Customer Confidentiality and Duty of Secrecy in Banking Ethics
When a customer walks into a bank branch or logs into net banking, they hand over more than money — they hand over financial history, family details, and business plans. Protecting that information is the essence of customer confidentiality and duty of secrecy, the ethical and legal promise that a bank will not disclose customer information without proper cause. For JAIIB, CAIIB, and Ethics in Banking candidates, this is not an abstract topic — it sits at the intersection of contract law, the Banking Companies (Acquisition and Transfer of Undertakings) Act, 1970, and the landmark English case Tournier v National Provincial and Union Bank of England. Get the boundaries wrong, and a bank faces litigation, regulatory censure, and lasting reputational damage.
🔐 The Legal Roots of Banking Secrecy
The banker's duty of secrecy is not a courtesy — it is an implied term of the contract between banker and customer, alongside the duty to honour cheques and exercise reasonable care. This principle traces back to Tournier v National Provincial and Union Bank of England (1924), an English Court of Appeal decision that remains the foundational authority cited in Indian banking ethics and law today.
In that case, the bank disclosed details of an employee-customer's overdraft and a suspicious cheque endorsement to his employer, without the customer's consent. The court held that a bank owes its customer a contractual duty of confidentiality, and that breaching it — even where the disclosed information was accurate — could give rise to damages. This established secrecy as a legal obligation, not merely good practice, and Indian courts and the IIBF ethics curriculum have adopted the same framework.
The duty covers far more than account balances. It extends to transaction patterns, loan and guarantee details, security offered, and even the bare fact that a person maintains an account with the bank. It survives well beyond a single transaction and continues to apply even after an account is closed, since the obligation arises from information obtained during the relationship, not from an active balance.

⚖️ The Four Tournier Exceptions
No duty in banking ethics is absolute, and the Tournier judgment itself carved out four situations where disclosure is permitted without breaching confidentiality. These four exceptions are among the most frequently tested points in the Ethics in Banking paper, precisely because examiners like to test whether candidates can tell a lawful disclosure from a careless leak.
First, disclosure under compulsion of law — for example, responding to a court summons, an income tax notice, or a reporting obligation under anti-money-laundering law. Second, a duty to the public to disclose, such as information relevant to national security or preventing a fraud on the state. Third, where the interests of the bank require disclosure, such as suing a defaulting borrower or realising security, where the bank must necessarily reveal account facts to protect its own position. Fourth, disclosure with the customer's express or implied consent, which covers most routine data sharing that customers agree to as part of availing a product or service.
Bankers preparing for exams should note that these four categories are exhaustive in the classic formulation — any disclosure that does not fall within one of them is presumptively a breach. The chapter on Banking Ethics — Changing Dynamics builds on this framework to show how digital banking has expanded, without replacing, these four grounds.
| Tournier Exception | What It Covers | Consent Needed | Typical Example |
|---|---|---|---|
| Compulsion of law | Statutory or judicial demand for information | ❌ No | Court summons, tax authority notice, AML/PMLA reporting |
| Duty to the public | Public interest overrides individual secrecy | ❌ No | Disclosure to prevent a fraud on the state |
| Bank's own interest | Protecting the bank's legitimate position | ❌ No | Suing a defaulting borrower, invoking a guarantee |
| Express or implied consent | Customer has authorised the disclosure | ✅ Yes | Sharing repayment data with a credit information company |
💡 Exam Tip: Remember the four Tournier grounds with the mnemonic "Law, Public, Bank, Consent." Questions often test whether a given scenario fits one of the four or is simply a breach dressed up as an exception.
🏛️ Statutory Backing in Indian Banking Law
While Tournier supplies the common-law foundation, Indian banking law reinforces the same duty through statute. Section 13 of the Banking Companies (Acquisition and Transfer of Undertakings) Act, 1970 places an explicit obligation on nationalised banks and their officers to maintain secrecy regarding the affairs of their constituents, and a breach can trigger disciplinary proceedings under the applicable staff conduct regulations, in addition to any civil liability the bank incurs under contract law.
For banks outside the nationalised structure — private sector and foreign banks — the same duty operates primarily through the implied contractual term recognised in Tournier, supplemented by sector-specific statutes. The Credit Information Companies (Regulation) Act, 2005 governs how banks may lawfully share borrower data with credit information companies, always subject to the customer's consent under the loan agreement. Reporting obligations under the Prevention of Money Laundering Act and the Reserve Bank of India's supervisory powers under the Banking Regulation Act, 1949 give regulators lawful access that falls squarely within the "compulsion of law" exception.
The Building an Ethical Organization chapter explains how banks translate these statutory obligations into internal policy — access controls, need-to-know restrictions, and escalation matrices — so that individual employees are not left to interpret the law on their own each time a request for information arrives.

📤 When Banks Can Legitimately Share Customer Data
In practice, banks share customer information constantly — with auditors, rating agencies, regulators, credit bureaus, and technology vendors. What separates a lawful transfer from a breach is whether the disclosure fits a Tournier exception and whether internal process was followed. A loan sanction letter that authorises the bank to report conduct of the account to a credit information company is valid consent; a call-centre agent casually confirming a customer's balance to an unverified caller is not.
Marketing and cross-selling deserve special caution. Using account data to identify a customer as a prospect for a new product is common, but sharing that data with a third-party seller, or using it for purposes the customer never agreed to, moves outside the consent exception and back into breach territory — this is the same boundary problem that fuels complaints tracked under the RBI Charter of Customer Rights, which places the right to privacy among the customer's core entitlements.
Every employee who handles account data — from the teller to the credit officer — carries personal responsibility here, not just the bank as an institution. That individual-level obligation is why work ethics training treats confidentiality as a conduct issue, not merely a compliance checkbox.
⚠️ Common Mistake: Assuming that because information is "already known internally," any employee can share it externally. Internal access does not equal external disclosure rights — each disclosure needs its own lawful basis.
🚨 Consequences of a Breach
The fallout from an unauthorised disclosure runs on three tracks simultaneously. Civilly, the bank can be sued for damages by the affected customer, exactly as happened to the bank in Tournier itself, where the disclosure caused the customer financial and reputational loss. Regulators can also take supervisory action against the institution where systemic weaknesses in data handling are exposed.
At the individual level, an employee who leaks customer information without lawful basis faces disciplinary action ranging from a warning to dismissal, and in serious cases exposure under applicable penal provisions where the breach involves fraud or corrupt inducement. Because trust is the core product a bank sells, the reputational cost of even a single well-publicised leak often outweighs any monetary damages — customers who feel their confidentiality was violated tend not to return, and word travels fast.
This is why building an ethical culture matters more than a one-time policy circular. The organisational safeguards discussed in Work Ethics and the Workplace — clear desk practices, restricted system access, and a culture where employees feel safe flagging a doubtful request rather than complying with it — do more to prevent breaches than punishment after the fact. A strong compliance culture in banks ties board-level accountability directly to how front-line staff handle everyday customer data requests.

📌 Remember: A breach of secrecy can trigger civil damages, regulatory scrutiny, and individual disciplinary action all at once — it is rarely just one consequence in isolation.
🎯 Building This Into Your Exam Preparation
Ethics in Banking examiners like scenario-based questions that describe a specific disclosure and ask whether it was lawful. The fastest way to answer correctly is to run the scenario through the four Tournier exceptions first, then check whether Indian statute — Section 13 of the BCA, 1970, or a sector-specific law — adds anything extra to that particular case. Candidates who memorise the case name but skip the reasoning behind each exception tend to lose marks on the applied questions, not the definitional ones.
It also helps to connect confidentiality to the broader ethics syllabus rather than studying it in isolation — how a bank builds an ethical culture, and how well-governed organisations translate values like organizational ethics in banks and corporate social responsibility in banks into day-to-day conduct, all sit alongside secrecy as facets of the same trust relationship with the customer. For the full spread of topics under this paper, browse the Ethics in Banking tag on iibf.store.
Ready to test yourself? Attempt chapter-wise mock questions on iibf.store/tests and revisit the Tournier framework until identifying the right exception becomes second nature.
🧠 Practice MCQs: Customer Confidentiality and Duty of Secrecy
Q1. The banker's duty of confidentiality as an implied contractual term was first established in which case? (a) Foley v Hill (b) Tournier v National Provincial and Union Bank of England (c) Joachimson v Swiss Bank Corporation (d) Woods v Martins Bank
Answer: (b) — Tournier v National Provincial and Union Bank of England (1924) is the foundational case establishing banking secrecy as an implied contractual duty.
Q2. Under the Tournier exceptions, which of the following justifies disclosure without the customer's consent? (a) The bank wants to use the data for marketing (b) Compulsion of law (c) An employee is simply curious (d) None of the above
Answer: (b) — Disclosure under compulsion of law, such as a court order or statutory reporting requirement, is one of the four recognised Tournier exceptions.
Q3. In India, the statutory obligation on nationalised banks to maintain secrecy of customer affairs is reinforced under which legislation? (a) The Banking Regulation Act, 1949 only (b) The Companies Act, 2013 (c) The Banking Companies (Acquisition and Transfer of Undertakings) Act, 1970 (d) The Negotiable Instruments Act, 1881
Answer: (c) — Section 13 of the Banking Companies (Acquisition and Transfer of Undertakings) Act, 1970 places a specific secrecy obligation on nationalised banks and their officers.
Q4. A bank shares a borrower's repayment history with a credit information company. This is permissible mainly because: (a) It falls under the duty to the public (b) It is covered by the bank's own-interest exception (c) The customer has given consent under the loan agreement (d) No consent or legal basis is required
Answer: (c) — Sharing data with credit information companies is lawful because the customer consents to it as part of the loan or credit agreement, fitting the consent exception.
Q5. Which of the following is a direct consequence when a bank employee breaches customer confidentiality without lawful justification? (a) An automatic government subsidy (b) Civil liability for the bank and disciplinary action against the employee (c) Mandatory public listing of the bank (d) No consequence if the disclosed information was factually true
Answer: (b) — An unlawful breach can expose the bank to civil liability, as in Tournier, and the individual employee to disciplinary action regardless of whether the disclosed facts were accurate.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
Does the duty of secrecy end when a customer closes their account?
No. The duty continues even after the account is closed, since it arises from information obtained during the banker-customer relationship rather than from a currently active balance.
Can a bank disclose customer information to the police without a court order?
Only under specific legal compulsion, such as a validly issued summons, a statutory reporting obligation, or a formal request from an authorised investigating agency. Voluntary disclosure without any legal basis is a breach of the duty of secrecy.
Is confirming that a person "banks with us" also covered by secrecy?
Yes. Even confirming the bare existence of an account or relationship, without revealing balances or transactions, can amount to a breach if disclosed to an unauthorised party without proper cause.
How does customer confidentiality differ from broader data protection law?
Confidentiality is the banker's ethical and contractual duty rooted in cases like Tournier and reinforced by banking statutes such as the BCA, 1970. Data protection law separately governs how personal data is collected, processed, and secured across sectors — the two overlap in practice but are not the same obligation.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.