India data protection and state surveillance

Opening GST Data to NATGRID Would Turn a Confidentiality Duty Into a Surveillance Feed Without a Statutory Guardrail

A proposal to give intelligence agencies and police API access to GST taxpayer data needs a legal basis, independent oversight and narrow scope first.

NATGRID and GST Data: The Numbers People of Internet Research · India 5 GST data categories proposed Registration, e-way bills, supplie… ~45,000 NATGRID monthly data requests Current volume of requests process… 10 Agencies in 2020 CBDT order Agencies given income-tax data via… peopleofinternet.com
NATGRID and GST Data: The Numbers People of Internet Research · India 5 GST data categories propo… ~45,000 NATGRID monthly data requests 10 Agencies in 2020 CBDT order peopleofinternet.com

Key Takeaways

India's GST Council is likely to consider, at an upcoming meeting, a proposal that would let central intelligence and investigative agencies, and State and Union Territory police, use NATGRID to access specified GST taxpayer data. MediaNama, relaying an anonymous senior official quoted by BusinessLine, reports that the data would flow through APIs giving agencies registered on NATGRID a structured way to pull disaggregated records. The report lists five categories: registration details including proprietors and business start dates; e-way bill details; inward and outward supplies over a specified period; PAN-based branch mapping for multi-branch companies; and supplies made through e-commerce platforms. The Council may separately consider letting the Statistics Ministry access certain taxpayer data.

This is a reported proposal, not a notified decision. That matters, because the details of any safeguards are what will decide whether it is defensible.

The strongest case for the proposal

The case for access is real. GST data is among the richest records of economic activity India holds. E-way bills trace goods in motion, and invoice-level supply data can expose shell companies, circular trading and the financing patterns behind organised crime and terror networks. NATGRID was conceived after the 26/11 Mumbai attacks to let authorised agencies query many databases in one place rather than file slow, siloed requests. Agencies already share some tax information: a July 2020 CBDT order opened PAN, TAN, bank account details and return summaries to ten agencies, conditional on the income-tax authority forming an opinion that sharing was necessary for the agency's legal functions (Business Today). A tax-fraud investigator who can query structured data in minutes is better placed than one waiting weeks for paper.

A country can legitimately want that capability. The question is the terms.

Why the terms matter more than the goal

Section 158 of the CGST Act, 2017 makes the particulars in returns, statements and documents confidential and bars disclosure, subject to listed exceptions. These include prosecutions, disclosure to the Central or State Government for carrying out the objects of the Act, and civil court proceedings (Section 158 text). Taxpayers hand over this data under a compulsory filing regime. They do so on the understanding that it serves tax administration. Routing it to police and intelligence bodies through a standing API changes the purpose of collection, which is the classic definition of function creep.

Three features of the arrangement make that risk concrete.

The constitutional yardstick

In Justice K.S. Puttaswamy v. Union of India (2017) 10 SCC 1, a nine-judge bench held privacy to be a fundamental right. The Court said state interference must meet the tests of legality, a legitimate state aim and proportionality (CLPR summary). A policy decision by an executive-heavy council, implemented through technical access credentials, sits uneasily with the legality limb. Proportionality is harder still to show when five whole categories of taxpayer data are opened to a wide user base, including state police forces.

There is also an economic cost the proposal ignores. GST data covers every registered business, including millions of small firms and e-commerce sellers. If filing a return means exposing supplier networks and branch structures to many agencies, compliant businesses face new risks. A rival, a corrupt official or an overzealous investigator becomes a possible leak point. That chills formalisation, which is the opposite of what a pro-growth tax system should do.

A narrower design that keeps the benefit

Proportionate regulation does not mean refusing access. It means building the guardrails first:

None of this stops investigators from catching fraud. It makes sure their access survives a constitutional challenge and does not erode trust in the tax system that supplies the data. The Council should treat the proposal as a drafting exercise for safeguards, not a switch to flip.

Sources & Citations

  1. MediaNama: GST Council may allow NATGRID access to taxpayer data
  2. PRS Legislative Research: Digital Personal Data Protection Bill, 2023
  3. CGST Act, 2017, Section 158 (text)
  4. Internet Freedom Foundation: Watch the Watchmen, NATGRID
  5. Business Today: I-T dept to share PAN, bank details with 10 agencies under NATGRID
  6. CLPR: Puttaswamy v. Union of India (2017) 10 SCC 1