Bangladesh
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Bangladesh — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Bangladesh passed a full privacy law in April 2026 and backdated it to November 2025. On paper you may send personal data abroad if the person agrees or a contract needs it. But nobody is policing this. The regulator named in the law has not been set up. The sections that create complaints and fines have not started. The real limits are in banking and payments. There, customer data must stay on servers in Bangladesh.
Data governance in Bangladesh
The eight things that decide how you handle data about people in Bangladesh. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office and no staff in Bangladesh. It applies if you handle the data of people who live, work or are temporarily staying in Bangladesh. It also applies to work done abroad when it is tied to selling goods or services to people in Bangladesh. The same goes for watching or profiling them. There is no size or money threshold. A small foreign start-up is caught on the same terms as a large group. There is no general duty to appoint a local representative yet.
Personal Data Protection Act 2026 (Act No. 63 of 2026), section 1(2)(a)-(c) and section 4(2)-(3). Section 4 says a breach committed from outside Bangladesh into Bangladesh is treated as if the whole thing happened in Bangladesh. The same applies to a breach committed from inside Bangladesh out to another country. The only duty to have someone in the country is section 23. An organisation that the government names a major data handler must appoint one or more Chief Data Officers. They work at a location the Authority decides. Section 23 has not started. It begins on a date the government sets by notification, and not before 18 months after the Act was issued on 10 April 2026. There is no registration or licence step for ordinary organisations.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
Where the data is allowed to live
It depends on your industry. Under the general privacy law you may send personal data abroad in three cases. The person consented. Or a contract that person is party to needs it. Or it is for their own business, study or migration matters. But the same section says data may only go to places or countries the regulator has approved as having the right protective technology. That approved list does not exist yet. Banking, finance companies and payment providers are the strict case. Their customer data must stay on servers in Bangladesh.
Personal Data Protection Act 2026, section 29. Section 29(3) sets the three routes: consent; a contract the person is party to; and consent-based business, education, emigration or immigration matters. Section 29(4) then limits transfers to places or countries named in regulations as having suitable technology and equipment for protecting personal data. No such regulations have been published. On a strict reading, no destination is currently approved. Section 29(6) requires you to tell the Authority before a large-volume transfer abroad of 'sensitive personally identifiable data'. That means government unique identifiers (national identity card number, passport number, taxpayer number), biometric identifiers, genetic or DNA information, and criminal records. Section 30 lets the government sign data-exchange deals with one or more other countries. INDUSTRY OVERRIDES. Banking, finance companies and payment service providers: the March 2026 electronic know-your-customer Guidelines require customer data to be kept on locally hosted servers or private cloud servers. They forbid sending it outside Bangladesh without Bangladesh Bank's prior approval. The 2023 Cloud Computing Guidelines separately bar customers' financial and other sensitive data from public and hybrid cloud outside the country, except with prior Bangladesh Bank approval. Rated closed. Mobile financial services: we found no storage-location rule in the 2022 Mobile Financial Services Regulations, but a six-year record-keeping minimum applies. Rated conditional. Government and public sector: the National Data Management Act 2026 lets the Authority make scheduled bodies store their data in the national data repository system. It also lets the government restrict exchange of state-critical sensitive data by notification. Rated conditional today. That changes if those powers are used. Telecoms: we found no rule forcing data to stay in the country. The 2025 licensing policy instead makes licence holders follow the privacy law and marks critical platforms as Critical Information Infrastructure. Health, insurance, securities, education, online gaming, mapping and defence: no storage rule found, checked 18 August 2026, medium confidence.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh Telecommunication Regulatory CommissionTelecommunications Network and Licensing Policy 2025 (clauses 11.9 and 11.10 on privacy standards and Critical Information Infrastructure)
btrc.gov.bd
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
The model is an approved-destination list, and the list is empty. Before data leaves you need one of three things. The person's consent. A contract they are party to. Or their consent for business, study or migration matters. On top of that, the law only allows transfers to places the regulator has approved. No approvals have been issued. If you are moving large volumes of identity numbers, fingerprints, face or iris data, DNA or criminal records, you must tell the regulator first.
- Ways to send data out:
- Explicit consent · Needed for a contract · Official 'this country is safe' decision · Government sign-off needed
Personal Data Protection Act 2026, section 29(3), (4) and (6). There is no standard contract template, no certification scheme and no company-wide-rules route published. The section 29(4) list of permitted destinations depends on regulations that do not exist. The complaint and fining sections have not started either. So transfers today happen in a legal grey zone rather than under a working approval system. Banks, finance companies and payment service providers have a separate route that does work. They get written prior approval from Bangladesh Bank, case by case, under the 2023 Cloud Computing Guidelines and the 2026 electronic know-your-customer Guidelines.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionGuidelines and strategy papers page - no rules or regulations under the Personal Data Protection Act 2026 listed as at 18 August 2026
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
On paper the enforcer is the National Data Management Authority, a body attached to the Prime Minister's Office. It is not running. The law that creates it says the government must appoint an executive chairman and six members by official notice. We found no sign that has happened. It is not on the Prime Minister's Office list of attached offices. The privacy fines cannot be issued yet anyway, because those sections have not started. The cyber security agency and the central bank are both working and issuing instructions.
National Data Management Act 2026 (Act No. 80 of 2026), sections 8 and 9. The Authority is a statutory body attached to the Prime Minister's Office. The government sets it up by notification, with one executive chairman and six members. The Personal Data Protection Act 2026 defines 'the Authority' by reference to that body. Sections 31 to 35 of the privacy law cover complaints, administrative fines, how fines are set, and compensation. None of them start until a date the government fixes, and not before 18 months after 10 April 2026. Section 38 lets the government direct the Authority on grounds of sovereignty, security, friendly relations with foreign states or public order. The Authority must comply, so it is not independent. Appeals against fines go to the tribunal set up under section 68 of the Information and Communication Technology Act, within 30 days. The National Cyber Security Agency is visibly working. Its National Cyber Security Council held its first meeting on 28 December 2025, and it runs a cyber incident reporting system. Bangladesh Bank is far more active by comparison. It issued a new Cybersecurity Framework on 29 March 2026 and electronic know-your-customer guidelines on 11 March 2026, and it grants or refuses cloud approvals.
Sources
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourcePrime Minister's OfficePrime Minister's Office - published list of attached offices and authorities (checked 18 August 2026)
pmo.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyNational Cyber Security Agency - home page, incident reporting services and news of the first National Cyber Security Council meeting on 28 December 2025
dsa.portal.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are minimum keeping periods, but no deadline to delete. The minimums: you must keep a register of how you use personal data for at least five years. Mobile financial services must keep customer identity and transaction records for at least six years. On deletion, the privacy law says you must not keep personal data longer than the period set by regulations. No regulations have been made, so there is no fixed deletion date yet. Where two rules clash, the more specific one wins. The five-year rule applies only when no other law says otherwise.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data · Keep logs
Personal Data Protection Act 2026, sections 18 and 19. Section 18 limits how long you may keep data to the period set by regulations. It makes an exception for public-interest, scientific, historical or statistical purposes while safeguards are being built. Section 19 requires you to keep a register of how you use personal data for at least five years, unless another law says otherwise. Bangladesh Mobile Financial Services Regulations 2022, section 18.1: records must be kept for not less than six years from when they arose. That covers know-your-customer and customer due diligence records. It applies to account holders and to wholesale and retail agents. It also covers records of mobile financial services transactions. Bangladesh Bank's 2026 Cybersecurity Framework requires audit logs to be kept in line with record retention requirements. It also requires a quarterly clear-out of stored sensitive data that is past its keeping period. It names no number of months.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankPSD Circular No. 04 of 15 February 2022 - Bangladesh Mobile Financial Services (MFS) Regulations, 2022
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least two deadlines, and neither is set in hours. Under the privacy law you must tell the regulator about a personal data breach that could seriously harm someone. The form, method and timing are left to regulations that do not exist yet. Under the cyber security law, any government, private or self-governing organisation hit by a cyber incident must tell the national computer emergency response team without delay. Banks and payment firms have a third deadline. They report to Bangladesh Bank and to the government computer incident response team under the central bank's rules.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents · Independent audit
Personal Data Protection Act 2026, section 20(1): you must tell the Authority where a personal data breach is likely to cause significant harm to the person the data is about. The form, manner and time are set by regulations. No regulations exist, and there is currently no Authority to receive the notice. Section 20 contains no express duty to tell the people affected. Cyber Security Act 2026, section 9(4) proviso: where a cyber incident happens at a government, private or autonomous body, that body must inform the national computer emergency response team without delay. Security operations centres of designated Critical Information Infrastructure must also file quarterly performance reports to the National Cyber Security Operation Centre. Critical Information Infrastructure must submit a yearly internal and external audit report. Bangladesh Bank's Cybersecurity Framework 2026 requires round-the-clock detection and response, and reporting to Bangladesh Bank and the government computer incident response team. It sets no number of hours. The 2023 Information and Communication Technology Security Guideline adds one more duty. The bank must tell Bangladesh Bank 'as soon as possible' when a critical system fails over to its disaster recovery site.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Cyber Security Act 2026 (Act No. 81 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 10 of 19 June 2023 - Guideline on ICT Security
bb.org.bd
Link checked 18 August 2026
What to do: Your breach process has to reach Bangladesh's regulator inside the deadline above.
What catches people out
Five things catch people out. One: the law was backdated. It counts as being in force from 6 November 2025, months before it was printed in April 2026. Two: the law covers dead people as well as living ones, so your duties do not end when a customer dies. Three: a child is anyone under 18, and a parent's consent covers them until their eighteenth birthday. Four: named directors, managing directors, officers and even ordinary employees can be fined personally. Five: banks, finance companies and payment providers must keep customer data on servers in Bangladesh.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Claims by individuals
(1) Personal Data Protection Act 2026, section 1(3): except sections 23 and 31 to 35, the Act is treated as having come into force on 6 November 2025. That is the date the repealed Personal Data Protection Ordinance 2025 was made. (2) Section 2(3): the person the data is about means a natural person who is identified or identifiable, 'whether living or dead'. (3) Section 2(19) defines a child as under 18, or such age as the government sets. Section 9(3) says parental or guardian consent covers the child until 18. (4) Section 36: where someone complains against a company, the Authority may fine any board member, managing director, officer connected with management, or employee involved in the breach. (5) Bangladesh Bank electronic know-your-customer Guidelines, March 2026: 'The bank/FC/PS provider shall preserve customer data on locally hosted servers or private cloud servers'. Data collected from customers must not be sent outside Bangladesh without Bangladesh Bank's prior approval. A sixth item is worth watching. Section 29(5) lets the government charge a fee on the yearly business or commercial profit an organisation makes from using Bangladeshi citizens' personal data. Most privacy laws have nothing like it.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
What's changing next
Three dated things. The privacy law's enforcement machinery starts on a date the government picks, and cannot start before about 10 October 2027. That covers complaints, fines, compensation and the Chief Data Officer duty. Banks must comply with the central bank's new cyber security rules by 31 December 2026. A further amendment to the cyber security law was with a cabinet committee in July 2026. The bigger risk is the powers the government can already use without asking anyone.
DATED. (1) Personal Data Protection Act 2026, section 1(3): sections 23 and 31 to 35 start on a date fixed by government notification after 18 months from the Act's issue on 10 April 2026. So 10 October 2027 at the earliest. (2) Bangladesh Bank BRPD-2 Circular 02 of 29 March 2026: compliance with the Cybersecurity Framework Version 1.0 must be ensured by 31 December 2026. (3) The Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026) took effect on 1 July 2026 and deleted section 20 of the Cyber Security Act, the online gambling offence. The Information and Communication Technology Division reported a cabinet committee meeting on 15 July 2026 to review and finalise a further draft amendment. POWERS THE GOVERNMENT CAN USE AT ANY TIME. (a) National Data Management Act 2026, section 32: the Authority may make it compulsory for scheduled bodies to store their data in the national data repository system. (b) Section 31(2): the government may by notification put limits and conditions on any organisation's data sharing where state-critical sensitive data is involved. That includes anything touching sovereignty, public safety, borders or a declared emergency. (c) Personal Data Protection Act 2026, section 29(1) and (4): the government may sort personal data into public, internal, confidential and restricted tiers, and set which countries may receive data at all. (d) Section 29(5): a charge on profits made from Bangladeshis' personal data. (e) Section 38: the government may direct the regulator, and the regulator must obey. (f) Section 43: in an emergency the government or the Authority may issue an order about any use, storage, keeping or transfer of data.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionNews item of 15 July 2026 - cabinet committee meeting to review and finalise the draft Cyber Security (Amendment) Act 2026
ictd.gov.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 1 July 2026 - Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026), deleting section 20
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
What to do: Diarise 10 October 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Guidelines on Electronic Know-Your-Customer (e-KYC) · BRPD-1 Circular No. 08 of 11 March 2026 · Regulator directive
Banks, finance companies and payment service providers must keep customer identity data on servers hosted in Bangladesh or in a private cloud. They may not send it out of the country without the central bank's prior approval. Identity is checked against the Election Commission's national identity verification server.
Enforced by Bangladesh Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryCustomer data must be preserved on locally hosted servers or private cloud servers.
- Put a transfer safeguard in placeNo transmission or transfer of customer data outside Bangladesh without Bangladesh Bank's prior approval, and the duty binds the third-party vendor as well as the regulated firm.
- Keep records of how you use dataDigital know-your-customer data and logs kept as required by the Payment and Settlement Systems Act 2024.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by Bangladesh Bank against the licensed bank, finance company or payment service provider.
Sources
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Guidelines on Cloud Computing · BRPD Circular No. 05 of 16 March 2023 (banks); DFIM Circular Letter No. 09 of 18 May 2023 (finance companies) · Regulator guideline
A bank's customers' financial and sensitive data may not sit in a public or hybrid cloud outside Bangladesh. Only in exceptional cases, and only with the central bank's prior approval, may it do so.
Enforced by Bangladesh Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryCustomers' financial and other sensitive data cannot be hosted in a cross-border public or hybrid cloud; a community cloud must be located within the country.
- Put a transfer safeguard in placeExceptions only with Bangladesh Bank's prior approval.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory direction to stop or unwind the cloud arrangement.
Sources
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Payments data rules
Official name: Bangladesh Mobile Financial Services (MFS) Regulations, 2022 · PSD Circular No. 04 of 15 February 2022 · Directly binding regulation
Mobile money providers must keep customer identity, agent and transaction records for at least six years. The regulations themselves set no storage-location rule, but the same firms are caught by the 2026 e-KYC guideline, which does.
Enforced by Bangladesh Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep data for a minimum period — 6 yearsCustomer and agent identity records and transaction records kept at least six years from the date they arose.
- Keep records of how you use data
What it costs if you get it wrong
- Loss of your licenceBreach of the licence conditions for a mobile financial services provider.
Sources
- Official sourceBangladesh BankPSD Circular No. 04 of 15 February 2022 - Bangladesh Mobile Financial Services (MFS) Regulations, 2022
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Government data rules
Official name: ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (Personal Data Protection Act, 2026) · Act No. 63 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026 · Act of parliament
Bangladesh's general privacy law. It is treated as being in force since 6 November 2025. But the sections that create complaints, fines and compensation do not start until the government says so, and not before about October 2027. The Chief Data Officer duty waits with them. Data may go abroad with consent or for a contract, but only to destinations the regulator approves. It has approved none.
That is a long gap: the duty is real law today, but no penalty can follow until 10 October 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by National Data Management Authority — not yet operational
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Explicit consent, Needed for a contract, Official 'this country is safe' decision
What you have to do
- Get consentConsent must be voluntary, specific, clear and possible to withdraw. Before the person consents you must tell them the purpose, how long you will keep the data, and any transfer. A short list of legitimate interests can replace consent.
- Tell people what you do
- Secure the data
- Keep records of how you use data — 5 yearsYou must keep a register of how you use personal data for at least five years, unless another law says otherwise.
- Delete data after a periodNot longer than the period prescribed by regulations. No regulations made as at 18 August 2026, so no fixed deletion date.
- Report breaches to the regulatorWhere the breach is likely to cause significant harm. Form, method and timing left to regulations that do not exist yet.
- Independent auditNamed types of organisation must be audited by an independent data auditor approved by the Authority. The Authority can also order an audit.
- Appoint a data protection officer — from 10 October 2027You need a Chief Data Officer only if the government names you a major data handler. They work at a place the Authority decides. Section 23 has not started.
- Get a parent's consent for childrenChild means under 18; parental consent covers the child until 18.
- Put a transfer safeguard in place
- Written vendor contractThe company that decides how the data is used stays liable when its supplier gets it wrong.
What it costs if you get it wrong
- Fixed maximum fine: BDT 2,500,000 (25 lakh taka) — about $21 thousandFailure to honour a data subject's rights, or failure to keep data secure. Not enforceable until sections 31-35 commence.
- Fixed maximum fine: BDT 5,000,000 (50 lakh taka) — about $41 thousandSame failure by a 'significant data-fiduciary'.
- Claims by individualsThe Authority may award compensation to the data subject on top of the fine.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
Government data rules (Government)
Official name: জাতীয় উপাত্ত ব্যবস্থাপনা আইন, ২০২৬ (National Data Management Act, 2026) · Act No. 80 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026 · Act of parliament
Creates the National Data Management Authority under the Prime Minister's Office, plus a national data-exchange platform for public bodies. It also gives the state two powers. It can order scheduled bodies to keep their data in the national repository. And it can restrict the sharing of anything it labels state-critical sensitive data.
Enforced by National Data Management Authority — not yet operational
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryA power, not yet used: the Authority may make it compulsory for scheduled bodies to store their data in the national data repository system.
- Written vendor contractA Data Resharing Agreement must be signed by both sides before any data moves across the national exchange platform.
- Keep records of how you use data
What it costs if you get it wrong
- Criminal liabilityNot criminal in the ordinary sense: a public servant involved in violating a data subject's rights while processing, storing, retaining, transferring or disclosing data is treated as guilty of misconduct and faces departmental proceedings.
Sources
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
Cyber security rules
Official name: সাইবার সুরক্ষা আইন, ২০২৬ (Cyber Security Act, 2026), as amended by সাইবার সুরক্ষা (সংশোধন) আইন, ২০২৬ · Act No. 81 of 2026 (gazetted 10 April 2026), amended by Act No. 99 of 2026 (gazetted 1 July 2026) · Act of parliament
Re-enacts the 2025 cyber security ordinance and is treated as in force from 21 May 2025. It sets up the National Cyber Security Agency, the national computer emergency response team, and a list of Critical Information Infrastructure. It makes cyber offences criminal rather than administrative. An amendment on 1 July 2026 deleted the online gambling offence.
Enforced by National Cyber Security Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidentsAny government, private or autonomous body suffering a cyber incident must inform the national computer emergency response team without delay. No hour count is given.
- Independent auditDesignated Critical Information Infrastructure must submit an annual internal and external audit report and run its own incident response team and security operations centre, which reports quarterly.
- Secure the data
What it costs if you get it wrong
- Criminal liability: 7 years imprisonment or BDT 10,000,000 (1 crore taka), or both — about $82 thousandUnlawful access to Critical Information Infrastructure and theft, destruction or alteration of data held there. Lesser offences carry up to 5 years or BDT 5,000,000.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Cyber Security Act 2026 (Act No. 81 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 1 July 2026 - Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026), deleting section 20
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyNational Cyber Security Agency - home page, incident reporting services and news of the first National Cyber Security Council meeting on 28 December 2025
dsa.portal.gov.bd
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the National Data Management Authority has been constituted and staffed
We could not confirm that this body has been set up. The law requires a government notification naming an executive chairman and six members. We found no such notification, no website for the body, and no entry on the Prime Minister's Office list of attached offices on 18 August 2026. It could still have been set up quietly, so check before you rely on this.
That no rules or regulations have been made under the Personal Data Protection Act 2026
We could not confirm that no rules have been made under the Act. The Information and Communication Technology Division's laws, policies and guidelines pages list nothing under the Act as at 18 August 2026. The Authority that would make the rules does not appear to exist. A gazette notice could exist without appearing on the department site. Check the gazette if this matters to you.
Which countries or places are approved destinations under section 29(4)
We could not confirm which countries or places are approved. The section only allows transfers to places named in regulations, and we found no such regulations. On a strict reading that means no destination is approved, which would make routine transfers unlawful on paper. There is no regulator in place to say so. We found no official statement settling this.
Whether the government has used its power to classify personal data into public, internal, confidential and restricted tiers under section 29(1)
We could not confirm whether the government has used this power. No classification notice appears on the sponsoring department's site.
The exact commencement date of sections 23 and 31 to 35 of the privacy law
We could not confirm the exact start date. The Act says a date fixed by notification after 18 months from issue. Counting from the 10 April 2026 gazette, that means 10 October 2027 at the earliest. No commencement notice has been issued yet.
The content of the Gambling Prevention Act 2026
We could not confirm what this Act says. The telecom regulator lists it among the laws applied to licence holders. The Cyber Security (Amendment) Act 2026 deleted the online gambling offence from the cyber law on 1 July 2026, which fits with a separate statute existing. We could not find the text on the Legislative Division's list of 2026 Acts.
Data storage and retention rules for insurance and securities firms
We could not check the storage and retention rules for insurance and securities firms. The Insurance Development and Regulatory Authority and the securities commission publish their document lists in a way our checks could not read. Treat this as unchecked, not as proof there are no rules. If you work in these industries, check before you rely on it.
Retention periods under the Payment and Settlement Systems Act 2024
We could not confirm how long records must be kept under this Act. The central bank's 2026 electronic know-your-customer guidelines point to it for digital know-your-customer data and logs. We could not find the Act's text on an official site.
Whether a further Cyber Security (Amendment) Act is in progress
We could not confirm whether a further amendment is on the way. The sponsoring department reported a cabinet committee meeting on 15 July 2026 to review and finalise a draft amendment. That was two weeks after Act No. 99 of 2026 was gazetted. It is unclear whether this is the same amendment or a second one.
Whether telecom or internet licence conditions impose keeping data in the country or log retention
We could not fully confirm what telecom and internet licences require. The 2025 licensing policy and the 2026 amendment to the telecom act contain no rule forcing data to stay in the country, in the parts we read. We did not review every licence guideline. If you hold a telecom licence, check yours.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.