India

Passed Without Debate in Lok Sabha: The New Bankers' Books Evidence Bill 2026 Gives Police Direct Access to Your Financial Records

By GS Team
5 Aug 20264 mins read
TukuTouch Logo
India's Lok Sabha passed the Bankers' Books Evidence Bill, 2026, replacing a 135-year-old law. It modernizes electronic record acceptance in court but allows police officers (SP rank or above) to access citizens' complete bank histories without judicial oversight. This raises severe privacy concerns, enabling unchecked surveillance and placing impossible legal burdens on bank managers regarding cybersecurity declarations. The bill now awaits Rajya Sabha approval.

Summarized by AI; it may make mistakes. Check important info

Passed Without Debate in Lok Sabha: The New Bankers' Books Evidence Bill 2026 Gives Police Direct Access to Your Financial Records
AI image

Amid loud opposition protests and zero parliamentary debate, the Lok Sabha passed the Bankers' Books Evidence Bill, 2026 by voice vote on Wednesday. Introduced by Union Finance Minister Nirmala Sitharaman to replace a 135-year-old law, the legislation ostensibly seeks to modernise how electronic and cloud-based financial records are admitted in court. However, buried inside its provisions lies a sweeping change: investigating police officers can now bypass judges to demand any citizen’s complete bank account history, raising severe privacy concerns and leaving bank customers vulnerable to unchecked state surveillance.

A 135-Year-Old Law Modernised—With a Catch

The Union government framed the new legislation as an essential update to the Bankers' Books Evidence Act of 1891. When the original law was enacted under British rule, banking records consisted entirely of physical, leather-bound ledgers. Today, financial entries sit on cloud servers, disaster-recovery sites, and core banking software operating across multiple states.

To reflect this reality, the 2026 Bill expands the definition of 'bankers' books' to cover physical, digital, virtual, and cloud-stored records, establishing them as legally enforceable evidence. It also allows the central government to extend these rules to any financial entity through official notifications.
While updating record-keeping rules for the digital era is necessary, the speed and manner of the Bill's passage—pushed through amidst parliament chaos without a single word of discussion—has alarmed legal experts, consumer rights advocates, and banking unions.

Section 11: Bypassing Judges for Unchecked Police Access

The most contentious element of the legislation is Section 11. Under the previous 1891 framework, law enforcement agencies needed an explicit court order to compel a bank to hand over a customer's financial records during an investigation.
Section 11 alters this dynamic entirely. It stipulates that for investigations and inquiries, any legal requirement for a court order "shall be construed as referring to an order made by an officer not below the rank of Superintendent of Police (SP)" or any other officer designated by the government.
In practice, the law strips away independent judicial oversight. Bank statements provide an intimately detailed map of an individual's private life—revealing medical transactions, political donations, trade union subscriptions, travel habits, and personal relationships. Giving police officers the power to issue these orders internally creates a high risk of broad fishing expeditions against political rivals, journalists, trade unions, and civil society groups, without the customer or the bank ever being heard in court.

WhatsApp Image 2026-08-05 at 18.46.51.jpeg

Devidas Tuljapurkar, chairman of the Banking Education Training Research Academy (BETRA) and a senior bank union leader, warned that an SP-rank officer cannot replace judicial independence because the person demanding the records belongs to the exact same institution conducting the investigation.
The Impossible Burden Placed on Branch Managers

Beyond surveillance risks, the Bill imposes unrealistic legal burdens on frontline banking staff. Under the Second Schedule of the legislation, every digital banking record presented as evidence must carry a signed certificate affirming that the computer system was operating properly, that data transfers were secure, and that the network was fully equipped to counter cyber threats.

The law mandates that branch heads or local office managers sign these declarations. However, modern branch managers do not manage data centres, oversee cloud infrastructure providers, or monitor cybersecurity logs. A manager sitting in a local branch has no technical visibility into whether a server outage in Pune affected a customer's transaction records in Delhi.

Requiring local staff to sign sworn statements regarding systems they cannot structurally inspect creates a trap: managers will either be forced into routine, rubber-stamp certifications or face severe personal legal liability if a cyber incident later compromises those records. Banking representatives have urged the government to adopt a modular certification system, where local officers certify specific transactions while central IT and cybersecurity departments handle system-integrity declarations.

Absolute Security Declarations: A Legal Paradox

Section 7(1)(i) of the Bill requires a blanket declaration that the bank’s devices, networks, and stored data were "secure and equipped to meet the challenge of cyber risks or threats."

In cybersecurity, absolute immunity does not exist. Even institutions adhering to strict Reserve Bank of India (RBI) controls and operating mature security centres remain susceptible to zero-day vulnerabilities, phishing, or third-party service glitches. Expecting employees to sign absolute security declarations establishes a legal standard that no honest technology professional can meet without qualification.

Furthermore, critics point out that the legislation fails to explicitly mandate comprehensive audit trails, cryptographic hash values, extraction logs, or chain-of-custody documentation—the exact technical details required to resolve disputes over cyber fraud, unauthorized transactions, or backdated entries.
With the Lok Sabha having cleared the Bill without scrutiny, all eyes now turn to the Rajya Sabha, where lawmakers face growing calls to send the legislation to a parliamentary committee for thorough revision before it permanently alters financial privacy in India.