Does Banker's Books Evidence Bill, 2026 Meet Constitutional Demands Of Privacy And Electronic Evidence?
On August 5, 2026, the Lok Sabha passed the Banker's Books Evidence Bill, 2026, by voice vote, amid opposition sloganeering that left the House without a substantive debate on its provisions. The Bill retires the Banker's Books Evidence Act, 1891, a statute drafted for leather-bound ledgers, and replaces it with a framework built for cloud servers, disaster-recovery sites and distributed core banking systems. That modernisation is overdue and, on its own terms, sound. What did not receive the scrutiny it deserved before passage is a second, quieter change buried in the same Bill: a provision allowing police officers of the rank of superintendent or above to demand a citizen's complete banking history without prior judicial authorisation. The Bill now moves to the Rajya Sabha, and the question that deserves the debate it did not get in the Lok Sabha is whether a statute reforming how bank records are proved in court can also, without more, expand how they are accessed by the state.
What the Bill actually changes
Three structural changes define the 2026 Bill. First, it expands the definition of “banker's books” to expressly cover physical, electronic, digital, virtual and cloud-based records, including those held at back-up and disaster-recovery sites, a necessary update given that no significant Indian bank today maintains records in a form the 1891 Act could meaningfully describe. Second, it introduces a two-track certification framework, separate certificate formats for physical and electronic records, intended to standardise how a bank attests to the authenticity of what it produces in litigation. Third, and this is the provision that has drawn criticism from commentators and civil society groups, it empowers investigating police officers at or above the rank of superintendent to requisition a customer's account records directly from banks, without the safeguard of prior judicial sanction that has historically accompanied compelled disclosure of financial information in Indian criminal procedure. Banks are required to notify affected customers of such access, but the Bill carves out broad exceptions to that notification duty, precisely the categories of case, ongoing investigations, national security, organised financial crime, where an affected customer would most want to know, and most need the opportunity to challenge the access.
The privacy problem is not that records are digital; it is that access is unsupervised
It would be a mistake to frame the constitutional objection to this Bill as a complaint about digitisation itself. Indian law has for some years recognised electronic financial records as evidence, and there is nothing intrinsically more invasive about a cloud-stored transaction ledger than a paper one. The constitutional problem is structural: the Bill removes a layer of independent oversight that has, in comparable contexts, been treated as constitutionally necessary rather than merely administratively convenient. The Supreme Court's nine-judge bench in K.S. Puttaswamy v. Union of India held that any state action restricting the right to privacy under Article 21 must satisfy a four-fold proportionality standard: a legitimate state aim, a rational connection between the measure and that aim, necessity in the sense that no less intrusive alternative would serve the same purpose, and a fair balance between the individual's right and the state's interest, including adequate procedural safeguards against arbitrary exercise of the power. Investigating financial crime is unquestionably a legitimate aim, and the rational-connection prong is easily satisfied; bank records are often central to establishing financial offences. Where the Bill runs into difficulty is on necessity and procedural safeguard: India's own criminal procedure, including provisions of the Bharatiya Nagarik Suraksha Sanhita governing search, seizure and production of documents, generally builds in either magistrate involvement or a structured internal sanctioning process for comparably intrusive measures. A provision that allows a single-rank threshold, superintendent of police, to authorise access to the complete financial history of any citizen, with notification as the exception-riddled afterthought rather than the rule, is difficult to reconcile with the “fair balance” and “least intrusive means” limbs of the Puttaswamy test, particularly when the Bill offers no independent body, judicial or quasi-judicial, to review or audit how the power is used after the fact.
This gap is compounded by the Digital Personal Data Protection Act, 2023, which itself exempts data processing for the prevention, detection, investigation or prosecution of offences from several of its core obligations, including, in defined circumstances, the data principal's right to notice. Read together, the two statutes leave a citizen whose bank records are accessed by police with neither an ex ante judicial check under the Banker's Books Evidence Bill nor a reliable ex post notification right under the DPDPA. Each statute, taken alone, might be defensible as a narrow, purpose-specific carve-out. Read together, they risk producing exactly the kind of unaccountable surveillance architecture that Puttaswamy's procedural-safeguard requirement was designed to prevent.
It is worth recalling, too, that the confidentiality a bank owes its customer is not simply a statutory or regulatory nicety in Indian law; it has long been treated as an implied contractual duty flowing from the banker-customer relationship, traceable to common law principles Indian courts have repeatedly applied. That duty has always yielded to compulsion of law, no version of banking confidentiality has ever been absolute, but the point of requiring judicial or magisterial sanction for such compulsion has been to ensure the yielding happens through a reasoned, reviewable process rather than an internal executive decision taken by the investigating agency itself. A superintendent-rank threshold does not eliminate compulsion of law as the basis for access; it simply relocates the decision entirely inside the police hierarchy, removing the external check that gave the underlying duty of confidentiality practical meaning.
The electronic evidence dimension has its own, separate gap
The Bill's second ambition, standardising certification of electronic banking records, runs into a version of a problem that has already surfaced in other areas of Indian evidence law. The Bharatiya Sakshya Adhiniyam, 2023, requires a certificate under Section 63 attesting to the integrity and provenance of the computer system that produced an electronic record, a requirement the Supreme Court's Constitution Bench in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal held to be mandatory rather than directory. The Banker's Books Evidence Bill's two-track certification framework operates on the same underlying logic: a certificate authenticates that a record came from a particular system in a particular form, not that the underlying data is accurate, unaltered at the point of entry, or free from internal manipulation. For core banking data, this distinction matters more than it might first appear, given that bank records are now frequently held on third-party cloud infrastructure and disaster-recovery sites outside the bank's direct physical control, and increasingly generated or reconciled through automated, AI-assisted back-office systems. A certification regime built around attesting to the reliability of a computer system says little about the integrity of a data pipeline that spans a bank's core system, a cloud vendor's infrastructure, and automated reconciliation software, none of which the certifying bank officer may fully control or even fully understand. The Bill does not require any forensic verification standard beyond the certificate itself, leaving courts in a position similar to the one they already face with AI-generated evidence more broadly: a formally compliant certificate that may or may not correspond to a reliable underlying record.
What Rajya Sabha scrutiny should focus on
None of this argues against modernising the evidentiary status of digital bank records; that reform is decades overdue and largely uncontroversial. What it argues for is separating that reform from the access provision, and subjecting the latter to the safeguards Puttaswamy requires: a judicial or magisterial sanctioning requirement before superintendent-rank access to a citizen's full banking history, a notification duty that operates as the default with narrowly and specifically defined exceptions rather than broad discretionary carve-outs, and an independent audit or oversight mechanism, whether judicial, parliamentary, or through a data protection authority, to review how the access power is actually exercised over time. On the evidentiary side, the certification framework would benefit from an explicit requirement that certifying officers address data provenance across third-party infrastructure, not merely the bank's own system, particularly where cloud or disaster-recovery records are at issue.
The Banker's Books Evidence Act, 1891, survived for 135 years partly because it was narrow: it addressed how a specific category of business record could be proved in court, nothing more. The 2026 Bill's ambition is broader, and so is its risk. A statute that quietly expands state access to financial records while modernising how those records are proved deserves exactly the debate it was denied in the Lok Sabha. The Rajya Sabha, and ultimately the courts if the Bill is challenged, will have to decide whether digitising the ledger also means digitising the safeguards that have historically stood between a citizen's bank account and the state.
Author is an assistant professor at CHRIST (Deemed to be University), Delhi NCR Campus. Views are personal.