Executive Summary & Statutory Authority
| Compliance area | Primary source to verify | Likely responsible body | Currentness note |
|---|---|---|---|
| Personal-data governance | Personal Data Protection Act 2026 (Act No. 63 of 2026), commencement and rules | Authority designated by the Act and current government instruments | Verify commencement, rules, forms and thresholds; no fixed fee or deadline asserted |
| Cross-border transfer | Act text, rules, sector directions and contract | Designated data-protection authority and relevant sector regulator | Transfer basis, approvals and localization depend on data, entity and current instruments |
| High-risk processing | Act, rules, authority guidance and sector instructions | Controller, processor and designated authority | DPO/DPIA/RoPA duties must be confirmed from the applicable source |
| Complaints and incidents | Act, rules, cyber law and sector reporting directions | Controller/processor and relevant authority | Use the current reporting channel and deadline; no universal SLA stated |
Featured Snippet: Bangladesh's data-protection analysis now requires the official Personal Data Protection Act 2026 (published by the ICT Division on 15 April 2026) to be read with its commencement provisions, rules and authority instruments, alongside Constitution Article 43(b), cyber legislation and sector-specific directions. No universal fee, DPO deadline, localization rule or cross-border approval route should be stated without the applicable current text.
The ICT Division's official laws portal records publication of the Personal Data Protection Act 2026 on 15 April 2026. This article therefore treats it as an enacted source requiring text-specific verification, not as a “draft” or merely prospective bill. Practitioners must still check commencement, rules, designated authority, forms, exemptions and transition provisions. Constitution Article 43(b), the ICT Act 2006, the Cyber Security Act 2023, Bangladesh Bank directions and BTRC instruments may also apply to the entity, data and processing activity.
Publication of the Act does not establish a universal compliance timetable or prove that every controller must register, appoint a DPO, localize every record or obtain prior transfer approval. Those conclusions require the relevant provisions, rules, authority guidance, sector directions and facts. The safe approach is a current source register and a documented data-flow assessment.
I. Constitutional Foundation and the Existing Penal-Regulatory Framework
A. Article 43(b): The Constitutional Genesis of Privacy
Article 43(b) of the Constitution guarantees every citizen, subject to reasonable restrictions imposed by law in the interest of state security, public order, public morality, or public health, the right to the privacy of correspondence and other means of communication. Although textually framed as protection against state surveillance, Bangladeshi courts have progressively extended its interpretive reach to inform private commercial conduct through statutory and tortious mechanisms — notably via the public policy doctrine embedded in Section 23 of the Contract Act, 1872, which renders agreements contrary to public policy (including those facilitating unauthorized data misappropriation) void.
The doctrine of horizontal application — whether a fundamental right enforceable primarily against the State can also bind private corporate actors — remains judicially unsettled in Bangladesh, unlike India's post-Puttaswamy trajectory (Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1), where the Indian Supreme Court recognized privacy as intrinsic to Article 21 and capable of restraining private data aggregators. Bangladeshi jurisprudence has approached this obliquely, primarily through writ petitions targeting government-mandated data collection schemes implemented via private corporate intermediaries (telecom operators, banks), effectively imposing privacy-protective conditions on private entities acting as statutory conduits.
B. The Information and Communication Technology Act, 2006
The ICT Act, 2006 (Act No. XXXIX of 2006), as amended in 2009 and 2013, remains the foundational penal statute governing unauthorized data interference:
- Do not rely on historic ICT Act section numbers or penalty figures without checking the offence, amendments, repeal/saving provisions and date applicable to the incident.
- Record the current law governing unauthorized access, data interference, corporate attribution, investigation and compensation for the actual facts.
- Keep cyber-security controls, evidence preservation and incident escalation separate from the data-protection legal basis; one does not automatically prove the other.
C. The Cyber Security Act, 2023
The Cyber Security Act 2023 (Act No. XXVII of 2023) repealed and replaced the controversial Digital Security Act, 2018, retaining core data-security offenses while introducing the concept of Critical Information Infrastructure (CII):
- Check whether the Cyber Security Act 2023 or the official Cyber Security Act 2026 and any later amendment governs the conduct and court process.
- Verify the current CII designation, offence elements, corporate attribution, investigation and penalty provisions from the official text.
- Do not reproduce historic section numbers or fixed imprisonment/fine figures without a current source and date qualification.
D. Telecommunications and Information Access Statutes
The Bangladesh Telecommunication Regulation Act, 2001 imposes confidentiality standards on telecom operators regarding subscriber metadata and Call Detail Records (CDRs) under Section 30, while Section 97A grants narrow, exceptional lawful interception powers exclusively to designated state agencies — a provision courts have interpreted strictly against private actors.
The Right to Information Act, 2009, under Section 7(h) and (i), exempts public authorities from disclosing personal information, trade secrets, or intellectual property where disclosure would breach individual privacy or cause commercial harm — an important shield invoked by corporate counsel resisting overbroad regulatory disclosure demands.
II. The Personal Data Protection Act 2026 (Act No. 63 of 2026): Institutional Architecture and Definitional Taxonomy
A. Jurisdictional Scope
The 2026 Act must be read for its territorial and extraterritorial scope, definitions, exemptions and commencement. Do not import GDPR Article 3 or describe every offshore service as covered without citing the applicable Bangladeshi provision and identifying the processing, data subject, controller and establishment facts.
B. Core Actors and Their Respective Duties
The Act and its subordinate instruments should be checked for the defined roles and duties of controllers, processors and data subjects. International terminology can help explain the concepts, but it does not replace the Bangladeshi definitions:
- Controller/owner role — verify the statutory definition, purposes, means and duties in the Act and rules.
- Processor/service-provider role — identify the statutory allocation of responsibility and record the contractual safeguards required for the actual service.
- Data subject — identify the rights, limitations, complaint route and exceptions stated in the Act and current instruments; do not assume an EU-style right without a Bangladeshi source.
C. The Designated Data-Protection Authority
Identify the authority designated by the enacted Act, commencement instruments and current government notices. Do not substitute “DPA,” “Directorate,” Digital Security Agency or Cyber Tribunal labels from an earlier draft for the authority actually established and empowered by the current law.
D. Classification of Personal Data
The article's earlier three-tier taxonomy was presented as settled without a verified current text. Classification, localization and transfer consequences must now be taken from the Act, rules and current authority/sector instruments:
- Personal data — use the statutory definition and any exclusions or pseudonymisation rules.
- Special or sensitive categories — use only categories and thresholds stated in the current Act, rules or designation.
- Critical or protected categories — verify any government designation and the exact storage, transfer and security consequence before advising a client.
This taxonomy is the operative pivot for the localization and cross-border rules discussed in Section IV below.
III. Lawful Processing Principles and the Mechanics of Consent
A. Canons of Lawful Processing
These are useful privacy-governance controls, but the enforceable duty, legal basis, exception and remedy must be tied to the current Act, rules, sector instrument or contract. Do not describe anticipated or international principles as already operative Bangladeshi statutory commands:
- Lawfulness, fairness, and transparency in all collection and processing activity.
- Purpose limitation — data collected for one stated purpose cannot be silently repurposed.
- Data minimization — only data strictly necessary for the stated purpose may be collected.
- Storage limitation — retention periods must be tied to defined business or legal necessity, not indefinite accumulation.
- Accuracy — controllers must maintain mechanisms for data subjects to correct inaccurate records.
B. Building an Enforceable Consent Architecture
Corporate consent instruments must satisfy the following cumulative standards to survive regulatory and judicial scrutiny:
- Clear notice and documented choice — record the notice, purpose, legal basis and any consent event required by the current source.
- Purpose and minimisation controls — limit collection and reuse to the statutory, contractual or documented business purpose that applies.
- Withdrawal and rights handling — provide the mechanism required by the Act and rules, subject to lawful retention and other exceptions.
- Children and vulnerable persons — verify the applicable age, consent and safeguarding rule; do not import a universal under-18 threshold without a Bangladeshi source.
C. Processing Without Consent
Processing without consent may be permitted or required by the Act, another statute, contract, court or regulator, but the legal basis and limits must be documented for the actual purpose. “Legitimate interest,” emergency, national-security and telecom-interception propositions must not be treated as universal exemptions.
IV. Cross-Border Data Transfer and Data Localization Architecture
A. The Sovereign Rationale for Localization
Cross-border risk is fact-specific. The Act, rules, authority directions, Bangladesh Bank/BTRC instruments, contract and data category must be checked together. Foreign hosting is not automatically unlawful, and local hosting is not automatically sufficient, without the applicable source and processing facts.
B. The Tiered Localization and Transfer Matrix
| Data Type | Local Retention Mandate | Cross-Border Transfer Conditions |
|---|---|---|
| Critical Personal Data (CPD) | Verify the Act, designation, rules and sector instrument | Verify the current legal basis, approval/notice route and exceptions |
| Sensitive Personal Data (SPD) | Do not assume a universal local-copy rule | Assess the current Act/rules and any Bangladesh Bank, BTRC or other sector requirement |
| General Personal Data | Category- and instrument-specific | Record the statutory, contractual or regulator-approved basis actually used |
C. Legal Pathways for Extraterritorial Transfer
- Adequacy Decisions — bilateral or unilateral government determinations that a destination jurisdiction maintains privacy protections substantially equivalent to Bangladesh's regime. As of the current draft cycle, no formal adequacy list has been published.
- Transfer contract and risk record — document the recipient, purpose, access, security, onward transfer, incident cooperation and the legal basis required by the current Act/rules; use SCCs or BCRs only if recognised or otherwise appropriate under the applicable source.
- Binding Corporate Rules (BCRs) — intra-group compliance codes for multinational corporate structures, subject to regulatory pre-approval, permitting harmonized global data flows without transaction-by-transaction contractual negotiation.
- Narrow Exceptions — international judicial assistance requests, emergency waivers, and case-specific explicit data subject consent for isolated transfers.
D. Sector-Specific Localization: Banking, Fintech, and MFS
Bangladesh Bank's ICT Security Guidelines for Scheduled Banks and Financial Institutions (Version 3.0/4.0) impose the most stringent localization mandate in the current regulatory landscape:
- Verify the current Bangladesh Bank ICT/cloud/security direction for the institution, data classification, core system, disaster-recovery copy and any approval or reporting route.
- Do not convert a sector guideline for a scheduled bank, FI, PSP or MFS provider into a universal localization rule for every company.
- Retention periods, cloud architecture and incident deadlines must be recorded from the current sector instrument and the actual licence.
A parent-company cloud arrangement is not automatically lawful or unlawful. Map the data, controller/processor roles, access, sub-processing, security, sector direction, contract and transfer mechanism; then verify the current authority or sector requirement before deployment.
E. Telecommunications Sector Restrictions
BTRC directives on biometric SIM verification prohibit central storage of raw biometric fingerprint templates by telecom operators; verification must occur via secure API handshake against the Election Commission's National ID database without local retention of the raw biometric hash — a principle directly affirmed in judicial precedent discussed below.
V. Corporate Governance, DPO Appointment, and Breach Response Protocols
A. Institutional Security Infrastructure
Bangladesh Bank and other sector regulators may prescribe security controls for covered institutions. Confirm the current guideline, classification, encryption standard, cloud restriction and reporting route before turning a technical recommendation into a universal legal mandate.
B. Mandatory Data Protection Officer (DPO) Appointment
Whether a DPO is mandatory, which entities must appoint one, and the DPO's independence and reporting duties must be taken from the enacted Act, rules, authority notices and sector directions. Organisations can appoint a privacy lead as a governance control, but should not label the appointment a universal statutory requirement without the applicable source.
C. Record of Processing Activities (RoPA) and DPIA
A RoPA and DPIA are sensible controls for material or high-risk processing. Their statutory trigger, required fields, submission route and deadline must be verified from the Act, rules and sector guidance; this article does not assert that every controller must file either document with an authority.
D. Breach Response and the 72-Hour Rule
Upon breach detection, the Controller must:
- Initiate immediate internal security containment.
- Identify the current authority and incident-reporting channel under the Act, rules and sector instruments.
- For CII, banking, telecom or other regulated entities, check the entity-specific incident direction and escalation chain.
- Record containment, investigation, evidence preservation, legal assessment and communications.
- Notify affected persons or counterparties only to the extent and within the time required by the applicable source.
VI. Landmark Judicial Precedents
A. Khondaker Hasan Reza v. Bangladesh and Others, Writ Petition No. 3433 of 2016 (High Court Division)
Facts: The petitioner challenged BTRC's mandate requiring biometric fingerprint submission for SIM registration, alleging the absence of statutory privacy safeguards for data held by private mobile network operators.
Use caution: A case citation or summary should not be treated as a universal biometric-storage rule without reviewing the judgment, order, parties and subsequent directions. Verify the current BTRC/Election Commission instrument and the specific operator's lawful role before advising on retention.
Principle: Corporate data collectors acquire no proprietary ownership over consumer biometrics — they act as regulated fiduciaries, not data owners. This precedent underpins the "conduit, not custodian" doctrine applicable to any corporate entity handling government-linked identity verification.
B. Advocate Mohammad Shishir Manir and Others v. Government of Bangladesh and Others, Writ Petition No. 5845 of 2021 (High Court Division)
Facts: Unauthorized audio recordings of private telephone conversations were leaked and disseminated across social media without judicial warrant or statutory authorization.
Use caution: Article 43(b), telecom confidentiality and lawful-interception questions require the current statute, instrument and verified judgment. Private entities should not intercept, disclose or retain communications outside a lawful basis, but the article does not certify a universal remedy or offence from an unverified case summary.
Principle: Telecommunication infrastructure providers and OTT communication services owe a strict duty of care over traffic data and metadata; corporate complicity may be presumed upon leakage absent demonstrated safeguards.
C. National ID Database Leakage Public Interest Litigation (2023, High Court Division)
Facts: Public exposure of millions of citizens' names, addresses, phone numbers, and NID numbers occurred via an unencrypted API endpoint of a government registrar.
Use caution: Reported leakage litigation, regulator directions and technical standards must be checked from the primary judgment or official notice. A data incident may create statutory, contractual, regulatory or constitutional exposure, but liability and remedy are fact-specific.
Principle: Technical negligence in data security architecture is independently actionable as a constitutional tort, irrespective of intent, where sensitive identifiers are exposed through inadequate encryption or access controls.
Statutory Document Checklist
Corporate counsel should consider assembling the following review binder, tailoring it to the current Act, rules, authority notices, sector directions and actual processing:
- Enterprise Data Privacy Policy (dual-language English/Bengali) — specifying controller identity, legal basis, processing purposes, cookie/tracking frameworks, third-party disclosures, retention lifecycle, and grievance redress mechanism.
- Explicit Consent Declaration Instrument — unbundled checkboxes separating general processing, marketing/profiling, and cross-border transit consent.
- Data Processing Agreement (DPA) for all controller-to-processor engagements, defining ownership, audit rights, indemnification, sub-processor onboarding, and post-termination deletion obligations.
- Data Protection Impact Assessment (DPIA) Template for high-risk processing (AI, biometrics, large-scale profiling).
- Record of Processing Activities (RoPA) Register classifying data flows, types, hosting environment, access controls, and disposal schedules.
- Standard Contractual Clauses (SCCs) binding offshore parents, cloud vendors, and SaaS providers to local sovereignty standards.
- DPO Appointment Charter — board resolution establishing independence, budget, reporting lines, and immunities.
- Cross-Border Transfer Risk Assessment Matrix evaluating destination country regimes and foreign intelligence access risk.
- Incident Response and Breach Notification Playbook covering identification, escalation, forensic investigation, and 72-hour/24-hour disclosure compliance.
- Supporting Proofs: corporate KYC/incorporation documents, board resolutions authorizing the DPO and privacy policy, ISO/IEC 27001 certification (if held), penetration testing reports, vendor audit certificates, and historical breach logs.
Regulatory Fees, Timelines & Penalty Matrix
Fees, deadlines and sanctions must be taken from the current Act, rules, gazette, authority schedule and sector instrument. The rows below identify verification workstreams; they do not assert fixed amounts or penalties.
| Instrument | Penal Sanction | Monetary/Administrative Exposure |
|---|---|---|
| Cyber law / CII incident | Verify the current Cyber Security Act and any 2026 amendment, offence, jurisdiction and procedure | Verify the current sanction, fine, compensation and authority direction; no fixed amount asserted |
| ICT Act 2006 / successor cyber law | Verify whether the cited provision remains applicable to the facts and date | Verify the current penalty and remedial route from the official text; no fixed amount asserted |
| Personal Data Protection Act 2026 | Verify commencement, offence, administrative and civil provisions | Verify authority schedule, enforcement order and appeal route |
Frequently Asked Questions
◆ Related Statutory Guides & Practice Insights
<li style="margin-bottom:12px; line-height:1.5;">
<a href="/en/patent-registration-bangladesh-pct-filing-guide/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">• Patent Registration in Bangladesh: Eligibility & PCT Filing</a>
</li>
<li style="margin-bottom:12px; line-height:1.5;">
<a href="/en/data-protection-privacy-law-bangladesh/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">• Data Protection and Privacy Law in Bangladesh: Legal Framework</a>
</li>
<li style="margin-bottom:12px; line-height:1.5;">
<a href="/en/trademark-registration-ip-enforcement-bangladesh-guide/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">• Trademark Registration and IP Enforcement in Bangladesh: The Definitive Legal & DPDT Guide</a>
</li>
<li style="margin-bottom:12px; line-height:1.5;">
<a href="/en/ai-copyright-deepfakes-intellectual-property-bangladesh/" style="color:#C5A059; font-weight:600; text-decoration:none; font-size:14px; display:inline-block; transition:color 0.2s;">• AI Copyright, Deepfakes & Intellectual Property Protection in Bangladesh: A Senior Advocate's Masterclass Handbook</a>
</li>
What is the primary objective of the Personal Data Protection Act 2026?
The official ICT Division portal records the Act as published on 15 April 2026. Its operative scope, rights, duties, authority and commencement must be read from the enacted text and current instruments alongside Article 43(b) and applicable cyber or sector law.
Must every foreign or local organisation appoint a DPO and register?
Not as a conclusion from this article alone. Confirm the Act, commencement, rules, authority notices, controller category, processing activity and any Bangladesh Bank/BTRC direction before treating DPO appointment or registration as mandatory.
What are the rules for cross-border data transfers?
Identify the data category, controller/processor roles, purpose, destination, contract, security, sector direction and any approval or notice required by the current Act and rules. No universal SCC, consent or prior-approval route is asserted here.
What consent controls should a company implement?
Use clear notice, documented purpose and a lawful basis; where consent is required, record how it was obtained and withdrawn. Check the Act and rules for exceptions, children, retention and rights before promising deletion or uninterrupted service.
Are fintech and telecom localisation rules identical to the general Act?
No assumption is safe. Financial and telecom entities may face additional directions, but the applicable data, system, licence, classification and current regulator instrument must be identified.
What penalties apply to non-compliance?
Verify the current offence, administrative measure, compensation, fine, procedure and appeal route under the applicable Act, rules and sector instrument. Historic draft figures in this article have been removed.