Skip to the content
Global Data RulesData governance rules, country by country

Nepal

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Dormant

Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.

Eight questions about Nepal

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Nepal's rules apply to my company?

It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.

Medium confidenceNational rulesRegister or notify

Can I store my users' data outside Nepal?

Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.

Medium confidenceDepends on your industryKeep the data in the countryAllowlist

What do I need in place before data leaves Nepal?

Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.

Medium confidenceNothing requiredAllowlistRegister or notify

Who enforces the rules in Nepal, and what can they do?

For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.

Medium confidenceDormantCriminal liabilityClaims by individuals

How long do I have to keep the data?

There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.

Medium confidenceReport cyber incidentsSecure the data

What trips people up in Nepal?

Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.

High confidenceCriminal liabilityGet a parent's consent for childrenSensitive personal data

What is changing soon in Nepal?

No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.

Medium confidenceProposedDraft law

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

गोपनियता सम्बन्धी ऐन, २०७५ (The Privacy Act, 2075 (2018))

Act of parliament · Act No. 14 of the year 2075

In forceYes — store it anywhere

Nepal's only general privacy statute. It creates consent, security and correction duties and bans public bodies from processing sensitive information, but it says nothing about sending data abroad, creates no regulator, and caps the fine at about 215 US dollars while allowing up to three years in prison.

In force since 18 September 2018

Enforced by District Courts of Nepal

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

वैयक्तिक गोपनीयता सम्बन्धी नियमावली, २०७७ (Individual Privacy Regulation, 2077)

Directly binding regulation

In forceYes — store it anywhere

The rules made under the Privacy Act. They fill in procedure for collecting and holding personal information and add requirements for closed-circuit television cameras. We found no cross-border transfer or storage-location provision in them.

In force since 1 January 2020

Enforced by Ministry of Law, Justice and Parliamentary Affairs

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

विद्युतीय (इलेक्ट्रोनिक) कारोबार ऐन, २०६३ (Electronic Transactions Act, 2063 (2008))

Act of parliament

In forceYes — store it anywhere

Nepal's computer-crime and electronic-signature law. It reaches acts committed outside Nepal that involve a computer inside Nepal, it is the source of the government's power to issue data centre and cloud directives, and its online-content offence carries up to five years in prison.

In force since 8 December 2008

Enforced by Department of Information Technology

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules3 rules

भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)

Regulator directive · Issued by the Payment Systems Department, consolidating directives up to 30 Chaitra 2082 · Payments

In forceNo — it stays put

Nepal's payments rulebook. Domestic-currency card transactions must be cleared and settled inside Nepal, licensed payment institutions must run a disaster recovery site alongside their data centre, and the licensing policy expressly reaches firms set up abroad that do payment business in Nepal.

In force since 13 April 2026

Enforced by Nepal Rastra Bank

Transfer model: Not allowed

Medium confidence

साइबर सुरक्षा विनियमावली, २०७७ (Cyber Security Byelaw, 2077 (2020))

Directly binding regulation · Made under section 62 of the Telecommunication Act, 2053 (1997) · Telecoms

In forceYes — store it anywhere

The binding cyber security rulebook for Nepali telecom and internet service providers. It sets log retention floors, encryption and audit duties, and a consent rule for sharing customer data with vendors, but it does not require anything to be stored inside Nepal.

In force since 1 January 2020

Enforced by Nepal Telecommunications Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

दूरसञ्चार सेवा प्रदायकले संकलन गरेको ग्राहकको फर्म लगायतका कागजात धुल्याउने विनियमावली, २०७७

Directly binding regulation · Made under section 62 of the Telecommunication Act, 2053; approved by Authority decision no. 4416 of 2077.06.23 · Telecoms

In forceYes — store it anywhere

A rare deletion duty in a country with almost none. Telecom operators must pulp the paper identity documents they collect from subscribers once those records have been digitised.

In force since 9 October 2020

Enforced by Nepal Telecommunications Authority

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • सूचना प्रविधि विभाग

    Data centres, cloud services, government IT systems, electronic transactions

    Actively running the data centre and cloud listing scheme; registration notice published in Mangsir 2082 (around December 2025) with application forms.

  • सञ्चार तथा सूचना प्रविधि मन्त्रालय

    Policy and directives on information technology, telecoms and broadcasting

    Published concept papers for a Telecommunications Bill and a National Mass Communication Bill on 20 Shrawan 2083 (5 August 2026).

  • राष्ट्रिय साइबर सुरक्षा केन्द्र

    Cyber security for government systems, forensic investigation, advisories

    Sits under the Office of the Prime Minister. Issued a ransomware advisory on 20 April 2026 and an infrastructure advisory on 7 January 2026, so demonstrably staffed and publishing.

  • नेपाल राष्ट्र बैंक

    Banking, payments, foreign exchange

    Consolidated its payment systems unified directive in Chaitra 2082 (around April 2026) and issues circulars continuously.

  • नेपाल दूरसञ्चार प्राधिकरण

    Telecom and internet licensing, cyber security byelaw, information system audits

    Publishes the list of licensees that have filed information system and cloud audit reports, and is consulting on amending the Cyber Security Byelaw 2077.

  • जिल्ला अदालत

    Criminal complaints and compensation claims under the Privacy Act; there is no privacy regulator

    The courts function, but we found no published privacy judgment or penalty. In practice the personal data regime is unenforced.

  • आन्तरिक राजस्व विभाग

    Tax record retention

  • नेपाल धितोपत्र बोर्ड

    Securities markets

    Operational, but no information technology or data storage guideline appears in its published guidelines as at 18 August 2026.

  • नेपाल बीमा प्राधिकरण

    Insurance

    Operational, but no data storage or localisation directive found on its own site as at 18 August 2026.

  • कानून, न्याय तथा संसदीय मामिला मन्त्रालय

    Custodian of the statute book, including the Privacy Act and its regulation

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Department of Information Technology has actually published a list of registered data centre and cloud service providers, and whether any foreign or global cloud provider is on it

    The Department's notice calling for registration is on its own site, and the directive requires the list to be published, but we could not open the list itself. This is the single most load-bearing unknown in this record: if the list is short and local, ordinary use of overseas cloud in Nepal is technically non-compliant.

  • Whether the customer-side restriction in the data centre directive is enforced against ordinary businesses that host with overseas providers

    The directive contains no penalty for a customer, only removal of a provider from the list. We found no enforcement action, so the practical effect is unknown.

  • Whether the Nepal Rastra Bank requires banks to keep their primary data centre and disaster recovery site inside Nepal

    The payment systems directive requires a data centre and a disaster recovery site but we could not find text placing them in Nepal, and the banking supervision guidelines are published only in a legacy Nepali font that we could not reliably read. Treat banking localisation as unresolved rather than absent.

  • The exact commencement date and gazette reference of the Individual Privacy Regulation, 2077

    The regulation is on the Law Commission's site but its text is in a legacy font that did not extract cleanly, so the date given here is approximate.

  • Whether the Information Technology Tribunal created by the Electronic Transactions Act is constituted and hearing cases

    The tribunal's procedural rules of 2064 exist on the statute book, but we found no roster, no cause list and no decisions.

  • The current legal force of the Social Networking Operation Directive 2080 and whether any platform is registered under it

    The Ministry's notices about regulating social media are on its own site but the notice text is in a legacy font we could not read, and we could not confirm from a government source what happened after the platform blocking episode of 2025.

  • Whether any localisation or storage rule exists in health, education, gaming, defence or mapping

    No rule found on the relevant government sites, checked 18 August 2026. Absence of a finding is not proof of absence; several Nepali ministries publish only in Nepali and only as scanned images.

  • Whether any Nepali court has ever imposed a penalty under the Privacy Act

    No published judgment located. The dormant enforcement rating rests on that absence plus the lack of any regulator, not on a positive statement by government.

60-day cadence. Almost every operative Nepali data rule is a ministerial directive made under section 79 of the Electronic Transactions Act 2063 and can be rewritten or tightened without parliament or consultation. The data centre listing scheme is new, its list is not yet visible to us, and the country is in a period of political transition, so the permissive headline could move quickly.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.