Cyber Security Act Offenses & Cyber Tribunal Bangladesh Guide

Featured Snippet: The Cyber Security Act, 2023 (Act No. XXVIII of 2023) is Bangladesh's principal cyber-crime statute, repealing the Cyber Security Act 2023. It defines 18 substantive offenses (Sections 17–34), establishes specialized Cyber Tribunals, restricts non-bailable offenses to Sections 17, 19, 27, and 33…

ID: 994 3,803 words

Source & verification

Trust signals for this guide

These signals describe the content record. They do not guarantee a legal outcome or establish that every rule remains current.

Ready for static publication
Statutory references
No source reference is supplied in this record.
Record status

Last audit date is not recorded

English–Bengali pair linked

Record ID: 994

Important: This is general information, not legal advice. For your situation, consult a qualified lawyer and verify the official publication.

At a glance

Executive summary

Featured Snippet: The Cyber Security Act, 2023 (Act No. XXVIII of 2023) is Bangladesh's principal cyber-crime statute, repealing the Cyber Security Act 2023. It defines 18 substantive offenses (Sections 17–34), establishes specialized Cyber Tribunals, restricts non-bailable offenses to Sections 17, 19, 27, and 33…

Practice area supreme court
Reading time About 18 min
Latest date Review pending
বাংলা সংস্করণ এই আইনি নির্দেশিকাটি বাংলায় পড়তে চান?
সম্পূর্ণ বাংলা সংস্করণ পড়ুন →

Executive Summary & Statutory Authority

Compliance Requirement / Procedural StepGoverning Section / Statutory RuleResponsible Regulatory AuthorityMandatory Fees & Processing Timelines
Critical Information Infrastructure (CII) Protection & AuditSection 17, Cyber Security Act 2023Digital Security Agency (DSA) / National Computer Incident Response TeamAs prescribed by Director General; Timeline: Annual security audit submission
Reporting Cyber Security Incidents & BreachesSection 16 & 25, Cyber Security Act 2023Bangladesh Computer Council & Cyber TribunalNo official filing fee; Immediate mandatory reporting within 24 hours of incident
Filing Complaint for Cyber Harassment & DefamationSection 25 & 29, Cyber Security Act 2023Cyber Police Bureau (CPB) & Cyber Tribunal DhakaNominal court fees; Investigation & charge sheet filing within 60 working days
Cyber Tribunal Bail Hearing & Legal RepresentationSection 54, Code of Criminal Procedure & CSA 2023 RulesCyber Tribunal Dhaka & High Court DivisionStandard legal retainers; Bail application hearing scheduled within 3 to 7 working days

The Cyber Security Act, 2023 received presidential assent on 13 September 2023, formally repealing the widely criticized Cyber Security Act 2023 (Act No. XLVI of 2018), which itself had replaced the notorious Section 57 of the Information and Communication Technology Act, 2006. The CSA 2023 operates as a hybrid statute — simultaneously a substantive penal code for cyber offenses, a jurisdictional charter establishing Cyber Tribunals under Section 38, and a procedural code interlocking with the Code of Criminal Procedure, 1898, the Evidence Act, 1872 (as amended in 2022), and the Bangladesh Telecommunication Regulation Act, 2001.

For criminal defense practitioners and technology compliance counsel, the CSA 2023 represents a partial liberalization from the DSA regime — most notably by rendering digital defamation (Section 29) non-cognizable and fine-only — while simultaneously retaining severe non-bailable exposure for hacking (Section 33), cyber terrorism (Section 27), critical infrastructure attacks (Section 17), and data/system damage (Section 19). This treatise provides an exhaustive doctrinal and procedural roadmap for navigating investigation, tribunal trial, bail litigation, and corporate compliance obligations under this framework.


1Incident / BreachIdentification2FIR / Complaintat Cyber Police3Investigation &Report Filing4Cyber TribunalCognizance5Trial or BailResolution

I. The Legislative Evolution: From ICT Act 2006 to CSA 2023

1.1 The Section 57 Controversy and the Cyber Security Act 2023 Interlude

Section 57 of the ICT Act 2006 criminalized the publication of material that was "fake and obscene," caused "deterioration of law and order," or hurt "religious belief," carrying penalties up to 14 years' imprisonment. Its vague drafting produced rampant misuse against journalists, bloggers, and political dissenters, prompting its repeal via the Cyber Security Act 2023. However, the Cyber Security Act 2023 replicated many of the same infirmities — particularly Sections 25 (false/offensive information), 28 (religious sentiment), 29 (defamation), and 31 (public disorder) — while adding Section 43, a warrantless search-and-arrest power that drew sustained constitutional criticism for violating Articles 31, 32, and 43 of the Constitution of Bangladesh.

1.2 Enactment of CSA 2023: Key Structural Revisions

The CSA 2023 retained the substantive skeleton of the DSA but introduced three critical reforms of direct relevance to defense counsel:

  1. Narrowed Non-Bailable Category: Whereas the DSA rendered numerous offenses (including defamation-adjacent provisions) effectively non-bailable in practice through police overreach, the CSA 2023 explicitly confines non-bailable status to only four sections: 17, 19, 27, and 33.
  2. Decriminalization Trend for Defamation: Section 29 (digital defamation) was converted into a non-cognizable, fine-only offense with no custodial sentence, aligning it more closely with ordinary civil/criminal defamation under the Penal Code.
  3. Renumbering and Consolidation: Provisions formerly scattered across Sections 25, 28, 31, and 43 of the DSA were consolidated and renumbered as Sections 21, 25, 28, 31, 33, and 42 respectively under the CSA.

1.3 Constitutional Tension: Article 39 vs. Cybersecurity Imperatives

Article 39 of the Constitution guarantees freedom of speech and expression subject to "reasonable restrictions" in the interest of the security of the State, public order, decency, or morality. The Appellate Division and High Court Division have repeatedly been called upon to police the boundary between legitimate restriction and unconstitutional overreach. The jurisprudence discussed in Section VIII below demonstrates that courts increasingly apply a "clear and present danger" proximate-causation test rather than accepting speculative harm as sufficient justification for either prosecution or continued pre-trial detention.


II. Deconstructing the Substantive Cyber Offenses

2.1 Critical Information Infrastructure Protection: Sections 17 & 19

Section 17 criminalizes unauthorized access to or attack upon a Critical Information Infrastructure (CII) — systems designated by government notification as vital to national security, the economy, public health, or safety (e.g., banking backbones, power grid SCADA systems, telecom switching centers). Punishment ranges from 3 to 6 years' imprisonment and/or a fine of up to BDT 1 crore. This is a cognizable, non-bailable offense.

Section 19 addresses damage to computer systems, digital networks, or data more broadly (not limited to CII), carrying 1 to 7 years imprisonment and fine up to BDT 10 lakh, also non-bailable. Defense counsel should scrutinize whether the prosecution has established (a) a formal CII gazette notification predating the alleged conduct for Section 17 charges, and (b) actual, provable damage (not mere unauthorized access) to sustain a Section 19 charge.

2.2 Cyber Terrorism, Espionage, and Hacking: Sections 27, 32 & 33

Section 27 (Cyber Terrorism) is the most severely punished offense under the Act — up to 14 years' imprisonment and fine up to BDT 1 crore — reserved for acts intended to threaten the unity, security, or sovereignty of the State, or to create panic among the public through digital means. Given its non-bailable status, prosecutors sometimes invoke Section 27 loosely against ordinary hacking or protest-related digital activity; defense strategy must force the prosecution to particularize the specific terroristic intent element, since generic mischief does not meet the statutory threshold (see Khadijatul Kubra, discussed below).

Section 32 penalizes breach of official secrets via digital devices (up to 3 years, BDT 10 lakh fine, bailable), while Section 33 (Hacking) — unauthorized modification, deletion, or destruction of computer systems/data — carries up to 14 years and BDT 1 crore fine and is non-bailable, mirroring the severity of cyber terrorism.

2.3 Identity, Impersonation, and Digital Fraud: Sections 22–26

Sections 22 (digital/electronic fraud), 23 (cheating by impersonation), 24 (identity theft), and 26 (unauthorized collection/use of personal identity data) form a cluster of financially-motivated offenses, each carrying up to 2 years imprisonment and fines between BDT 5 lakh, all bailable and cognizable. These provisions are frequently invoked in fintech fraud, SIM-swap, and phishing prosecutions, and require the prosecution to establish both the unauthorized data acquisition and a fraudulent intent or resulting pecuniary loss.

2.4 Speech, State Security, and Religious Sentiment: Sections 21, 25, 28 & 31

Section 21 criminalizes propaganda against the Liberation War, the Father of the Nation, the national flag, or the national anthem (up to 5 years, BDT 1 crore fine, bailable). Section 25 targets transmission of false, offensive, or threatening information (up to 2 years). Section 28 covers hurting religious sentiment via digital media (up to 2 years). Section 31 addresses deterioration of law and order or fomenting enmity between classes (up to 5 years, BDT 25 lakh fine). All four are bailable, marking a deliberate legislative softening compared to their DSA predecessors, though they remain cognizable and thus subject to warrantless arrest under Section 42.

2.5 Digital Defamation (Section 29): The Fine-Only Regime

Section 29 is the CSA's signature reform: defamation via digital medium carries no term of imprisonment whatsoever, only a fine up to BDT 25 lakh, and is expressly non-cognizable. This means police cannot register an FIR, investigate, or arrest without a Magistrate's order under Section 155(2) CrPC. As detailed in Section V below, this classification is routinely violated in practice, giving rise to one of the most potent defense tools available under the Act.

2.6 Corporate Liability: Section 37

Section 37 imposes vicarious criminal liability on every director, partner, manager, secretary, or officer "in charge of and responsible to the company for the conduct of its business" at the time of the offense, unless that individual proves (a) the offense was committed without their knowledge, or (b) they exercised all due diligence to prevent its commission. This "due diligence" defense is the linchpin of corporate compliance strategy discussed in Section VII.


III. Enforcement Mechanics: The Limits of Police Authority

3.1 Section 42 Warrantless Search, Seizure & Arrest

Section 42 empowers a police officer not below the rank of Sub-Inspector, or an authorized officer of the designated Agency, to enter and search any premises, seize computers/networks, and arrest a person without a warrant, provided the officer has "reason to believe" an offense under the Act is being or has been committed. This sweeping power is the most litigated provision of the statute. It does not, however, dispense with the safeguards of the CrPC — search and seizure must still comply with Section 103 CrPC, requiring a written seizure list (Jabtanama) executed at the spot in the presence of at least two independent, respectable witnesses.

3.2 The Digital Chain of Custody

Once seized, digital media must be forensically imaged using a bit-by-bit duplication process, with a cryptographic hash (MD5 or SHA-256) computed immediately upon seizure and again upon laboratory ingestion. Any variance between these hash values is fatal to the prosecution's claim of evidentiary integrity. Devices should be transported in tamper-evident, anti-static bags and delivered to an accredited forensic laboratory (CID Forensic Training Institute, National Cyber Security Agency Lab, or Bangladesh Computer Council Cyber Lab) within 24 hours of seizure — any unexplained delay is a legitimate ground for challenging admissibility.

3.3 Remand Under Section 167 CrPC

Because Section 44 of the CSA imports the CrPC wholesale (save where inconsistent), remand applications for cyber offenses follow ordinary Section 167 CrPC limits — a maximum of 15 days' cumulative police custody. Defense counsel should object to remand applications lacking specific, case-linked justification (e.g., generic assertions of "further investigation needed" without identifying what evidence remains to be recovered from the accused).


IV. Procedural Architecture of the Cyber Tribunals

4.1 Establishment and Jurisdiction

Section 38 establishes Cyber Tribunals at each divisional headquarters — Dhaka, Chattogram, Rajshahi, Khulna, Barishal, Sylhet, Rangpur, and Mymensingh — vested with exclusive original jurisdiction over offenses under the Act. Cases originate either via FIR at a police station under Section 154 CrPC (for cognizable offenses) or via direct complaint (C.R. Case) under Section 200 CrPC before the Tribunal itself (mandatory for the non-cognizable Section 29 offense).

4.2 The Section 40 Investigation Clock

Investigations must conclude within a base period of 60 working days. If incomplete, the Investigating Officer may seek a first extension of 15 working days by recording written reasons and notifying the Agency's Director General or the Tribunal. A final extension of 30 working days requires a formal petition and Tribunal approval. The aggregate ceiling is 105 working days. Failure to conclude within this window empowers the Tribunal to order departmental action against the IO and reassign the case — and critically, gives the defense a substantive statutory ground for bail based on prosecutorial default.

4.3 Cognizance, Discharge, and Charge Framing

Upon receipt of the police report (Section 173 CrPC) or complaint inquiry report, the Tribunal scrutinizes the record for cognizance. Defense counsel should file a discharge application analogous to Sections 241A/265C CrPC at the earliest opportunity, arguing absence of prima facie material — particularly effective where the sole evidence is uncertified electronic material (see Section VI).

4.4 Trial and Appeal

Trial proceeds through prosecution evidence, cross-examination (including of forensic experts — see the playbook in Section VIII), examination of the accused under Section 342 CrPC, and final arguments. Section 45 provides a 30-day appellate window to the High Court Division from any Tribunal judgment, order, or sentence.


V. The Comprehensive Bail Blueprint

5.1 Bailable Offenses: An Absolute Right

For the fourteen bailable sections (18, 20–26, 28–32, 34), bail is a matter of statutory right under Section 496 CrPC. Once identity is confirmed and reasonable local sureties are furnished, the Magistrate or Tribunal has no residual discretion to refuse bail. In practice, Magistrates sometimes wrongly treat cyber cases as presumptively serious and delay bail orders — a posture that is legally untenable and should be challenged immediately via revision or, where necessary, a habeas corpus petition.

5.2 Non-Bailable Offenses: Sections 17, 19, 27, 33

Bail here is discretionary under Section 497 CrPC, requiring the defense to demonstrate the absence of reasonable grounds for believing the accused committed an offense punishable with death or life imprisonment (Section 27 alone reaches 14 years, not life, which itself is a persuasive threshold argument). Effective strategies include:

  • Forensic Linkage Challenges: Demonstrating that the IP address relied upon was dynamically allocated via Carrier-Grade NAT (CGNAT), shared among numerous subscribers, and therefore incapable of uniquely identifying the accused.
  • Device Non-Ownership: Establishing the seized device was not registered to, or in exclusive possession of, the accused.
  • Statutory Delay: Invoking breach of the Section 40 105-working-day ceiling as an independent ground.

5.3 High Court Division Bail — Section 498 CrPC

Where Tribunal or Sessions-level bail is refused, recourse lies to the High Court Division under Section 498 CrPC, either as regular bail or anticipatory bail. Persuasive HCD arguments include violation of Articles 31 and 32 (right to life and liberty and due process), prolonged incarceration absent trial commencement, absence of a valid Section 65B evidentiary certificate underpinning the prosecution's entire case, and mischaracterization of ordinary conduct as "cyber terrorism" absent any threat to national security infrastructure.

5.4 Default Bail via Investigation Delay

Where the aggregate 60+15+30 working-day investigation period lapses without submission of a police report, defense counsel should move for bail citing prosecutorial default as a substantive, independent ground — reinforced by the constitutional principle against indefinite pre-trial detention articulated in Khadijatul Kubra v. The State.


VI. Digital Evidence Under the Evidence (Amendment) Act, 2022

6.1 The End of Bare Printout Admissibility

The Evidence (Amendment) Act, 2022 inserted Sections 22A, 65A, 65B, 85A, 85B, and 85C into the Evidence Act, 1872. Section 65B is decisive: electronic records (screenshots, chat logs, CCTV footage, audio/video files) are inadmissible unless accompanied by a certificate from a person in lawful control of the relevant computer/device attesting that:

  1. The output was produced during a period when the device was in regular use;
  2. Information was fed into the system in the ordinary course of activities;
  3. The device was operating properly throughout, with no unauthorized interference.

6.2 Drafting and Contesting the Section 65B Certificate

The certificate must specify the device, the manner of production, and be signed by a person occupying a "responsible official position" in relation to the device. Defense counsel must object at the point of tender — the landmark ruling in S.M. Mahbubur Rahman v. The State (72 DLR 158, HCD) holds that uncertified printouts cannot form the sole basis for framing charges, and that failure to object contemporaneously may waive the objection on appeal. Early, formal objection is therefore a non-negotiable defense discipline.

6.3 Forensic Reports and CDR/IPDR Evidence

Call Detail Records (CDR) and Internet Protocol Detail Records (IPDR) obtained from telecom operators must likewise be authenticated via Section 65B certification from the operator's authorized custodian. Cross-examination should target whether the IP address resolution accounts for CGNAT sharing, whether port/session logs were matched, and whether the forensic analyst used a certified write-blocker to prevent metadata contamination during device examination.


VII. Corporate Compliance, Platform Liability & Data Governance

7.1 Data Retention and the 180-Day Rule

To defend against Section 37 exposure and to respond promptly to lawful requests, entities operating digital platforms, banks, and fintechs should retain network access logs, authentication trails, and IP allocation records for a rolling minimum of 180 days, consistent with BTRC directives.

7.2 Immutable Logging and Section 65B Readiness

Logging systems should be architected to permit a designated System Administrator or Data Protection Officer to issue a valid Section 65B certificate on demand, without post-hoc reconstruction, to withstand judicial scrutiny.

7.3 Law Enforcement Request Triage

Corporations should maintain a documented protocol for receiving, verifying, and responding to subpoenas, National Cyber Security Agency (NCSA) directives, and BTRC takedown notices within the mandated turnaround windows (typically 6–24 hours), preserving an audit trail of every request and response.

7.4 The Due Diligence Defense in Practice

To invoke the Section 37 due diligence defense, companies should maintain: (a) a written acceptable-use and BYOD policy, (b) a designated Chief Information Security Officer, (c) periodic security audits, and (d) documented incident-response procedures demonstrating proactive prevention rather than reactive damage control.


Statutory Document Checklist

Prosecution / Investigating Agency Documents: - [ ] First Information Report (FIR) or Complaint Petition (C.R. Case) under Section 154/200 CrPC - [ ] Seizure List (Jabtanama) under Section 103 CrPC with two independent witness signatures - [ ] MD5/SHA-256 hash generation record (contemporaneous with seizure) - [ ] Tamper-evident evidence bag chain-of-custody log - [ ] Digital Forensic Analysis Report from CID/NCSA/BCC accredited laboratory - [ ] Section 65B Evidence Act certificate from ISP/MNO/platform administrator - [ ] CDR/IPDR records with dynamic IP allocation tables - [ ] Section 40 investigation extension orders (if applicable) - [ ] Charge sheet / Police Report under Section 173 CrPC

Defense Counsel Documents: - [ ] Certified copy of FIR, seizure list, and charge sheet - [ ] Independent forensic mirror-image verification petition - [ ] BTRC dynamic IP / CGNAT audit request - [ ] Device ownership/non-ownership proof (purchase records, SIM registration) - [ ] Chain-of-custody challenge sheet documenting delays/breaches - [ ] Computation sheet of Section 40 working-day timeline - [ ] Bail petition (Section 496/497/498 CrPC as applicable) - [ ] Section 561A quashment petition (where applicable)


Regulatory Fees, Timelines & Penalty Matrix

Item Detail
FIR filing No fee; filed at Thana or Cyber Tribunal (complaint case)
Court fee — Bail Petition Nominal court-fee stamp (BDT 20–50 typically) per petition
Court fee — Quashment (561A) / Writ Petition Court-fee stamp as per HCD schedule, generally BDT 300–1,000
Appeal filing (Section 45 CSA) Within 30 days of Tribunal judgment; court fee per HCD Rules
Investigation timeline 60 working days (base) + 15 (first ext.) + 30 (final ext.) = 105 days max
Remand (Section 167 CrPC) Maximum 15 days cumulative police custody
Section 17 penalty 3–6 years imprisonment; fine up to BDT 1 crore; non-bailable
Section 19 penalty 1–7 years imprisonment; fine up to BDT 10 lakh; non-bailable
Section 27 penalty Up to 14 years imprisonment; fine up to BDT 1 crore; non-bailable
Section 29 penalty No imprisonment; fine up to BDT 25 lakh; non-cognizable/bailable
Section 33 penalty Up to 14 years imprisonment; fine up to BDT 1 crore; non-bailable
Default consequence (IO delay) Departmental proceedings against IO; ground for accused's bail
Log retention (corporate) Minimum 180 days rolling retention recommended
Forensic transmission window Within 24 hours of seizure to accredited lab

Common Legal Traps & Compliance Pitfalls

  1. Unlawful Arrest Under Section 29 (Defamation): Police frequently register FIRs and arrest suspects for online defamation despite Section 29 being non-cognizable and fine-only. Senior counsel immediately files for release under Section 496 CrPC and pursues quashment under Section 561A CrPC, citing the illegality of proceeding without a Magistrate's order under Section 155(2) CrPC.

  2. Overbroad Section 42 Seizures: Investigators often seize unrelated devices (family members' phones, entire office servers) under the guise of urgency. Counsel should file a preliminary objection challenging the legality of the seizure and move to suppress evidence obtained beyond the scope of "reasonable belief," invoking Article 43 constitutional privacy protections.

  3. **Unc

Frequently Asked Questions

◆ Related Statutory Guides & Practice Insights

    <li style="margin-bottom:12px; line-height:1.5;">
      <a href="/en/bangladesh-patent-act-2023-filing-utility-models-novelty-criteria-priority-rights-trips-compliance/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">&bull; Bangladesh Patent Act 2023: Utility Models & TRIPS Guide</a>
    </li>
    
    <li style="margin-bottom:12px; line-height:1.5;">
      <a href="/en/cyber-security-act-2023-compliance-guide/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">&bull; Cyber Security Act 2023: Corporate Compliance & Data Protection</a>
    </li>
    
    <li style="margin-bottom:12px; line-height:1.5;">
      <a href="/en/trademark-registration-bangladesh-process-fees-timeline/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">&bull; Trademark Registration in Bangladesh: Process, Fees & Timeline</a>
    </li>
    
    <li style="margin-bottom:12px; line-height:1.5;">
      <a href="/en/copyright-protection-bangladesh-creators-tech-guide/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">&bull; Copyright Protection in Bangladesh: Guide for Creators & Tech</a>
    </li>

Official Regulatory Authorities, Gazettes & Forms

Governing Primary Statutes: Trademarks Act 2009, Bangladesh Patent Act 2023, Copyright Act 2023, Cyber Security Act 2023

<div style="margin-bottom:12px; padding-bottom:12px; border-bottom:1px solid #1E293B;">
  <a href="https://dpdt.gov.bd/" target="_blank" rel="noopener noreferrer" style="color:#C5A059; font-weight:600; font-size:14px; text-decoration:underline;">Department of Patents, Designs and Trademarks (DPDT) &nearr;</a>
  <p style="color:#94A3B8; font-size:12px; margin:4px 0 0 0; line-height:1.4;">Official Trademark Journal, Patent Applications & IP Opposition Gazettes</p>
</div>

<div style="margin-bottom:12px; padding-bottom:12px; border-bottom:1px solid #1E293B;">
  <a href="https://copyrightoffice.gov.bd/" target="_blank" rel="noopener noreferrer" style="color:#C5A059; font-weight:600; font-size:14px; text-decoration:underline;">Copyright Office Bangladesh &nearr;</a>
  <p style="color:#94A3B8; font-size:12px; margin:4px 0 0 0; line-height:1.4;">Software, Literary, Artistic & Musical Works Copyright Registration</p>
</div>

<div style="margin-bottom:12px; padding-bottom:12px; border-bottom:1px solid #1E293B;">
  <a href="https://www.wipo.int/" target="_blank" rel="noopener noreferrer" style="color:#C5A059; font-weight:600; font-size:14px; text-decoration:underline;">World Intellectual Property Organization (WIPO) &nearr;</a>
  <p style="color:#94A3B8; font-size:12px; margin:4px 0 0 0; line-height:1.4;">International IP Systems, Madrid Protocol & PCT Regulations</p>
</div>

What is the primary difference between the Digital Security Act (DSA) and the Cyber Security Act 2023?

The Cyber Security Act 2023 replaced the controversial DSA by introducing key reforms such as converting several previously non-bailable offenses into bailable ones, reducing maximum prison sentences for specific digital speech offenses, and replacing harsh imprisonment terms with monetary fines for initial infractions.

What constitutes unauthorized system access and hacking under Section 17 of the Cyber Security Act?

Section 17 deals with attacking Critical Information Infrastructure (CII). Unauthorized entry, hacking, disabling, or damaging computer networks, servers, or databases designated as CII by the government constitutes a severe offense punishable by long-term imprisonment and hefty financial penalties.

How are cyber harassment, bullying, and online defamation prosecuted in Bangladesh?

Offenses involving online harassment, defamation, or publication of electronic content that hurts religious sentiments or deteriorates law and order are prosecuted under Sections 25, 28, and 29. Victims can file a case directly with the Cyber Police Bureau or through a petition to the Cyber Tribunal.

What is the procedure for securing bail at the Cyber Tribunal in Dhaka?

To secure bail at the Cyber Tribunal Dhaka, a formal bail petition must be filed by defense counsel through a licensed advocate. The judge evaluates the nature of the offense, police report, and bailable status under the Act. If denied at the Tribunal level, petitioners can move the High Court Division for bail.

Which regulatory body oversees digital compliance and critical infrastructure in Bangladesh?

The Digital Security Agency (DSA), operating under the Ministry of Posts, Telecommunications and Information Technology, alongside the National Computer Incident Response Team (BGD e-GOV CIRT), oversees digital compliance, audits, and incident responses.

Are offenses under the Cyber Security Act bailable or non-bailable?

It depends on the specific section violated. While the Cyber Security Act 2023 converted several speech-related offenses into bailable categories to protect civil liberties, severe financial crimes, hacking of critical infrastructure, and repeat offenses remain strictly non-bailable.

Tailored Legal Counsel

Need direct legal advice on this matter?

Consult with our senior advocates and corporate practice specialists to evaluate your compliance requirements and legal strategy.

MAINTENANCE LOOP

Found an issue in this guide?

Report a citation, link, translation, or currentness concern with the record ID. This is an editorial report, not an automatic legal update or advice channel.