Delhi High Court Upholds "Zero Liability" for Customer in Cyber Fraud Case
The Delhi High Court recently ruled in favor of a customer who was a victim of cyber fraud, upholding the "zero liability" principle and holding the State Bank of India (SBI) accountable for deficiencies in service. The court's decision, in the case of Hare Ram Singh v. Reserve Bank of India & Ors., has significant implications for consumer protection in India's rapidly digitizing economy.
Key Takeaways:
- The Petitioner, Hare Ram Singh, was a victim of cyber fraud after clicking a suspicious link in an SMS message, resulting in two unauthorized transactions totaling Rs. 2,60,000 from his account in SBI.
- The Petitioner reported the incident promptly and filed a complaint with the Banking Ombudsman (BO), but the BO rejected the complaint, citing that the transactions were conducted through Internet Banking (INB) and authenticated with OTPs received by the Petitioner.
- The Delhi High Court held that the Petitioner's actions did not constitute negligence, and the responsibility for the unauthorized electronic transactions lies with the Respondent No. 2 bank, as per the RBI guidelines.
- The court relied on the RBI Circular dated 6.7.2017, titled "Customer Protection- Limiting Liability of Customers in Unauthorised Electronic Banking Transactions," which places the burden of proving the customer's liability on the bank.
- The court also cited the case of Tony Enterprises v. Reserve Bank of India, AIR OnLine 2019 KER 674, decided by the Kerala High Court, which held the bank liable for failing to detect and prevent unauthorized activity.
- The Respondent No. 2 bank failed to follow RBI's Master Directions on Digital Payment Security Controls (dated 18.02.2021), which mandate banks to maintain robust security systems and mechanisms to prevent such fraud.
- The court awarded the Petitioner "zero liability" under the RBI guidelines, compensating him for the financial loss incurred, along with interest, and paying token compensation for the inconvenience caused due to the bank's deficient services.
- The Banking Ombudsman's order dated 20.10.2021 was set aside, and a writ of mandamus was issued against the State Bank of India to pay Rs. 2,60,000 to the Petitioner with 9% annual interest from the date of the fraud (April 18, 2021), and pay Rs. 25,000 towards the costs of legal proceedings.
Statistics:
- Rs. 2,60,000: Total amount lost by the Petitioner in unauthorized transactions.
- Rs. 33,340: Amount reimbursed by the BO to the Petitioner, which was later adjusted towards the interest.
- 9%: Annual interest rate awarded to the Petitioner on the amount lost.
- Rs. 25,000: Amount awarded to the Petitioner as token compensation for the inconvenience caused due to the bank's deficient services.
- 20.10.2021: Date of the Banking Ombudsman's order that was set aside.
- April 18, 2021: Date of the cyber fraud incident.
- 06.07.2017: Date of the RBI Circular titled "Customer Protection- Limiting Liability of Customers in Unauthorised Electronic Banking Transactions."
- 18.02.2021: Date of RBI's Master Directions on Digital Payment Security Controls.
Sources:
- Hare Ram Singh v. Reserve Bank of India & Ors.
- RBI Circular dated 6.7.2017, titled "Customer Protection- Limiting Liability of Customers in Unauthorised Electronic Banking Transactions."
- Tony Enterprises v. Reserve Bank of India, AIR OnLine 2019 KER 674.
- RBI's Master Directions on Digital Payment Security Controls (dated 18.02.2021).