Nepal
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Nepal — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
On paper, data can leave Nepal freely. Nepal's privacy law says nothing about sending data abroad. There is no privacy regulator at all. Breaches are criminal matters taken to a local court. The maximum fine is about 215 US dollars, and no case has produced a public penalty. The real limit is a 2025 rule on data centres and cloud services. It says customers may only buy hosting from providers on a government list.
Data governance in Nepal
The eight things that decide how you handle data about people in Nepal. Same eight on every country page, so you can compare.
Who has to follow these rules
It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies that handle people's information. It never says whether it reaches a company sitting outside Nepal. It does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad. The computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal. The central bank's payment licensing policy expressly covers firms set up abroad that do payment business inside Nepal. There is no revenue or company-size threshold to fall below.
- What you have to do here:
- Register or notify
The Privacy Act 2075, sections 23 and 26, place duties on a 'public body or body corporate'. Neither section says which countries it covers. The Electronic Transactions Act 2063, section 55, expressly applies to computer offences committed outside Nepal. The Nepal Rastra Bank licensing policy for payment institutions, 2079 (first amendment 2080), says at clause 1(2) who it covers. It covers institutions set up in Nepal that operate outside Nepal. It also covers institutions set up outside Nepal that do payment work inside Nepal. Separately, the Ministry of Communication and Information Technology has published notices calling on social media platforms to register with it. Those notices rely on the Social Networking Operation Directive 2080. That is a ministerial directive, not a statute.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानीसम्बन्धी कार्य गर्ने संस्थालाई प्रदान गरिने अनुमति नीति (प्रथम संशोधन, २०८०), २०७९ — licensing policy for payment institutions
nrb.org.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technologyसामाजिक सञ्जालको प्रयोगलाई व्यवस्थित गर्ने सम्बन्धमा मन्त्रालयको सूचना (Ministry notice on regulating social media use), 21 Magh 2081
mocit.gov.np
Link checked 18 August 2026
Where the data is allowed to live
Under the privacy law, yes. It says nothing about sending personal data out of Nepal, so there is nothing to comply with. But Nepal still has limits, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list. Listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre. And card payments made in Nepali rupees must be settled inside Nepal.
Sector by sector. All industries. The Data Center and Cloud Service (Operation and Management) Directives 2081, section 8(1), cover this. They say that before using data centre and cloud services, any client shall only obtain services from providers listed in the department's published list. Government and public sector: section 3(7) makes use of the Integrated Data Management Centre compulsory for Government of Nepal security agencies. Section 3(9) requires other government bodies to move departmental data centres into the government data centre, on a timetable set by a steering committee. Section 6(3) requires any data centre holding government data to be Tier 3 or better. Payments: the Nepal Rastra Bank Unified Directive on Payment Systems 2082 covers card transactions. Transactions in Nepali rupees, made in Nepal on payment cards issued by licensed institutions, must be settled within Nepal. Any bond or guarantee issued to an international switch for that purpose must be in Nepali rupees. Telecoms: the Cyber Security Byelaw 2077 imposes encryption, audit and log duties, but says nothing about where data must sit. Securities, insurance and health: we found no rule about storage or location on the regulators' own sites, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082), Chaitra 2082
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceSecurities Board of NepalGuidelines of the Securities Board of Nepal — no information technology or data storage guideline listed
sebon.gov.np
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Nothing. There is no approval to get, no standard contract to sign and no list of approved countries. Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round. It is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.
- What you have to do here:
- Register or notify
- Ways to send data out:
- Nothing required
So the data itself can move freely, while the hosting must come from an approved list. Providers already operating when the directive started had six months to apply for listing. Listing requires a company or firm registration certificate, a building completion certificate, a map of the site, an internet protocol address pool in the provider's own name, and an information security standard certificate. A provider with no physical presence in Nepal cannot realistically meet those requirements. The Department can strike a provider off the list, and the customer must then move its systems immediately.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
The regulator, and whether it actually acts
For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months. The court can also award compensation. The bodies that are actually active work on cyber security and on industry rules, not on privacy. The National Cyber Security Center published advisories as recently as April 2026. The telecoms authority collects security audit reports. The central bank issues payment directives. The Department of Information Technology runs the data centre listing scheme.
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
The Privacy Act 2075, sections 29 to 31, sets out how breaches are punished. Offences are prosecuted under the National Criminal Procedure Code 2074, with the Government of Nepal as plaintiff for a defined subset. Otherwise a person complains privately to the district court within three months. Punishment is up to three years in prison, or a fine of up to thirty thousand rupees, or both. Compensation and departmental discipline for public officials can be added. We found no published privacy enforcement decision from any Nepali body. So enforcement for personal data is rated dormant, even though several sector regulators are clearly working.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNational Cyber Security Center, Office of the Prime Minister and Council of MinistersPublications and advisories of the National Cyber Security Center, including a ransomware advisory of 20 April 2026
ncsc.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankPayment Systems Department — directives, policies and oversight reports
nrb.org.np
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months, and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date. The only real deletion duty we found is a telecom rule. It says paper customer forms must be destroyed once they have been scanned.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
Minimum keeping periods. The Income Tax Act 2058, section 81: five years from the end of the income year. The Cyber Security Byelaw 2077, rules 47 and 48: security logs six months, network address translation logs three months, or as the telecoms authority directs. The Data Center and Cloud Service Directives 2081, section 7(13)(s): closed-circuit television footage kept at least three months. On the other side, the Privacy Act sets no maximum keeping period at all. The 2077 telecom bylaw on destroying customer documents requires identity documents collected at sign-up to be scanned, and the paper then destroyed. Nepal has no published rule for resolving a clash between a duty to keep and a duty to delete. The duty to keep tends to win, because it carries a tax or licence penalty and the duty to delete does not.
Sources
- Official sourceNepal Law Commissionआयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81 — records to be kept five years after the end of the income year
lawcommission.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications Authorityदूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ (Bylaw on destruction of customer forms and documents, 2077)
nta.gov.np
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There is no general duty to report a personal data breach in Nepal. You need not tell a regulator, and you need not tell the people affected. We found no rule setting a deadline in hours. Two narrower duties do exist. A data centre or cloud provider must report anyone who gets into its systems without permission. It must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.
- What you have to do here:
- Report cyber incidents · Secure the data
The Data Center and Cloud Service Directives 2081, section 7(5), cover unauthorised access. They require immediate notice to the regulatory body and to the National Cyber Security Center. Section 8(3) requires a customer that spots unauthorised access to tell its provider. The customer must also notify the Center in writing if a forensic investigation is needed, and the Center must report back within one month. The Cyber Security Byelaw 2077, rules 58 to 60, require licensees to have an incident response team and a plan. They must work with a named task force chaired by the Director of the Monitoring Division of the telecoms authority. The central bank's Cyber Resilience Guidelines of August 2023 set a two-hour target for resuming critical operations after a disruption. That is a recovery target, not a reporting deadline. So there is really one clock, and it says 'immediately' rather than a number.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankCyber Resilience Guidelines, August 2023, and other Payment Systems Department policies
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
What catches people out
Five things. One: privacy breaches are criminal, not administrative. The exposure is up to three years in prison for an individual, not a company fine. Two: a victim has only three months from the act to complain, so most claims die of old age. Three: your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Four: anyone under 18 needs a guardian's consent. There is no lower digital age. Five: the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality. It is written vaguely enough to catch ordinary posts.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
(1) Privacy Act 2075, section 29(2): prison up to three years, or a fine up to thirty thousand rupees (about 215 US dollars), or both. The fine is trivial. The prison term is not, and it attaches to people. (2) Section 30(2): complain to the district court within three months of the act. (3) Data Center and Cloud Service Directives 2081, section 8. (4) Section 33: only a guardian or curator can consent for anyone under eighteen, of unsound mind, or with an intellectual disability. Consent works only where publication benefits that person. (5) Electronic Transactions Act 2063, section 47: up to five years in prison, or a fine up to one hundred thousand rupees (about 720 US dollars), or both. That covers publishing material online that is contrary to public morality or decent behaviour. It also covers material that spreads hatred between communities. Section 48 adds up to two years for divulging information obtained under that Act. Also worth knowing: the Privacy Act bans a public body from handling sensitive information about caste, ethnicity, political affiliation, religion, health, sexual life or property at all. There are only narrow exceptions for health and for self-publication.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
What's changing next
No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting. The ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on three things. Amending its 2020 cyber security rules. Rules for streaming and messaging services. And a rule to force the move to newer internet addressing.
Powers that can be used without warning matter more here than pending legislation. Most of Nepal's data rules are ministerial directives made under section 79 of the Electronic Transactions Act 2063. They can be rewritten without going near parliament. Four to watch. First, the Department of Information Technology can remove a data centre or cloud provider from its list, after a fifteen-day show-cause and a seven-day decision. That forces every customer of that provider to migrate. Second, the steering committee chaired by the ministry secretary can order any government body into the state data centre at a time of its choosing. Third, the ministry can issue new directives under section 79 at will. That is exactly how the 2025 data centre rule appeared. Fourth, the telecoms authority can amend the Cyber Security Byelaw 2077 by board decision. Treat the current permissive position as revocable rather than settled.
Sources
- Official sourceMinistry of Communication and Information TechnologyActs and laws of the Ministry of Communication and Information Technology — concept papers for a Telecommunications Bill and a National Mass Communication Bill, 20 Shrawan 2083
mocit.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityPublic notices — consultation on amending the Cyber Security Byelaw 2077, draft Over-the-Top regulatory framework, IPv6 Migration Byelaw 2082 consultation
nta.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payments data must stay in the country
Official name: भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082) · Issued by the Payment Systems Department, consolidating directives up to 30 Chaitra 2082 · Regulator directive
Nepal's payments rulebook. Card transactions in Nepali rupees must be cleared and settled inside Nepal. Licensed payment institutions must run a disaster recovery site alongside their data centre. The licensing policy expressly reaches firms set up abroad that do payment business in Nepal.
Enforced by Nepal Rastra Bank
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryCard transactions carried out in Nepal in Nepali rupees must be settled inside Nepal. Any bond or guarantee issued to an international switch for this purpose must be in Nepali rupees.
- Secure the dataLicensed institutions must have a disaster recovery plan. It must cover the data centre, the standby or disaster recovery site, data and system backup, recovery time and recovery point objectives, and data integrity between the two sites.
- Independent auditRegular information system audit covering database and transaction security, encryption standards and incident management.
Sources
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082), Chaitra 2082
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानीसम्बन्धी कार्य गर्ने संस्थालाई प्रदान गरिने अनुमति नीति (प्रथम संशोधन, २०८०), २०७९ — licensing policy for payment institutions
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankPayment Systems Department — directives, policies and oversight reports
nrb.org.np
Link checked 18 August 2026
Cyber security rules
Official name: साइबर सुरक्षा विनियमावली, २०७७ (Cyber Security Byelaw, 2077 (2020)) · Made under section 62 of the Telecommunication Act, 2053 (1997) · Directly binding regulation
The binding cyber security rulebook for Nepali telecom and internet service providers. It sets minimum log keeping periods, encryption and audit duties. It also sets a consent rule for sharing customer data with vendors. It does not require anything to be stored inside Nepal.
Enforced by Nepal Telecommunications Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 6 monthsSecurity logs at least six months; internet address translation logs at least three months, or as the telecoms authority directs.
- Secure the dataEncryption in transit, and masking, anonymising or encryption for customer data at rest.
- Extra vendor secrecy termsNon-disclosure agreements with staff and vendors; customer data may not be shared with any third party without the customer's consent, except with law enforcement.
- Independent audit — 6 monthsInternal security audit report to the authority every six months, plus an annual information system audit by an auditor designated by the authority or the government.
- Report cyber incidentsLicensees must form an incident response team and work with a standing task force at the telecoms authority when an incident occurs.
Sources
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityBylaws of the Nepal Telecommunications Authority — full list including the Cyber Security Byelaw 2077
nta.gov.np
Link checked 18 August 2026
Telecoms rules
Official name: दूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ · Made under section 62 of the Telecommunication Act, 2053; approved by Authority decision no. 4416 of 2077.06.23 · Directly binding regulation
A rare deletion duty in a country with almost none. Telecom operators must destroy the paper identity documents they collect from subscribers, once those records have been digitised.
Enforced by Nepal Telecommunications Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Delete data after a periodPaper customer forms and attached identity documents such as citizenship certificate and passport copies must be destroyed once the records have been converted to digital form.
Sources
- Official sourceNepal Telecommunications Authorityदूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ (Bylaw on destruction of customer forms and documents, 2077)
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityBylaws of the Nepal Telecommunications Authority — full list including the Cyber Security Byelaw 2077
nta.gov.np
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: गोपनियता सम्बन्धी ऐन, २०७५ (The Privacy Act, 2075 (2018)) · Act No. 14 of the year 2075 · Act of parliament
Nepal's only general privacy statute. It creates consent, security and correction duties. It bans public bodies from handling sensitive information. It says nothing about sending data abroad, and it creates no regulator. The fine is capped at about 215 US dollars, but prison of up to three years is possible.
Enforced by District Courts of Nepal
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consentPersonal information held by a public body or a company may not be used or given to anyone without the person's consent, subject to listed exceptions.
- Tell people what you doWhen information is collected for study or research the purpose, content, method and protection arrangements must be stated up front.
- Secure the dataPublic bodies must guard against unauthorised access, use, change, disclosure, publication or transmission.
- Let people correct their dataA person may apply to the holding body to correct wrong information, unless they have already taken a benefit on the basis of it.
- Get a parent's consent for children — applies at: under 18Consent of a guardian or curator, and only if publication benefits the person.
What it costs if you get it wrong
- Criminal liability: 3 years imprisonment and/or NPR 30,000 — about $215Any listed privacy offence, including using personal information without consent or processing sensitive information
- Claims by individualsDamage, loss or injury caused by a privacy offence; the district court fixes compensation
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Law Commissionगोपनियता सम्बन्धी ऐन, २०७५ / The Privacy Act, 2075 — record page
lawcommission.gov.np
Link checked 18 August 2026
General data protection law (2020)
Official name: वैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077) · Directly binding regulation
The rules made under the Privacy Act. They fill in the procedure for collecting and holding personal information, and add requirements for closed-circuit television cameras. We found no rule in them about sending data abroad or about where data must be stored.
Enforced by Ministry of Law, Justice and Parliamentary Affairs
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataProcedural detail for collecting, storing, protecting, analysing and using personal data. Also rules on closed-circuit television, including storage capacity.
Sources
- Official sourceNepal Law Commissionवैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077)
lawcommission.gov.np
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: विद्युतीय (इलेक्ट्रोनिक) कारोबार ऐन, २०६३ (Electronic Transactions Act, 2063 (2008)) · Act of parliament
Nepal's computer-crime and electronic-signature law. It reaches acts committed outside Nepal that involve a computer inside Nepal. It is the source of the government's power to issue data centre and cloud directives. Its online-content offence carries up to five years in prison.
Enforced by Department of Information Technology
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataDuties on certifying authorities and network service providers; section 79 lets the government issue binding directives, which is how the 2025 data centre rule was made.
What it costs if you get it wrong
- Criminal liability: 5 years imprisonment and/or NPR 100,000 — about $720Publishing material online contrary to public morality or decent behaviour, or spreading hatred between communities
- Criminal liability: 3 years imprisonment and/or NPR 200,000 — about $1 thousandUnauthorised access to a computer, or altering computer source code
- Criminal liability: 2 years imprisonment and/or NPR 10,000 — about $72Divulging confidential records or information obtained under the Act
Sources
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyActs and Laws — Electronic Transactions Act 2063 and Rules 2064
doit.gov.np
Link checked 18 August 2026
Cloud and outsourcing rules (2025)
Official name: डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081) · Made under section 79 of the Electronic Transactions Act, 2063; approved by Ministerial decision · Government rules
The rule that decides where data sits in Nepal. Data centre and cloud providers must be listed by the Department of Information Technology. Getting listed usually requires a Nepal-registered company with a building in Nepal. Customers are told to buy only from listed providers. Government security agencies must use the state data centre, and other government bodies are being moved into it.
Enforced by Department of Information Technology
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Register or notify — from 28 July 2025Providers operating when the rule started had six months to apply for listing; new providers must be listed before offering services. Listing needs a Nepal company or firm registration certificate, a building completion certificate and a map of the site.
- Keep the data in the countryCustomers may only buy data centre and cloud services from providers on the Department's published list. Government security agencies must use the state's Integrated Data Management Centre.
- Hold a security certificateInformation security standard certificate for both the main site and the disaster recovery site; cloud providers also need an IT service management standard certificate.
- Independent audit — 1 yearSecurity audit of the infrastructure at least once a year.
- Appoint a data protection officerA compliance officer must be appointed, or compliance services bought in.
- Report cyber incidentsUnauthorised access must be reported immediately, by the fastest possible means, to the regulatory body and the National Cyber Security Center.
- Keep logs — 3 monthsClosed-circuit television footage of the data centre.
- Make switching cloud provider possibleProviders must help a customer remove infrastructure or move a hosted system elsewhere, including on dissolution.
What it costs if you get it wrong
- Order to stopRemoval from the Department's list after a fifteen-day show-cause; customers must then move their systems immediately
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyDirectives and procedures — Data Center and Cloud Service (Operation and Management) Directives, 2081
doit.gov.np
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: आयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81 · Act of parliament
The main retention floor. Business records must be kept for five years after the end of the tax year. If you do not keep them, the tax office assesses your income itself.
Enforced by Inland Revenue Department
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 5 yearsDocuments must be kept for five years from the end of the income year they relate to. If you fail to keep them, the tax office can estimate your income for that year.
Sources
- Official sourceNepal Law Commissionआयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81 — records to be kept five years after the end of the income year
lawcommission.gov.np
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Department of Information Technology has actually published a list of registered data centre and cloud service providers, and whether any foreign or global cloud provider is on it
We could not confirm who is on the government's list of approved data centre and cloud providers. The Department's notice calling for registration is on its own site, and the directive requires the list to be published. This is the most important unknown in this record. If the list is short and local, ordinary use of overseas cloud in Nepal breaks the rule. Ask the Department for the current list before you choose a provider.
Whether the customer-side restriction in the data centre directive is enforced against ordinary businesses that host with overseas providers
We could not confirm what happens to a customer that uses an unlisted provider. The directive sets no penalty for a customer. It only allows removal of a provider from the list. We found no enforcement action, so check with the Department before you rely on this.
Whether the Nepal Rastra Bank requires banks to keep their primary data centre and disaster recovery site inside Nepal
We could not confirm whether Nepali banks must keep data inside the country. The payment systems directive requires a data centre and a disaster recovery site, but we found no text placing them in Nepal. The banking supervision guidelines are published only in a legacy Nepali font that we could not read reliably. Treat this as unresolved rather than absent, and check with the central bank.
The exact commencement date and gazette reference of the Individual Privacy Regulation, 2077
We could not confirm the date of this regulation. Its text is on the Law Commission's site in a legacy font that did not extract cleanly, so the date given here is approximate.
Whether the Information Technology Tribunal created by the Electronic Transactions Act is constituted and hearing cases
We could not confirm whether the tribunal is actually operating. Its procedural rules of 2064 exist on the statute book, but we found no roster, no cause list and no decisions.
The current legal force of the Social Networking Operation Directive 2080 and whether any platform is registered under it
We could not confirm what rules now apply to social media platforms. The Ministry's notices about regulating social media are on its own site, but the text is in a legacy font we could not read. We also could not confirm from a government source what happened after the platform blocking episode of 2025.
Whether any localisation or storage rule exists in health, education, gaming, defence or mapping
We found no such rule on the relevant government sites, checked 18 August 2026. Several Nepali ministries publish only in Nepali, and only as scanned images. If this affects your industry, check with the ministry before you rely on it.
Whether any Nepali court has ever imposed a penalty under the Privacy Act
We found no published judgment. The dormant enforcement rating rests on that absence, plus the lack of any regulator. No government body has stated that the law goes unenforced.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.