Banker's Books Evidence Bill, 2026 Raises Privacy Concerns Over Unsupervised Police Access to Bank Records

The Lok Sabha on August 5, 2026, passed the Banker's Books Evidence Bill, 2026, by voice vote amid opposition sloganeering that left little room for substantive debate. The Bill, which now moves to the Rajya Sabha, retires the 135-year-old Banker's Books Evidence Act, 1891, and replaces it with a framework designed for digital banking. While modernising evidentiary rules for electronic records is widely seen as overdue, the Bill contains a provision that has sparked serious constitutional concern: it empowers police officers of the rank of superintendent and above to demand a citizen's complete banking history directly from a bank without prior judicial authorisation. Legal commentators and civil society groups argue that this unsupervised access may violate the right to privacy as interpreted by the Supreme Court in K.S. Puttaswamy v. Union of India.

A Modernisation Long Overdue, but at What Cost?

The 1891 Act was drafted for leather-bound ledgers and physical bank branches. In an era where every significant Indian bank maintains its records on cloud servers, core banking systems, and disaster-recovery sites, the law's obsolescence was undeniable. The 2026 Bill makes three structural changes that address this gap. First, it expands the definition of "banker's books" to expressly cover physical, electronic, digital, virtual and cloud-based records, including those held at backup and disaster-recovery locations. Second, it introduces a two-track certification framework with separate certificate formats for physical and electronic records, standardising how banks attest to authenticity in litigation.

The third change is the most controversial: Section [provision number] allows investigating police officers at or above the rank of superintendent to requisition a customer's account records directly from a bank without first obtaining a judicial or magisterial sanction. Banks are ordinarily required to notify affected customers of such access, but the Bill carves out broad exceptions for ongoing investigations, national security, and organised financial crime — precisely the situations where an affected customer would most want to know.

The Privacy Problem: Unsupervised Access

The constitutional objection is not about digitisation itself. Indian law has long recognised electronic financial records as evidence, and a cloud-stored transaction ledger is no more inherently invasive than a paper one. The real problem is structural: the Bill removes a layer of independent oversight that has been treated as constitutionally necessary.

The Supreme Court's nine-judge bench in Puttaswamy held that any state action restricting the right to privacy under Article 21 must satisfy a four-fold proportionality standard: legitimate aim, rational connection, necessity (no less intrusive alternative), and fair balance with adequate procedural safeguards. Investigating financial crime is a legitimate aim, and the rational connection to bank records is obvious. But on necessity and procedural safeguard, the Bill runs into difficulty. India's own criminal procedure — including provisions of the Bharatiya Nagarik Suraksha Sanhita governing search, seizure, and production of documents — generally requires either magistrate involvement or a structured internal sanctioning process for comparably intrusive measures. A single rank threshold (superintendent) to authorise access to a citizen's entire financial history, with notification as an exception-riddled afterthought, is difficult to reconcile with the least intrusive means and fair balance limbs of the Puttaswamy test. The Bill offers no independent body, judicial or quasi-judicial, to review or audit how the power is used after the fact.

This gap is compounded by the Digital Personal Data Protection Act, 2023, which exempts data processing for prevention, detection, investigation, or prosecution of offences from several core obligations, including the data principal's right to notice. Read together, the two statutes leave a citizen whose bank records are accessed by police with neither an ex ante judicial check under the Banker's Books Evidence Bill nor a reliable ex post notification right under the DPDPA. Each statute alone might be defensible as a narrow carve-out, but together they risk producing an unaccountable surveillance architecture that Puttaswamy 's procedural safeguard requirement was designed to prevent.

Banking confidentiality has long been treated as an implied contractual duty in Indian common law, a duty that has always yielded to compulsion of law. But the point of requiring judicial or magisterial sanction has been to ensure that yielding happens through a reasoned, reviewable process, not an internal executive decision taken by the investigating agency itself. A superintendent-rank threshold does not eliminate compulsion of law; it simply relocates the decision entirely inside the police hierarchy, removing the external check that gave the duty of confidentiality practical meaning.

The Electronic Evidence Dimension: Certification Isn't Enough

The Bill's second ambition — standardising certification of electronic banking records — also has a significant gap. The Bharatiya Sakshya Adhiniyam, 2023, requires a certificate under Section 63 attesting to the integrity and provenance of the computer system that produced an electronic record. The Supreme Court's Constitution Bench in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal held that requirement to be mandatory. The Banker's Books Evidence Bill's two-track certification framework operates on the same logic: a certificate authenticates that a record came from a particular system in a particular form, not that the underlying data is accurate or free from manipulation.

For core banking data, this distinction matters because bank records are now frequently held on third-party cloud infrastructure and disaster-recovery sites outside the bank's direct physical control, and increasingly generated or reconciled through automated, AI-assisted back-office systems. A certification regime built around attesting to the reliability of a computer system says little about the integrity of a data pipeline that spans a bank's core system, a cloud vendor's infrastructure, and automated reconciliation software — none of which the certifying bank officer may fully control or even fully understand. The Bill does not require any forensic verification standard beyond the certificate itself, leaving courts in a position similar to the one they already face with AI-generated evidence more broadly: a formally compliant certificate that may or may not correspond to a reliable underlying record.

What Rajya Sabha Scrutiny Should Focus On

None of this argues against modernising the evidentiary status of digital bank records; that reform is decades overdue and largely uncontroversial. What it argues for is separating that reform from the access provision and subjecting the latter to the safeguards Puttaswamy requires. Specifically, legal experts suggest three measures for the Rajya Sabha to consider.

First, the access provision should require prior judicial or magisterial sanction before a superintendent-rank officer can obtain a citizen's full banking history. This aligns with the existing criminal procedure framework and ensures independent oversight at the point of access. Second, the notification duty should operate as the default, with narrowly and specifically defined exceptions rather than broad, discretionary carve-outs. Citizens should know when their financial records have been accessed and have an opportunity to challenge the access. Third, an independent audit or oversight mechanism — whether judicial, parliamentary, or through a data protection authority — should be established to review how the access power is exercised over time. On the evidentiary side, the certification framework would benefit from an explicit requirement that certifying officers address data provenance across third-party infrastructure, not merely the bank's own system, particularly where cloud or disaster-recovery records are at issue.

Conclusion

The Banker's Books Evidence Act, 1891, survived for 135 years partly because it was narrow: it addressed how a specific category of business record could be proved in court, nothing more. The 2026 Bill's ambition is broader, and so is its risk. A statute that quietly expands state access to financial records while modernising how those records are proved deserves exactly the debate it was denied in the Lok Sabha. The Rajya Sabha, and ultimately the courts if the Bill is challenged, will have to decide whether digitising the ledger also means digitising the safeguards that have historically stood between a citizen's bank account and the state. For legal professionals watching this space, the questions are pressing: does the Bill meet the proportionality standard of Puttaswamy ? Can a certification regime built for in-house systems adequately vouch for data held on third-party clouds? And most fundamentally, can a statute reforming evidence law simultaneously expand police surveillance powers without constitutional scrutiny? The answers will shape not only banking litigation but the broader architecture of financial privacy in India.