Bank secrecy and cybercrime investigations involving digital banking transactions in the Philippines
Bank secrecy remains protected, but certain account-identifying information may be disclosed through a valid cybercrime warrant.

For businesses and bank customers, one question often arises after a cyber fraud incident: Can a bank be required to disclose information about an account used to receive stolen money?

 

This question was addressed in EastWest Rural Bank v. Philippine National Police Anti-Cybercrime Group Regional Anti-Cybercrime Unit 1. The case clarifies how the Bank Secrecy Law operates alongside the Cybercrime Prevention Act in investigations involving digital transactions.

 

The short answer is that bank secrecy remains protected. However, it does not prevent the disclosure of certain identifying information when a valid court-issued warrant and the requirements of the Cybercrime Prevention Act are satisfied.

 

Disclosure of Account Information

 

The case arose from an investigation into a fraudulent electronic transfer. The Philippine National Police Anti-Cybercrime Group traced the funds to an account maintained with EastWest Rural Bank and obtained a Warrant to Disclose Computer Data (WDCD) to obtain information identifying the account holder.

 

EastWest Rural Bank questioned the disclosure, arguing, among other things, that the information was protected by the Bank Secrecy Law.

 

The Supreme Court rejected the bank’s challenge. It held that a bank may qualify as a service provider under the Cybercrime Prevention Act and may be required, pursuant to a valid WDCD, to disclose information necessary to identify an account holder in a cybercrime investigation.

 

The ruling, however, does not give law enforcement unrestricted access to a customer’s bank account.

 

Bank Secrecy Has Not Been Abolished

 

The Court expressly held that the Cybercrime Prevention Act did not repeal the Bank Secrecy Law. The confidentiality of bank deposits therefore remains protected, subject to the exceptions recognized by law.

 

The Court distinguished between information that identifies an account holder and information concerning the financial contents of the account.

 

In this case, the information sought included details such as the account holder’s name, address, identification information, and contact details. The Court held that such information could be disclosed under a properly issued cybercrime warrant.

 

This is different from allowing investigators to conduct an unrestricted examination of a customer’s deposits, balances, or complete banking history.

 

That distinction is important for both businesses and customers.

 

What This Means for Businesses

 

Businesses that make or receive electronic payments may become involved in a cybercrime investigation even when they are not accused of wrongdoing.

 

For example, a company’s account could receive funds obtained through phishing, business email compromise, or another form of online fraud. Investigators may need information from the receiving bank to determine who controls the account and trace the movement of the funds.

 

Businesses should therefore have clear procedures for responding to suspected fraudulent transactions.

 

In response, businesses should consider the following:

 

(i)  Act promptly. Notify the relevant bank or financial institution as soon as possible. Delays may make it more difficult to trace or recover funds.

 

(ii) Preserve evidence. Keep transaction records, emails, text messages, screenshots, payment instructions, call details, and other relevant digital evidence.

 

(iii) Understand requests for information. When law enforcement requests customer or account information, businesses should determine what information is being sought and the legal authority supporting the request.

 

(iv) Review internal controls. Payment approval procedures, changes to account details, and unusual requests for funds or credentials should be subject to appropriate safeguards.

 

(v) Protect customer information. A fraud investigation does not eliminate a business’ obligations under applicable privacy and confidentiality laws.

 

The decision therefore has implications beyond the banking sector. Businesses that rely on electronic payments should be prepared not only to prevent fraud but also to respond appropriately when one occurs.

 

What This Means for Customers

 

For customers, the decision is a reminder that bank secrecy provides important protection but does not create absolute anonymity.

 

If an account becomes relevant to a cybercrime investigation, certain identifying information may be disclosed when the legal requirements are met. At the same time, the ruling does not authorize unrestricted access to the financial contents of a customer’s account.

 

Customers should also remain cautious when dealing with unsolicited calls, messages, and emails concerning their bank accounts. One-time passwords, PINs, passwords, and other authentication credentials should not be disclosed simply because someone claims to represent a bank or financial institution.

 

If an unauthorized transaction occurs, customers should immediately notify their bank, secure the affected account, preserve relevant communications and transaction records, and report the incident to the appropriate authorities.

 

Balancing Privacy and Cybercrime Enforcement

 

The above-mentioned case illustrates the need to balance privacy with the practical realities of investigating cybercrime.

 

The decision does not make bank secrecy meaningless. Rather, it recognizes that certain account-identifying information may be obtained through a lawful judicial process when necessary to investigate cybercrime.

 

As financial transactions increasingly move online, businesses and customers should expect digital records to play an important role when fraud occurs. Businesses should have appropriate fraud-response and information-handling procedures, while customers should remain vigilant in protecting their banking credentials and act quickly when an unauthorized transaction is discovered.

 

Bank secrecy remains an important protection. But as the Supreme Court’s decision makes clear, that protection must operate alongside legally supervised mechanisms that allow authorities to identify and investigate those who misuse the financial system for cybercrime.

NARP LAW assists clients in navigating complex legal issues, regulatory requirements, and legal risks by structuring operations for compliance and growth.

 

For more information, you may contact us at info@narplaw.com or at +639063731095.

Scroll to Top