Bangladesh
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Bangladesh passed a full privacy law in April 2026 and backdated it to November 2025. On paper you may send personal data abroad if the person agrees or a contract needs it. In practice nobody is policing this: the regulator named in the law has not been set up, and the sections that create complaints and fines have not started. The real walls are in banking and payments, where customer data must stay on servers in Bangladesh.
Data governance in Bangladesh
The eight things that decide how you handle data about people in Bangladesh. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office and no staff in Bangladesh. It applies if you handle the data of people who live, work or are temporarily staying in Bangladesh, and it applies to processing done abroad when it is tied to selling goods or services to people in Bangladesh, or to watching or profiling them. There is no size or money threshold, so a small foreign start-up is caught on the same terms as a large group. There is no general duty to appoint a local representative yet.
Personal Data Protection Act 2026 (Act No. 63 of 2026), section 1(2)(a)-(c) and section 4(2)-(3). Section 4 states that a breach committed from outside Bangladesh into Bangladesh, and a breach committed from inside Bangladesh out to another country, are both treated as if the whole thing happened in Bangladesh. The only in-country personnel duty is section 23: an organisation designated a 'significant data-fiduciary' must appoint one or more Chief Data Officers, who work at a location the Authority decides. Section 23 has not commenced - it starts on a date the government sets by notification, and not before 18 months after the Act was issued on 10 April 2026. There is no registration or licence step for ordinary organisations.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
Where the data is allowed to live
It depends on your industry. Under the general privacy law personal data may go abroad if the person consented, or if it is needed for a contract that person is party to, or for their own business, study or migration matters. But the same section says data may only go to places or countries that the regulator has approved as having the right protective technology, and that approved list does not exist yet. Banking, finance companies and payment providers are the hard wall: their customer data must stay on servers in Bangladesh.
Personal Data Protection Act 2026, section 29. Section 29(3) sets the three gateways (consent; a contract the data subject is party to; consent-based business, education, emigration or immigration matters). Section 29(4) then limits transfers to places or countries prescribed by regulations as having suitable technology and equipment for protecting personal data - no such regulations have been published, so on a strict reading no destination is currently approved. Section 29(6) requires mandatory notification to the Authority before a large-volume cross-border transfer of 'sensitive personally identifiable data', defined as government unique identifiers (national identity card number, passport number, taxpayer number), biometric identifiers, genetic or DNA information, and criminal records. Section 30 lets the government sign bilateral and multilateral data-exchange arrangements. SECTOR OVERRIDES. Banking, finance companies and payment service providers: the March 2026 e-KYC Guidelines require customer data to be kept on locally hosted servers or private cloud servers and forbid transmission or transfer outside Bangladesh without Bangladesh Bank's prior approval; the 2023 Cloud Computing Guidelines separately bar customers' financial and other sensitive data from cross-border public and hybrid cloud except with prior Bangladesh Bank approval - rate closed. Mobile financial services: no storage-location rule found in the 2022 MFS Regulations, but a six-year record-keeping floor applies - rate conditional. Government and public sector: the National Data Management Act 2026 lets the Authority compel scheduled bodies to store their data in the national data repository system and lets the government restrict exchange of state-critical sensitive data by notification - rate conditional today, mirror if those powers are used. Telecoms: no localisation rule found; the 2025 licensing policy instead makes licensees follow the privacy law and designates critical platforms as Critical Information Infrastructure. Health, insurance, securities, education, online gaming, mapping and defence: no sector storage rule found, checked 18 August 2026, medium confidence.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh Telecommunication Regulatory CommissionTelecommunications Network and Licensing Policy 2025 (clauses 11.9 and 11.10 on privacy standards and Critical Information Infrastructure)
btrc.gov.bd
Link checked 18 August 2026
Sending data out of the country
The model is an approved-destination list, and the list is empty. Before data leaves you need one of three things: the person's consent, a contract they are party to, or their consent for business, study or migration matters. On top of that the law only allows transfers to places the regulator has approved, and no approvals have been issued. If you are moving large volumes of identity numbers, fingerprints, face or iris data, DNA or criminal records, you must tell the regulator first.
Personal Data Protection Act 2026, section 29(3), (4) and (6). There is no standard contract template, no certification scheme and no group-wide-rules route published. Because the section 29(4) list of permitted destinations depends on regulations that do not exist, and because the complaint and fining sections have not commenced, transfers today happen in a legal grey zone rather than under a working approval system. Banks, finance companies and payment service providers have a separate and operational route: written prior approval from Bangladesh Bank, case by case, under the 2023 Cloud Computing Guidelines and the 2026 e-KYC Guidelines.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionGuidelines and strategy papers page - no rules or regulations under the Personal Data Protection Act 2026 listed as at 18 August 2026
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
The regulator, and whether it actually acts
On paper the enforcer is the National Data Management Authority, a body attached to the Prime Minister's Office. It is not running. The law that creates it says the government must appoint an executive chairman and six members by official notice, and we found no sign that has happened - it is not on the Prime Minister's Office list of attached offices. The privacy fines cannot be issued yet anyway, because those sections have not started. By contrast the cyber security agency and the central bank are both working and issuing instructions.
National Data Management Act 2026 (Act No. 80 of 2026), sections 8 and 9: the Authority is a statutory body attached to the Prime Minister's Office, constituted by government notification with one executive chairman and six members. The Personal Data Protection Act 2026 defines 'the Authority' by reference to that body. Sections 31 to 35 of the privacy law - complaints, administrative fines, factors in setting fines, and compensation - do not commence until a date the government fixes, and not before 18 months after 10 April 2026. Section 38 lets the government direct the Authority on grounds of sovereignty, security, friendly relations with foreign states or public order, and the Authority must comply, so it is not independent. Appeals against fines go to the tribunal set up under section 68 of the Information and Communication Technology Act, within 30 days. The National Cyber Security Agency is observably operational: its National Cyber Security Council held its first meeting on 28 December 2025 and it runs a cyber incident reporting system. Bangladesh Bank is active and aggressive by comparison - it issued a new Cybersecurity Framework on 29 March 2026 and e-KYC guidelines on 11 March 2026, and it grants or refuses cloud approvals.
Sources
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourcePrime Minister's OfficePrime Minister's Office - published list of attached offices and authorities (checked 18 August 2026)
pmo.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyNational Cyber Security Agency - home page, incident reporting services and news of the first National Cyber Security Council meeting on 28 December 2025
dsa.portal.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and the ceiling is blank. The floor: an organisation must keep a register of its personal data processing for at least five years, and mobile financial services must keep customer identity and transaction records for at least six years. The ceiling: the privacy law says you must not keep personal data longer than the period set by regulations, but no regulations have been made, so there is no fixed deletion date yet. Where two rules clash, the specific one wins - the five-year rule applies only when no other law says otherwise.
Personal Data Protection Act 2026, section 18 (retention limited to the period prescribed by regulations, with an exception for public-interest, scientific, historical or statistical purposes while safeguards are being built) and section 19 (records of processing to be kept in a register for at least five years, 'unless specifically stated in any other provision'). Bangladesh Mobile Financial Services Regulations 2022, section 18.1: know-your-customer and customer due diligence records for account holders, wholesale and retail agents, and records of MFS transactions, must be retained for not less than six years from origination. Bangladesh Bank's 2026 Cybersecurity Framework requires audit logs to be kept in line with record retention requirements and a quarterly process to delete stored sensitive data past its retention period, without naming a number of months.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankPSD Circular No. 04 of 15 February 2022 - Bangladesh Mobile Financial Services (MFS) Regulations, 2022
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
If something goes wrong
There are at least two clocks and neither is expressed in hours. Under the privacy law you must tell the regulator about a personal data breach that could seriously harm someone, but the form, method and timing are left to regulations that do not exist yet. Under the cyber security law any government, private or self-governing organisation that suffers a cyber incident must tell the national computer emergency response team without delay. Banks and payment firms have a third clock: they report to Bangladesh Bank and to the government computer incident response team under the central bank's framework.
Personal Data Protection Act 2026, section 20(1): notification to the Authority where a personal data breach is likely to cause significant harm to the data subject, in the form, manner and time prescribed by regulations. No regulations exist, and there is currently no Authority to receive the notification. There is no express duty in section 20 to notify affected individuals. Cyber Security Act 2026, section 9(4) proviso: where a cyber incident occurs at a government, private or autonomous body, that body must inform the national computer emergency response team without delay. Security operations centres of designated Critical Information Infrastructure must also file quarterly performance reports to the National Cyber Security Operation Centre, and Critical Information Infrastructure must submit an annual internal and external audit report. Bangladesh Bank's Cybersecurity Framework 2026 requires 24/7 detection and response and reporting to Bangladesh Bank and the government computer incident response team, without a stated hour count; the 2023 ICT Security Guideline requires the bank to inform Bangladesh Bank 'as soon as possible' when a critical system fails over to its disaster recovery site.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Cyber Security Act 2026 (Act No. 81 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD Circular No. 10 of 19 June 2023 - Guideline on ICT Security
bb.org.bd
Link checked 18 August 2026
What catches people out
Five things bite. One: the law was backdated - it counts as being in force from 6 November 2025, months before it was printed in April 2026. Two: a 'data subject' includes dead people, so the duties do not end when a customer dies. Three: a child is anyone under 18 and a parent's consent covers them until their eighteenth birthday. Four: named directors, managing directors, officers and even ordinary employees can be fined personally. Five: banks, finance companies and payment providers must keep customer data on servers in Bangladesh.
(1) Personal Data Protection Act 2026, section 1(3): except sections 23 and 31 to 35, the Act is deemed to have come into force on 6 November 2025 - the date the repealed Personal Data Protection Ordinance 2025 was made. (2) Section 2(3): 'data subject' means a natural person related to personal data who is identified or identifiable, 'whether living or dead'. (3) Section 2(19) defines a child as under 18 or such age as the government sets, and section 9(3) says parental or guardian consent covers the child until 18. (4) Section 36: where a data subject complains against a company, the Authority may impose an administrative fine on any board member, managing director, officer connected with management, or employee involved in the breach. (5) Bangladesh Bank e-KYC Guidelines, March 2026: 'The bank/FC/PS provider shall preserve customer data on locally hosted servers or private cloud servers' and data collected from customers must not be transmitted or transferred outside Bangladesh without Bangladesh Bank's prior approval. A sixth item worth watching: section 29(5) lets the government set a fee or charge on the annual business or commercial profit an organisation makes from using Bangladeshi citizens' personal data - a revenue power with no equivalent in most privacy laws.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
What's changing next
Three dated things. The privacy law's enforcement machinery - complaints, fines, compensation and the Chief Data Officer duty - starts on a date the government picks, and cannot start before about 10 October 2027. Banks must comply with the central bank's new cybersecurity framework by 31 December 2026. A further amendment to the cyber security law was with a cabinet committee in July 2026. The bigger risk is the switches the government can already flip without asking anyone.
DATED. (1) Personal Data Protection Act 2026, section 1(3): sections 23 and 31 to 35 commence on a date fixed by government notification after 18 months from the Act's issue on 10 April 2026 - so 10 October 2027 at the earliest. (2) Bangladesh Bank BRPD-2 Circular 02 of 29 March 2026: compliance with the Cybersecurity Framework Version 1.0 must be ensured by 31 December 2026. (3) The Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026) took effect on 1 July 2026 and deleted section 20 of the Cyber Security Act, the online gambling offence; the ICT Division reported a cabinet committee meeting on 15 July 2026 to review and finalise a further draft amendment. DORMANT SWITCHES. (a) National Data Management Act 2026, section 32: the Authority may make it compulsory for scheduled bodies to store their data in the national data repository system. (b) Section 31(2): the government may by notification impose limits and conditions on any organisation's data interoperability and exchange where state-critical sensitive data is involved, which includes anything touching sovereignty, public safety, borders or a declared emergency. (c) Personal Data Protection Act 2026, section 29(1) and (4): the government may classify personal data into public, internal, confidential and restricted tiers and prescribe which countries may receive data at all. (d) Section 29(5): a levy on profits made from Bangladeshis' personal data. (e) Section 38: the government may direct the regulator and the regulator must obey. (f) Section 43: in an emergency the government or the Authority may issue an order about any processing, storage, retention or transfer.
Sources
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceBangladesh BankBRPD-2 Circular No. 02 of 29 March 2026 - Cybersecurity Framework, Version 1.0 (2026)
bb.org.bd
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionNews item of 15 July 2026 - cabinet committee meeting to review and finalise the draft Cyber Security (Amendment) Act 2026
ictd.gov.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 1 July 2026 - Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026), deleting section 20
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Guidelines on Electronic Know-Your-Customer (e-KYC)
Regulator directive · BRPD-1 Circular No. 08 of 11 March 2026
Banks, finance companies and payment service providers must keep customer identity data on servers hosted in Bangladesh or in a private cloud, and may not send it out of the country without the central bank's prior approval. Identity is checked against the Election Commission's national identity verification server.
Enforced by Bangladesh Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryCustomer data must be preserved on locally hosted servers or private cloud servers.
- Put a transfer safeguard in placeNo transmission or transfer of customer data outside Bangladesh without Bangladesh Bank's prior approval, and the duty binds the third-party vendor as well as the regulated firm.
- Keep records of processingDigital know-your-customer data and logs kept as required by the Payment and Settlement Systems Act 2024.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by Bangladesh Bank against the licensed bank, finance company or payment service provider.
Sources
- Official sourceBangladesh BankBRPD-1 Circular No. 08 of 11 March 2026 - Guidelines on Electronic Know-Your-Customer (e-KYC)
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Guidelines on Cloud Computing
Regulator guideline · BRPD Circular No. 05 of 16 March 2023 (banks); DFIM Circular Letter No. 09 of 18 May 2023 (finance companies)
A bank's customers' financial and sensitive data may not sit in a public or hybrid cloud outside Bangladesh. Only in exceptional cases, and only with the central bank's prior approval, may it do so.
Enforced by Bangladesh Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryCustomers' financial and other sensitive data cannot be hosted in a cross-border public or hybrid cloud; a community cloud must be located within the country.
- Put a transfer safeguard in placeExceptions only with Bangladesh Bank's prior approval.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory direction to stop or unwind the cloud arrangement.
Sources
- Official sourceBangladesh BankBRPD Circular No. 05 of 16 March 2023 - Guidelines on Cloud Computing
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Bangladesh Mobile Financial Services (MFS) Regulations, 2022
Directly binding regulation · PSD Circular No. 04 of 15 February 2022
Mobile money providers must keep customer identity, agent and transaction records for at least six years. The regulations themselves set no storage-location rule, but the same firms are caught by the 2026 e-KYC guideline, which does.
Enforced by Bangladesh Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep data for a minimum period — 6 yearsCustomer and agent identity records and transaction records kept at least six years from the date they arose.
- Keep records of processing
What it costs if you get it wrong
- Loss of your licenceBreach of the licence conditions for a mobile financial services provider.
Sources
- Official sourceBangladesh BankPSD Circular No. 04 of 15 February 2022 - Bangladesh Mobile Financial Services (MFS) Regulations, 2022
bb.org.bd
Link checked 18 August 2026
- Official sourceBangladesh BankCirculars and circular letters index (checked to 18 August 2026)
bb.org.bd
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (Personal Data Protection Act, 2026)
Act of parliament · Act No. 63 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026
Bangladesh's general privacy law. It is treated as being in force since 6 November 2025, but the sections that create complaints, fines and compensation, and the Chief Data Officer duty, do not start until the government says so and not before about October 2027. Data may go abroad with consent or for a contract, but only to destinations the regulator approves, and it has approved none.
Enforced by National Data Management Authority — not yet operational
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Explicit consent, Needed for a contract, Official 'this country is safe' decision
What it makes you do
- Get consentConsent must be voluntary, specific, clear and withdrawable, and the person must be told the purpose, the retention period and any transfer before giving it. A short list of legitimate interests replaces consent.
- Tell people what you do
- Secure the data
- Keep records of processing — 5 yearsRegister of processing kept at least five years unless another law says otherwise.
- Delete data after a periodNot longer than the period prescribed by regulations. No regulations made as at 18 August 2026, so no fixed deletion date.
- Report breaches to the regulatorWhere the breach is likely to cause significant harm. Form, method and timing left to regulations that do not exist yet.
- Independent auditPrescribed classes of organisation must be audited by an independent data auditor approved by the Authority; the Authority can also order an audit.
- Appoint a data protection officer — from 10 October 2027Chief Data Officer, only for 'significant data-fiduciaries', working at a place the Authority determines. Section 23 has not commenced.
- Get a parent's consent for childrenChild means under 18; parental consent covers the child until 18.
- Put a transfer safeguard in place
- Written vendor contractThe data-fiduciary stays liable for its processor's failures.
What it costs if you get it wrong
- Fixed maximum fine: BDT 2,500,000 (25 lakh taka) — about $21 thousandFailure to honour a data subject's rights, or failure to keep data secure. Not enforceable until sections 31-35 commence.
- Fixed maximum fine: BDT 5,000,000 (50 lakh taka) — about $41 thousandSame failure by a 'significant data-fiduciary'.
- Claims by individualsThe Authority may award compensation to the data subject on top of the fine.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Personal Data Protection Act 2026 (Act No. 63 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
জাতীয় উপাত্ত ব্যবস্থাপনা আইন, ২০২৬ (National Data Management Act, 2026)
Act of parliament · Act No. 80 of 2026, Bangladesh Gazette Extraordinary, 10 April 2026
Creates the National Data Management Authority under the Prime Minister's Office and a national data-exchange platform for public bodies. It also gives the state two switches: it can order scheduled bodies to keep their data in the national repository, and it can restrict the exchange of anything it labels state-critical sensitive data.
Enforced by National Data Management Authority — not yet operational
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryA power, not yet used: the Authority may make it compulsory for scheduled bodies to store their data in the national data repository system.
- Written vendor contractA Data Resharing Agreement must be signed by both sides before any data moves across the national exchange platform.
- Keep records of processing
What it costs if you get it wrong
- Criminal liabilityNot criminal in the ordinary sense: a public servant involved in violating a data subject's rights while processing, storing, retaining, transferring or disclosing data is treated as guilty of misconduct and faces departmental proceedings.
Sources
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - National Data Management Act 2026 (Act No. 80 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
সাইবার সুরক্ষা আইন, ২০২৬ (Cyber Security Act, 2026), as amended by সাইবার সুরক্ষা (সংশোধন) আইন, ২০২৬
Act of parliament · Act No. 81 of 2026 (gazetted 10 April 2026), amended by Act No. 99 of 2026 (gazetted 1 July 2026)
Re-enacts the 2025 cyber security ordinance and is treated as in force from 21 May 2025. It sets up the National Cyber Security Agency, the national computer emergency response team and a list of Critical Information Infrastructure, and it makes cyber offences criminal rather than administrative. An amendment on 1 July 2026 deleted the online gambling offence.
Enforced by National Cyber Security Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidentsAny government, private or autonomous body suffering a cyber incident must inform the national computer emergency response team without delay. No hour count is given.
- Independent auditDesignated Critical Information Infrastructure must submit an annual internal and external audit report and run its own incident response team and security operations centre, which reports quarterly.
- Secure the data
What it costs if you get it wrong
- Criminal liability: 7 years imprisonment or BDT 10,000,000 (1 crore taka), or both — about $82 thousandUnlawful access to Critical Information Infrastructure and theft, destruction or alteration of data held there. Lesser offences carry up to 5 years or BDT 5,000,000.
Sources
- Official sourceInformation and Communication Technology DivisionLaws page listing the Personal Data Protection Act 2026, the National Data Management Act 2026 and the Cyber Security Act 2026 (published 15 April 2026)
ictd.gov.bd
Link checked 18 August 2026
- Official sourceLegislative and Parliamentary Affairs DivisionGazette copies of Acts passed in 2026 - Act 63 (Personal Data Protection), Act 80 (National Data Management), Act 81 (Cyber Security), Act 99 (Cyber Security Amendment)
legislativediv.gov.bd
Link checked 18 August 2026
- Secondary sourceInformation and Communication Technology Division (government object storage)Bangladesh Gazette, Extraordinary, 10 April 2026 - Cyber Security Act 2026 (Act No. 81 of 2026), full text
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Secondary sourceLegislative and Parliamentary Affairs Division (government object storage)Bangladesh Gazette, Extraordinary, 1 July 2026 - Cyber Security (Amendment) Act 2026 (Act No. 99 of 2026), deleting section 20
objectstorage.ap-dcc-gazipur-1.oraclecloud15.com
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyNational Cyber Security Agency - home page, incident reporting services and news of the first National Cyber Security Council meeting on 28 December 2025
dsa.portal.gov.bd
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the National Data Management Authority has been constituted and staffed
The law requires a government notification naming an executive chairman and six members. We found no such notification, no website for the body, and no entry on the Prime Minister's Office list of attached offices on 18 August 2026. We cannot prove a negative, so this is rated medium confidence rather than high.
That no rules or regulations have been made under the Personal Data Protection Act 2026
The Information and Communication Technology Division's own laws, policies and guidelines pages list nothing under the Act as at 18 August 2026, and the Authority that would make regulations does not appear to exist. A gazette notification could exist without being mirrored on the department site.
Which countries or places are approved destinations under section 29(4)
The section only permits transfers to places prescribed by regulations. No such regulations were found. On a strict reading that means no destination is currently approved, which would make routine transfers unlawful on paper; in practice there is no regulator to say so. We could not find any official statement resolving this.
Whether the government has used its power to classify personal data into public, internal, confidential and restricted tiers under section 29(1)
No classification notification found on the sponsoring department's site.
The exact commencement date of sections 23 and 31 to 35 of the privacy law
The Act says a date fixed by notification after 18 months from issue. We date that to 10 October 2027 at the earliest, counting from the 10 April 2026 gazette. No commencement notification has been issued yet.
The content of the Gambling Prevention Act 2026
The telecom regulator lists it among the laws applied to licensees, and the Cyber Security (Amendment) Act 2026 deleted the online gambling offence from the cyber law on 1 July 2026, which is consistent with a dedicated statute. We could not locate the text on the Legislative Division's list of 2026 Acts.
Data storage and retention rules for insurance and securities firms
The Insurance Development and Regulatory Authority and the securities commission both serve their document lists through scripts that did not render for automated checking. No rule found; treat as unchecked rather than as an absence of rules.
Retention periods under the Payment and Settlement Systems Act 2024
The central bank's 2026 e-KYC guidelines point to that Act for how long digital know-your-customer data and logs must be kept. We could not locate the Act's text on an official site.
Whether a further Cyber Security (Amendment) Act is in progress
The sponsoring department reported a cabinet committee meeting on 15 July 2026 to review and finalise a draft amendment, two weeks after Act No. 99 of 2026 was gazetted. It is unclear whether this refers to the same instrument or a second one.
Whether telecom or internet licence conditions impose data localisation or log retention
The 2025 licensing policy and the 2026 amendment to the telecom act contain no localisation rule in the parts we read, but individual licence guidelines were not all reviewed.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Put this next to another country
Bangladesh versus
Compare