The Hanoi and Budapest Conventions What They Mean for the Philippines
Cybercrime evidence almost always sits in another country. The scammer’s account is hosted abroad, the platform’s servers are overseas, the hacker routed through three jurisdictions. Two treaties are the plumbing that lets investigations cross those borders: the Budapest Convention, in force for two decades, and the new UN Convention against Cybercrime, signed in Hanoi in October 2025. The Philippines is connected to both, and the window before the new treaty takes effect is exactly when companies touched by it should understand what is coming.
This guide explains both conventions from the Philippine side: what each does, how they differ, why the new one is controversial, and what they mean in practice for the businesses, service providers, and individuals this firm advises. It is written by STLAF Global’s International Cybercrime practice, led by Atty. Gabriel D. Adora.
Why these treaties exist
Cybercrime evidence almost always sits on servers in another country, and the Budapest and Hanoi conventions are the legal machinery that lets investigations reach across borders.
Without a treaty, a Philippine investigator who needs data held by a foreign provider has no direct legal route to it, and a foreign authority that needs data held in the Philippines has none either. The conventions solve this three ways: they make member countries criminalize a common core of offenses, so the same act is a crime on both ends of a request; they require common investigative tools, so evidence can be preserved and produced fast enough to matter; and they build the cooperation channels, mutual legal assistance and round-the-clock contact points, through which requests lawfully move.
For a sense of how that machinery touches a single case, our cyber libel and RA 10175 guides show the domestic side; this page is about the layer above it.
The Budapest Convention: the one already in force
The Budapest Convention, in force since 2004, is the first binding international cybercrime treaty, and the Philippines has been a party since 2018.
Formally the Council of Europe Convention on Cybercrime, it was opened for signature in Budapest in 2001 and entered into force in 2004. It does three things: sets the baseline offenses members must criminalize (illegal access, illegal interception, data and system interference, computer-related fraud and forgery, and others), gives law enforcement common procedural tools (expedited preservation of stored data, production orders, search and seizure of computer data), and creates the cooperation framework, including a 24/7 contact-point network for cross-border evidence requests.
The Philippines helped shape it from the start: it was one of a handful of non-European states that participated in drafting the Convention back in 2001. It formally acceded in 2018, with the Convention entering into force for the Philippines on 1 July 2018, becoming part of a system that now spans dozens of countries. Membership cuts both ways, and that is the point: Philippine investigations can reach data held in other member states, and other members’ investigations can reach data held here, each through defined legal channels rather than informal pressure.
The Convention has continued to evolve, including through a Second Additional Protocol on enhanced cooperation and cross-border electronic evidence. In the Philippines, the treaty’s machinery runs through the DOJ Office of Cybercrime, the central authority for cybercrime mutual assistance, working with the cybercrime warrant system our RA 10175 guide explains.
The Hanoi Convention: the new global treaty
The UN Convention against Cybercrime, signed in Hanoi in October 2025, is the first global cybercrime treaty negotiated under the United Nations, and the Philippines signed it among the first countries; it has not yet entered into force.
The treaty was adopted by the UN General Assembly on 24 December 2024 and opened for signature at a ceremony in Hanoi on 25 and 26 October 2025, drawing roughly seventy signatories including the European Union, one of the largest first-day signings of any recent multilateral treaty. The Philippines signed at the ceremony, with the signature delivered by the Secretary of the Department of Information and Communications Technology. The country was no bystander in the drafting: Philippine agencies co-led the national delegation through years of negotiation, pressing for stronger online child protection and for balance between enforcement powers and human rights.
What it covers runs on three pillars. First, criminalization: members must make crimes of a defined list including illegal access and interception, data and system interference, computer-related forgery, theft and fraud, offenses around child sexual abuse material, non-consensual sharing of intimate images, and laundering of the proceeds. Second, procedural powers: authorities must be able to preserve, produce, search, seize, and in defined cases intercept electronic data. Third, international cooperation: the widest measure of mutual legal assistance, extradition provisions, and another 24/7 network.
One feature matters more than any other for businesses: the treaty’s cross-border cooperation powers are not limited to cybercrime. They extend to electronic evidence for any “serious crime,” meaning offenses punishable by at least four years, which makes the treaty a general-purpose cross-border evidence instrument, not a narrow cybercrime tool.
The Convention is signed but not in force. It takes effect 90 days after the fortieth ratification, and as of June 2026 only three states have ratified (Qatar, Azerbaijan, and Viet Nam), far short of the forty required. For the Philippines, ratification requires Senate concurrence, and no timeline has been announced.
How Hanoi and Budapest differ
Hanoi is broader and newer, Budapest is narrower and proven, and the most important difference is that Hanoi’s cooperation powers extend to electronic evidence for any serious crime, not only cybercrime.
| Budapest Convention | Hanoi Convention | |
|---|---|---|
| Origin | Council of Europe, 2001 | United Nations, 2024 |
| Status | In force since 2004; established practice and case experience | Signed October 2025; not yet in force |
| Membership | Dozens of parties, Philippines since 2018 | More than 70 signatories; only 3 ratifications as of June 2026 (40 needed to enter into force) |
| Scope | Defined cybercrime offenses and their evidence | Cyber offenses, plus electronic evidence for any serious crime |
| Safeguards | Mature framework, refined by two decades of practice and protocols | Criticized as weaker; fewer hard limits on cooperation |
| For the Philippines | The operating reality today | The coming layer, if ratified |
The two are designed to coexist; Hanoi does not repeal or replace Budapest, and most Hanoi signatories that are Budapest parties, the Philippines included, will simply operate under both. For anyone subject to both regimes, the real questions become which instrument a given request travels under and which safeguards attach, and those are exactly the questions counsel exists to answer.
What this means for companies and service providers
For service providers and companies holding data with a Philippine connection, the conventions translate into concrete duties: preserve data on demand, produce it under lawful orders, assist investigations, and often stay silent about the request.
The most exposed group is service providers in the broad sense: telcos, ISPs, hosting and cloud companies, platforms, BPOs, and fintechs. Once the Hanoi Convention is in force for a country, providers connected to it face standing preservation and production obligations, requests routed from foreign authorities through the cooperation channels, and confidentiality requirements that can bar them from telling the affected user. For a provider also subject to other regimes, a request lawful under one treaty can sit in tension with data-protection duties elsewhere, which is the conflict-of-laws exposure that makes these matters legal work rather than form-filling.
Ordinary companies are affected too, in three roles. As custodians: production orders can reach corporate-held data, not only platform data, so any company can become the respondent to legal process. As victims: the treaties exist to make cross-border pursuit of intrusion, fraud, and data theft workable, which is good news for a company chasing a cross-border offender. And as compliance subjects: multinationals will need protocols for receiving, validating, and responding to cross-border demands.
The practical advice fits in one sentence: the window before the Hanoi Convention enters into force is the time to build the request-handling readiness, not after the first order arrives. Our Cross-Border Data Requests and MLA service is the working face of that advice.
The controversies, honestly
The Hanoi Convention is genuinely contested: critics argue its powers reach beyond cybercrime into general surveillance, with safeguards weaker than the Budapest framework.
The criticism deserves a straight summary. Human rights organizations and much of the technology industry opposed the treaty’s final shape, on several grounds: that extending cooperation powers to any serious crime turns a cybercrime treaty into a broad surveillance instrument; that its human rights safeguards are written in general language without enforceable standards; that broad definitions of offenses like illegal access could expose legitimate security researchers; and that confidentiality provisions can prevent providers from ever notifying the people whose data was handed over. Proposals during negotiation to add speech-related offenses failed, but critics argue the structural concerns remain.
None of this is a reason to ignore the treaty; it is the reason to take it seriously. The contested provisions are precisely where companies will need judgment: when to comply, when to narrow, when to challenge, and how to honor conflicting legal duties. A treaty this debated does not produce routine compliance work; it produces hard questions, which is why preparation beats improvisation.
What the Philippines should expect next
Ratification would layer the Hanoi Convention onto an established Philippine regime of RA 10175, RA 11930, and Budapest membership, rather than create one from scratch.
The Philippines is unusually well positioned among developing countries: it already operates a comprehensive cybercrime statute, a dedicated central authority in the DOJ Office of Cybercrime, the cybercrime warrant system, and two decades of Budapest-aligned practice. If the Senate concurs in ratification, the working questions will be implementation ones: how the new cooperation lanes plug into existing machinery, what implementing legislation or rules follow, and how the wider “serious crime” scope is applied in practice.
For companies, the planning assumption is simple: the direction of travel is more cross-border requests, moving faster, under wider authority. Building the response capability now, while the treaty is still gathering ratifications, is cheap; building it during your first contested order is not.
Frequently asked questions
Is the Philippines a party to the Budapest Convention?
Yes, since 2018. Philippine investigations can use its channels to reach evidence abroad, and foreign members’ investigations can lawfully reach data held here.
Has the Philippines ratified the Hanoi Convention?
It signed in October 2025 among the first countries, but ratification, which requires Senate concurrence, has not happened and no timeline has been announced.
Is the Hanoi Convention in force?
Not yet. It enters into force 90 days after the fortieth ratification, and as of June 2026 only three states have ratified, far short of the forty required.
Does the Hanoi Convention replace the Budapest Convention?
No. The two coexist and are broadly complementary; countries party to both will operate under both.
What does the Hanoi Convention mean for my company?
If you hold data with a Philippine connection, or operate across borders, expect preservation, production, and assistance duties once it is in force, including requests originating abroad. The preparation window is now.
Why is the Hanoi Convention controversial?
Because its cooperation powers extend beyond cybercrime to electronic evidence for any serious crime, and critics consider its safeguards weaker than the Budapest framework’s. The controversy is real and it is exactly why affected companies need considered, not reflexive, responses.
The Philippine side of a cross-border world
Treaties set the channels; someone still has to do the work when a request lands or a case needs to cross a border. STLAF acts as Philippine-side counsel for exactly that: responding to data demands, working the mutual assistance routes in both directions, and preparing companies for the regime that is coming. Start with our Cross-Border Data Requests and Mutual Legal Assistance service, or contact the team directly.
This guide is general legal information, not legal advice for a specific situation. Treaty status changes; this page was last reviewed in June 2026 against the UN Treaty Collection and Council of Europe Treaty Office registers.
