Banks are service providers under the Cybercrime Prevention Act. – “The Cybercrime Prevention Act defines “service provider” as “(1)[a]ny public or private entity that provides to users of its service the ability to communicate by means of a computer system, and (2)[a]ny other entity that processes or stores computer data on behalf of such communication service or users of such service.”
Service providers bear specific duties and responsibilities toward law enforcement authorities. Specifically, service providers are obligated, among others, to cooperate and assist law enforcement in the collection and recording of various types of data, including traffic data, subscriber information content data, and computer data. This assistance may involve technical support or system access, but it is contingent upon the existence of a lawful order, particularly a court warrant. Accordingly, upon the issuance of a court warrant, law enforcement authorities may compel service providers to disclose or submit pertinent computer data within their custody or control. Furthermore, service providers are required to preserve data as directed by law enforcement with varying preservation periods depending on the data type and the status of legal proceedings.”
XXX
How does banks align with the statutory definition of a “service provider” under the Cybercrime Prevention Act? –
“Petitioner’s operational activities related to its banking or financial services demonstrate that it falls within the ambit of service providers defined under the Cybercrime Prevention Act. Modern banking practices, which petitioner undoubtedly employs, relies heavily on computer systems to facilitate customer communication. This is evident in petitioner’s array of digital services, including online banking platforms, mobile applications, and automated email notification. Through these digital platforms, petitioner effectively provides its customers communication channels for various financial activities and customer service operations. This capability clearly demonstrates its role as a service provider. Importantly, while communication may not be petitioner’s primary function, the Court recognizes that the mere fact that it offers these communicative capabilities through computer systems substantially fulfills the Act’s criteria for a “service provider.”
Moreover, as a banking institution, petitioner undeniably processes and stores substantial amounts of computer data, both for its own operations and for its customers. This data includes account balances, transaction histories, and personal information of its customers/ To Our mind, this processing and storage of data are considered to be “on behalf of…users of such service.”, referring to petitioner’s customers/ Given that petitioner, by virtue of its function as a banking institution, processes and stores significant volumes of computerized data – both on its operational capacity and on behalf of its customers – it clearly meets the statutory definition of “statutory provider.”
Consequently, petitioner, by virtue of tis communication services and data management practices, clearly qualifies as a “service provider” under the Cybercrime Prevention Act. As such, petitioner is bound by the provisions of the Act, particularly those relating to data disclosure as stipulated in Section 14.”[1]
[1] Eastwest Rural Bank vs. Philippine National Police Anti-Cybercrime Group Regional Anti Cybercrime Unit, G.R. No. 273720, July 27, 2025