Skip to the content
Global Data RulesData governance rules, country by country

Bangladesh

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Dormant

Bangladesh passed a full privacy law in April 2026 and backdated it to November 2025. On paper you may send personal data abroad if the person agrees or a contract needs it. In practice nobody is policing this: the regulator named in the law has not been set up, and the sections that create complaints and fines have not started. The real walls are in banking and payments, where customer data must stay on servers in Bangladesh.

Data governance in Bangladesh

The eight things that decide how you handle data about people in Bangladesh. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office and no staff in Bangladesh. It applies if you handle the data of people who live, work or are temporarily staying in Bangladesh, and it applies to processing done abroad when it is tied to selling goods or services to people in Bangladesh, or to watching or profiling them. There is no size or money threshold, so a small foreign start-up is caught on the same terms as a large group. There is no general duty to appoint a local representative yet.

High confidenceNational rulesControllerProcessor

Where the data is allowed to live

It depends on your industry. Under the general privacy law personal data may go abroad if the person consented, or if it is needed for a contract that person is party to, or for their own business, study or migration matters. But the same section says data may only go to places or countries that the regulator has approved as having the right protective technology, and that approved list does not exist yet. Banking, finance companies and payment providers are the hard wall: their customer data must stay on servers in Bangladesh.

Medium confidenceDepends on your industryAllowlistFinanceGovernment

Sending data out of the country

The model is an approved-destination list, and the list is empty. Before data leaves you need one of three things: the person's consent, a contract they are party to, or their consent for business, study or migration matters. On top of that the law only allows transfers to places the regulator has approved, and no approvals have been issued. If you are moving large volumes of identity numbers, fingerprints, face or iris data, DNA or criminal records, you must tell the regulator first.

Medium confidenceAllowlistExplicit consentNeeded for a contractOfficial 'this country is safe' decisionGovernment sign-off needed

The regulator, and whether it actually acts

On paper the enforcer is the National Data Management Authority, a body attached to the Prime Minister's Office. It is not running. The law that creates it says the government must appoint an executive chairman and six members by official notice, and we found no sign that has happened - it is not on the Prime Minister's Office list of attached offices. The privacy fines cannot be issued yet anyway, because those sections have not started. By contrast the cyber security agency and the central bank are both working and issuing instructions.

Medium confidenceDormantRegulator

How long you must keep it — and when to delete it

There is a floor and a ceiling, and the ceiling is blank. The floor: an organisation must keep a register of its personal data processing for at least five years, and mobile financial services must keep customer identity and transaction records for at least six years. The ceiling: the privacy law says you must not keep personal data longer than the period set by regulations, but no regulations have been made, so there is no fixed deletion date yet. Where two rules clash, the specific one wins - the five-year rule applies only when no other law says otherwise.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processingKeep logs

If something goes wrong

There are at least two clocks and neither is expressed in hours. Under the privacy law you must tell the regulator about a personal data breach that could seriously harm someone, but the form, method and timing are left to regulations that do not exist yet. Under the cyber security law any government, private or self-governing organisation that suffers a cyber incident must tell the national computer emergency response team without delay. Banks and payment firms have a third clock: they report to Bangladesh Bank and to the government computer incident response team under the central bank's framework.

High confidenceReport breaches to the regulatorReport cyber incidentsIndependent audit

What catches people out

Five things bite. One: the law was backdated - it counts as being in force from 6 November 2025, months before it was printed in April 2026. Two: a 'data subject' includes dead people, so the duties do not end when a customer dies. Three: a child is anyone under 18 and a parent's consent covers them until their eighteenth birthday. Four: named directors, managing directors, officers and even ordinary employees can be fined personally. Five: banks, finance companies and payment providers must keep customer data on servers in Bangladesh.

High confidenceGet a parent's consent for childrenClaims by individualsKeep the data in the countryChildren's data

What's changing next

Three dated things. The privacy law's enforcement machinery - complaints, fines, compensation and the Chief Data Officer duty - starts on a date the government picks, and cannot start before about 10 October 2027. Banks must comply with the central bank's new cybersecurity framework by 31 December 2026. A further amendment to the cyber security law was with a cabinet committee in July 2026. The bigger risk is the switches the government can already flip without asking anyone.

Medium confidenceDraft lawProposedKeep the data in the country

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Guidelines on Electronic Know-Your-Customer (e-KYC)

Regulator directive · BRPD-1 Circular No. 08 of 11 March 2026

In forceNo — it stays put

Banks, finance companies and payment service providers must keep customer identity data on servers hosted in Bangladesh or in a private cloud, and may not send it out of the country without the central bank's prior approval. Identity is checked against the Election Commission's national identity verification server.

In force since 11 March 2026

Enforced by Bangladesh Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Guidelines on Cloud Computing

Regulator guideline · BRPD Circular No. 05 of 16 March 2023 (banks); DFIM Circular Letter No. 09 of 18 May 2023 (finance companies)

In forceNo — it stays put

A bank's customers' financial and sensitive data may not sit in a public or hybrid cloud outside Bangladesh. Only in exceptional cases, and only with the central bank's prior approval, may it do so.

In force since 16 March 2023

Enforced by Bangladesh Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Payments

Bangladesh Mobile Financial Services (MFS) Regulations, 2022

Directly binding regulation · PSD Circular No. 04 of 15 February 2022

In forceYes, with paperwork

Mobile money providers must keep customer identity, agent and transaction records for at least six years. The regulations themselves set no storage-location rule, but the same firms are caught by the 2026 e-KYC guideline, which does.

In force since 15 February 2022

Enforced by Bangladesh Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (Personal Data Protection Act, 2026)

Act of parliament · Act No. 63 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026

Partly in forceYes, with paperwork

Bangladesh's general privacy law. It is treated as being in force since 6 November 2025, but the sections that create complaints, fines and compensation, and the Chief Data Officer duty, do not start until the government says so and not before about October 2027. Data may go abroad with consent or for a contract, but only to destinations the regulator approves, and it has approved none.

In force since 6 November 2025But only enforceable from 10 October 2027

Enforced by National Data Management Authority — not yet operational

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Explicit consent, Needed for a contract, Official 'this country is safe' decision

High confidence
Government

জাতীয় উপাত্ত ব্যবস্থাপনা আইন, ২০২৬ (National Data Management Act, 2026)

Act of parliament · Act No. 80 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026

In forceYes, with paperwork

Creates the National Data Management Authority under the Prime Minister's Office and a national data-exchange platform for public bodies. It also gives the state two switches: it can order scheduled bodies to keep their data in the national repository, and it can restrict the exchange of anything it labels state-critical sensitive data.

In force since 6 November 2025

Enforced by National Data Management Authority — not yet operational

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

সাইবার সুরক্ষা আইন, ২০২৬ (Cyber Security Act, 2026), as amended by সাইবার সুরক্ষা (সংশোধন) আইন, ২০২৬

Act of parliament · Act No. 81 of 2026 (gazetted 10 April 2026), amended by Act No. 99 of 2026 (gazetted 1 July 2026)

In forceYes — store it anywhere

Re-enacts the 2025 cyber security ordinance and is treated as in force from 21 May 2025. It sets up the National Cyber Security Agency, the national computer emergency response team and a list of Critical Information Infrastructure, and it makes cyber offences criminal rather than administrative. An amendment on 1 July 2026 deleted the online gambling offence.

In force since 21 May 2025

Enforced by National Cyber Security Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • জাতীয় উপাত্ত ব্যবস্থাপনা কর্তৃপক্ষ

    The regulator named in the privacy law and the data management law: complaints, fines, audits, transfer rules

    Created by the National Data Management Act 2026 as a statutory body attached to the Prime Minister's Office, to be constituted by government notification with one executive chairman and six members. We found no notification constituting it, no separate website, and it does not appear on the Prime Minister's Office published list of attached offices as at 18 August 2026. Its fining powers could not be used in any event, because sections 31 to 35 of the privacy law have not commenced.

  • জাতীয় সাইবার সুরক্ষা এজেন্সি

    Cyber incidents, Critical Information Infrastructure, national computer emergency response team

    Working. The National Cyber Security Council held its first meeting on 28 December 2025 and the agency runs a cyber incident reporting system and publishes advisories and alerts.

  • তথ্য ও যোগাযোগ প্রযুক্তি বিভাগ

    Sponsoring ministry for the privacy, data management and cyber laws; publishes the statutes and will make the rules

  • বাংলাদেশ ব্যাংক

    Banks, finance companies, payment service providers and mobile financial services - including where their data may be stored

    The most active data regulator in the country in practice. It issued a new Cybersecurity Framework on 29 March 2026 and e-KYC guidelines on 11 March 2026, and it decides cloud and cross-border approvals case by case.

  • বাংলাদেশ টেলিযোগাযোগ নিয়ন্ত্রণ কমিশন

    Telecom and internet licensees, over-the-top services

    Active. Its 2025 licensing policy requires licensees to follow the privacy law and marks critical platforms as Critical Information Infrastructure.

  • লেজিসলেটিভ ও সংসদ বিষয়ক বিভাগ

    Publishes the official gazette copies of Acts

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the National Data Management Authority has been constituted and staffed

    The law requires a government notification naming an executive chairman and six members. We found no such notification, no website for the body, and no entry on the Prime Minister's Office list of attached offices on 18 August 2026. We cannot prove a negative, so this is rated medium confidence rather than high.

  • That no rules or regulations have been made under the Personal Data Protection Act 2026

    The Information and Communication Technology Division's own laws, policies and guidelines pages list nothing under the Act as at 18 August 2026, and the Authority that would make regulations does not appear to exist. A gazette notification could exist without being mirrored on the department site.

  • Which countries or places are approved destinations under section 29(4)

    The section only permits transfers to places prescribed by regulations. No such regulations were found. On a strict reading that means no destination is currently approved, which would make routine transfers unlawful on paper; in practice there is no regulator to say so. We could not find any official statement resolving this.

  • Whether the government has used its power to classify personal data into public, internal, confidential and restricted tiers under section 29(1)

    No classification notification found on the sponsoring department's site.

  • The exact commencement date of sections 23 and 31 to 35 of the privacy law

    The Act says a date fixed by notification after 18 months from issue. We date that to 10 October 2027 at the earliest, counting from the 10 April 2026 gazette. No commencement notification has been issued yet.

  • The content of the Gambling Prevention Act 2026

    The telecom regulator lists it among the laws applied to licensees, and the Cyber Security (Amendment) Act 2026 deleted the online gambling offence from the cyber law on 1 July 2026, which is consistent with a dedicated statute. We could not locate the text on the Legislative Division's list of 2026 Acts.

  • Data storage and retention rules for insurance and securities firms

    The Insurance Development and Regulatory Authority and the securities commission both serve their document lists through scripts that did not render for automated checking. No rule found; treat as unchecked rather than as an absence of rules.

  • Retention periods under the Payment and Settlement Systems Act 2024

    The central bank's 2026 e-KYC guidelines point to that Act for how long digital know-your-customer data and logs must be kept. We could not locate the Act's text on an official site.

  • Whether a further Cyber Security (Amendment) Act is in progress

    The sponsoring department reported a cabinet committee meeting on 15 July 2026 to review and finalise a draft amendment, two weeks after Act No. 99 of 2026 was gazetted. It is unclear whether this refers to the same instrument or a second one.

  • Whether telecom or internet licence conditions impose data localisation or log retention

    The 2025 licensing policy and the 2026 amendment to the telecom act contain no localisation rule in the parts we read, but individual licence guidelines were not all reviewed.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Bangladesh versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.