Skip to the content
Global Data RulesData governance rules, country by country

Nepal

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Nepal — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Dormant

On paper, data can leave Nepal freely. Nepal's privacy law says nothing about sending data abroad. There is no privacy regulator at all. Breaches are criminal matters taken to a local court. The maximum fine is about 215 US dollars, and no case has produced a public penalty. The real limit is a 2025 rule on data centres and cloud services. It says customers may only buy hosting from providers on a government list.

Data governance in Nepal

The eight things that decide how you handle data about people in Nepal. Same eight on every country page, so you can compare.

Who has to follow these rules

It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies that handle people's information. It never says whether it reaches a company sitting outside Nepal. It does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad. The computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal. The central bank's payment licensing policy expressly covers firms set up abroad that do payment business inside Nepal. There is no revenue or company-size threshold to fall below.

What you have to do here:
Register or notify
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Under the privacy law, yes. It says nothing about sending personal data out of Nepal, so there is nothing to comply with. But Nepal still has limits, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list. Listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre. And card payments made in Nepali rupees must be settled inside Nepal.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Nothing. There is no approval to get, no standard contract to sign and no list of approved countries. Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round. It is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.

What you have to do here:
Register or notify
Ways to send data out:
Nothing required
Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months. The court can also award compensation. The bodies that are actually active work on cyber security and on industry rules, not on privacy. The National Cyber Security Center published advisories as recently as April 2026. The telecoms authority collects security audit reports. The central bank issues payment directives. The Department of Information Technology runs the data centre listing scheme.

What it costs if you get it wrong:
Criminal liability · Claims by individuals
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months, and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date. The only real deletion duty we found is a telecom rule. It says paper customer forms must be destroyed once they have been scanned.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There is no general duty to report a personal data breach in Nepal. You need not tell a regulator, and you need not tell the people affected. We found no rule setting a deadline in hours. Two narrower duties do exist. A data centre or cloud provider must report anyone who gets into its systems without permission. It must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.

What you have to do here:
Report cyber incidents · Secure the data
Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. One: privacy breaches are criminal, not administrative. The exposure is up to three years in prison for an individual, not a company fine. Two: a victim has only three months from the act to complain, so most claims die of old age. Three: your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Four: anyone under 18 needs a guardian's consent. There is no lower digital age. Five: the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality. It is written vaguely enough to catch ordinary posts.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting. The ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on three things. Amending its 2020 cyber security rules. Rules for streaming and messaging services. And a rule to force the move to newer internet addressing.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data must stay in the country

Official name: भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082) · Issued by the Payment Systems Department, consolidating directives up to 30 Chaitra 2082 · Regulator directive

In forceNo — it stays put

Nepal's payments rulebook. Card transactions in Nepali rupees must be cleared and settled inside Nepal. Licensed payment institutions must run a disaster recovery site alongside their data centre. The licensing policy expressly reaches firms set up abroad that do payment business in Nepal.

In force since 13 April 2026

Enforced by Nepal Rastra Bank

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Telecoms

Cyber security rules

Official name: साइबर सुरक्षा विनियमावली, २०७७ (Cyber Security Byelaw, 2077 (2020)) · Made under section 62 of the Telecommunication Act, 2053 (1997) · Directly binding regulation

In forceYes — store it anywhere

The binding cyber security rulebook for Nepali telecom and internet service providers. It sets minimum log keeping periods, encryption and audit duties. It also sets a consent rule for sharing customer data with vendors. It does not require anything to be stored inside Nepal.

In force since 1 January 2020

Enforced by Nepal Telecommunications Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Telecoms

Telecoms rules

Official name: दूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७ · Made under section 62 of the Telecommunication Act, 2053; approved by Authority decision no. 4416 of 2077.06.23 · Directly binding regulation

In forceYes — store it anywhere

A rare deletion duty in a country with almost none. Telecom operators must destroy the paper identity documents they collect from subscribers, once those records have been digitised.

In force since 9 October 2020

Enforced by Nepal Telecommunications Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: गोपनियता सम्बन्धी ऐन, २०७५ (The Privacy Act, 2075 (2018)) · Act No. 14 of the year 2075 · Act of parliament

In forceYes — store it anywhere

Nepal's only general privacy statute. It creates consent, security and correction duties. It bans public bodies from handling sensitive information. It says nothing about sending data abroad, and it creates no regulator. The fine is capped at about 215 US dollars, but prison of up to three years is possible.

In force since 18 September 2018

Enforced by District Courts of Nepal

How this country controls where data goes: No restriction · Accepted routes: Nothing required

General data protection law (2020)

Official name: वैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077) · Directly binding regulation

In forceYes — store it anywhere

The rules made under the Privacy Act. They fill in the procedure for collecting and holding personal information, and add requirements for closed-circuit television cameras. We found no rule in them about sending data abroad or about where data must be stored.

In force since 1 January 2020

Enforced by Ministry of Law, Justice and Parliamentary Affairs

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Cloud and outsourcing rules

Official name: विद्युतीय (इलेक्ट्रोनिक) कारोबार ऐन, २०६३ (Electronic Transactions Act, 2063 (2008)) · Act of parliament

In forceYes — store it anywhere

Nepal's computer-crime and electronic-signature law. It reaches acts committed outside Nepal that involve a computer inside Nepal. It is the source of the government's power to issue data centre and cloud directives. Its online-content offence carries up to five years in prison.

In force since 8 December 2008

Enforced by Department of Information Technology

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • सूचना प्रविधि विभाग

    Data centres, cloud services, government IT systems, electronic transactions

    Actively running the data centre and cloud listing scheme; registration notice published in Mangsir 2082 (around December 2025) with application forms.

  • सञ्चार तथा सूचना प्रविधि मन्त्रालय

    Policy and directives on information technology, telecoms and broadcasting

    Published concept papers for a Telecommunications Bill and a National Mass Communication Bill on 20 Shrawan 2083 (5 August 2026).

  • राष्ट्रिय साइबर सुरक्षा केन्द्र

    Cyber security for government systems, forensic investigation, advisories

    Sits under the Office of the Prime Minister. Issued a ransomware advisory on 20 April 2026 and an infrastructure advisory on 7 January 2026, so demonstrably staffed and publishing.

  • नेपाल राष्ट्र बैंक

    Banking, payments, foreign exchange

    Consolidated its payment systems unified directive in Chaitra 2082 (around April 2026) and issues circulars continuously.

  • नेपाल दूरसञ्चार प्राधिकरण

    Telecom and internet licensing, cyber security byelaw, information system audits

    Publishes the list of licensees that have filed information system and cloud audit reports, and is consulting on amending the Cyber Security Byelaw 2077.

  • जिल्ला अदालत

    Criminal complaints and compensation claims under the Privacy Act; there is no privacy regulator

    The courts function, but we found no published privacy judgment or penalty. So the personal data rules go unenforced.

  • आन्तरिक राजस्व विभाग

    Tax record retention

  • नेपाल धितोपत्र बोर्ड

    Securities markets

    Operational, but no information technology or data storage guideline appears in its published guidelines as at 18 August 2026.

  • नेपाल बीमा प्राधिकरण

    Insurance

    Operational. We found no directive on its own site about data storage, or about where data must sit, as at 18 August 2026.

  • कानून, न्याय तथा संसदीय मामिला मन्त्रालय

    Custodian of the statute book, including the Privacy Act and its regulation

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Department of Information Technology has actually published a list of registered data centre and cloud service providers, and whether any foreign or global cloud provider is on it

    We could not confirm who is on the government's list of approved data centre and cloud providers. The Department's notice calling for registration is on its own site, and the directive requires the list to be published. This is the most important unknown in this record. If the list is short and local, ordinary use of overseas cloud in Nepal breaks the rule. Ask the Department for the current list before you choose a provider.

  • Whether the customer-side restriction in the data centre directive is enforced against ordinary businesses that host with overseas providers

    We could not confirm what happens to a customer that uses an unlisted provider. The directive sets no penalty for a customer. It only allows removal of a provider from the list. We found no enforcement action, so check with the Department before you rely on this.

  • Whether the Nepal Rastra Bank requires banks to keep their primary data centre and disaster recovery site inside Nepal

    We could not confirm whether Nepali banks must keep data inside the country. The payment systems directive requires a data centre and a disaster recovery site, but we found no text placing them in Nepal. The banking supervision guidelines are published only in a legacy Nepali font that we could not read reliably. Treat this as unresolved rather than absent, and check with the central bank.

  • The exact commencement date and gazette reference of the Individual Privacy Regulation, 2077

    We could not confirm the date of this regulation. Its text is on the Law Commission's site in a legacy font that did not extract cleanly, so the date given here is approximate.

  • Whether the Information Technology Tribunal created by the Electronic Transactions Act is constituted and hearing cases

    We could not confirm whether the tribunal is actually operating. Its procedural rules of 2064 exist on the statute book, but we found no roster, no cause list and no decisions.

  • The current legal force of the Social Networking Operation Directive 2080 and whether any platform is registered under it

    We could not confirm what rules now apply to social media platforms. The Ministry's notices about regulating social media are on its own site, but the text is in a legacy font we could not read. We also could not confirm from a government source what happened after the platform blocking episode of 2025.

  • Whether any localisation or storage rule exists in health, education, gaming, defence or mapping

    We found no such rule on the relevant government sites, checked 18 August 2026. Several Nepali ministries publish only in Nepali, and only as scanned images. If this affects your industry, check with the ministry before you rely on it.

  • Whether any Nepali court has ever imposed a penalty under the Privacy Act

    We found no published judgment. The dormant enforcement rating rests on that absence, plus the lack of any regulator. No government body has stated that the law goes unenforced.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.