Office or a law school legal aid clinic about eligibility. | Copies of the request, warrant, return and any inventory of seized devices or data. |
Deadlines: apart from the 72-hour period in a §14 disclosure order and the six-month minimum preservation period in §13, this guide did not verify a fixed filing period for complaints; prescription depends on the specific offense, so report early.
First action today: preserve the evidence (original messages, headers, receipts and the request itself) before deleting, replying or producing anything, then contact the office that matches your situation above.
Frequently asked questions
Can CICC investigate cybercrime on its own?
RA 10175 §10 assigns enforcement to NBI and PNP. CICC coordinates, monitors and assists under §§24–26 as modified by RA 10844. The powers of a separately authorized investigator must be identified in that investigator’s actual capacity.
Can DICT force a social network to remove a post?
Its general ICT mandate does not itself supply an unrestricted takedown power. Check a specific applicable law, valid order or platform rule. The Supreme Court struck down RA 10175 §19.
Can CICC ask another agency for assistance?
Yes. Section 26(g) permits requests for help with CICC’s mandated tasks. The assisting agency’s own powers and privacy limits still apply.
Who issues a cybercrime search warrant?
A competent court issues the appropriate warrant under the applicable rules. DICT and CICC do not issue judicial warrants.
Where should a victim complain?
For a suspected cybercrime, start with an NBI or PNP cybercrime unit. For a personal-data violation, assess the NPC process. Multiple issues may call for distinct routes; a report to one office is not automatically a complaint to all.
Related CyberCode guides
- CICC’s mandate and agency structure
- DICT Act and its functions
- Cybercrime Prevention Act guide
- E-Governance Act guide
Primary sources
- RA 10175, §§10–16, 23–26 (Supreme Court E-Library)
- RA 10844, §15(b) (Supreme Court E-Library)
- Disini v. Secretary of Justice, G.R. No. 203335, February 11, 2014
- RA 10173, Data Privacy Act (Supreme Court E-Library)
- Philippine News Agency: government anti-scam hotline 1326 (August 14, 2023)
Philippine national law. This guide does not decide the validity of a particular request or warrant; seek advice on contested facts.
Sources rechecked as of: September 28, 2026

