Vedik Bairwa and Awaneesh Kumar are fourth year students at Gujarat National Law University, Gandhinagar

A. Introduction

The Income Tax Bill, 2025 has proposed a sweeping expansion of power to state via a new inclusion of Clause 247, which stated that if a convict is fully inducted, it would grant tax authorities the ability to access an individual’s emails, social media accounts, cloud storage and even encrypted digital communications. This has raised alarms in terms of invasion of privacy, deep constitutional, legal, and ethical concerns. In addition to whether the income tax authorities even have such power to go ahead with Clause 247. The government is justifying this move as a necessary step, tackling tax evasions in this rapid growing digital economy.

Under the current legal framework, tax authorities already have substantial powers for investigation. As under Section 132 of the Income Tax Act, 1961, Income tax officials are permitted to search and seize financial records if they have “reasons to believe” that such undisclosed income exists with any individual. However, these searchers are usually limited to the physical premises and require authorities to establish “prima facie”justification, before they proceed with this search and seizer.

Unlike traditional search and seizure procedures, which require judicial authorization in many cases, Clause 247 would be operating primarily on an officer’s subjective determination or say intuition. This subjective determination raises fundamental concerns about legal arbitrariness, as the mere “subjective determination” aspect creates a high potential for abuse of power. The absence of a clear procedural safeguard, a defined threshold of suspicion or even a redressal mechanism, Makes the provision not only overboard but potentially unconstitutional.

B. Clause 247 and the Right to Privacy: Is It Too Invasive?

One of the most significant concerns pertaining to Clause 247 is its potential for violating right to privacy , which was declared a fundamental right under Article 21 via, K.S. Puttaswamy v. Union of India. This ruling laid down a a three-pronged test for the validity of any state intrusion into an individual’s privacy: (i) the restriction must be based on a legitimate state aim; (ii) it must be necessary and proportionate to achieve that aim; and (iii) it must be supported by a valid law that contains procedural safeguards.

Despite tax evasion being a legitimate concern, Clause 247 fails the proportionality test because it grants officials unrestricted access to digital data without the requirement to prove necessity. The provision doesn’t provide any distinguishing between routine tax inquires and for matter of serious tax fraud investigations, hence allowing tax officials to demand access to all digital communications without a clear threshold for suspicion. Another key issue is the absence of  procedural safeguards, which the Supreme Court has consistently held that state surveillance must be subject to judicial oversight to prevent arbitrariness and excessive state intrusion. Clause 247, however, contains no requirements to challenge wrongful access to their private digital data and without any clear procedural protections this provision runs the risk of being unconstitutional.

C. Unequal Application of Data Privacy Norms Between Private Firms and the State

The Digital Personal Data Protection Act (DPDPA), 2023, was enacted to regulate the collection, processing, and access to personal data in India. The law places strict restrictions, in terms of how private entities can handle digital data, requiring explicit consent before any personal information can be accessed. However, the law provides broad exemptions for government agencies, which herein creates a troubling inconsistency.

As per the law, private companies handling user data are mandated to comply with principles of necessity, proportionality, and purpose limitation. However, Clause 247 doesn’t impose any similar safeguard on the tax department. Private entities can’t access user emails without explicit consent, a tax officer on other hand via powers from Clause 247 could demand full access to an individual’s email accounts, cloud storage, or even encrypted chats without their consent. This legal disparity makes India’s data protection regime untrustworthy which indicates that the government is not subject to the same privacy standard, which it mandates for private firms.

Clause 247 comes out as double standard, as private players are tied down with rigorous compliance, while exempting state actors via discretionary power and limited regulatory oversight. This raises important questions about fairness and how much control the state should have over our personal information.

While Rule 5 in conjunction with Section 7(b) permits consent to be waived for delivering benefits or services, this should never be twisted into a license for unchecked surveillance. The glaring issue here is the complete absence an accountability framework for the government that even remotely matches what private companies have to face. Moreover, the centralization of enforcement authority under Section 19, the Data Protection Board (DPB), which is wholly appointed by the central government, significantly compromises its independence. This structural flaw makes the DPB little more than a puppet, incapable of regulating the state impartially. Enforcement turns into a discretionary tool wielded by those who should be regulated.

D. How Do Other Countries Regulate Government Access to Digital Data?

In other parts of the world, some countries have granted their tax authorities some level of digital access to combat tax evasion, but most democracies impose strict legal safeguards to prevent the abuse of power.In the United States, the Internal Revenue Service cannot access a taxpayer’s digital records without first obtaining a court approved warrant. The Fourth Amendment provides protection against unreasonable searches and seizures. The US SC in Carpenter v. United States (2018) reiterated that an access without a valid warrant to personal digital data violates constitutional privacy rights.

While, The European Union’s General Data Protection Regulation (GDPR), impose strict conditions for state agencies in case they are to access personal data. The law in the EU requires government agencies to justify their digital surveillance as strictly necessary and also to obtain judicial authorization before inspecting private digital records. In contrast, Clause 247 offers no obvious rationale system and no clear instructions on how collected digital data will be stored, used, or safeguarded against misuse. Absence of transparency and accountability systems raises severe concerns about government overreach and data misuse. Both the US and EU follows a highly restrictive approach. As under GDPR and national privacy laws, tax authorities can request access to digital information, but only under stringent conditions, which duly require specific judicial authorization and independent oversight. As a recent case study from Dutch shows how, tax department was fined €3.7 million. The Dutch Tax Administration’s Fraud Signalling Facility operated for 17 years, gathering detailed personal data such as income and marital status without a legal mandate. Later in April 2022, the Dutch Data Protection Authority imposed a €3.7 million fine on the agency for multiple violations of the GDPR. These infringements included processing data without statutory authority, lack of clarity regarding the system’s purpose, retention of inaccurate and outdated information, unlawful data retention periods, inadequate security protocols, and delayed consultation with the Data Protection Officer.

By Contrast, China and Russia have opted for a more authoritarian approaches, allowing government agencies unrestricted access to digital communications. China’s Golden tax system IV allows real time tracking of financial transactions and Russia’s Yarovaya Law grants security agencies full access to encrypted messaging services without any resections.

The lack of safeguards in proposed Clause 247 puts Indian tax surveillance model very close to these authoritarian regimes rather than the balanced approach existing in western democracies.

E. The Cost of Unchecked Tax Powers: Political, Economic, and Cybersecurity Risks

Beyond legal concerns, Clause 247 has significant risks of political misuse, economic fallout, and data security breaches. Historically, tax raids in India have been weaponized against opposition politicians, journalists, and activists. With unrestricted access to digital files, Clause 247 opens this door for a massive surveillance under the pretext of tax enforcement and since. As India has faced several large-scale data breaches, including the 2023 Telangana Police leak.

Economically, these unregulated surveillance laws may raise concerns among foreign investors.. Since Digital services trade relies heavily on the ability of organisations to process and transfer data across borders, Companies tend to favour jurisdictions with robust and predictable data protection norms. While this may not be an immediate deterrent India might lose heavily if companies would view these data regulations as antagonistic to privacy and corporate confidentiality. 

F. TACKLING TAX EVASION WITHOUT VIOLATING PRIVACY: A WAY FORWARD

While maintaining personal privacy, nations have indeed found a way where enforcement is made. Countries like Switzerland and Japan have successfully modernized this aspect. They have implemented Zero-Knowledge Proofs (ZKPs) and homomorphic encryption which allows government to access financial transactions without revealing raw personal data and, In South Korea, AI Driven public analytics are used which focuses on high-risk financial behaviours rather than indiscriminate surveillance. These approaches show cases the aspect, that indeed surveillance can be done without invading privacy of individuals.

The proposed Clause 247 in the Income Tax Bill raises serious concerns about state surveillance, privacy and constitutional rights. Right to Privacy is one of the most cherished fundamental rights guaranteed under the Constitution of India and hence, every law must pass its test. The absence of clear safeguards and judicial oversight echoes practices of authoritarian regimes rather than a balanced democratic approach. Such a provision provides blatant and arbitrary powers to the state. With potential risks which span to political misuse, economic deterrence, and cybersecurity vulnerabilities, unchecked tax powers threaten not only personal freedoms but also India’s global business reputation.  India should re-examine Clause 247, taking lessons from Switzerland and EU, which not only serves national interest but also constitutional rights of its citizen and fosters trust in governmental institutions.

Share this post