Income-tax Act 2025

Section 247(1)(b)(iii), IT Act, 2025 allows an authorised officer to override access codes to reach any computer system or “virtual digital space” when the code is not available.

Introduction

The income tax regime in India underwent a significant change in 2025 through the enactment of the Income-tax Act, 2025 (IT Act, 2025), which came into force on 1 April 2026.1 Among its most contested features is the expansion of the “search and seizure” powers under Section 247(1)(b)(iii), IT Act, 2025, which now extends beyond physical premises to include virtual digital space (VDS).

Under the earlier Income-tax Act, 1961 (IT Act, 1961), such powers were confined largely to physical searches.2 By contrast, Section 247(1)(b)(iii), IT Act, 2025 allows an authorised officer to override access codes to reach any computer system or “virtual digital space” when the code is not available. The term VDS is further defined in Section 261(j), IT Act, 2025 as a non-physical space created and accessed through computers where people interact, and perform activities through computer systems, communication devices, cyberspace, the World Wide Web, storage or exchange of electronic information. It will include social media accounts, online investment accounts, remote servers/cloud servers, email servers, and other similar internet-based platforms, networks and devices.3

The author in this blog compares the provisions of search and seizure under the IT Act, 1961 and the IT Act, 2025, and analyses the legislative intent behind the expansion in the definition of search and seizure. The paper then enters into a critical analysis of such expansion and does a comparative analysis with the practices of the United States, the United Kingdom, and Australia. The paper finally lays down the best practices that can be followed while retaining the legislative intent.

Expansion in the power of search and seizure and the rationality behind it

A. Comparison of Section 132, IT Act, 1961 and Section 247, IT Act, 2025

Section 132, IT Act, 1961 defines search and seizure. It authorises the designated officers to conduct searches, inspect records, and seize books of account, documents, money, bullion, jewellery, or other valuable articles where there is a reason to believe that a person has failed to disclose income or is in possession of undisclosed assets. This clearly is limited to physical search and seizure. As aforesaid, the new IT Act, 2025 has expanded the definition of search and seizure under Section 247(1)(b)(iii). It empowers the authorised income tax officers to undertake search and seizure operations where they have a “reason to believe”4 that a person is in possession of undisclosed income, or assets, or documents, or information relevant to proceedings. It permits the authorised officer to—

break open the lock of any door, box, locker, safe, almirah, or other receptacle or override the access code to any computer system for exercising the powers conferred by clause (i) where the keys thereof are, or the access to such building, place, etc., or the access code to such computer system, as the case may be, is not available.

Further, the authorised officer under Section 247, IT Act, 2025 are approving authority, Joint Director/Joint Commissioner, Assistant Director/Assistant Commissioner, Income Tax Officer.5 The approving authority further includes Principal Director General or the Director General; or the Principal Chief Commissioner or the Chief Commissioner; or the Principal Director or the Director; or the Principal Commissioner or the Commissioner.6 The authorised officer under Section 247, IT Act, 2025 and Section 132, IT Act, 1961 are identical.

Section 247(5) further states that the authorised officer may order the services of (a) any police officer or any officer of the Central Government, or both; or (b) any person or organisation approved by the Principal Chief Commissioner, Chief Commissioner, Principal Director General, or Director General, following the prescribed procedure.7

Such officers, persons, or organisations must assist the authorised officer, and it is their duty to comply with the request.

B. Rationality behind such expansion in the definition of search and seizure

The memorandum that has explained the provisions in the Finance Bill, 2025 did not explain the reason for permitting tax officers to enter into VDS for search and seizure. However, the government has taken the stand that tax authorities often face challenges in detecting concealed income and undisclosed transactions occurring through online wallets, crypto-assets, or offshore accounts.8 The IT Act, 2025 closes the issue of tax evasion in the virtual arena by ensuring that it can be investigated similar to physical records.

During the parliamentary debate on the Income-Tax Bill, 2025, Union Finance Minister, Nirmala Sitharaman, defended the inclusion of powers by citing instances where digital evidence had played a crucial role in uncovering tax evasion. She stated that WhatsApp communications9 enabled authorities to trace approximately Rs 200 crores of unaccounted money linked to crypto-assets, while encrypted messages recovered from mobile devices contributed to the detection of even larger amounts of undisclosed income. She added that the investigators had relied upon Google Maps location history to identify locations frequently visited by taxpayers, which ultimately led to the discovery of cash hideouts and undisclosed transactions. Similarly, the analysis of Instagram accounts was reportedly used to establish beneficial ownership of assets and detect instances of benami property holdings.10 These scenarios were mentioned to assert that modern tax evasion increasingly leaves a digital footprint across communication platforms, social media accounts, and location-based services, thus necessitating the expansion of search and seizure powers into the VDS.

International Reports

Various reports of transnational institution support the stand taken by the government. The International Monetary Fund (IMF) Report states that the crypto-assets has posed serious challenges for tax systems due to their rapid growth and pseudonymity.11 The governments are struggling to tax these assets effectively, risking revenue losses and weakening tax enforcement. The core challenge is crypto’s pseudonymity, which makes it hard to trace users. The Financial Action Task Force (FATF) also explicitly warns that the anonymity of virtual assets attracts criminals, who have used virtual assets to launder proceeds from a range of offences.12 Further, in March 2018, the inclusive framework on Base Erosion and Profit Shifting (BEPS) issued tax challenges arising from digitalisation — interim report 2018 (the interim report) (OECD, 2018), which was presented to the G20 finance ministers and it noted the importance of the tax evasion risks associated with virtual currencies and indicated that further work would be needed in this area.13

Critical analysis of the expansion of search and seizure

The inclusion of VDS within the definition of “search and seizure” has attracted significant criticism from the public and legal commentators alike. In this section, the author examines the implications of this expansion on multiple dimensions, including privacy rights, the scope of State surveillance, procedural safeguards, and the practical enforcement powers of tax authorities. It also assesses whether the broadened definition creates greater administrative efficiency or, conversely, opens the door to arbitrary intrusion into digital spaces.

A. Expansion in the statutory presumptions under Sections 132(4-A) and 292-C, IT Act, 1961

The expansion in the definition of search and seizure to include VDS has correspondingly enlarged the scope of the statutory presumptions under Sections 132(4)(a) and 292-C, IT Act, 1961. These provisions now operate not only in relation to physical books of account and documents, but also to electronic records, digital content, communications, and data found on computer systems and other virtual platforms. The impact is that if any material is discovered in the course of a search, it may be presumed that it belongs to the person in control or possession of it, its contents are true, and the relevant signatures, handwriting, execution, or attestation are genuine, thereby strengthening the evidentiary reach of search proceedings in the digital era.

B. Blanket power to tax authorities

Section 247(1), IT Act, 2025 states that the tax authorities can do search and seizure when they have a “reason to believe”, however, there is no threshold defined for reason to believe. This gives room for subjective discretion. Section 249, IT Act, 2025 further adds to this by stating that the reason to believe shall not be revealed to any person or authority including the Appellate Tribunal. Further, Section 247(5), IT Act, 2025 states that the authorised officer may order the services of any police officer or any officer of the Central Government or any person or organisation approved by approving authorities. There is no qualification in the provision as if these service provider under this section are qualified enough to handle the digital evidence.

C. Violation of legal framework

Passwords are termed as sensitive personal data under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and it is mandatory to take free consent before their collection and usage.14 The Digital Personal Data Protection Act, 2023 requires that notices be issued to the data principal, informing them of the purpose for which their data is being processed.15 The overriding of legally mandated provisions may undermine the Rule of Law.

In K.S. Puttaswamy (Privacy-9J.) v. Union of India16, the Supreme Court affirmed that the right to privacy is a fundamental right and held that any infringement of this right must satisfy a fourfold test, i.e. first, it must be authorised by law; second, it must pursue a legitimate aim in a democratic society; third, the extent of interference must be proportionate to the objective sought to be achieved; and fourth, it must be accompanied by adequate procedural safeguards.

Although Section 247, IT Act, 2025 may satisfy the requirements of legal sanction and legitimate purpose, namely, curbing tax evasion, it may fall short of the proportionality and procedural safeguard standards. The IT Act, 2025 does not provide sufficient safeguards to ensure that searches are carried out in a manner that adequately protects individual privacy.

A public interest litigation (PIL) Vishwaprasad Alva v. Union of India17, was filed in the Supreme Court challenging the inclusion of VDS into the regime of search and seizure without any proper safeguard. However, the court dismissed the petition after observing that the existing search and seizure law already had safeguards, such as recording reasons before authorising a raid and allowing limited judicial review. The Bench held that it should not interfere with Parliament’s policy choice because the petitioner argued for the possibility of a better design. The court also stated that the advance notice in digital searches would let people delete or hide evidence before officials could act. It also accepted that these powers are meant to deal with serious tax evasion, though it acknowledged that misuse is possible. The petition was therefore dismissed as withdrawn, with liberty to approach the government by representation, so the larger constitutional questions remain open.

D. Silence on critical issues

The IT Act, 2025 does not address several important issues, including the time period for data retention, the permissible extent of its reuse, and the scope of sharing with other government agencies. It also does not lay down any mechanism for grievance redressal or independent oversight. These omissions leave significant aspects of data governance unregulated.

Comparative jurisdiction: Learning the best practices

In this section, the author undertakes a comparative analysis of the power of search and seizure under tax law as it operates in other jurisdictions. The objective is to identify procedural safeguards and institutional best practices that may be adapted into the existing Indian framework without discarding the legislative intent behind the introduction of VDS. The comparison is restricted to three jurisdictions: the United States, the United Kingdom, and Australia. These jurisdictions have been selected because they are established democratic legal systems and, in varying ways, incorporate protections for individuals when authorised officers exercise search and seizure powers in relation to digital or virtual spaces. By examining these legal frameworks, the section seeks to determine whether the Indian regime can be refined to better balance enforcement efficiency with constitutional and procedural safeguards.

A. United States

The Fourth Amendment protects the right to be secure against unreasonable searches and seizures and mandates the Internal Revenue Service (IRS) Criminal Investigation Officers are authorised to execute judicial search warrants under 26 U.S.C. §7608 for the seizure of digital content if the taxpayer does not consent voluntarily.18 These warrants require probable cause of tax-evasion evidence, supported by Oath or affirmation.19 This probable cause must be included in the written affidavit and it must be shown that the evidence seized must have a rational nexus with the criminal offence under tax. The warrant must particularly describe the place to be searched, and the persons or things to be seized as advised by the Computer Investigative Specialist.20 The fact that a warrant must clearly mention the exact place to be searched and the things to be seized helps to stop broad and random searching of someone’s property, which is what Section 247, IT Act, 2025 allows.

Section 9.4.9 of the IRS Internal Revenue Manual (United States) requires that, at each stage, officers obtain formal authorisation from a prosecutor or Judge before seeking access to digital records. Once authorisation is granted, a preservation letter must be sent immediately to the service provider so that no data is deleted or altered.21 Every approval must also be documented, including the identity of the approving authority, the time of approval, and the manner in which the data was retrieved or copied.

The Manual further emphasises the need to maintain a proper chain of custody.22 Every item of evidence, including hard drives, USB devices, printouts, and digital files, must be assigned a unique label recording the date and time of collection, the place of collection, and the identity of the person who handled it.

B. United Kingdom

There is no formal distinction between civil and criminal investigation under Section 247, IT Act, 2025. In contrast to this, in UK we see the two different routes in the civil and criminal investigation.

The civil route is under Schedule 36 of the Finance Act, 2008 (UK) which empowers His Majesty’s Revenue and Customs (HMRC) to request information which they believe is reasonably required23 from taxpayers to check their tax position. Section 247, IT Act, 2025 contains no equivalent “reasonably required” standard. The officer’s “reason to believe” concerns whether a search may be started at all, not how far the access may extend once the search has begun. This gives them a huge discretionary power to almost ask for anything under the sun.

If the HMRC does not get a response from the taxpayer for the information they have asked then they can issue Schedule 36 notice24. In case the request made does not meet the legal test, i.e. the reasonable requirement and the information must be in possession of the taxpayer then the taxpayers have the right to appeal the notice.25 Third party notices26 to intermediaries such as banks can only be issued with the consent of the taxpayer or approval of the Tribunal.

Similar to IRS Internal Revenue Manual (United States), the UK’s HMRC Internal Manual specifically EM2809 states that if it is necessary to inspect the computer system then only an “authorised person”27 can carry out this kind of computer check. This means a trained HMRC officer or a specialist consultant hired by HMRC. Officers must be satisfied that such checks are both proportionate in scope and reasonably required for the audit. If a taxpayer or operator refuses to provide or permit inspection of the relevant computer records during an authorised inspection, HMRC may copy or remove the data28 in the same manner as any other relevant document but only under an inspection notice29 that has been approved by a Tribunal30

The investigation can escalate from civil to criminal. Section 8, Police and Criminal Evidence Act, 1984 (PACE) authorises HMRC to do search.31 Under this framework, a judicial search warrant has to be obtained and the reason for its issuance must be specified.

If HMRC uncovers evidence of serious tax fraud, it may forward the case to the crown prosecution service (CPS), which will decide whether to bring criminal charges.32 The decision to prosecute is made by CPS entirely independent of HMRC. In India, the same institution that conducts the digital search, i.e. the Income Tax Department also drives the subsequent proceedings.

C. Australia

The Australian Taxation Office (ATO) is empowered under the Taxation Administration Act, 1953 to require the production of documents and to inspect records at a taxpayer’s premises.33 The Act authorises officers to enter business premises at all reasonable times, ordinarily during business hours, upon prior notice34 to the taxpayer. Only in exceptional circumstances, where there is a genuine risk that records may be destroyed or concealed, may entry be affected without advance warning. Upon request, the officer must produce an inspection notice signed by the Commissioner, and failure to do so may invalidate the officer’s authority to remain on the premises.35

The powers of inspection are confined to the examination, copying, photographing, or testing of books, documents, goods, and electronic records that are directly relevant to the tax matters under investigation.36 The taxation officers are required to protect the confidentiality of the information given by taxpayers.37 The disclosure is permitted only in one situation and, i.e. when the public benefit derived from the disclosure outweighs the privacy of the taxpayer.38 The information is also subject to the privacy policy of ATO in such a way that it aligns with the Privacy Act, 1988 (AU).

A clear delineation between civil or administrative and criminal investigative functions must be maintained if criminal investigation powers are granted to the ATO. Even though the ATO has broad administrative information-gathering powers, it cannot itself obtain or execute search warrants.39 The Australian Federal Police (AFP) or State police execute warrants in case of criminal investigation.40 It means that the most intrusive enforcement action requires the involvement of at least two institutions, i.e. the ATO and the AFP. A single officer cannot unilaterally authorise and execute a digital search in Australia as Section 247 permits in India.

Recommendations

The expansion of search and seizure powers to include VDS should be accompanied by a more structured framework. The recommendations in this section are drawn from the comparative analysis in the previous chapter. At present, Section 247, IT Act, 2025 grants wide discretion to tax authorities through the vague standard of “reason to believe”, without defining its threshold or requiring meaningful disclosure. This creates the risk of arbitrary or excessive intrusion into digital privacy. The law should therefore prescribe a clearer and objective test for initiating search and seizure, along with a requirement that reasons be recorded in writing and subjected to limited but effective review by an independent authority.

Further, the statute should incorporate express safeguards for digital evidence. Only trained and qualified officers, or technically certified experts, should be permitted to access, collect, copy, and handle electronic records. A chain-of-custody protocol should be made mandatory to preserve evidentiary integrity. The law should also require prior judicial or quasi-judicial authorisation for highly intrusive digital searches, especially where passwords, private communications, or cloud-based data are involved.

In addition, the Act should expressly regulate the reuse, and inter-agency sharing of data collected during search proceedings. There should also be an independent grievance redressal mechanism for taxpayers, along with post-search oversight to ensure accountability.

Comparative practice from the United States, the United Kingdom, and Australia shows that effective tax enforcement can coexist with procedural safeguards, specialisation, and proportionality. India should adopt a similar model by ensuring that the power to investigate digital tax evasion remains strong, but not unbounded. The objective should be to preserve the effectiveness of tax administration while bringing the law into closer alignment with constitutional guarantees of privacy, fairness, and due process.

Conclusion

The inclusion of VDS within the scope of search and seizure marks a significant transformation in tax enforcement. It reflects the practical reality that evidence of tax evasion increasingly exists in digital form and cannot be effectively reached through traditional physical search mechanisms alone. However, the expansion also raises serious constitutional and procedural concerns.

A balanced approach is necessary. The law must not abandon digital search powers, but it must regulate them through clear limits, independent scrutiny, and stronger safeguards for taxpayers. Only then can the regime achieve both effective tax administration and fidelity to the Rule of Law.


*5th year, IX semester, National Law University Delhi. Author can be reached at: beauty.gupta22@nludelhi.ac.in.

1. Press Release, Ministry of Finance, The Income-tax Act, 2025 to Come Into Effect from 1st April, 2026 (1-4-2026).

2. Income-tax Act, 1961, S. 132.

3. Income-tax Act, 2025, S. 261(j).

4. Income-tax Act, 2025, S. 247(1).

5. Income-tax Act, 2025, S. 247(b).

6. Income-tax Act, 2025, S. 261.

7. Income-tax Act, 2025, S. 247(5).

8. Lok Sabha Secretariat, Lok Sabha Debates (Part II — Proceedings other than Questions and Answers, 25 March 2025) 100, available at <https://eparlib.sansad.in/bitstream/123456789/2989560/1/UCD_18_4_25-03-2025_Fullday.pdf> accessed 18-4-2026.

9. Lok Sabha Secretariat, Lok Sabha Debates (Part II — Proceedings other than Questions and Answers, 25 March 2025) 100, available at <https://eparlib.sansad.in/bitstream/123456789/2989560/1/UCD_18_4_25-03-2025_Fullday.pdf> accessed 18-4-2026.

10. Lok Sabha Secretariat, Lok Sabha Debates (Part II — Proceedings other than Questions and Answers, 25 March 2025) 100, available at <https://eparlib.sansad.in/bitstream/123456789/2989560/1/UCD_18_4_25-03-2025_Fullday.pdf> accessed 18-4-2026.

11. Katherine Baer, Ruud A. de Mooij, Shafik Hebous and Michael Keen, Taxing Cryptocurrencies 27-28 (IMF Working Paper No 23/144, July 2023).

12. Financial Action Task Force, “Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing” (14-9-2020).

13. Organisation for Economic Co-operation and Development, Inclusive Framework on BEPS: Tax Challenges Arising from Digitalisation — Interim Report 2018 (2018).

14. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Rr. 3 and 5.

15. Digital Personal Data Protection Act, 2023, S. 5.

16. (2017) 10 SCC 1 : (2017) 10 SCR 569.

17. Vishwaprasad Alva v. Union of India, W.P.(C) No. 114/2026.

18. Fourth Amendment to the Constitution of the United States; 26 USC § 7608.

19. Internal Revenue Service, IRM 9.4.9, Search Warrants, Evidence and Chain of Custody (13-2-2025).

20. Groh v. Ramirez et al, 2004 SCC OnLine US SC 10; United States v. Bridges, 344 F 3d 1010 (9th Cir 2003).

21. Groh v. Ramirez et al, 2004 SCC OnLine US SC 10; United States v. Bridges, 344 F 3d 1010 (9th Cir 2003).

22. Groh v. Ramirez et al, 2004 SCC OnLine US SC 10; United States v. Bridges, 344 F 3d 1010 (9th Cir 2003).

23. Finance Act, 2008, Sch. 36, para 1(1).

24. Finance Act, 2008, Sch. 36.

25. Finance Act, 2008, Sch. 36 para 29(1).

26. Finance Act, 2008, Sch. 36 Part-I, Power to obtain information and documents from third party <Finance Act, 2008> accessed on 16-4-2025.

27. HM Revenue & Customs, Enquiry Manual, “EM2809 — Examining Accounts: Computer Generated Records: What Documents and Systems We Can Legally Examine” (12-4-2016).

28. HM Revenue & Customs, Compliance Handbook, “CH25320 — Information & Inspection Powers: Inspection Powers: Obtaining and Recording Information and Copying Documents” (updated 30-1-2026).

29. HM Revenue & Customs, Compliance Handbook, “CH25540 — Information & Inspection Powers: Types of Inspection: Tribunal Approval” (updated 18-3-2026).

30. HM Revenue & Customs, Compliance Handbook, “CH25540 — Information & Inspection Powers: Types of Inspection: Tribunal Approval” (updated 18-3-2026).

31. Police and Criminal Evidence Act, 1984 (UK), S. 8.

32. HM Revenue & Customs, “HMRC’s Criminal Investigation Powers and Safeguards” (13-7-2021) available at <https://www.gov.uk/government/publications/criminal-investigation/criminal-investigation> accessed 19-4-2026.

33. Taxation Administration Act, 1953 (Cth), Sch. 1, Ss. 353—15.

34. Australian Taxation Office, Our Formal Access Powers (1-5-2024) available at <https://www.ato.gov.au/about-ato/commitments-and-reporting/information-and-privacy/information-management/our-approach-to-information-gathering/our-formal-access-powers> accessed 19-4-2026.

35. Taxation Administration Act, 1953 (Cth), Sch. 1.

36. Taxation Administration Act, 1953 (Cth), Sch. 1.

37. Taxation Administration Act, 1953 (Cth), Sch. 1, Ss. 353—10.

38. Taxation Administration Act, 1953 (Cth), Sch. 1, Ss. 355—1.

39. ATO Under Investigation, “ATO’s Information Gathering Powers” available at <https://www.atocorruption.org/atos-information-gathering-powers/> accessed 19-4-2026.

40. ATO Under Investigation, “ATO’s Information Gathering Powers” available at <https://www.atocorruption.org/atos-information-gathering-powers/> accessed 19-4-2026.

Join the discussion

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.