India's GST Council is likely to consider, at an upcoming meeting, a proposal that would let central intelligence and investigative agencies, and State and Union Territory police, use NATGRID to access specified GST taxpayer data. MediaNama, relaying an anonymous senior official quoted by BusinessLine, reports that the data would flow through APIs giving agencies registered on NATGRID a structured way to pull disaggregated records. The report lists five categories: registration details including proprietors and business start dates; e-way bill details; inward and outward supplies over a specified period; PAN-based branch mapping for multi-branch companies; and supplies made through e-commerce platforms. The Council may separately consider letting the Statistics Ministry access certain taxpayer data.
This is a reported proposal, not a notified decision. That matters, because the details of any safeguards are what will decide whether it is defensible.
The strongest case for the proposal
The case for access is real. GST data is among the richest records of economic activity India holds. E-way bills trace goods in motion, and invoice-level supply data can expose shell companies, circular trading and the financing patterns behind organised crime and terror networks. NATGRID was conceived after the 26/11 Mumbai attacks to let authorised agencies query many databases in one place rather than file slow, siloed requests. Agencies already share some tax information: a July 2020 CBDT order opened PAN, TAN, bank account details and return summaries to ten agencies, conditional on the income-tax authority forming an opinion that sharing was necessary for the agency's legal functions (Business Today). A tax-fraud investigator who can query structured data in minutes is better placed than one waiting weeks for paper.
A country can legitimately want that capability. The question is the terms.
Why the terms matter more than the goal
Section 158 of the CGST Act, 2017 makes the particulars in returns, statements and documents confidential and bars disclosure, subject to listed exceptions. These include prosecutions, disclosure to the Central or State Government for carrying out the objects of the Act, and civil court proceedings (Section 158 text). Taxpayers hand over this data under a compulsory filing regime. They do so on the understanding that it serves tax administration. Routing it to police and intelligence bodies through a standing API changes the purpose of collection, which is the classic definition of function creep.
Three features of the arrangement make that risk concrete.
- Scale without scrutiny. MediaNama reports NATGRID handles about 45,000 data requests a month and classifies financial records as highly sensitive. Nothing in the reporting says how many GST queries would be permitted, who approves them, or whether a request must name a suspect or an offence. API access is built for volume, which is the opposite of case-by-case justification.
- No statutory anchor. The Internet Freedom Foundation's analysis records that NATGRID operates without a dedicated law, that the government said it had no plan to create one, and that its only oversight body is an internal audit committee headed by the Deputy National Security Advisor (IFF). MediaNama adds that it sits outside the Right to Information Act, so citizens cannot even ask how it is used.
- A weakened data-protection backstop. PRS Legislative Research notes that the Digital Personal Data Protection Bill, 2023 lets the central government exempt agencies by notification on grounds such as security of the state and public order, with no judicial oversight. It also drops the earlier drafts' requirement that exemptions be necessary, proportionate and backed by law (PRS). The data-protection regime therefore offers little protection against this kind of sharing.
The constitutional yardstick
In Justice K.S. Puttaswamy v. Union of India (2017) 10 SCC 1, a nine-judge bench held privacy to be a fundamental right. The Court said state interference must meet the tests of legality, a legitimate state aim and proportionality (CLPR summary). A policy decision by an executive-heavy council, implemented through technical access credentials, sits uneasily with the legality limb. Proportionality is harder still to show when five whole categories of taxpayer data are opened to a wide user base, including state police forces.
There is also an economic cost the proposal ignores. GST data covers every registered business, including millions of small firms and e-commerce sellers. If filing a return means exposing supplier networks and branch structures to many agencies, compliant businesses face new risks. A rival, a corrupt official or an overzealous investigator becomes a possible leak point. That chills formalisation, which is the opposite of what a pro-growth tax system should do.
A narrower design that keeps the benefit
Proportionate regulation does not mean refusing access. It means building the guardrails first:
- Put it in law. Amend the GST framework, or pass a NATGRID statute, to define permitted purposes, rather than rely on a Council recommendation.
- Tie queries to cases. Require a case or FIR reference and a named authorising officer for each query, and log every query.
- Add independent review. Give a judicial or independent authority power to audit logs and sanction misuse. An internal committee is not enough.
- Minimise the data. Offer registration and e-way bill data for serious offences before opening supply-level records. Keep the Statistics Ministry on aggregated or anonymised data.
- Disclose usage. Publish annual aggregate figures on GST queries by agency, as is routine in transparency reports elsewhere.
None of this stops investigators from catching fraud. It makes sure their access survives a constitutional challenge and does not erode trust in the tax system that supplies the data. The Council should treat the proposal as a drafting exercise for safeguards, not a switch to flip.