India updates historic bank records law to match digital era but faces privacy concerns

India’s parliament has enacted a new bill to modernise how bank records are accepted as evidence in court, replacing an 1891 law with regulations suited for the digital age. While aiming to streamline legal processes, the legislation raises critical questions over privacy and cybersecurity, prompting debate among legal experts and regional lawmakers.

India’s parliament has passed a bill that would overhaul how bank records are treated in court, replacing a law that dates to 1891 with rules built for the digital age. According to reports from Indian media, the Bankers’ Books Evidence Bill, 2026 is intended to recognise electronic records kept on local servers, off-site systems and cloud platforms, while making it easier for banks to submit evidence without routinely sending officials to court.

The legislation sets out a more formal system for certifying digital bank records, with prescribed formats meant to establish authenticity in the same way that electronic evidence is handled under newer criminal and civil procedure rules. It also seeks to clarify when a record may be challenged, including where there are doubts about accuracy, interruptions in record-keeping or failure to comply with inspection orders. Supporters say the changes should speed up cases such as cheque-bounce disputes and reduce the administrative burden on banks, while retaining police access to bank records for investigations led by senior officers.

Yet the measure has drawn criticism from legal and policy observers, who argue that the bill modernises procedure without fully addressing the risks that come with digital records. Concerns have centred on privacy, since electronic banking data can be copied and shared far more easily than paper files, and on cybersecurity, because the bill does not appear to spell out stronger protections against leaks, tampering or unauthorised disclosure. Some experts have also questioned the absence of hash-value safeguards, which can act as a digital fingerprint to show whether a record has been altered.

Other objections focus on how the law would work in practice. Critics say requiring branch heads to certify the security of systems may be unrealistic if those officials do not control the bank’s data centres, cloud providers or security architecture. There are also worries that the government’s ability to extend the law to other financial entities by notification could give lightly regulated fintech platforms a level of evidentiary credibility similar to that of banks. In Kerala, the legislative assembly passed a resolution opposing the bill and called for a wider review, underscoring the political unease around the balance between efficiency and privacy.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.