LHC declares banking data as property
Rules misuse of customer data may invite criminal breach of trust charges

In a landmark ruling defining the legal status of digital banking data, the Lahore High Court (LHC) held that customer data entrusted to bank employees constitutes "property" under the Prevention of Electronic Crimes Act (PECA), 2016the country's cybercrime law.
The court noted that a bank employee who has functional control over such data can, in appropriate circumstances, will be prosecuted for criminal breach of trust under Section 409 of the Pakistan Penal Code (PPC).
However, it clarified that Section 409 would not automatically apply to every bank employee, but only to those entrusted with or exercising dominion over customer data as part of their banking functions.
Justice Tariq Saleem Sheikh announced the ruling while dismissing the post-arrest bail petition of UBL Branch Services Supervisor Muhammad Atif and granting bail to Muhammad Usman, who was allegedly linked to a Jazz franchise, in a high-profile SIM-swap banking fraud case.
The National Cyber Crime Investigation Agency (NCCIA) was the prosecution in the case.
The case originated from complaints received by the Pakistan Telecommunication Authority (PTA) that duplicate SIM cards had been fraudulently issued against customers' Computerised National Identity Cards (CNICs) and subsequently used to gain access to their UBL mobile banking accounts.
According to investigators, the fraudsters blocked victims' original SIM cards, activated duplicate SIMs through a Jazz franchise, registered new devices and transferred more than Rs10.45 million from six bank accounts.
During a raid on the franchise, NCCIA and PTA officials recovered SIM scanners, a biometric verification system (BVS) device, computers and around 150 suspicious SIM cards.
In its judgment, the court rejected the defence argument that offences under the PPC could not be invoked alongside PECA, holding that the two laws can operate simultaneously where the ingredients of offences under both statutes are established.
The court observed that PECA supplements rather than excludes the PPC in such cases.
It further ruled that PECA expressly treats information systems and data as "property" for offences relating to property, making confidential customer banking information capable of attracting criminal breach of trust provisions where it is dishonestly misused.
It held that a bank employee entrusted with customer data may fall within the ambit of Section 409 PPC if his assigned functions confer authority or dominion over such data in the course of banking business.
Examining Muhammad Atif's role, it noted that he served as branch services supervisor at UBL's District Courts Jhang branch and, according to internal bank reports and the investigation, had accessed confidential customer information through the bank's system without a satisfactory explanation.

















1727268465-0/Untitled-design-(42)1727268465-0-208x130.webp)

COMMENTS
Comments are moderated and generally will be posted if they are on-topic and not abusive.
For more information, please see our Comments FAQ