Raises Privacy Concerns Over Unsupervised Police Access to Bank Records
The on , passed the , by voice vote amid opposition sloganeering that left little room for substantive debate. The Bill, which now moves to the , retires the 135-year-old , and replaces it with a framework designed for digital banking. While modernising evidentiary rules for electronic records is widely seen as overdue, the Bill contains a provision that has sparked serious constitutional concern: it empowers police officers of the rank of superintendent and above to demand a citizen's complete banking history directly from a bank without prior judicial authorisation. Legal commentators and civil society groups argue that this unsupervised access may violate the as interpreted by the in .
A Modernisation Long Overdue, but at What Cost?
The 1891 Act was drafted for leather-bound ledgers and physical bank branches. In an era where every significant Indian bank maintains its records on cloud servers, core banking systems, and disaster-recovery sites, the law's obsolescence was undeniable. The 2026 Bill makes three structural changes that address this gap. First, it expands the definition of "" to expressly cover physical, electronic, digital, virtual and cloud-based records, including those held at backup and disaster-recovery locations. Second, it introduces a two-track with separate certificate formats for physical and electronic records, standardising how banks attest to authenticity in litigation.
The third change is the most controversial: Section [provision number] allows investigating police officers at or above the rank of superintendent to requisition a customer's account records directly from a bank without first obtaining a . Banks are ordinarily required to notify affected customers of such access, but the Bill carves out broad exceptions for ongoing investigations, national security, and organised financial crime — precisely the situations where an affected customer would most want to know.
The Privacy Problem: Unsupervised Access
The constitutional objection is not about digitisation itself. Indian law has long recognised electronic financial records as evidence, and a cloud-stored transaction ledger is no more inherently invasive than a paper one. The real problem is structural: the Bill removes a layer of independent oversight that has been treated as constitutionally necessary.
The 's nine-judge bench in Puttaswamy held that any restricting the under must satisfy a : , , , and with . Investigating financial crime is a , and the to bank records is obvious. But on necessity and procedural safeguard, the Bill runs into difficulty. India's own criminal procedure — including provisions of the governing — generally requires either magistrate involvement or a structured internal sanctioning process for comparably intrusive measures. A single rank threshold (superintendent) to authorise access to a citizen's entire financial history, with notification as an exception-riddled afterthought, is difficult to reconcile with the and limbs of the Puttaswamy test. The Bill offers no independent body, judicial or quasi-judicial, to review or audit how the power is used after the fact.
This gap is compounded by the , which exempts data processing for prevention, detection, investigation, or prosecution of offences from several core obligations, including the . Read together, the two statutes leave a citizen whose bank records are accessed by police with neither an under the Evidence Bill nor a reliable under the DPDPA. Each statute alone might be defensible as a narrow carve-out, but together they risk producing an unaccountable surveillance architecture that Puttaswamy 's procedural safeguard requirement was designed to prevent.
Banking confidentiality has long been treated as an in Indian common law, a duty that has always yielded to . But the point of requiring has been to ensure that yielding happens through a reasoned, reviewable process, not an internal executive decision taken by the investigating agency itself. A superintendent-rank threshold does not eliminate ; it simply relocates the decision entirely inside the police hierarchy, removing the external check that gave the duty of confidentiality practical meaning.
The Electronic Evidence Dimension: Certification Isn't Enough
The Bill's second ambition — standardising certification of electronic banking records — also has a significant gap. The , requires a certificate under attesting to the integrity and provenance of the computer system that produced an . The 's in held that requirement to be mandatory. The Evidence Bill's two-track operates on the same logic: a certificate authenticates that a record came from a particular system in a particular form, not that the underlying data is accurate or free from manipulation.
For core banking data, this distinction matters because bank records are now frequently held on third-party cloud infrastructure and disaster-recovery sites outside the bank's direct physical control, and increasingly generated or reconciled through automated, AI-assisted back-office systems. A certification regime built around attesting to the reliability of a computer system says little about the integrity of a data pipeline that spans a bank's core system, a cloud vendor's infrastructure, and automated reconciliation software — none of which the certifying bank officer may fully control or even fully understand. The Bill does not require any beyond the certificate itself, leaving courts in a position similar to the one they already face with AI-generated evidence more broadly: a formally compliant certificate that may or may not correspond to a reliable underlying record.
What Scrutiny Should Focus On
None of this argues against modernising the evidentiary status of digital bank records; that reform is decades overdue and largely uncontroversial. What it argues for is separating that reform from the access provision and subjecting the latter to the safeguards Puttaswamy requires. Specifically, legal experts suggest three measures for the to consider.
First, the access provision should require prior before a superintendent-rank officer can obtain a citizen's full banking history. This aligns with the existing criminal procedure framework and ensures independent oversight at the point of access. Second, the notification duty should operate as the default, with narrowly and specifically defined exceptions rather than broad, discretionary carve-outs. Citizens should know when their financial records have been accessed and have an opportunity to challenge the access. Third, an independent audit or oversight mechanism — whether judicial, parliamentary, or through a data protection authority — should be established to review how the access power is exercised over time. On the evidentiary side, the would benefit from an explicit requirement that certifying officers address across third-party infrastructure, not merely the bank's own system, particularly where cloud or disaster-recovery records are at issue.
Conclusion
The , survived for 135 years partly because it was narrow: it addressed how a specific category of business record could be proved in court, nothing more. The 2026 Bill's ambition is broader, and so is its risk. A statute that quietly expands state access to financial records while modernising how those records are proved deserves exactly the debate it was denied in the . The , and ultimately the courts if the Bill is challenged, will have to decide whether digitising the ledger also means digitising the safeguards that have historically stood between a citizen's bank account and the state. For legal professionals watching this space, the questions are pressing: does the Bill meet the proportionality standard of Puttaswamy ? Can a certification regime built for in-house systems adequately vouch for data held on third-party clouds? And most fundamentally, can a statute reforming evidence law simultaneously expand police surveillance powers without constitutional scrutiny? The answers will shape not only banking litigation but the broader architecture of financial privacy in India.