Nepal
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
Eight questions about Nepal
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Nepal's rules apply to my company?
It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.
Privacy Act 2075 sections 23 and 26 impose duties on a 'public body or body corporate' without a territorial clause. Electronic Transactions Act 2063 section 55 is expressly extraterritorial for computer offences. The Nepal Rastra Bank licensing policy for payment institutions, 2079 (first amendment 2080), states at clause 1(2) that its provisions apply to institutions established in Nepal operating outside Nepal and to institutions established outside Nepal carrying out payment work inside Nepal. Separately, the Ministry of Communication and Information Technology has published notices calling on social media platforms to register with it under the Social Networking Operation Directive 2080; that is a ministerial directive rather than a statute.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानीसम्बन्धी कार्य गर्ने संस्थालाई प्रदान गरिने अनुमति नीति (प्रथम संशोधन, २०८०), २०७९ — licensing policy for payment institutions
nrb.org.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technologyसामाजिक सञ्जालको प्रयोगलाई व्यवस्थित गर्ने सम्बन्धमा मन्त्रालयको सूचना (Ministry notice on regulating social media use), 21 Magh 2081
mocit.gov.np
Link checked 18 August 2026
Can I store my users' data outside Nepal?
Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.
Sector by sector. All industries: Data Center and Cloud Service (Operation and Management) Directives 2081, section 8(1) — 'Before using data center and cloud services, any client shall only obtain services from providers listed in the department's published list.' Government and public sector: section 3(7) makes use of the Integrated Data Management Centre mandatory for Government of Nepal security agencies, and section 3(9) requires other government bodies to move departmental data centres into the government data centre on a timetable set by a steering committee; section 6(3) requires any data centre holding government data to be Tier 3 or better. Payments: the Nepal Rastra Bank Unified Directive on Payment Systems 2082 requires that transactions in Nepali rupees made in Nepal on payment cards issued by licensed institutions be settled within Nepal, and that any bond or guarantee issued to an international switch for that purpose be denominated in Nepali rupees. Telecoms: the Cyber Security Byelaw 2077 imposes encryption, audit and log duties but no localisation. Securities, insurance and health: no storage or localisation rule found on the regulators' own sites, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082), Chaitra 2082
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceSecurities Board of NepalGuidelines of the Securities Board of Nepal — no information technology or data storage guideline listed
sebon.gov.np
Link checked 18 August 2026
What do I need in place before data leaves Nepal?
Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.
So the transfer model is best described as unrestricted for the data itself and an allowlist for the infrastructure. Providers already operating when the directive commenced had six months to apply for listing. Listing requires a company or firm registration certificate, a building completion certificate, a map of the site, an internet protocol address pool in the provider's own name and an information security standard certificate — requirements a provider with no physical presence in Nepal cannot realistically meet. The Department can strike a provider off the list, and the customer must then move its systems immediately.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
Who enforces the rules in Nepal, and what can they do?
For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.
Privacy Act 2075 sections 29 to 31: offences are prosecuted under the National Criminal Procedure Code 2074 with the Government of Nepal as plaintiff for a defined subset, and otherwise by private complaint to the district court within three months. Punishment is up to three years' imprisonment or a fine of up to thirty thousand rupees or both, plus compensation and departmental discipline for public officials. We found no published privacy enforcement decision from any Nepali body. Enforcement is therefore rated dormant for personal data even though several sector regulators are demonstrably operational.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNational Cyber Security Center, Office of the Prime Minister and Council of MinistersPublications and advisories of the National Cyber Security Center, including a ransomware advisory of 20 April 2026
ncsc.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankPayment Systems Department — directives, policies and oversight reports
nrb.org.np
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.
Floor: Income Tax Act 2058 section 81 (five years from the end of the income year); Cyber Security Byelaw 2077 rules 47 and 48 (security logs six months, network address translation logs three months, or as directed by the telecoms authority); Data Center and Cloud Service Directives 2081 section 7(13)(s) (closed-circuit television storage of at least three months). Ceiling: the Privacy Act contains no storage limitation principle. The 2077 telecom bylaw on destruction of customer documents requires that identity documents collected when signing up a customer be digitised and the paper then destroyed. Nepal has no published rule for resolving a clash between a keep-it duty and a delete-it duty; in practice the keep-it duty wins because it carries a tax or licence penalty and the delete-it duty does not.
Sources
- Official sourceNepal Law Commissionआयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81 — records to be kept five years after the end of the income year
lawcommission.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications Authorityदूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ (Bylaw on destruction of customer forms and documents, 2077)
nta.gov.np
Link checked 18 August 2026
What happens if there is a breach?
There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.
Data Center and Cloud Service Directives 2081 section 7(5) requires immediate notification of unauthorised access to the regulatory body and to the National Cyber Security Center; section 8(3) requires a customer that spots unauthorised access to tell its provider and to notify the Center in writing if a forensic investigation is needed, and the Center must report back within one month. Cyber Security Byelaw 2077 rules 58 to 60 require licensees to have an incident response team and a plan and to work with a named task force chaired by the Director of the Monitoring Division of the telecoms authority. The central bank's Cyber Resilience Guidelines of August 2023 set a two-hour target for resuming critical operations after a disruption, which is a recovery objective rather than a reporting deadline. So there is effectively one clock, and it says 'immediately' rather than a number.
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankCyber Resilience Guidelines, August 2023, and other Payment Systems Department policies
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
What trips people up in Nepal?
Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.
(1) Privacy Act 2075 section 29(2): imprisonment up to three years or a fine up to thirty thousand rupees (about 215 US dollars) or both. The fine is trivial; the prison term is not, and it attaches to people. (2) Section 30(2): complaint to the district court within three months of the act. (3) Data Center and Cloud Service Directives 2081 section 8. (4) Section 33: for anyone under eighteen, or of unsound mind, or with an intellectual disability, only a guardian or curator can consent, and only where publication benefits that person. (5) Electronic Transactions Act 2063 section 47: up to five years' imprisonment or a fine up to one hundred thousand rupees (about 720 US dollars) or both for publishing material online that is contrary to public morality or decent behaviour, or that spreads hatred between communities. Section 48 adds up to two years for divulging information obtained under that Act. Also worth knowing: the Privacy Act bans a public body from processing sensitive information about caste, ethnicity, political affiliation, religion, health, sexual life or property at all, with only narrow health and self-publication exceptions.
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
What is changing soon in Nepal?
No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.
Dormant switches matter more here than pending legislation, because most of Nepal's data rules are ministerial directives made under section 79 of the Electronic Transactions Act 2063 and can be rewritten without going near parliament. Four to watch. First, the Department of Information Technology can remove a data centre or cloud provider from its list after a fifteen-day show-cause and seven-day decision, which forces every customer of that provider to migrate. Second, the steering committee chaired by the ministry secretary can order any government body into the state data centre at a time of its choosing. Third, the ministry can issue new directives under section 79 at will, which is exactly how the 2025 data centre rule appeared. Fourth, the telecoms authority can amend the Cyber Security Byelaw 2077 by board decision. Treat the current permissive position as revocable rather than settled.
Sources
- Official sourceMinistry of Communication and Information TechnologyActs and laws of the Ministry of Communication and Information Technology — concept papers for a Telecommunications Bill and a National Mass Communication Bill, 20 Shrawan 2083
mocit.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityPublic notices — consultation on amending the Cyber Security Byelaw 2077, draft Over-the-Top regulatory framework, IPv6 Migration Byelaw 2082 consultation
nta.gov.np
Link checked 18 August 2026
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
गोपनियता सम्बन्धी ऐन, २०७५ (The Privacy Act, 2075 (2018))
Act of parliament · Act No. 14 of the year 2075
Nepal's only general privacy statute. It creates consent, security and correction duties and bans public bodies from processing sensitive information, but it says nothing about sending data abroad, creates no regulator, and caps the fine at about 215 US dollars while allowing up to three years in prison.
Enforced by District Courts of Nepal
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consentPersonal information held by a public body or a company may not be used or given to anyone without the person's consent, subject to listed exceptions.
- Tell people what you doWhen information is collected for study or research the purpose, content, method and protection arrangements must be stated up front.
- Secure the dataPublic bodies must guard against unauthorised access, use, change, disclosure, publication or transmission.
- Let people correct their dataA person may apply to the holding body to correct wrong information, unless they have already taken a benefit on the basis of it.
- Get a parent's consent for children — applies at: under 18Consent of a guardian or curator, and only if publication benefits the person.
What it costs if you get it wrong
- Criminal liability: 3 years imprisonment and/or NPR 30,000 — about $215Any listed privacy offence, including using personal information without consent or processing sensitive information
- Claims by individualsDamage, loss or injury caused by a privacy offence; the district court fixes compensation
Sources
- Official sourceNepal Law CommissionThe Privacy Act, 2075 (2018) — official English text, Act No. 14 of 2075
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceNepal Law Commissionगोपनियता सम्बन्धी ऐन, २०७५ / The Privacy Act, 2075 — record page
lawcommission.gov.np
Link checked 18 August 2026
वैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077)
Directly binding regulation
The rules made under the Privacy Act. They fill in procedure for collecting and holding personal information and add requirements for closed-circuit television cameras. We found no cross-border transfer or storage-location provision in them.
Enforced by Ministry of Law, Justice and Parliamentary Affairs
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataProcedural detail for collecting, storing, protecting, analysing and processing personal data, and rules on closed-circuit television including storage capacity.
Sources
- Official sourceNepal Law Commissionवैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077)
lawcommission.gov.np
Link checked 18 August 2026
विद्युतीय (इलेक्ट्रोनिक) कारोबार ऐन, २०६३ (Electronic Transactions Act, 2063 (2008))
Act of parliament
Nepal's computer-crime and electronic-signature law. It reaches acts committed outside Nepal that involve a computer inside Nepal, it is the source of the government's power to issue data centre and cloud directives, and its online-content offence carries up to five years in prison.
Enforced by Department of Information Technology
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataDuties on certifying authorities and network service providers; section 79 lets the government issue binding directives, which is how the 2025 data centre rule was made.
What it costs if you get it wrong
- Criminal liability: 5 years imprisonment and/or NPR 100,000 — about $720Publishing material online contrary to public morality or decent behaviour, or spreading hatred between communities
- Criminal liability: 3 years imprisonment and/or NPR 200,000 — about $1 thousandUnauthorised access to a computer, or altering computer source code
- Criminal liability: 2 years imprisonment and/or NPR 10,000 — about $72Divulging confidential records or information obtained under the Act
Sources
- Official sourceDepartment of Information TechnologyElectronic Transactions Act, 2063 (2008) — official English text
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyActs and Laws — Electronic Transactions Act 2063 and Rules 2064
doit.gov.np
Link checked 18 August 2026
डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
Government rules · Made under section 79 of the Electronic Transactions Act, 2063; approved by Ministerial decision
The rule that actually determines where data sits in Nepal. Data centre and cloud providers must be listed by the Department of Information Technology, listing in practice requires a Nepal-registered company with a building in Nepal, and customers are told to buy only from listed providers. Government security agencies must use the state data centre and other government bodies are being migrated into it.
Enforced by Department of Information Technology
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Register or notify — from 28 July 2025Providers operating when the rule started had six months to apply for listing; new providers must be listed before offering services. Listing needs a Nepal company or firm registration certificate, a building completion certificate and a map of the site.
- Keep the data in the countryCustomers may only buy data centre and cloud services from providers on the Department's published list, and government security agencies must use the state's Integrated Data Management Centre.
- Hold a security certificateInformation security standard certificate for both the main site and the disaster recovery site; cloud providers also need an IT service management standard certificate.
- Independent audit — 1 yearSecurity audit of the infrastructure at least once a year.
- Appoint a data protection officerA compliance officer must be appointed, or compliance services bought in.
- Report cyber incidentsUnauthorised access must be reported immediately, by the fastest possible means, to the regulatory body and the National Cyber Security Center.
- Keep logs — 3 monthsClosed-circuit television footage of the data centre.
- Make switching cloud provider possibleProviders must help a customer remove infrastructure or move a hosted system elsewhere, including on dissolution.
What it costs if you get it wrong
- Order to stopRemoval from the Department's list after a fifteen-day show-cause; customers must then move their systems immediately
Sources
- Official sourceMinistry of Communication and Information Technology / Department of Information TechnologyData Center and Cloud Service (Operation and Management) Directives, 2081 — official English translation, approved 28 January 2025
giwmscdnone.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyNotice calling data centre and cloud service providers to be listed, with application forms
doit.gov.np
Link checked 18 August 2026
- Official sourceDepartment of Information TechnologyDirectives and procedures — Data Center and Cloud Service (Operation and Management) Directives, 2081
doit.gov.np
Link checked 18 August 2026
आयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81
Act of parliament
The main retention floor. Business records must be kept for five years after the end of the tax year, and the penalty for not keeping them is that the tax office assesses your income itself.
Enforced by Inland Revenue Department
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 5 yearsDocuments must be kept for five years from the end of the income year they relate to; failing to keep them lets the tax office estimate your income for that year.
Sources
- Official sourceNepal Law Commissionआयकर ऐन, २०५८ (Income Tax Act, 2058 (2002)), section 81 — records to be kept five years after the end of the income year
lawcommission.gov.np
Link checked 18 August 2026
Industry rules3 rules
भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)
Regulator directive · Issued by the Payment Systems Department, consolidating directives up to 30 Chaitra 2082 · Payments
Nepal's payments rulebook. Domestic-currency card transactions must be cleared and settled inside Nepal, licensed payment institutions must run a disaster recovery site alongside their data centre, and the licensing policy expressly reaches firms set up abroad that do payment business in Nepal.
Enforced by Nepal Rastra Bank
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryCard transactions carried out in Nepal in Nepali rupees must be settled inside Nepal; any bond or guarantee issued to an international switch for this purpose must be in Nepali rupees.
- Secure the dataLicensed institutions must have a disaster recovery plan covering the data centre, the standby or disaster recovery site, data and system backup, recovery time and recovery point objectives, and data integrity between the two sites.
- Independent auditRegular information system audit covering database and transaction security, encryption standards and incident management.
Sources
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082), Chaitra 2082
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Rastra Bank, Payment Systems Departmentभुक्तानीसम्बन्धी कार्य गर्ने संस्थालाई प्रदान गरिने अनुमति नीति (प्रथम संशोधन, २०८०), २०७९ — licensing policy for payment institutions
nrb.org.np
Link checked 18 August 2026
- Official sourceNepal Rastra BankPayment Systems Department — directives, policies and oversight reports
nrb.org.np
Link checked 18 August 2026
साइबर सुरक्षा विनियमावली, २०७७ (Cyber Security Byelaw, 2077 (2020))
Directly binding regulation · Made under section 62 of the Telecommunication Act, 2053 (1997) · Telecoms
The binding cyber security rulebook for Nepali telecom and internet service providers. It sets log retention floors, encryption and audit duties, and a consent rule for sharing customer data with vendors, but it does not require anything to be stored inside Nepal.
Enforced by Nepal Telecommunications Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 6 monthsSecurity logs at least six months; internet address translation logs at least three months, or as the telecoms authority directs.
- Secure the dataEncryption in transit, and masking, anonymising or encryption for customer data at rest.
- Extra vendor secrecy termsNon-disclosure agreements with staff and vendors; customer data may not be shared with any third party without the customer's consent, except with law enforcement.
- Independent audit — 6 monthsInternal security audit report to the authority every six months, plus an annual information system audit by an auditor designated by the authority or the government.
- Report cyber incidentsLicensees must form an incident response team and work with a standing task force at the telecoms authority when an incident occurs.
Sources
- Official sourceNepal Telecommunications AuthorityCyber Security Byelaw, 2077 (2020), made under section 62 of the Telecommunication Act 2053
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityBylaws of the Nepal Telecommunications Authority — full list including the Cyber Security Byelaw 2077
nta.gov.np
Link checked 18 August 2026
दूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७
Directly binding regulation · Made under section 62 of the Telecommunication Act, 2053; approved by Authority decision no. 4416 of 2077.06.23 · Telecoms
A rare deletion duty in a country with almost none. Telecom operators must pulp the paper identity documents they collect from subscribers once those records have been digitised.
Enforced by Nepal Telecommunications Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Delete data after a periodPaper customer forms and attached identity documents such as citizenship certificate and passport copies must be destroyed once the records have been converted to digital form.
Sources
- Official sourceNepal Telecommunications Authorityदूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ (Bylaw on destruction of customer forms and documents, 2077)
nta.gov.np
Link checked 18 August 2026
- Official sourceNepal Telecommunications AuthorityBylaws of the Nepal Telecommunications Authority — full list including the Cyber Security Byelaw 2077
nta.gov.np
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Department of Information Technology has actually published a list of registered data centre and cloud service providers, and whether any foreign or global cloud provider is on it
The Department's notice calling for registration is on its own site, and the directive requires the list to be published, but we could not open the list itself. This is the single most load-bearing unknown in this record: if the list is short and local, ordinary use of overseas cloud in Nepal is technically non-compliant.
Whether the customer-side restriction in the data centre directive is enforced against ordinary businesses that host with overseas providers
The directive contains no penalty for a customer, only removal of a provider from the list. We found no enforcement action, so the practical effect is unknown.
Whether the Nepal Rastra Bank requires banks to keep their primary data centre and disaster recovery site inside Nepal
The payment systems directive requires a data centre and a disaster recovery site but we could not find text placing them in Nepal, and the banking supervision guidelines are published only in a legacy Nepali font that we could not reliably read. Treat banking localisation as unresolved rather than absent.
The exact commencement date and gazette reference of the Individual Privacy Regulation, 2077
The regulation is on the Law Commission's site but its text is in a legacy font that did not extract cleanly, so the date given here is approximate.
Whether the Information Technology Tribunal created by the Electronic Transactions Act is constituted and hearing cases
The tribunal's procedural rules of 2064 exist on the statute book, but we found no roster, no cause list and no decisions.
The current legal force of the Social Networking Operation Directive 2080 and whether any platform is registered under it
The Ministry's notices about regulating social media are on its own site but the notice text is in a legacy font we could not read, and we could not confirm from a government source what happened after the platform blocking episode of 2025.
Whether any localisation or storage rule exists in health, education, gaming, defence or mapping
No rule found on the relevant government sites, checked 18 August 2026. Absence of a finding is not proof of absence; several Nepali ministries publish only in Nepali and only as scanned images.
Whether any Nepali court has ever imposed a penalty under the Privacy Act
No published judgment located. The dormant enforcement rating rests on that absence plus the lack of any regulator, not on a positive statement by government.
60-day cadence. Almost every operative Nepali data rule is a ministerial directive made under section 79 of the Electronic Transactions Act 2063 and can be rewritten or tightened without parliament or consultation. The data centre listing scheme is new, its list is not yet visible to us, and the country is in a period of political transition, so the permissive headline could move quickly.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Nepal versus Argentina
- Nepal versus Armenia
- Nepal versus Australia
- Nepal versus Austria
- Nepal versus Azerbaijan
- Nepal versus Brazil
- Nepal versus Bulgaria
- Nepal versus Cambodia
- Nepal versus Canada
- Nepal versus China
- Nepal versus Croatia
- Nepal versus Cyprus
- Nepal versus Estonia
- Nepal versus France
- Nepal versus Georgia
- Nepal versus Germany
- Nepal versus Greece
- Nepal versus Hong Kong SAR
- Nepal versus Hungary
- Nepal versus Iceland
- Nepal versus India
- Nepal versus Indonesia
- Nepal versus Ireland
- Nepal versus Israel
- Nepal versus Italy
- Nepal versus Japan
- Nepal versus Latvia
- Nepal versus Lithuania
- Nepal versus Luxembourg
- Nepal versus Malta
- Nepal versus Mexico
- Nepal versus Mongolia
- Nepal versus Netherlands
- Nepal versus Poland
- Nepal versus Russia
- Nepal versus Saudi Arabia
- Nepal versus Serbia
- Nepal versus Singapore
- Nepal versus Slovakia
- Nepal versus Slovenia
- Nepal versus South Korea
- Nepal versus Spain
- Nepal versus Sri Lanka
- Nepal versus Sweden
- Nepal versus Switzerland
- Nepal versus Taiwan
- Nepal versus Thailand
- Nepal versus Turkey
- Nepal versus Ukraine
- Nepal versus United Arab Emirates
- Nepal versus United Kingdom
- Nepal versus United States
- Nepal versus Uzbekistan