Skip to the content
Global Data RulesData governance rules, country by country

Bangladesh

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Bangladesh — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Dormant

Bangladesh passed a full privacy law in April 2026 and backdated it to November 2025. On paper you may send personal data abroad if the person agrees or a contract needs it. But nobody is policing this. The regulator named in the law has not been set up. The sections that create complaints and fines have not started. The real limits are in banking and payments. There, customer data must stay on servers in Bangladesh.

Data governance in Bangladesh

The eight things that decide how you handle data about people in Bangladesh. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office and no staff in Bangladesh. It applies if you handle the data of people who live, work or are temporarily staying in Bangladesh. It also applies to work done abroad when it is tied to selling goods or services to people in Bangladesh. The same goes for watching or profiling them. There is no size or money threshold. A small foreign start-up is caught on the same terms as a large group. There is no general duty to appoint a local representative yet.

Where the data is allowed to live

It depends on your industry. Under the general privacy law you may send personal data abroad in three cases. The person consented. Or a contract that person is party to needs it. Or it is for their own business, study or migration matters. But the same section says data may only go to places or countries the regulator has approved as having the right protective technology. That approved list does not exist yet. Banking, finance companies and payment providers are the strict case. Their customer data must stay on servers in Bangladesh.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

The model is an approved-destination list, and the list is empty. Before data leaves you need one of three things. The person's consent. A contract they are party to. Or their consent for business, study or migration matters. On top of that, the law only allows transfers to places the regulator has approved. No approvals have been issued. If you are moving large volumes of identity numbers, fingerprints, face or iris data, DNA or criminal records, you must tell the regulator first.

Ways to send data out:
Explicit consent · Needed for a contract · Official 'this country is safe' decision · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

On paper the enforcer is the National Data Management Authority, a body attached to the Prime Minister's Office. It is not running. The law that creates it says the government must appoint an executive chairman and six members by official notice. We found no sign that has happened. It is not on the Prime Minister's Office list of attached offices. The privacy fines cannot be issued yet anyway, because those sections have not started. The cyber security agency and the central bank are both working and issuing instructions.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There are minimum keeping periods, but no deadline to delete. The minimums: you must keep a register of how you use personal data for at least five years. Mobile financial services must keep customer identity and transaction records for at least six years. On deletion, the privacy law says you must not keep personal data longer than the period set by regulations. No regulations have been made, so there is no fixed deletion date yet. Where two rules clash, the more specific one wins. The five-year rule applies only when no other law says otherwise.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least two deadlines, and neither is set in hours. Under the privacy law you must tell the regulator about a personal data breach that could seriously harm someone. The form, method and timing are left to regulations that do not exist yet. Under the cyber security law, any government, private or self-governing organisation hit by a cyber incident must tell the national computer emergency response team without delay. Banks and payment firms have a third deadline. They report to Bangladesh Bank and to the government computer incident response team under the central bank's rules.

What you have to do here:
Report breaches to the regulator · Report cyber incidents · Independent audit

What to do: Your breach process has to reach Bangladesh's regulator inside the deadline above.

What catches people out

Five things catch people out. One: the law was backdated. It counts as being in force from 6 November 2025, months before it was printed in April 2026. Two: the law covers dead people as well as living ones, so your duties do not end when a customer dies. Three: a child is anyone under 18, and a parent's consent covers them until their eighteenth birthday. Four: named directors, managing directors, officers and even ordinary employees can be fined personally. Five: banks, finance companies and payment providers must keep customer data on servers in Bangladesh.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Claims by individuals

What's changing next

Three dated things. The privacy law's enforcement machinery starts on a date the government picks, and cannot start before about 10 October 2027. That covers complaints, fines, compensation and the Chief Data Officer duty. Banks must comply with the central bank's new cyber security rules by 31 December 2026. A further amendment to the cyber security law was with a cabinet committee in July 2026. The bigger risk is the powers the government can already use without asking anyone.

What to do: Diarise 10 October 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Cloud and outsourcing rules

Official name: Guidelines on Electronic Know-Your-Customer (e-KYC) · BRPD-1 Circular No. 08 of 11 March 2026 · Regulator directive

In forceNo — it stays put

Banks, finance companies and payment service providers must keep customer identity data on servers hosted in Bangladesh or in a private cloud. They may not send it out of the country without the central bank's prior approval. Identity is checked against the Election Commission's national identity verification server.

In force since 11 March 2026

Enforced by Bangladesh Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Cloud and outsourcing rules (Banking)

Official name: Guidelines on Cloud Computing · BRPD Circular No. 05 of 16 March 2023 (banks); DFIM Circular Letter No. 09 of 18 May 2023 (finance companies) · Regulator guideline

In forceNo — it stays put

A bank's customers' financial and sensitive data may not sit in a public or hybrid cloud outside Bangladesh. Only in exceptional cases, and only with the central bank's prior approval, may it do so.

In force since 16 March 2023

Enforced by Bangladesh Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Payments

Payments data rules

Official name: Bangladesh Mobile Financial Services (MFS) Regulations, 2022 · PSD Circular No. 04 of 15 February 2022 · Directly binding regulation

In forceYes, with paperwork

Mobile money providers must keep customer identity, agent and transaction records for at least six years. The regulations themselves set no storage-location rule, but the same firms are caught by the 2026 e-KYC guideline, which does.

In force since 15 February 2022

Enforced by Bangladesh Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Government data rules

Official name: ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (Personal Data Protection Act, 2026) · Act No. 63 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026 · Act of parliament

Partly in forceYes, with paperwork

Bangladesh's general privacy law. It is treated as being in force since 6 November 2025. But the sections that create complaints, fines and compensation do not start until the government says so, and not before about October 2027. The Chief Data Officer duty waits with them. Data may go abroad with consent or for a contract, but only to destinations the regulator approves. It has approved none.

In force since 6 November 2025In force now, but not enforced until 10 October 2027

That is a long gap: the duty is real law today, but no penalty can follow until 10 October 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by National Data Management Authority — not yet operational

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Explicit consent, Needed for a contract, Official 'this country is safe' decision

Government

Government data rules (Government)

Official name: জাতীয় উপাত্ত ব্যবস্থাপনা আইন, ২০২৬ (National Data Management Act, 2026) · Act No. 80 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026 · Act of parliament

In forceYes, with paperwork

Creates the National Data Management Authority under the Prime Minister's Office, plus a national data-exchange platform for public bodies. It also gives the state two powers. It can order scheduled bodies to keep their data in the national repository. And it can restrict the sharing of anything it labels state-critical sensitive data.

In force since 6 November 2025

Enforced by National Data Management Authority — not yet operational

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Cyber security rules

Official name: সাইবার সুরক্ষা আইন, ২০২৬ (Cyber Security Act, 2026), as amended by সাইবার সুরক্ষা (সংশোধন) আইন, ২০২৬ · Act No. 81 of 2026 (gazetted 10 April 2026), amended by Act No. 99 of 2026 (gazetted 1 July 2026) · Act of parliament

In forceYes — store it anywhere

Re-enacts the 2025 cyber security ordinance and is treated as in force from 21 May 2025. It sets up the National Cyber Security Agency, the national computer emergency response team, and a list of Critical Information Infrastructure. It makes cyber offences criminal rather than administrative. An amendment on 1 July 2026 deleted the online gambling offence.

In force since 21 May 2025

Enforced by National Cyber Security Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • জাতীয় উপাত্ত ব্যবস্থাপনা কর্তৃপক্ষ

    The regulator named in the privacy law and the data management law: complaints, fines, audits, transfer rules

    Created by the National Data Management Act 2026 as a statutory body attached to the Prime Minister's Office. The government sets it up by notification, with one executive chairman and six members. We found no such notification and no separate website. It does not appear on the Prime Minister's Office published list of attached offices as at 18 August 2026. Its fining powers could not be used anyway, because sections 31 to 35 of the privacy law have not started.

  • জাতীয় সাইবার সুরক্ষা এজেন্সি

    Cyber incidents, Critical Information Infrastructure, national computer emergency response team

    Working. The National Cyber Security Council held its first meeting on 28 December 2025 and the agency runs a cyber incident reporting system and publishes advisories and alerts.

  • তথ্য ও যোগাযোগ প্রযুক্তি বিভাগ

    Sponsoring ministry for the privacy, data management and cyber laws; publishes the statutes and will make the rules

  • বাংলাদেশ ব্যাংক

    Banks, finance companies, payment service providers and mobile financial services - including where their data may be stored

    The most active data regulator in the country. It issued a new Cybersecurity Framework on 29 March 2026 and electronic know-your-customer guidelines on 11 March 2026. It decides cloud and cross-border approvals case by case.

  • বাংলাদেশ টেলিযোগাযোগ নিয়ন্ত্রণ কমিশন

    Telecom and internet licensees, over-the-top services

    Active. Its 2025 licensing policy requires licensees to follow the privacy law and marks critical platforms as Critical Information Infrastructure.

  • লেজিসলেটিভ ও সংসদ বিষয়ক বিভাগ

    Publishes the official gazette copies of Acts

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the National Data Management Authority has been constituted and staffed

    We could not confirm that this body has been set up. The law requires a government notification naming an executive chairman and six members. We found no such notification, no website for the body, and no entry on the Prime Minister's Office list of attached offices on 18 August 2026. It could still have been set up quietly, so check before you rely on this.

  • That no rules or regulations have been made under the Personal Data Protection Act 2026

    We could not confirm that no rules have been made under the Act. The Information and Communication Technology Division's laws, policies and guidelines pages list nothing under the Act as at 18 August 2026. The Authority that would make the rules does not appear to exist. A gazette notice could exist without appearing on the department site. Check the gazette if this matters to you.

  • Which countries or places are approved destinations under section 29(4)

    We could not confirm which countries or places are approved. The section only allows transfers to places named in regulations, and we found no such regulations. On a strict reading that means no destination is approved, which would make routine transfers unlawful on paper. There is no regulator in place to say so. We found no official statement settling this.

  • Whether the government has used its power to classify personal data into public, internal, confidential and restricted tiers under section 29(1)

    We could not confirm whether the government has used this power. No classification notice appears on the sponsoring department's site.

  • The exact commencement date of sections 23 and 31 to 35 of the privacy law

    We could not confirm the exact start date. The Act says a date fixed by notification after 18 months from issue. Counting from the 10 April 2026 gazette, that means 10 October 2027 at the earliest. No commencement notice has been issued yet.

  • The content of the Gambling Prevention Act 2026

    We could not confirm what this Act says. The telecom regulator lists it among the laws applied to licence holders. The Cyber Security (Amendment) Act 2026 deleted the online gambling offence from the cyber law on 1 July 2026, which fits with a separate statute existing. We could not find the text on the Legislative Division's list of 2026 Acts.

  • Data storage and retention rules for insurance and securities firms

    We could not check the storage and retention rules for insurance and securities firms. The Insurance Development and Regulatory Authority and the securities commission publish their document lists in a way our checks could not read. Treat this as unchecked, not as proof there are no rules. If you work in these industries, check before you rely on it.

  • Retention periods under the Payment and Settlement Systems Act 2024

    We could not confirm how long records must be kept under this Act. The central bank's 2026 electronic know-your-customer guidelines point to it for digital know-your-customer data and logs. We could not find the Act's text on an official site.

  • Whether a further Cyber Security (Amendment) Act is in progress

    We could not confirm whether a further amendment is on the way. The sponsoring department reported a cabinet committee meeting on 15 July 2026 to review and finalise a draft amendment. That was two weeks after Act No. 99 of 2026 was gazetted. It is unclear whether this is the same amendment or a second one.

  • Whether telecom or internet licence conditions impose keeping data in the country or log retention

    We could not fully confirm what telecom and internet licences require. The 2025 licensing policy and the 2026 amendment to the telecom act contain no rule forcing data to stay in the country, in the parts we read. We did not review every licence guideline. If you hold a telecom licence, check yours.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.