The Banker’s Books Evidence Bill, 2026, passed by the Lok Sabha on August 5, has brought renewed attention to the balance between modernising India’s banking evidence framework and protecting citizens’ financial privacy. The Bill seeks to replace the Banker’s Books Evidence Act, 1891, expanding the legal framework to cover electronic, digital, virtual and cloud-based banking records. At the same time, concerns have been raised over a provision that would allow investigating police officers of the rank of superintendent or above to seek customers’ banking records directly from banks without prior judicial authorisation.
The Bill was passed by voice vote and will now move to the Rajya Sabha. While the modernisation of a law originally designed around physical banking ledgers has been described as necessary, the proposed framework has prompted questions over the safeguards governing access to sensitive financial information and the reliability of electronic evidence produced from increasingly complex banking systems.
Bill Expands Scope to Digital and Cloud-Based Records
The proposed legislation makes three significant structural changes to the existing framework. It broadens the meaning of “banker’s books” to expressly include physical, electronic, digital, virtual and cloud-based records, including information maintained at backup and disaster-recovery locations.
It also introduces separate certification mechanisms for physical and electronic banking records. The objective is to standardise the process through which banks certify the authenticity of documents and records produced during litigation or investigation.
The more contentious provision concerns access to banking information. According to the article, investigating police officers at or above the rank of superintendent would be able to requisition a customer’s account records directly from a bank without first obtaining judicial sanction.
Banks would ordinarily be required to inform customers about such access, but the Bill reportedly contains broad exceptions to this notification requirement, including cases involving ongoing investigations, national security and organised financial crime.
Privacy Safeguards Come Under Scrutiny
Questions have been raised over whether allowing police access to a citizen’s complete banking history without prior independent scrutiny is consistent with constitutional privacy protections.
The concerns have been examined in the context of the Supreme Court’s privacy judgment in K.S. Puttaswamy v. Union of India, which requires restrictions on privacy to satisfy standards including a legitimate state objective, necessity, proportionality and adequate safeguards against arbitrary exercise of power.
The criticism is not directed at the digitisation of banking records itself, but at the mechanism through which authorities may obtain access to those records. The article argues that comparable intrusive measures under criminal procedure generally involve either a magistrate or some structured system of authorisation.
The issue is further linked to the Digital Personal Data Protection Act, 2023, which provides exemptions in certain circumstances for processing data for the prevention, detection, investigation or prosecution of offences. Read together, the two frameworks could potentially leave customers without prior judicial review in some cases and without guaranteed subsequent notification.
Banking confidentiality has also been cited as an important consideration. The banker-customer relationship has traditionally carried a duty of confidentiality, although that obligation can yield where disclosure is required by law.
Questions Remain Over Reliability of Electronic Evidence
The Bill’s treatment of electronic records has also attracted scrutiny over whether certification alone is sufficient to establish the integrity of modern banking data.
The article refers to the Bharatiya Sakshya Adhiniyam, 2023, and its certification requirements for electronic records. It notes that certification may establish that a record was generated from a particular computer system in a specified form, but may not by itself prove that the underlying information was accurate when entered or remained free from internal manipulation.
This issue becomes more complex as banking records may be stored on third-party cloud infrastructure, disaster-recovery systems and automated back-office platforms outside a bank’s direct physical control.
The article argues that the certification framework could be strengthened by requiring greater attention to data provenance across third-party systems and infrastructure.
As the Bill moves to the Rajya Sabha, the debate is expected to focus not on whether banking evidence laws require modernisation, but on whether expanded access powers should be accompanied by stronger safeguards. Suggested measures include prior judicial or magisterial approval for access to complete banking histories, clearer notification requirements with narrowly defined exceptions, independent oversight of the exercise of such powers and stronger standards for verifying the provenance of electronic banking records.
The broader question before lawmakers is whether a legal framework designed for digital banking can modernise the treatment of electronic evidence without weakening protections surrounding citizens’ financial information.
About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.
