Sadsad Tamesis Legal and Accountancy Firm

Cross-Border Data Requests and Mutual Legal Assistance | STLAF Global

Cross-Border Data Requests and Mutual Legal Assistance

A data demand puts a company between two duties. Hand over too much and you may violate the Data Privacy Act and your promises to users. Refuse and you risk contempt or obstruction. The way out is neither instinct; it is analysis: what is this instrument, what can it lawfully reach, and how do you respond without creating new liability in either direction.

STLAF acts for the companies that hold the data and for the parties that need it: service providers and BPOs served with subpoenas and cybercrime warrants, Philippine entities handed a foreign demand by an overseas parent, and counsel working mutual legal assistance channels into or out of the Philippines. For the treaties behind this machinery, read our guide to the Hanoi and Budapest Conventions; this page is the response work.

Know what is in front of you: the demand ladder

A preservation letter, a subpoena, and a cybercrime warrant carry different powers, and the most common compliance mistake is answering one as if it were another.

The instrumentWhat it isWhat it can reach
Preservation request or letterAn order to freeze specified data so it is not deletedPreservation only; it does not by itself compel you to hand anything over
SubpoenaA demand to produce specified information or appearLimited categories of data; as a rule it is not the lawful instrument for message content
Cybercrime warrants (WDCD, WICD, WSSECD, WECD)Court-issued warrants under the Rule on Cybercrime Warrants (A.M. No. 17-11-03-SC)To disclose (WDCD), intercept (WICD), search, seize and examine (WSSECD), or examine (WECD) computer data, each within its defined scope; preservation is a separate law-enforcement order, not a warrant
MLAT / treaty requestA foreign authority’s request routed through official channels, in the Philippines via the DOJ Office of CybercrimeWhat Philippine law allows, executed through Philippine process; foreign demands do not reach Philippine data directly

Two ladder rules account for most of the mistakes we see. Upward confusion: producing message content in answer to a bare subpoena hands over more than the instrument lawfully commands, and the liability for that sits with you. Downward confusion: ignoring a cybercrime warrant as if it were a mere letter invites contempt or obstruction exposure; a warrant you believe is defective is challenged through counsel, not shelved.

Responding without creating new liability

The right response to a data demand is validity analysis first: what this instrument can lawfully reach, whether it is properly issued and scoped, and only then how to comply or challenge.

The engagement runs in a fixed order. First, identification and validity: what the instrument is, whether it was lawfully issued, and whether its scope matches what it asks for. Overbroad demands are common, and narrowing them is a legitimate, recognized response. Second, the decision: lawful compliance built to satisfy the demand exactly, without volunteering what was not commanded; or a challenge, through a motion to quash or its procedural equivalent, where the defects are real. Third, execution: the production or the challenge done cleanly, the confidentiality terms of the order respected (many of these orders restrict telling the affected user, and handling that correctly is part of the work), and a documented record that shows a company that responded lawfully, whichever way it responded.

That record is not bureaucracy. It is what protects you when the affected user, a regulator, or a court later asks why you did what you did.

For service providers and BPOs: standing readiness

Providers that hold user data need a request-handling protocol before the first demand arrives: intake, validation, escalation, response, and the retention posture the law already requires.

If your company is a telco, ISP, hosting or cloud provider, platform, fintech, or BPO, demands are not a possibility; they are a matter of time, and Philippine law already imposes duties that exist before any request, including minimum retention of traffic and subscriber data (at least six months under RA 10175, Section 13). Readiness work builds the machine: an intake and validation protocol so the front line never hands data to a letterhead, escalation paths and response timelines, templates for lawful narrow compliance, and training for the people who will actually receive the knock. Where this overlaps your wider privacy program, it connects to our Data Privacy and NPC Compliance service; the two are built to fit together.

Mutual legal assistance, both directions

When evidence sits abroad, or a foreign authority needs evidence here, the route is mutual legal assistance through the DOJ Office of Cybercrime, and STLAF works that route in both directions.

Outbound: a Philippine matter, a fraud, a defamation case, an intrusion, needs data held by a foreign provider. A Philippine subpoena will not reach it; the workable route runs through preservation requests and the treaty channels, prepared so the request is specific enough to act on. Inbound: a foreign authority or foreign counsel needs the Philippine leg of an investigation handled, from understanding what Philippine process will and will not produce, to representing the local entity through execution.

Honesty about timelines is part of the counsel: treaty-channel requests are measured in months, not weeks, which is exactly why the preservation step, which is fast, comes first, and why early advice changes outcomes. Where a matter needs coordination beyond the Philippines, STLAF works through its international partner network, with the Philippine side, the part a Philippine-licensed firm can truly own, as our seat.

Why STLAF

STLAF is Philippine-side counsel built for cross-border matters: a law and accountancy firm, led on cybercrime by Atty. Gabriel D. Adora, recognized by Legal 500, Mondaq, the International Bar Association, and as a Finalist at the ALB Philippine Law Awards 2025.

The practice is structured for exactly this seat: the validity analysis, the response work, and the treaty channels, connected to the firm’s wider cybercrime, privacy, and breach-response capability. And because the firm pairs law with accountancy, demands that involve financial records, fraud trails, and transaction data are read by people who investigate such records for a living, not merely passed along.

Frequently asked questions

We received a subpoena for user data. Do we have to comply?

It depends on what the instrument is and what it asks for. A subpoena cannot lawfully reach everything, and validity and scope are checked before anything is produced.

As a rule, no. Cross-border reach runs through treaty and cooperation channels, not domestic subpoenas, in both directions.

Outright refusal invites contempt or obstruction exposure. The lawful way to resist a defective warrant is a challenge through counsel, and the lawful way to comply with a valid one is exact, not generous.

Often the order restricts disclosure, and breaching that restriction creates its own exposure. Handling confidentiality correctly, including against your transparency commitments, is part of the response.

Months as a rule, varying by channel and jurisdiction. That is why preservation moves first and why we set expectations honestly at intake.

Philippine law sets minimum retention periods for service providers: at least six months for traffic data and subscriber information under RA 10175, Section 13, extendable once by another six months on a law-enforcement order. Your retention posture is part of readiness, because it determines what exists to be demanded at all.

Talk to us

A demand is a deadline. If one has arrived, have it identified before anyone answers it; if one has not yet, build the protocol while that is still cheap.

This page is general legal information, not legal advice for a specific situation.

https://157.245.54.109/ https://128.199.163.73/ https://cadizguru.com/ https://167.71.213.43/
Scroll to Top