Information Technology has transformed banking from a branch-centric physical model to a technology-driven service. The legal framework supporting digital banking rests on the Information Technology Act, 2000 (legal recognition of electronic records), the Payment and Settlement Systems Act, 2007 (regulation of payment systems), and RBI guidelines on internet banking, mobile banking, and cybersecurity.
Legal Framework
| Provision | Subject |
|---|---|
| S.4 IT Act | Legal recognition of electronic records |
| S.5 IT Act | Legal recognition of electronic signatures |
| S.43 IT Act | Penalty for unauthorised access to computer systems |
| S.43A IT Act | Compensation for failure to protect sensitive personal data |
| S.66 IT Act | Computer-related offences (hacking) |
| S.72A IT Act | Disclosure of information in breach of lawful contract |
| S.2(p) PSS Act | "Payment system" defined |
| S.4 PSS Act | RBI designated authority for payment systems |
| S.7 PSS Act | Authorisation to operate payment system |
| S.6 NI Act | Cheque in electronic form (added by 2002 Amendment) |
| S.81A NI Act | Cheque Truncation System |
Evolution of Technology in Indian Banking
| Phase | Period | Development |
|---|---|---|
| Mechanisation | 1960s-1980s | Ledger posting machines, ALPMs |
| Computerisation | 1980s-1990s | Bank branch computerisation; Rangarajan Committee (1984, 1989) |
| Core Banking Solution | 2000s | Centralised database; any-branch banking |
| Internet Banking | 2001 onwards | RBI Guidelines on Internet Banking (2001) |
| Mobile Banking | 2008 onwards | RBI Framework for Mobile Banking (2008) |
| Real-Time Payments | 2004-present | RTGS (2004), NEFT (2005), IMPS (2010), UPI (2016) |
| Digital-only Banking | 2014 onwards | Payments banks, India Stack (Aadhaar + UPI + eKYC) |
Key Digital Banking Systems
| System | Full Form | Year | Operator | Characteristic |
|---|---|---|---|---|
| RTGS | Real Time Gross Settlement | 2004 | RBI | Real-time, high-value (min. Rs.2 lakh); gross settlement |
| NEFT | National Electronic Funds Transfer | 2005 | RBI | Near real-time (24x7 since Dec 2019); batch settlement |
| IMPS | Immediate Payment Service | 2010 | NPCI | Instant, 24x7, up to Rs.5 lakh |
| UPI | Unified Payments Interface | 2016 | NPCI | Interoperable, real-time, mobile-first, no limit (bank-set) |
| CTS | Cheque Truncation System | 2010 | RBI | Electronic image-based cheque clearing (S.81A NI Act) |
| NACH | National Automated Clearing House | 2012 | NPCI | Bulk/repetitive electronic payments |
| BBPS | Bharat Bill Payment System | 2016 | NPCI | Interoperable bill payment |
| CBDC | Central Bank Digital Currency (e-Rupee) | 2022 | RBI | Digital legal tender pilot |
Why: Technology reduces transaction costs, eliminates geographic barriers, and enables financial inclusion. The legal infrastructure (IT Act + PSS Act) ensures these electronic transactions have the same legal validity as paper-based transactions.
Legal Issues in E-Banking
| Issue | Legal Provision | Protection |
|---|---|---|
| Validity of electronic contracts | S.4, S.5 IT Act | Electronic records and signatures have legal recognition |
| Unauthorised electronic transfer | S.43 IT Act + RBI Circular (2017) | Zero liability if customer reports within 3 days; limited liability for 4-7 days |
| Data protection | S.43A IT Act; DPDP Act, 2023 | Compensation for data breach; reasonable security practices mandatory |
| Phishing and cyber fraud | S.66C, S.66D IT Act | Identity theft and impersonation punishable |
| Cheque in electronic form | S.6 NI Act (amended 2002) | Electronic cheques valid as negotiable instruments |
| Truncated cheque | S.81A NI Act | Image-based clearing without physical movement of instrument |
| Digital signature | S.3 IT Act | Asymmetric crypto system; legally equivalent to handwritten signature |
RBI Framework on Customer Liability (2017 Circular)
| Scenario | Customer Liability | Reporting Window |
|---|---|---|
| Bank/third-party breach; customer not at fault | Zero liability | Regardless of time |
| Neither bank nor customer at fault; system breach | Zero liability if reported within 3 days | 3 working days |
| Same; reported between 4-7 days | Limited liability (capped per transaction type) | 4-7 working days |
| Same; reported after 7 days | As per bank policy (board-approved) | Beyond 7 days |
| Customer negligence (shared credentials) | Full liability on customer | N/A |
Illustrations
-
S.4 IT Act in banking (why your UPI transfer is legally valid): You transfer Rs.25,000 to your landlord via UPI at 11 PM on Sunday. No paper, no signature, no branch visit. Is this legally valid? S.4 IT Act says: "Where any law requires information to be in writing, such requirement is deemed satisfied if the information is rendered in electronic form." Your UPI instruction is an "electronic record" legally equivalent to a signed cheque. The Payment and Settlement Systems Act, 2007 (S.7) further requires NPCI to be authorised by RBI. Both Acts together make your 11 PM Sunday transfer as legally valid as a cheque handed over at a bank counter on Monday morning.
-
Customer liability for fraud (the 3-day rule): Priya's debit card is cloned at a petrol pump. Rs.80,000 is withdrawn from an ATM at 2 AM. Priya was asleep. She discovers the debit next morning and calls the bank at 9 AM (within 24 hours = within 3 working days). Under RBI's 2017 Circular: Priya's liability = ZERO. The bank bears the entire Rs.80,000 loss. Now change one fact: Priya discovers it but procrastinates for 6 days before reporting. Now she's in the "4-7 days" bracket. Her liability is capped at Rs.10,000 (for a savings account). The bank bears Rs.70,000. Change again: Priya shared her OTP with a caller claiming to be "bank security." Now she's negligent shared credentials. Full liability: Rs.80,000 on Priya, regardless of when she reports. Speed of reporting matters, but negligence trumps everything.
-
CTS (Cheque Truncation) why your cheque doesn't travel anymore: Old process: You deposit a cheque at SBI Hyderabad drawn on ICICI Mumbai. The physical cheque travels by courier from Hyderabad to Mumbai clearing house. Takes 3-5 days. Risk: cheque gets lost in transit. CTS process (post-2010): SBI Hyderabad scans the cheque, captures the electronic image + MICR data, sends ONLY the digital image to ICICI Mumbai through the clearing house. Physical cheque stays in Hyderabad. Clearing happens same day. S.81A NI Act makes this legally valid the image has the same evidentiary value as the original paper.
-
CBDC vs UPI (the difference most people miss): UPI transfers money between bank accounts the money is still a bank deposit (bank's liability to you). If your bank fails, your UPI balance is at risk (subject to DICGC Rs.5 lakh limit). e-Rupee (CBDC) is digital currency issued by RBI itself it's legal tender, like a Rs.500 note but digital. If your bank fails, your e-Rupee is safe because it's RBI's direct liability, not the bank's. It's like holding cash in your wallet vs. holding a bank balance. Same digital interface, fundamentally different legal nature.
Recall Check
- What is the legal basis for recognising electronic fund transfers as valid banking transactions?
- How does the Payment and Settlement Systems Act, 2007 complement the IT Act, 2000 in regulating digital banking?
- What is "cheque truncation" and which provision of the NI Act enables it?
Key Cases
Trimex International v. Vedanta Aluminium (2010) Trimex-International-v-Vedanta-Aluminium-2010 Issue: Whether emails exchanged between parties constitute valid contracts under the IT Act. Rule: S.4 IT Act grants legal recognition to information in electronic form; S.10A (Indian Contract Act amendment) validates e-contracts. Held: Emails are valid electronic records under the IT Act. A contract concluded via electronic communication is enforceable. Banking instructions transmitted electronically have binding force.
ICICI Bank v. Official Liquidator of APS Star Industries (2010) ICICI-Bank-v-Official-Liquidator-APS-Star-2010 Issue: Whether electronic banking records (computer printouts) are admissible as evidence under S.65B of the Indian Evidence Act. Rule: S.65B prescribes conditions for admissibility of electronic records; certificate required. Held: Electronic bank statements are admissible if accompanied by S.65B certificate certifying the computer output. Banks must maintain proper electronic audit trails.
Distinctions
| Aspect | Traditional Banking | E-Banking |
|---|---|---|
| Medium | Physical branch, paper instruments | Internet, mobile, electronic channels |
| Operating hours | Branch hours (10 AM to 3/4 PM) | 24x7x365 |
| Jurisdiction | Branch location | Borderless (cybersecurity challenges) |
| Evidence | Physical documents, signed instruments | Electronic records, digital signatures (S.65B proof) |
| Customer authentication | Signature verification | PIN, OTP, biometric, digital signature |
| Settlement | Clearing house (T+1 or T+2) | Real-time (RTGS, UPI) or near-real-time (NEFT) |
| Risk profile | Physical fraud (forgery, theft) | Cyber fraud (phishing, hacking, identity theft) |
| Regulatory framework | BR Act + NI Act | BR Act + NI Act + IT Act + PSS Act |
Flashcards
Q: Which Act provides legal recognition to electronic records in India? A: Information Technology Act, 2000 (S.4: legal recognition of electronic records).
Q: What is the Payment and Settlement Systems Act, 2007? A: Legislation designating RBI as the authority to regulate and supervise payment systems in India; requires authorisation for operating any payment system (S.7).
Q: What is Cheque Truncation System (CTS)? A: Electronic image-based cheque clearing where the physical cheque is scanned at the presenting bank and only the electronic image is transmitted to the paying bank. Enabled by S.81A NI Act.
Q: Under RBI's 2017 circular, what is a customer's liability for an unauthorised electronic transaction reported within 3 working days? A: Zero liability (provided the customer is not at fault and reports within 3 working days of receiving communication from the bank).
Q: What section of the IT Act penalises unauthorised access to computer systems? A: S.43 (civil liability: compensation up to Rs.5 crore); S.66 (criminal: up to 3 years imprisonment + fine).
Q: When was UPI launched and who operates it? A: Launched in 2016; operated by National Payments Corporation of India (NPCI).
Q: What is the legal requirement for admissibility of electronic bank records in court? A: Must comply with S.65B of the Indian Evidence Act (certificate from person in charge of computer; conditions regarding regular use, proper operation, and accurate reproduction).
Q: What is RTGS and how does it differ from NEFT? A: RTGS: Real Time Gross Settlement (individual transactions settled in real-time, minimum Rs.2 lakh). NEFT: National Electronic Funds Transfer (settled in batches, 24x7, no minimum amount).
Exam Scenario
A customer's bank account is debited Rs.50,000 through an unauthorised UPI transaction. The customer did not share OTP or credentials with anyone. He reports the transaction to the bank on the 5th working day after receiving the SMS alert. Discuss the customer's liability.
Under RBI's Circular on Customer Protection (2017), the liability framework for unauthorised electronic transactions depends on: (a) who is at fault, and (b) when reported.
Since the customer did not share credentials (not negligent), and the breach was neither caused by the bank nor the customer (system vulnerability or third-party fraud), the case falls in the "third-party breach" category. Reported on the 5th working day (between 4-7 days), the customer's maximum liability is capped per the transaction-type limits set by RBI: Rs.10,000 for savings accounts for BSBD accounts, Rs.10,000 for other savings accounts. The bank bears the remaining loss.
Had the customer reported within 3 working days, liability would be zero. Had the customer shared OTP or credentials, full liability would rest on the customer regardless of reporting time. The bank must re-credit the disputed amount within 10 working days and resolve the complaint within 90 days.