LHC Declares Bank Customer Data a Form of Legal Property

LHC Declares Bank Customer Data a Form of Legal Property

The Lahore High Court (LHC) has ruled that customer data held by a bank can be considered “property” under Pakistani law. The court also stated that the dishonest use or disclosure of such information may, in certain circumstances, amount to criminal breach of trust.

Justice Tariq Saleem Sheikh gave the ruling while deciding bail applications in a case involving an alleged SIM-swap fraud. The case involved the alleged use of customers’ Computerised National Identity Cards (CNICs) and fingerprints to obtain duplicate SIM cards. According to the investigation, the fraud resulted in unauthorised transfers of approximately Rs10.45 million from the accounts of six customers.

The National Cyber Crime Investigation Agency (NCCIA) registered the case in connection with the alleged fraud. The investigation focused on the suspected misuse of customer information, including registered mobile numbers, which was allegedly used to facilitate the fraudulent SIM replacements and subsequent access to bank accounts.

Customer Information and the Law

According to the court, information maintained by banks, such as account details and registered mobile numbers, falls within the definition of “data” under the Prevention of Electronic Crimes Act (Peca). The court referred to Section 27(2) of Peca, which treats certain forms of electronic data as property for offences relating to property under the Pakistan Penal Code (PPC).

The court explained that when such information is entrusted to a bank employee, dishonest disclosure or unauthorised use of the data can potentially constitute criminal breach of trust. The ruling also highlighted the confidentiality responsibilities associated with employment in the banking sector.

The court further referred to Section 33A of the Banking Companies Ordinance, 1962, in relation to the confidentiality obligations connected with banking information.

LHC Declares Bank Customer Data a Form of Legal Property

Justice Sheikh observed that modern banking depends heavily on electronic systems. Customers’ money is accessed, verified and protected through digital information and authentication systems.

Because of this, a person who has control over important customer information may, in practical terms, have the ability to facilitate access to the customer’s funds. Therefore, the court considered the protection of customer data an important part of protecting customers’ financial assets.

However, the court clarified that every bank employee who can access customer information cannot automatically be charged under Section 409 of the PPC.

Functional Role of Bank Employees

The court stated that a functional test should be used to determine whether Section 409 PPC applies to a particular employee. The provision may apply when an employee is entrusted with, or exercises control over, customer funds or important customer information used for access, verification, authentication or banking transactions as part of their official duties.

Employees whose access to such information is only incidental or occasional would not automatically fall within the scope of this provision.

Case Against the Bank Employee

In the case of bank employee Muhammad Atif, the court found that the available investigation material provided sufficient grounds to proceed against him at the bail stage.

The material reportedly included investigation records, internal fraud reports prepared by the bank and account-access logs. According to the allegations, Atif had disclosed customers’ registered mobile numbers, which helped facilitate the alleged SIM-swap fraud.

The court therefore concluded that Section 409 PPC was prima facie applicable to the allegations against him and rejected his post-arrest bail request.

Bail Granted to Franchise Operator

The court reached a different conclusion in the case of Muhammad Usman, who was allegedly associated with the cellular company franchise where the duplicate SIM cards were issued.

The prosecution alleged that Usman managed the franchise. However, Justice Sheikh found that the available evidence did not sufficiently establish his connection with the disputed SIM activations, alleged manipulation of the biometric verification system, or assistance in the dishonest use of customer data.

The court considered the allegations against Usman a matter requiring further inquiry. As a result, he was granted post-arrest bail against surety bonds of Rs1 million.

Final Verdict:

The Lahore High Court’s ruling highlights the growing legal importance of customer information in modern banking. The decision indicates that bank-held customer data may receive legal protection similar to property when it is entrusted to employees and is misused for fraudulent purposes.

At the same time, the court made it clear that criminal liability cannot be imposed on every bank employee simply because they have access to customer information. Their actual responsibilities, level of control and connection with the alleged misuse must be examined.

The ruling therefore emphasizes both the importance of protecting banking data and the need to establish an employee’s specific role before applying criminal breach of trust provisions.

Mobile Phone Taxes Portal

Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.

Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).

Explore NowFollow us on Google News!

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *