Bangladesh
Bangladesh Data Privacy Laws: The Personal Data Protection Act 2026
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 7 primary sources cited on this page. How we verify our legal content

Bangladesh's data protection law is the Personal Data Protection Act, 2026 (Act No. 63 of 2026), passed on 10 April 2026 by the Parliament elected that February. Section 44 of the Act repealed the Personal Data Protection Ordinance 2025 and its February 2026 amendment ordinance. Rooted in constitutional privacy rights under Article 43, the Act requires voluntary, specific, clear and revocable consent before personal data is collected, stored, transferred or used, and section 1(3) deems it effective from 6 November 2025 apart from the deferred enforcement sections.
Bangladesh crossed a historic threshold in 2025. For decades the country had no dedicated data protection statute, relying instead on scattered provisions in laws designed for other purposes. That gap closed when the interim government led by Chief Adviser Muhammad Yunus promulgated two ordinances in November 2025: the Personal Data Protection Ordinance and the National Data Management Ordinance. An amendment followed in February 2026, and on 10 April 2026 the newly elected Parliament repealed all three and re-enacted the framework as the Personal Data Protection Act, 2026 and the National Data Management Act, 2026.
This guide covers the complete legal framework governing data privacy in Bangladesh: constitutional roots, the evolution of cyber legislation, the 2025 ordinances and the 2026 Acts that replaced them, the supervisory authority, data subject rights, cross-border transfer rules, penalties, the compliance timeline, and what businesses operating in or with Bangladesh need to do now.
Quick Answer: Where Does Bangladesh Stand Today?
As of 10 September 2026, Bangladesh has a comprehensive data protection law in force with its enforcement machinery still switched off. The Personal Data Protection Act, 2026 (Act No. 63 of 2026) was passed on 10 April 2026 and repealed both the 2025 ordinance and its February 2026 amendment. Section 1(3) deems the Act effective from 6 November 2025 except for section 23 and sections 31 to 35, which cover the Chief Data Officer duty, complaints to the Authority, administrative fines and compensation. Those sections begin only on a date the Government fixes by gazette notification, and section 1(3) permits that only after 18 months from the issue of the Act.
This means the transition window is open right now. Organizations processing Bangladeshi personal data should treat this period as their compliance runway, not as a grace period to ignore the law.
Constitutional Foundation: Article 43
The right to privacy in Bangladesh begins with the Constitution of the People's Republic of Bangladesh. Article 43, found in Part III (Fundamental Rights), provides two core guarantees.
Every citizen has the right to be secured in their home against entry, search, and seizure. Every citizen also has the right to privacy of correspondence and other means of communication.
These rights are not absolute. The Constitution permits reasonable restrictions imposed by law in the interests of state security, public order, public morality, or public health.
Public Interest Litigation and the Limits of Article 43
Bangladeshi courts have widened the practical reach of fundamental rights through public interest litigation. The leading example is Dr. Mohiuddin Farooque v. Secretary, Ministry of Commerce, Writ Petition No. 92 of 1996, decided by the High Court Division on 1 July 1996. It concerned a consignment of radioactive skimmed milk powder cleared for import, and it was argued on the right to life under Articles 31 and 32. The judgment addresses neither Article 43 nor telephone records.
The practical limits on interception therefore come from statute rather than from a reported Article 43 ruling on electronic communications. Section 97Ka of the Bangladesh Telecommunication Act, 2001 was substituted in 2026 and now carries those limits, as set out below. Constitutional protection alone proved insufficient for the complexities of the digital age, which drove successive legislative efforts.
The ICT Act 2006: First-Generation Digital Law
The Information and Communication Technology Act 2006 was Bangladesh's first major legislation addressing digital activities. Its primary contributions to data privacy are structural rather than substantive.
Confidentiality obligation. The Act requires that information declared confidential by law be protected through means appropriate to the mode of transmission, including on communication networks. This created a baseline obligation for digital confidentiality.
Interception powers under Section 46. The ICT Controller may direct law enforcement to intercept information transmitted through any computer resource and may order subscribers to assist in decrypting relevant data. No judicial oversight or time limit is specified.
Digital signatures and electronic records. The Act gives legal recognition to electronic records and digital signatures, making them equivalent to physical counterparts. This framework underpins the validity of electronic consent mechanisms used in data processing.
The ICT Act's controversial Section 57, which broadly criminalized online speech, was later repealed by the Digital Security Act 2018.
The Digital Security Act 2018: Data Privacy Enters the Picture
The Digital Security Act 2018 (Act No. 46 of 2018) replaced the speech provisions of the ICT Act and added Section 26, the first statutory data privacy protection in Bangladesh.

Section 26: Identity Information Protection
Section 26 defined "identity information" broadly as any external, biological, or physical information that can identify a person or system. The definition covered names, addresses, dates of birth, national identity card numbers, birth and death registration numbers, fingerprints, passport numbers, bank account numbers, driver's licenses, electronic and digital signatures, credit and debit card numbers, biometric data including voice prints and retina and iris images, and DNA profiles.
Section 26 imposed a strict consent requirement: unless the data subject expressly consented, collecting or processing identity information was prohibited. Once withdrawn, consent could not be overridden.
Section 8: Data Removal Powers
Section 8 granted the Bangladesh Telecommunication Regulatory Commission (BTRC) broad authority to remove or block data-information that threatened digital security. This provision gave the government expansive discretion over online content.
Why the Digital Security Act Failed
Despite its privacy provisions, the Digital Security Act became notorious for chilling free expression. ARTICLE 19 documented extensive misuse of the law to prosecute journalists, activists, and ordinary citizens. Many offenses were non-bailable, and the law was widely used by the Sheikh Hasina government against critics. It was repealed in September 2023.
The Cyber Security Act 2023: A Short-Lived Revision
The Cyber Security Act 2023 replaced the Digital Security Act in September 2023. The government described it as a reformed law. In practice, it retained most of the Digital Security Act's structure, including Section 26 on identity information.

Some previously non-bailable offenses became bailable. Certain penalties were reduced. Fines were increased. The provision for additional punishment for repeated offenses was removed. The prison term for publishing information that "hurts religious values" dropped from five years to two, and the transmission of "defamatory information" was replaced with a fine.
Criticism was swift and sustained. Amnesty International described the Cyber Security Act as a replication of the "draconian" Digital Security Act. The U.S. Embassy stated that the new legislation continued to criminalize free expression, retained non-bailable offenses, and could too easily be misused to silence critics.
The Cyber Security Act 2023 survived less than two years.
Political Context: The 2024 Student Revolution and Yunus Interim Government
Understanding the 2025 ordinances requires understanding the political rupture that made them possible.
On August 5, 2024, Prime Minister Sheikh Hasina fled Bangladesh after a student-led uprising that began over a government job quota system. Nobel Peace Prize laureate Muhammad Yunus was sworn in as Chief Adviser on August 8, 2024, heading an interim government.
The interim government inherited a body of digital laws that had been used extensively to suppress dissent under Hasina. Reforming that legal architecture was an early priority. The Cyber Security Ordinance 2025 and the data protection ordinances of November 2025 were products of this reform agenda.
Elections in February 2026 returned an elected Parliament, and on 10 April 2026 it replaced the interim government's ordinances with Acts: the Personal Data Protection Act, 2026 (Act 63 of 2026), the National Data Management Act, 2026 (Act 80 of 2026) and the Cyber Security Act, 2026 (Act 81 of 2026). Each repealed its 2025 ordinance predecessor, and the data protection Act also repealed the February 2026 amendment ordinance.
The Cyber Security Act 2026: Current Cyber Law
The Cyber Security Ordinance 2025, gazetted on May 21, 2025, replaced the Cyber Security Act 2023. The interim government concluded that the 2023 Act contained inadequate civil protection provisions, enabled abuse, and undermined fundamental rights including freedom of expression.
That ordinance is no longer the operative law. The Cyber Security Act, 2026 (Act No. 81 of 2026), passed on 10 April 2026, re-enacted it as a statute and repealed it by section 51, while section 50 repealed the Cyber Security Act 2023 outright. Section 1(2) of the Act deems it to have come into force on 21 May 2025, the date the ordinance it re-enacts was gazetted, so these rules have run continuously since then even though Parliament passed the Act on 10 April 2026. The Cyber Security (Amendment) Act, 2026 (Act No. 99 of 2026), passed on 1 July 2026, then deleted section 20 of the 2026 Act. References below to current cyber law mean Act 81 of 2026 as amended.
Nine Sections Whose Pending Cases Were Cancelled
Section 50(1) of the Cyber Security Act, 2026 repealed the Cyber Security Act 2023 outright. Section 50(4) then singles out nine of its sections for a further step, cancelling the cases still pending under them:
- Section 21: Criminalizing criticism of the Liberation War, Bangabandhu, national anthem, or flag
- Section 24: Penalizing the use of fake or deceptive identity
- Section 25: Criminalizing offensive, false, or fear-inducing information
- Section 26: Prohibiting unauthorized collection or use of identity information
- Section 27: Cyber terrorism (redefined, not simply narrowed, as section 23 of the 2026 Act: the maximum falls from 14 years to 10 and clause (d) gains a whistleblower exemption, but a new clause (e) extends the offence to concealing or assuming an identity, defacing a national ID card or passing off another person's data as one's own in order to commit the other clauses; only the pending 2023 Act cases were cancelled)
- Section 28: Punishing publication of information hurting religious sentiments
- Section 29: Criminalizing defamatory information
- Section 31: Criminalizing content that undermines law and order
- Section 34: Filing false cases or complaints under the Act
Automatic Case Dismissals
Section 50(4) of the Cyber Security Act, 2026 cancels every pending case, proceeding and police investigation under those nine sections of the Cyber Security Act 2023, bars any further action under them, and nullifies sentences and fines already imposed. Section 50(5) does the same for proceedings still running under sections 21 and 24 to 29 and 31 of the Digital Security Act 2018.
The cancellation is not general, and it is easy to read it too broadly. Section 50(2) expressly preserves pending cases under sections 17, 18, 19, 20, 22, 23, 30, 32 and 35 of the Cyber Security Act 2023, along with appeals against orders, judgments and sentences in them. Those continue before the tribunals as though the 2023 Act had not been repealed. Hacking was section 32 of that Act, so a live hacking prosecution survives. Cyber terrorism was section 27, so those prosecutions were cancelled. The offence itself survives as section 23 of the Cyber Security Act, 2026, which section 1(2) deems in force from 21 May 2025, so there is no gap in coverage.
Press reporting at the time of the 2025 ordinance quoted a government adviser putting the share of pending cases filed under the repealed sections at about 95 percent. That figure traces to a ministerial statement rather than to any published court or ministry case count, and the legal effect does not depend on it.
Remaining Provisions and Bail Status
Not every remaining offence is bailable, and two years is not the ceiling. Section 46(2) of the Cyber Security Act, 2026 makes section 17, section 18(1)(c), section 19, section 22 and section 23 non-bailable. Section 22 is cyber deception, which press summaries usually call cyber fraud. The bailable offences are section 18(1)(a) and (b), section 21, and sections 24 to 26, which cover forgery, unauthorised e-transactions, blackmail and sexual harassment material, and hate speech.
The maximum penalty under the Act is 10 years' imprisonment or a fine of up to BDT 10,000,000 for cyber terrorism under section 23. Unlawful access to critical information infrastructure that leads to data theft or damage carries up to 7 years under section 17(1)(b). Hacking under section 18(1)(c), damage to computer systems under section 19 and cyber deception under section 22 each carry up to 5 years.
Impact on Data Privacy
The deletion of Section 26 created a temporary gap in statutory data privacy protection. That gap was filled by the Personal Data Protection Ordinance 2025 and, since 10 April 2026, by the Personal Data Protection Act, 2026, which provides far more comprehensive protection than Section 26 ever offered.
Personal Data Protection Act 2026: Bangladesh's Comprehensive Data Law
The Personal Data Protection Act, 2026 (Act No. 63 of 2026) is dated 10 April 2026 and is Bangladesh's dedicated data protection statute. Section 44 repealed both the Personal Data Protection Ordinance 2025 (Ordinance No. 61 of 2025), gazetted on 6 November 2025, and the Personal Data Protection (Amendment) Ordinance 2026 (Ordinance No. 23 of 2026), while preserving anything already done under them.
Section 1(3) deems the Act effective from 6 November 2025, so the substantive duties run from that date without a gap. The provisions that changed most between the ordinance and the Act are the penalty chapter, the localization clause and the children's data section, each covered below.

Scope and Extraterritorial Reach
Section 1(2) applies the Act to anyone processing personal data inside Bangladesh other than data merely in transit, to Bangladeshi citizens and to people resident, ordinarily resident, working or temporarily present in Bangladesh, and to processing carried out abroad in connection with offering goods or services to data subjects located in Bangladesh or monitoring or profiling them. Section 4 adds that a violation committed outside Bangladesh is treated as if it had been committed inside. The Act draws no distinction by size of organization, and government agencies, autonomous bodies and state-owned enterprises are covered.
Data Ownership Principle
The foundational premise of the Act, stated in its preamble and in its long title, is that a person's personal data belongs to that person. Neither the government nor any organization holds primary ownership. Consent under section 5(1) is therefore the primary basis on which an entity may collect, store, transfer or use personal data.
Under section 5(2), consent must be voluntary, specific, clear and revocable, and the data subject must be told the purpose of processing, the retention period, any transfer and how to withdraw. Section 13(1) lets a data subject withdraw consent at any time by the simpler procedure to be set in regulations. Section 5(4) places the burden of proving that consent was properly obtained on the data fiduciary, not the data subject.
Data Classification System
Section 29(1) does not classify anything by itself. It empowers the Government, considering the characteristics described in the Schedule to the Act, to classify personal data into four categories: public or open, internal, confidential and restricted. Section 29(2) lets the Government amend that Schedule after consulting the Authority.
The consolidated text published by the Legislative and Parliamentary Affairs Division does not reproduce the Schedule, and no classification notification appears on the statute book, so the contents of each tier are not yet fixed in a form a business can apply. Descriptions of what falls in each tier, common in commentary written about the ordinance, do not come from the operative sections.
Where the Act names a tier, the consequence is real. Section 13(3) lets a data fiduciary refuse a deletion request where the data is confidential or restricted personal data. Under section 29(3) and (4), classified personal data may go abroad only on a listed ground and only to a place with the prescribed suitable technology and equipment.
Sensitive Personal Data
Section 2(21) defines sensitive personal data separately from the tiers, and the list is longer than most summaries suggest: genetic data; biometric data; data relating to small ethnic groups, ethnic communities and communities; political or philosophical ideology, religious belief or similar; trade union membership; health data; sexual orientation; data on the commission of offences, criminal proceedings and convictions; data about offences a person is alleged to have committed; real-time location or geo-location; and any further category prescribed by rules or regulations.
Section 7 sets the conditions for processing it: the data subject's specific consent, performance of a contract to which the data subject is a party, employment and social protection duties, treatment by a health worker including emergency care where life or health is at risk, a duty imposed by or under any law, or data the person has voluntarily made public.
Children's Data
Section 9 requires the consent of a parent, legal guardian or other person empowered to decide before a child's personal data is collected or processed, and section 2(19) sets the age at under 18 unless the Government fixes another age. Processing must be carried out so that the child's rights and interests are protected, and consent given on a child's behalf remains valid until the child turns 18.
One protection did not survive the move from ordinance to Act. Section 9(3) of the repealed 2025 ordinance banned tracking, monitoring, profiling and targeted advertising aimed at children outright. Section 9 of the Personal Data Protection Act, 2026 has only the three sub-sections described above and carries no such ban.
Rights of Data Subjects
Chapter 3 of the Act grants individuals a set of rights that section 10(4) makes universal, inherent, non-transferable and inviolable, and that cannot be cancelled by contract or notice:
Right of access, with portability as a discretion. Section 11(1) gives the data subject access to the data processed about them, and section 11(3) requires a copy in a concise and intelligible format together with the purposes, recipients, retention, source, cross-border safeguards and the logic of any automated decision. Portability is weaker than the label suggests: section 11(2) says the fiduciary may, where applicable, arrange direct transfer to another fiduciary using federated interoperable ecosystems. Section 11(5) requires the fiduciary to refer a request to the Authority where disclosure could threaten national security, law and order or the rights of a third party.
Right to correction. Section 12 gives the data subject the right to have inaccurate or misleading personal data corrected, incomplete data completed, and out-of-date data brought up to date. A fiduciary that refuses must give written reasons, and a fiduciary that acts must tell the data subject within 30 days. Section 14 then requires system-wide propagation of an approved correction or deletion. The Authority fixes an order of precedence among the registries that hold the same field and treats the most reliable of them as the Primary Source of Truth (Explanation to section 14), directs every secondary fiduciary and processor to apply the change, and records it on an immutable ledger (section 14(4)).
Right to consent withdrawal and deletion. Individuals may revoke consent for storage, processing, or automated decision-making, and may request erasure of their personal data under specified conditions.
Right to restrict automated decisions. Citizens may challenge and restrict decisions made solely through automated data processing.
Lawful Processing Grounds
Consent is the primary lawful basis. Section 5(3) allows processing without consent on seven grounds and only those seven, each subject to the benefit, necessity, proportionality and purpose-limitation conditions in the opening words of the sub-section and to conditions set by regulations:
- Performance of a contract to which the data subject is a party
- Steps taken at the data subject's request in order to conclude a contract
- Necessity to establish a legal right or to defend a suit or legal proceeding
- Protection of vital interests such as life or health
- Implementation of legal rights on employment, labour rights or social protection
- Data the data subject has voluntarily made public
- Risk of harm to another person where consent is unreasonably withheld
There is no legal obligation ground and no public interest task ground in Bangladeshi law. Both are familiar from the GDPR, and neither appears in section 5(3).
Data Controller and Processor Obligations
Organizations processing personal data must:
- Implement transparency and accountability measures
- Respect purpose limitation, collecting only what is necessary
- Apply pseudonymization and encryption where appropriate
- Maintain processing records for a minimum of five years
- Notify the Authority, and only the Authority, where a breach is likely to cause significant harm to the data subject (section 20(1)), in the form, manner and time to be prescribed by regulations
- Conduct data audits and prepare data protection plans
- Not retain data beyond the period necessary for the original processing purpose
Significant Data Fiduciaries
The Act keeps the category of "significant data fiduciary". Section 2(5) defines it as a data fiduciary determined by regulations on the basis of the potential effect on state sovereignty, the volume of data or the financial exposure it carries, the risk to data subject rights, and possible threats to national security, public order, public safety, economic order and public health. No regulations setting those thresholds appear on the statute book as of 10 September 2026.
Significant data fiduciaries must:
- Appoint a Chief Data Officer to represent the organization before the Authority, submit required reports, facilitate data subject rights, and handle complaints
- Undergo audits by an independent data auditor where their class is prescribed for audit under section 21
- Face a higher administrative fine ceiling, up to BDT 5,000,000 rather than BDT 2,500,000, under section 32(2)
Data Localization and Cross-Border Transfer Rules
This area changed twice in six months, and the version most sources still describe is no longer law.
The Repealed Local Copy Rule
When the ordinance was gazetted in November 2025, its section 29(7) reached any personal data transferred to, stored on or processed in any cloud infrastructure, domestic or foreign, and required at least one synchronized real-time copy of that cloud data to be kept inside Bangladesh. This applied broadly and created a significant compliance burden for technology companies.
The fee power did survive into current law. Section 29(5) of the Personal Data Protection Act, 2026 lets the Government fix, by gazette notification, a fee or charge on the annual business or commercial profit an organization derives from using Bangladeshi citizens' personal data. The mechanics of that levy remain undefined.
The February 2026 Amendment and What Happened To It
On February 5, 2026, the President promulgated the Personal Data Protection (Amendment) Ordinance, 2026 (Ordinance No. 23 of 2026). It had exactly two operative sections.
The first narrowed the local copy duty in section 29(7)(b) of the ordinance so that it reached only restricted personal data and data processed by Critical Information Infrastructure (CII). The second replaced imprisonment with a fine in section 48 of the ordinance, which had exposed managing directors of offending companies to a jail term.
Both changes are now of historical interest only. Section 44 of the Personal Data Protection Act, 2026 repealed the amendment ordinance along with the ordinance it amended.
There Is No Localization Requirement Today
Section 29 of the Personal Data Protection Act, 2026 runs to seven sub-sections and contains no local copy or data residency obligation of any kind. There is no section 29(7)(b) in the Act: section 29(7) is simply the Authority's power to make regulations. The narrowed clause the amendment ordinance inserted was not carried forward. A business assessing its Bangladeshi exposure today has no statutory duty to mirror Bangladeshi personal data inside the country.
Cross-Border Transfer Framework
Section 29(3) allows classified personal data to be sent abroad on one of three grounds: the data subject's consent, a contract to which the data subject is a party covering the exchange of goods or services, or, with consent, a matter connected to that person's business, education, departure or migration.
Section 29(4) adds a condition about the destination that is written in terms of capability rather than legal adequacy. Personal data may be transferred only to places or countries that have the suitable technology and equipment for protecting personal data prescribed by regulations.
Section 29(6) imposes a notification duty, not an approval requirement. Anyone making a large-volume cross-border transfer of sensitive personally identifiable data must notify the Authority. The Explanation defines that data as government unique identifiers such as national ID, passport and taxpayer numbers, biometric identifiers, genetic or DNA information, and criminal or sentencing records. The duty is not limited to significant data fiduciaries, and no prior permission regime exists.
National Data Management Act 2026
The companion instrument was never called a data governance ordinance. It was the National Data Management Ordinance 2025 (Ordinance No. 60 of 2025), gazetted alongside the data protection ordinance, and section 49 of the National Data Management Act, 2026 (Act No. 80 of 2026, dated 10 April 2026) repealed it. The two 2026 Acts form a paired architecture for Bangladesh's digital economy.
National Data Management Authority
Section 8 of the National Data Management Act, 2026 establishes the National Data Management Authority as a statutory body attached to the Prime Minister's Office, and section 2(4) of the data protection Act makes that same body the data protection regulator. Section 9 constitutes it as an Executive Chairman and six members appointed by government notification. Its responsibilities include:
- Designing and operating the national data architecture
- Formulating data policies and ensuring legal compliance
- Resolving complaints across all data management activities
- Guaranteeing security across national databases and software systems
Civil society organizations have raised structural concerns about the Authority. The concern is real, but the widely repeated line about a five-member, all-government oversight committee describes neither body under the 2026 Act. Section 5(1) places the Authority under a policy-making board chaired by the Prime Minister with roughly twenty members: eight ministers, the Cabinet Secretary, the Principal Secretary, the Governor of Bangladesh Bank, the ICT Division Secretary, the Election Commission Secretariat Secretary, the Executive Chairman, two Members of Parliament nominated by the Speaker, one from the governing party and one from the opposition, six subject-matter experts nominated by the Government of whom at least two must be women, and one representative from a civil society or human rights organization.
The structural objection survives that correction. The Authority still designs the national data architecture, operates it and enforces compliance against everyone connected to it, and its policy board is chaired by the head of government, so the independent check that data protection regulators elsewhere rely on is absent.
National Responsible Data Exchange
The Act establishes the National Responsible Data Exchange (NRDEX) platform, a secure interface layer for purpose-based data sharing between government agencies and approved institutions. The platform is designed to reduce data duplication and improve interoperability. Participating organizations must meet security and data handling standards set by the Authority.
Unified Digital Identity
The Act tasks the Authority with an electronic citizen identification and authentication system and a unified identity management layer that connects the core citizen registers, including the National ID, passport and tax identification records, into a single authenticated identity layer. The system is intended to streamline access to government and digital services.
National Source Code Repository
To prevent vendor lock-in, the Act requires the Authority to establish a national code repository holding the up-to-date source code, under version control and with full documentation, of every software system built or bought for government, with provision for reuse of that code across state software.
Telecommunications Act 2001 and Surveillance Authority
The Bangladesh Telecommunication Act, 2001 established the BTRC and governs telecommunications services. Its provisions interact with the data protection framework in important ways, and its interception section was rewritten in February 2026.
Section 97(Ka): Government Surveillance Powers
Section 97Ka was substituted by section 64 of the Bangladesh Telecommunication (Amendment) Act, 2026 (Act No. 51 of 2026) with effect from 5 February 2026, so the open-ended version described in most commentary is gone.
The current section allows the Government, or an authority it designates, to authorise the interception, monitoring, retention or analysis of a user's messages, conversations or related information in the interest of state security, public order or the prevention of serious crime, for a specified period, while ensuring necessity, proportionality and legality. Section 97Ka(10) defines "Government" for this purpose as the Ministry of Home Affairs.
The safeguards are new:
- Section 97Ka(2): no interception takes effect without the prior approval of a court or a government-constituted authority, with a temporary emergency authorisation as the only exception
- Section 97Ka(5): the duration, scope and purpose must be specifically fixed, interception is permitted only where the information cannot be obtained by a less intrusive method, and full logs, records and an audit trail must be kept
- Section 97Ka(6): intercepted material must be destroyed once the fixed period expires unless it is needed in pending proceedings
- Section 97Ka(7): the Government must constitute an independent review council or committee to review the legality, necessity and accountability of interception at intervals
Section 97Kha then makes lawfully intercepted material admissible only where the authorisation was lawful, an unbroken chain of custody was maintained, and authenticity and integrity are proved. Material gathered purely for intelligence purposes is not independently admissible unless it is re-proved through a lawful process.
How much of this binds in practice depends on the rules the Government makes under section 97Ka(9) and on whether the review council is actually constituted. The statutory text, however, no longer supports the common claim that interception in Bangladesh is open-ended and free of judicial control.
Supervisory Authority and Enforcement Structure
Section 2(4) of the Act makes the National Data Management Authority, constituted under the National Data Management Act, 2026, the supervisory body. Sections 25 to 28 set out its functions and powers, which include:
- Issuing binding instructions to data fiduciaries and processors
- Conducting inspections and directing data audits
- Imposing administrative fines
- Suspending cross-border data transfers
The Deferred Sections and When They Start
Section 1(3) deems the Act effective from 6 November 2025 with two carve-outs: section 23, the Chief Data Officer duty, and sections 31 to 35, which cover complaints to the Authority, administrative fines, the factors that set them and compensation. Those sections start on a date the Government fixes by gazette notification, and only after 18 months have passed from the issue of the Act on 10 April 2026.
Two consequences follow. The earliest possible commencement is around October 2027 rather than May 2027, and commencement is not automatic on any date. It requires a notification, and none appears in the consolidated text as of 10 September 2026.
The delay still works like a runway. Organizations that build compliant structures during this window will be in a stronger position than those that wait for a notification they cannot schedule.
Penalties and Liability
Administrative Fines
The turnover-percentage model is gone. It belonged to the repealed ordinance, and the Personal Data Protection Act, 2026 uses fixed ceilings instead.
Section 32(1) allows an administrative fine of up to BDT 2,500,000 on a data fiduciary or processor that fails to honour a data subject right. Section 32(2) raises that ceiling to BDT 5,000,000 for a significant data fiduciary. Section 32(3) allows an additional fine for a second or repeated violation.
Section 33 allows a fine of up to BDT 2,500,000 for failing to provide the protection and security required by the Act, the rules, the regulations or the standard operating procedures.
Section 34 lists what the Authority weighs in setting an amount, including the nature, extent, seriousness, timing and repetition of the failure, the likely harm to the data subject and gain to the fiduciary, and whether the breach was reported promptly. Section 35 lets the Authority award compensation to the data subject on top of the fine.
There is no BDT 300,000 to BDT 500,000 band. That figure appears in neither the Act nor the ordinance it replaced.
No Criminal Penalties Under the Data Protection Act
The Personal Data Protection Act, 2026 contains no offences chapter and no imprisonment. Its nine chapters run from section 1 to section 45 and end with administrative fines in chapter 8 and miscellaneous provisions in chapter 9.
The prison terms often quoted for Bangladesh, 5 to 7 years for unauthorized collection or disclosure of personal data, came from chapter 9 of the repealed 2025 ordinance and were not carried into the Act. Criminal exposure for misusing data now runs through the Cyber Security Act, 2026 and the general criminal law rather than through the data protection statute.
What the Act provides instead is administrative: fines under sections 32 and 33, compensation under section 35, officer-level liability under section 36, and an appeal under section 37 to the tribunal established under section 68 of the Information and Communication Technology Act, filed within 30 days of the order.
Corporate and Personal Liability
Officer liability is built into the law, and it is administrative. Section 36 provides that where a data subject complains of a rights violation by a company, the Authority may impose an administrative fine on any board member, managing director, officer connected with management, or employee engaged in day-to-day operations who was involved in the violation.
The repealed ordinance did expose managing directors to imprisonment, and the February 2026 amendment ordinance replaced that with a fine. The Act settles the point by dropping imprisonment altogether.
Public-sector liability moved the other way. The ordinance carried a provision, section 47 as originally gazetted rather than anything the 2026 amendment added, making the government employee involved answerable where a government or statutory body breached it. The Personal Data Protection Act, 2026 has no equivalent. Section 36, its only officer-liability provision, is written for companies.
Civil Society Concerns and Ongoing Debates
The 2025 ordinances and the 2026 Acts that replaced them have drawn sustained criticism from legal scholars, civil society organizations and international bodies. Most of the published critique was written about the ordinance text, and the provisions criticised were largely carried into the Acts.
The consent exemptions in section 24. Section 24(1) lists ten situations in which consent is not required, opening with national security, defence, public order or the public interest, none of which the Act defines. The list is not confined to the state: it also covers personal, recreational or household use, statistics and scientific or historical research, and publication, journalism, archival, educational, artistic or literary work in the public interest.
Section 24(2) matters as much as the list. It provides that exemption from taking consent does not exempt anyone from the provisions governing processing, storage, retention or disclosure, and section 24(3) applies both sub-sections to every data fiduciary and to anyone else involved in processing. The fair criticism is that the grounds in section 24(1)(a) are undefined and that section 38 lets the Government direct the Authority on sovereignty, security and public order grounds, not that section 24 lifts state actors out of the Act.
Concentrated regulatory power. The National Data Management Authority sits within the executive branch and serves simultaneously as data infrastructure architect, operator and compliance enforcer, under a policy board chaired by the Prime Minister. An appeal against its fines lies to the tribunal under section 68 of the ICT Act, but no independent regulator sits between the Authority and the Government.
Accelerated drafting process. Legal scholars have noted that significant provisions changed between draft versions without documented public consultation. Mohammad Ershadul Karim observed that the ordinance "omits key principles considered the lifeblood of such laws."
Foreign enforcement gaps. Critics note that the practical mechanisms for enforcing the Act against foreign technology companies remain underspecified, creating potential liability evasion routes.
Surveillance infrastructure risk. Critiques written in early 2026 warned that localization would concentrate Bangladeshi personal data where the state could reach it. The localization clause did not survive into the Act, but the underlying concern shifted rather than disappeared: the NRDEX platform and the unified identity layer built under the National Data Management Act, 2026 join citizen registers together by design.
The Tech Global Institute, ARTICLE 19, the Global Network Initiative, and the Robert F. Kennedy Human Rights Center have each issued statements urging stronger safeguards, clearer limits on government access, and independent oversight of the Authority.
Right to Information Act 2009: Counterbalancing Transparency
The Right to Information Act 2009 creates an important counterbalance. Sections 7(h), 7(i), and 7(r) exempt authorities from disclosing information that may reveal personal privacy, endanger life or physical safety, or is protected under other laws.
Section 3 gives the RTI Act supremacy over conflicting provisions in other laws. Section 3 of the Personal Data Protection Act, 2026, however, asserts its own precedence over anything inconsistent in any other law in force. Courts will likely need to resolve conflicts between the right to information and the right to data protection as both frameworks mature.
Business Compliance: What Organizations Need to Do
The substantive duties already bind. What is deferred is the machinery that punishes breaching them, and it starts on a notification nobody can date yet. Here is what compliance preparation should look like:
Determine applicability. The Act applies to any organization processing personal data inside Bangladesh, and to processing abroad tied to offering goods or services to data subjects in Bangladesh or to monitoring or profiling them. It covers companies of all sizes.
Audit your data. Map what personal data you hold about Bangladeshi data subjects. Note the four tiers the Government may set under section 29 (public, internal, confidential, restricted), remembering that no classification has been notified, and identify whether any of it falls in the ten sensitive categories in section 2(21).
Review consent mechanisms. Assess existing collection against section 5(2): consent must be voluntary, specific, clear and revocable, and the data subject must be told the purpose, the retention period, any transfer and how to withdraw. Legacy opt-out or implied consent models will not satisfy the law.
Update privacy notices. Section 15(2) requires you to tell data subjects the categories of data collected and how it is collected, the purposes, the categories that carry a risk of harm, how to exercise their rights and complain to the Authority, any transfer, and how to reach you.
Do not budget for data localization. The Act imposes no local-copy or residency duty. Check instead that you have a section 29(3) ground for any transfer, that the destination meets the section 29(4) suitable technology and equipment condition, and that you notify the Authority under section 29(6) before a large-volume transfer of sensitive personally identifiable data.
Evaluate significant data fiduciary status. Regulations setting the section 2(5) thresholds have not been issued, so large-scale processors should anticipate designation. A significant data fiduciary must appoint a Chief Data Officer once section 23 commences, and faces a BDT 5,000,000 fine ceiling instead of BDT 2,500,000.
Implement security measures. Section 17 requires technical and organizational measures including pseudonymization, encryption, resilience, timely restoration of access after an incident, periodic risk assessment and regular testing of what you have put in place.
Establish retention policies. Personal data must not be kept longer than necessary for its original processing purpose. Implement data retention schedules and deletion procedures.
Maintain processing records. Retain records of data processing activities for a minimum of five years.
Prepare for children's data. If minors may use your service, build verifiable parental or guardian consent under section 9. Note that the Act carries no ban on profiling or advertising to children, so any such limit has to come from your own policy or from another jurisdiction's law.
Note cross-border transfer requirements. Document the section 29(3) ground you rely on and the destination's suitability under section 29(4). Any transferor, not only a significant data fiduciary, must notify the Authority of a large-volume cross-border transfer of sensitive personally identifiable data under section 29(6).
For information on related laws, see the guide to Bangladesh recording laws.
Recent Developments
What changed on 10 April 2026. The Parliament elected in February 2026 replaced the interim government's ordinances with Acts on a single day. The Personal Data Protection Act, 2026 (Act 63 of 2026) repealed the Personal Data Protection Ordinance 2025 and the February 2026 amendment ordinance by section 44. The National Data Management Act, 2026 (Act 80 of 2026) repealed the National Data Management Ordinance 2025 by section 49. The Cyber Security Act, 2026 (Act 81 of 2026) repealed the Cyber Security Act 2023 by section 50 and the Cyber Security Ordinance 2025 by section 51.
This was not a re-enactment of the same text. Three changes matter to anyone acting on the law. The localization clause disappeared, so no local-copy duty exists. The criminal offences chapter disappeared, so the data protection statute now carries administrative fines only, capped at BDT 2,500,000 and BDT 5,000,000. The outright ban on tracking, profiling and targeted advertising aimed at children disappeared, leaving parental consent as the only protection in section 9.
1 July 2026. The Cyber Security (Amendment) Act, 2026 (Act 99 of 2026) deleted section 20 of the Cyber Security Act, 2026.
5 February 2026. Section 97Ka of the Bangladesh Telecommunication Act, 2001, the interception power, was substituted by the Bangladesh Telecommunication (Amendment) Act, 2026 (Act 51 of 2026). It now requires prior approval by a court or a constituted authority, a fixed period, audit logs, destruction of material after the period, and an independent review council.
Still outstanding as of 10 September 2026. No gazette notification has commenced section 23 or sections 31 to 35 of the data protection Act, and section 1(3) does not permit one before roughly October 2027. No regulations have been issued setting significant data fiduciary thresholds, complaint procedures, breach notification form and timing, or a classification under the Schedule. Until they are, several duties in the Act cannot be complied with at the level of detail the Act contemplates.
International observers continue to monitor whether the undefined grounds in section 24(1) will be used in ways that undermine the Act's stated rights protections.
This article is for informational purposes only and does not constitute legal advice. Bangladesh's data protection framework is evolving rapidly as implementing regulations are developed. Consult a qualified attorney licensed to practice in Bangladesh for guidance on specific compliance obligations.
Frequently Asked Questions
Does Bangladesh have a comprehensive data protection law?
Yes. The Personal Data Protection Act, 2026 (Act No. 63 of 2026), passed on 10 April 2026, is Bangladesh's comprehensive data protection law. It repealed the Personal Data Protection Ordinance 2025 and is deemed in force from 6 November 2025. It covers consent, data subject rights, security, breach notification to the regulator and administrative fines, and it contains no data localization requirement. Its Chief Data Officer, complaint and fine sections are deferred to a date the Government must fix by gazette notification.
What did the February 2026 amendment change?
It had exactly two operative sections. It narrowed the local copy duty in section 29(7)(b) of the 2025 ordinance so that only restricted personal data and Critical Information Infrastructure data needed a synchronized real-time copy in Bangladesh, and it replaced imprisonment with a fine for managing directors in section 48 of that ordinance. It did nothing about government employees; that liability was in section 47 of the ordinance as originally gazetted. Both the amendment ordinance and the ordinance it amended were repealed on 10 April 2026 by section 44 of the Personal Data Protection Act, 2026, which has no localization clause and no imprisonment at all.
What penalties apply for violating Bangladesh data privacy laws?
The Personal Data Protection Act, 2026 imposes administrative penalties only. Section 32(1) allows a fine of up to BDT 2,500,000 for failing to honour a data subject right, and section 32(2) raises that to BDT 5,000,000 for a significant data fiduciary, with an additional fine for repeat violations under section 32(3). Section 33 allows up to BDT 2,500,000 for a security failure, and section 35 allows compensation on top. The Act contains no imprisonment and no turnover-percentage bands. The turnover bands and the 5 to 7 year prison terms often quoted came from the repealed 2025 ordinance, and no BDT 300,000 to BDT 500,000 band appears in either instrument.
What happened to the Digital Security Act and Cyber Security Act?
The Digital Security Act 2018 was repealed by the Cyber Security Act 2023, which was replaced by the Cyber Security Ordinance 2025, gazetted May 21, 2025. Current law is the Cyber Security Act, 2026 (Act No. 81 of 2026), passed on 10 April 2026, which repealed both the ordinance and the 2023 Act, and which was amended on 1 July 2026 by Act 99 of 2026. Section 50(4) cancels every pending case under sections 21, 24, 25, 26, 27, 28, 29, 31 and 34 of the 2023 Act, including the section 26 identity information offence, and nullifies sentences already imposed. Not all remaining offences are bailable: section 46(2) makes sections 17, 18(1)(c), 19, 22 and 23 non-bailable, and the maximum penalty is 10 years for cyber terrorism under section 23.
Are there data localization requirements in Bangladesh?
No. The Personal Data Protection Act, 2026 contains no data residency or local copy requirement. Section 29 runs to seven sub-sections and none of them requires a copy inside Bangladesh. The synchronized real-time copy rule existed in the 2025 ordinance, was narrowed by the February 2026 amendment ordinance, and lapsed when both were repealed on 10 April 2026. What remains is the section 29(3) transfer grounds, the section 29(4) condition that the destination have the prescribed suitable technology and equipment, and the section 29(6) duty to notify the Authority of a large-volume transfer of sensitive personally identifiable data.
What is a significant data fiduciary under Bangladesh law?
A significant data fiduciary is one determined by regulations under section 2(5) of the Personal Data Protection Act, 2026, judged by the potential effect on state sovereignty, the volume or financial exposure of the data processed, the risk to data subject rights, and threats to national security, public order, public safety, economic order and public health. No such regulations have been issued. A significant data fiduciary must appoint a Chief Data Officer under section 23 once that section commences, may be required to undergo an independent data audit under section 21, and faces an administrative fine ceiling of BDT 5,000,000 rather than BDT 2,500,000.
When does Bangladesh's data protection law become fully enforceable?
Most of the Act has applied since 6 November 2025, the date section 1(3) deems it effective. Section 23, the Chief Data Officer duty, and sections 31 to 35, covering complaints, administrative fines and compensation, are deferred. They start on a date the Government fixes by gazette notification, which section 1(3) permits only after 18 months have passed from the issue of the Act on 10 April 2026, so the earliest possible date is around October 2027. No commencement notification has been published as of 10 September 2026. The May 2027 date that circulated widely was calculated from the ordinance's gazette date and has no basis in the Act.
Updates
Rewritten around the Personal Data Protection Act, 2026 (Act 63 of 2026), which repealed the 2025 ordinance and its February 2026 amendment on 10 April 2026: the page had stated a data localization duty, turnover-based and BDT 300,000 to 500,000 fines, 5 to 7 year prison terms, a ban on advertising to children, a May 2027 enforcement date, GDPR lawful bases that do not exist in Bangladeshi law, and an Article 43 phone-records holding the cited 1996 case never made, none of which are correct. Corrected the commencement of the Cyber Security Act, 2026: section 1(2) deems it in force from 21 May 2025, not from its 10 April 2026 passage, so there is no gap between the cancelled 2023 Act cyber terrorism cases and the current offence. Also described how section 23 of the 2026 Act differs from section 27 of the 2023 Act, and retitled the section on the nine repealed offences to reflect that section 50(1) repealed the whole 2023 Act while section 50(4) cancelled pending cases under those nine sections.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded to 5,000+ words. Added the Personal Data Protection (Amendment) Ordinance 2026 (Ordinance No. 23, February 5, 2026), the companion 2025 data ordinance, civil society concerns, a full compliance checklist and the political context of the Yunus interim government and the February 2026 transition. That ordinance framework was repealed on 10 April 2026 and the page has since been rewritten around the Personal Data Protection Act, 2026.
Reviewed and approved by an editor
Initial publication. Covered PDPO 2025, Cyber Security Ordinance 2025, Constitutional Article 43, and enforcement timeline.
Sources and References
- Constitution of Bangladesh - Article 43(bdlaws.minlaw.gov.bd).gov
- Personal Data Protection Act, 2026 (Act No. 63 of 2026) - full text, Legislative and Parliamentary Affairs Division(bdlaws.minlaw.gov.bd).gov
- Personal Data Protection Amendment Ordinance 2026(digitalpolicyalert.org)
- PDPO 2025 Key Takeaways - Daily Star(thedailystar.net)
- PDPO 2025 Key Highlights for Businesses(mahbub-law.com)
- National Data Management Ordinance 2025 gazetted (news report); repealed by section 49 of the National Data Management Act, 2026 (Act No. 80 of 2026)(tbsnews.net)
- Cyber Security Ordinance 2025 Nine Sections Repealed(tbsnews.net)
- Cyber Security Ordinance 2025 Gazette(en.prothomalo.com)
- Digital Security Act 2018 English Version(icnl.org)
- Cyber Security Act 2023 (Act No. 39 of 2023) - full text(bdlaws.minlaw.gov.bd).gov
- PDPO Risk of Misuse - Prothom Alo(en.prothomalo.com)
- Bangladesh Telecommunication Act 2001 - consolidated text including section 97Ka as substituted in 2026(bdlaws.minlaw.gov.bd).gov
- ICT Act 2006 Bangladesh(samsn.ifj.org)
- Right to Information Act 2009 Summary(humanrightsinitiative.org)
- Broad Exemptions Could Open Door to Surveillance(thedailystar.net)
- Bangladesh Digital ID and Data Security(biometricupdate.com)
- National Data Management Act, 2026 (Act No. 80 of 2026) - full text(bdlaws.minlaw.gov.bd).gov
- Cyber Security Act, 2026 (Act No. 81 of 2026) - full text(bdlaws.minlaw.gov.bd).gov
- Cyber Security (Amendment) Act, 2026 (Act No. 99 of 2026)(bdlaws.minlaw.gov.bd).gov
- Dr. Mohiuddin Farooque v. Secretary, Ministry of Commerce, Writ Petition No. 92 of 1996 (judgment text)(globalhealthrights.org)