Bank Account Issue · 9 min read · 13 min 44 sec listen · Published 22 July 2026

Your Bank Is Sharing Your Data — Here's How to Stop It Under Indian Law

Learn how to stop banks from sharing your personal data for marketing under Indian law. Know your rights, legal sections, and practical steps.

Your Bank Is Sharing Your Data — Here's How to Stop It Under Indian Law
One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

TL;DR: Yes, you can opt out. Banks must give you a choice under the Information Technology Act, 2000 rules. Send a written opt-out request, and if ignored, approach the Banking Ombudsman. You also have the right to know exactly what data they share.

Key Facts of the Case

  • A 19-year-old client opened a savings account with a public sector bank in Pune — similar to Central Bank of India — in March 2025.
  • The bank's privacy policy stated it shared customer data with third parties for marketing and analytics.
  • The client was not informed at account opening about the data sharing or opt-out option.
  • No prior consent was taken for sharing personal data like name, email, birth date, or spending patterns.
  • The client approached the Chamber of Advocate Sudhir Rao after reading the privacy policy online.
  • Advocate Sudhir Rao's office sent a formal written notice to the bank under Rule 5 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
  • The bank responded within 30 days confirming the opt-out and provided a list of data categories shared.
  • The client's account remained active, and no services were discontinued.
Can a bank share my personal data without my consent?

No, not without your clear consent. Under Rule 5 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, a body corporate — including banks — must obtain written consent before collecting or sharing sensitive personal data. And here's the thing: they must also give you an option to withdraw consent at any time.

What data are they sharing?

You have the right to know. The bank must, on request, tell you exactly what personal information they share, with whom, and for what purpose. Under the same Rules, if you ask in writing, they must respond within a reasonable time — typically 30 days.

How do I opt out?

Write a formal letter or email to your bank's branch manager or grievance officer. State clearly that you withdraw consent for sharing data with third parties for marketing or analytics. Mention the IT Rules, 2011. Keep a copy. If they don't act within 30 days, escalate to the Banking Ombudsman.

Advice in Such Cases

Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Make no mistake — this area of law involves nuanced distinctions between "personal data" and "sensitive personal data." Banks often argue that marketing data isn't covered. An advocate who handles data protection and banking matters regularly will spot these arguments and counter them effectively. General practitioners may overlook the specific IT Rules or fail to frame the complaint properly before the Banking Ombudsman.

Also, always send your opt-out request by registered post or email with read receipt. This creates a paper trail — crucial if you need to escalate later.

Applicable Sections of Law

This is a civil regulatory matter, not a criminal case. Key legal provisions apply:

  • Rule 5, Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — mandates consent for data collection and sharing, and gives opt-out rights.
  • Section 43A, Information Technology Act, 2000 — imposes liability for failure to protect sensitive personal data, with compensation for damages.
  • Banking Ombudsman Scheme, 2006 — Clause 8 covers complaints relating to non-adherence to RBI fair practices codes, including data privacy breaches.
  • Reserve Bank of India's Master Direction on Digital Payment Security Controls, 2021 — requires banks to protect customer data and limit third-party sharing.

Punishment and Penalties

This is a civil case. No criminal punishment applies. However, if the bank fails to comply with the IT Rules, you can claim compensation under Section 43A IT Act for negligence in data protection. The Banking Ombudsman can also award compensation up to Rs. 20 lakh for loss or inconvenience caused by the bank's deficiency in service. Repeated violations may attract RBI penalties on the bank itself.

Jurisdiction — Where to File the Case

For initial complaints, write to the bank's internal grievance officer. If unresolved in 30 days, escalate to the Banking Ombudsman of your state. The Ombudsman has jurisdiction over all scheduled commercial banks and can pass binding orders. For compensation claims, you can file a civil suit in the district court where the bank branch is located. Pecuniary jurisdiction follows the amount claimed — for claims under Rs. 20 lakh, it's usually the civil judge (junior division). For higher amounts, the district court.

Limitation Period

Under the Limitation Act, 1963, the period for filing a civil suit for compensation is three years from the date the cause of action arises. The clock starts ticking when the bank refuses your opt-out request or shares your data without consent. For Banking Ombudsman complaints, the limitation is one year from the date of the bank's final response or six months from the date of the incident if no response. Missing these deadlines can be fatal. Courts may condone delay only in exceptional circumstances.

Interim Reliefs Available

Yes, interim reliefs matter here. You can seek a temporary injunction under Order 39 Rule 1 CPC to restrain the bank from sharing your data until the final hearing. This is especially useful if the data sharing is ongoing and causing you harm — like spam calls or identity risks. You can also seek an attachment before judgment under Order 38 CPC if you suspect the bank may destroy records. A status quo order can preserve the evidence of the data sharing practice. But remember, these are discretionary. Courts grant them only when you show a prima facie case, balance of convenience, and irreparable injury.

If You Are the Victim

  • Immediately read your bank's privacy policy and note the data-sharing clauses.
  • Send a written opt-out request via registered post or email with acknowledgment.
  • Ask the bank in writing for a list of all data shared with third parties and their names.
  • Save all correspondence — emails, letters, bank responses, and the policy screenshots.
  • If ignored or denied, escalate to the Banking Ombudsman using Form 1 under the Scheme.

Documents You Must Keep Ready

  • Copy of your bank account statement and account opening form
  • Printout or screenshot of the bank's privacy policy
  • All correspondence with the bank — letters, emails, and replies
  • Proof of sending the opt-out request — registered post receipt or email send confirmation
  • Any spam calls or messages that trace back to the bank's data sharing (record call logs, SMS screenshots)
  • Your Aadhaar, PAN, and identity proof for verification
  • Bank's grievance redressal reference number, if any

What Evidence Is Required?

  • The bank's privacy policy clearly stating data sharing with third parties
  • Proof of your written opt-out request sent to the bank
  • The bank's response — or silence — showing refusal or inaction
  • Any direct evidence of your data being used by third parties (e.g., marketing calls from companies you never contacted)
  • Correspondence showing the bank did not inform you of opt-out options at account opening

How Courts Typically Approach Such Cases

Civil courts and the Banking Ombudsman treat these as deficiency in service and breach of contract. Courts examine whether the bank obtained valid consent under the IT Rules. They also check if the bank gave a clear, upfront opt-out mechanism. The burden of proof often shifts to the bank to show it complied with consent requirements. If the bank fails to produce evidence of customer consent, courts presume the data sharing was unauthorized. Courts also weigh the sensitivity of the data — spending habits and birth dates are considered less sensitive than passwords or financial account numbers, but still protected.

  • Day 1: Send opt-out letter to bank. Wait 30 days for response.
  • Day 31: If no response, file complaint with Banking Ombudsman. Ombudsman takes 30-45 days for preliminary response.
  • Month 2-4: Ombudsman hears both sides, may pass award within 60 days of receipt of complete documents.
  • Month 5-6: If unsatisfied, appeal to RBI Deputy Governor within 30 days of award.
  • Month 7-12: If still unresolved, file civil suit. Trial may take 6 to 18 months depending on court workload.
  • Appeal: A district court decree can be appealed to the High Court within 30 days, adding 6 to 12 months.

Understanding the Costs

The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.

A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.

Can the Matter Be Settled Out of Court?

Absolutely. Banks often prefer to settle data privacy complaints internally to avoid regulatory scrutiny. You can engage in mediation or go to Lok Adalat for a binding settlement. For Banking Ombudsman complaints, the bank may agree to stop sharing data and issue an apology or token compensation. If the matter is already in civil court, you can file a compromise deed under Order 23 CPC and close the case. Settlement is advisable when the bank acknowledges the breach and agrees to your terms — you save time and legal costs. Just ensure the settlement includes a written undertaking to not share your data in future.

Common Mistakes People Make

  • Not reading the privacy policy before signing the account opening form — many tick boxes agreeing to data sharing without realizing it.
  • Ignoring the problem and doing nothing — data sharing continues and can lead to spam, phishing, or identity theft.
  • Engaging a lawyer who does not regularly handle data protection or banking matters — these cases involve specific IT Rules and RBI circulars that a non-specialist may miss, leading to weak arguments or missed deadlines.
  • Sending an opt-out request verbally or by casual email without proof — courts and Ombudsman need documentary evidence.
  • Posting about the issue on social media before consulting a lawyer — this can prejudice your case or alert the bank to destroy records.
  • Assuming the Banking Ombudsman has unlimited powers — it can award compensation but cannot order criminal prosecution.

FAQs People Normally Have

Is this a criminal case?

No. Unauthorized data sharing by a bank is a civil wrong — breach of contract and deficiency in service. It is not a criminal offence unless there is hacking or fraud, which is rare in these scenarios.

Can my bank close my account if I opt out?

No. Banks cannot penalize you for exercising your legal right. If they threaten account closure, escalate to the Banking Ombudsman immediately.

How do I know if my data has been shared?

Ask the bank in writing. They must respond within a reasonable time. Also check if you get unsolicited calls, emails, or SMS from marketing companies you never contacted.

Can I demand compensation?

Yes, if the data sharing caused you actual harm — like financial loss or harassment from spam calls. The Banking Ombudsman can award up to Rs. 20 lakh. Civil courts can award higher damages based on the harm proved.

Do these rules apply to private banks too?

Yes. The IT Rules, 2011 and the Banking Ombudsman Scheme apply to all scheduled commercial banks — both public and private sector. Co-operative banks have a separate Ombudsman scheme.

This article is general legal information, not legal advice. Consult a qualified advocate about your specific situation.

Advocate Sudhir Rao, Supreme Court of India

Was this article useful?

/5 (0 ratings)