TRW Knowledge / Technology, data & digital evidence

Information and Communication Technology Act, 2006: Electronic Records, Signatures and the 2026 Legal Context

This guide replaces an earlier, imprecise description of a single “Bangladesh IT Act 2023”. The official Bangladesh Laws database identifies the Information and Communication Technology Act, 2006 as the statute that addresses legal recognition and security for information and communication technology. It is a different instrument from the cyber-security and personal-data measures discuss

Originally published 09 July 2026

2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.

Scope of this guide

This guide replaces an earlier, imprecise description of a single “Bangladesh IT Act 2023”. The official Bangladesh Laws database identifies the Information and Communication Technology Act, 2006 as the statute that addresses legal recognition and security for information and communication technology. It is a different instrument from the cyber-security and personal-data measures discussed below.The historical URL and original publication date are retained for continuity. The legal discussion has been updated for 2026 and is deliberately limited to high-level, source-grounded information. It is not a substitute for verifying the current official text, subordinate rules, regulator guidance or the facts of a specific matter.

What the Information and Communication Technology Act, 2006 does

The official title and preamble of the 2006 Act describe its purpose as providing legal validity and security for information and communication technology and related matters. Its text addresses concepts that remain central to digital transactions: electronic records, electronic signatures, authentication, electronic signature certificates, electronic data interchange and the legal effect of records kept in electronic form.For organisations, the practical significance is not that every online action is automatically valid. Rather, the Act provides a statutory framework through which electronic records and signatures may be recognised when the conditions of the Act and the relevant transaction are satisfied. Contractual terms, a sector regulator’s requirements, evidence rules and the formality requirements of another statute may all remain important.The official text recognises that a record may be created, received or stored in electronic form. It also addresses situations in which a legal requirement for writing or printed form may be met through an accessible electronic record that can be used for later reference. This makes the quality of record management a legal as well as operational issue.A transaction team should therefore ask practical questions before relying on an electronic record: what is the authoritative version; who created or approved it; can the record be retrieved; is there an audit trail; and can a later change be identified? Those questions become more important when a record will be used in a dispute, a regulatory process or a cross-border transaction.

Electronic signatures and authentication

The 2006 Act contains provisions concerning authentication of electronic records and legal recognition of electronic signatures. Its definitions describe an electronic signature as information in electronic form connected to other electronic data and authenticated through stated conditions. The statute also addresses secure signature-creation arrangements and electronic signature certificates.In practice, a business should avoid treating a platform click, an emailed name, a scanned signature and a certified electronic-signature process as interchangeable without analysis. The transaction documents, the required formalities, the parties’ agreement, the method used to identify the signatory and the integrity of the record can all affect risk. Where execution certainty is material, the relevant statutory text and the parties’ evidence plan should be reviewed before signing.

Government processes and electronic communication

The Act also contains provisions concerning use of electronic records and signatures in government offices, statutory bodies and government-controlled authorities. The existence of the statutory framework does not by itself mean that every authority must accept every electronic format. A filing, licence, approval or payment process should be checked against the specific authority’s current rules, portal requirements and published directions.For regulated or high-value activity, organisations should retain the submission confirmation, the version filed, relevant correspondence and any proof of the authority’s acceptance. A well-maintained record helps separate an operational submission problem from a question of legal effect.

Cross-border dimension

The official 2006 Act includes provisions on extra-territorial application in circumstances involving conduct outside Bangladesh and computers, systems or networks connected with Bangladesh. That does not eliminate the need for jurisdiction-specific advice. Cross-border matters can engage contracts, foreign governing law, data-location questions, regulator expectations and procedural issues at the same time.Where an organisation uses regional cloud infrastructure, outsources technology services or contracts with an overseas counterparty, a disciplined review should map the actors, systems, data flows, governing documents and the law chosen for the agreement. The result should not be assumed from a single statutory label.Bangladesh’s legal landscape should be described with precision. The official Bangladesh Laws database separately lists the Cyber Security Act, 2023, whose official preamble states that it repealed the Digital Security Act, 2018. The database also lists the Cyber Security Ordinance, 2025, whose official preamble states that it repeals the Cyber Security Act, 2023.Personal-data protection is also addressed separately. The official database lists the Personal Data Protection Ordinance, 2025, describing a framework for protecting personal data and for lawful processing with consent, together with related matters. The operative scope, requirements and any later amendments or rules must be checked from primary materials before a business relies on a compliance conclusion.Accordingly, electronic-record validity, cyber-security exposure and personal-data governance should be analysed as related but distinct workstreams. Combining them under an invented or catch-all statute can lead to the wrong questions, the wrong owner inside an organisation and a misleading public explanation.

Building a defensible digital-record programme

For many businesses, the most useful starting point is a practical inventory. Identify which records establish commitments, approvals, payments, instructions, customer communications and regulatory filings. Then identify the systems that create and retain them, the people able to make changes and the evidence available if the record is challenged.A second step is to align the process with the transaction. A routine internal approval may call for a different authentication and retention approach from a financing document, a board resolution, a government filing or a high-value cross-border contract. The appropriate standard depends on the document, the applicable law and the level of risk, not simply on whether the record is digital.Third, organisations should test retrieval. A record that exists but cannot be located, opened, attributed or explained under pressure may offer limited practical value. Retention schedules, access controls, versioning, backups and incident procedures should be designed with potential regulatory and dispute use in mind.

Technology contracting and operational controls

Technology agreements often allocate responsibility for availability, security, change management, intellectual-property ownership, audit access, subcontractors and incident communication. Those clauses should be read with the electronic-record process, not in isolation. For example, if a vendor hosts approval records or provides an e-signature workflow, the contract should make clear how the organisation can access its evidence, what happens on termination and how material incidents will be handled.Operational controls should be proportionate. Useful measures may include role-based access, multi-factor authentication, change logs, documented approval pathways, business-continuity arrangements and periodic testing of restore and retrieval processes. The right combination is fact-specific. A legal assessment should not promise that a generic control set meets every statutory or regulatory requirement.

Incident response and evidence preservation

A suspected technology or security incident should be approached methodically. The immediate aim is often to contain harm and preserve reliable information. Teams should identify the affected systems, keep a contemporaneous action log, preserve available logs and records, control external communications and determine which contractual, regulatory or legal questions are engaged.Because notification, reporting and investigative issues can depend on the particular statute, regulator, industry and facts, organisations should confirm the applicable requirements from official sources and case-specific advice. The 2006 Act should not be used as shorthand for every cyber or personal-data obligation.A focused review can be more effective than a broad statement that the organisation is “digitally compliant”. Decision-makers can begin with the following questions: Which electronic records are legally important? What authentication method is used for each? Which laws or regulators apply to the transaction? Where are the records and related data processed? What evidence can the organisation produce if a record is disputed? What contractual protections and escalation processes apply to third-party systems?Answers should be documented with the date and version of the official source used. This is particularly important where a legal area is evolving or where a title used in legacy content does not accurately identify the operative instrument.Digital regulation frequently intersects with commercial contracting, disputes and organisational governance. Explore TRW’s practice areas for relevant legal capability, visit Services to start with the legal question, or read our arbitration guidance where technology contracts give rise to a dispute. For a confidential discussion, use the consultation link or contact the firm directly.

Five practical FAQs

Is there a Bangladesh IT Act 2023?

The official Bangladesh Laws database identifies the Information and Communication Technology Act, 2006. Cyber-security legislation was addressed separately through the Cyber Security Act, 2023 and, according to the official database, the Cyber Security Ordinance, 2025 repeals that 2023 Act. The exact instrument relevant to a matter should be verified against the official text.

What does the Information and Communication Technology Act, 2006 address?

The official text addresses the legal recognition and security of information and communication technology, including electronic records and electronic signatures. It should be read alongside the particular transaction, sectoral regulation and any applicable subordinate instruments.

Are electronic signatures automatically valid for every document?

The 2006 Act recognises electronic signatures and electronic records subject to its terms. Whether a particular document, approval process or evidentiary use is effective will depend on the governing instrument, applicable formalities and the facts.

Does the 2006 Act contain all personal-data protection rules?

No. The official Bangladesh Laws database separately lists the Personal Data Protection Ordinance, 2025. Organisations should identify the exact legal instrument and any sector-specific requirement relevant to their processing activity before relying on a compliance conclusion.

What should an organisation review first?

A useful starting point is to identify the transaction, systems, records, counterparties and regulator involved; review the authoritative text and any applicable rules; preserve the relevant evidence; and obtain advice tailored to the specific issue before taking a legal position.

Official materials and next steps

For the authoritative statutory text, consult the Bangladesh Laws entries for the Information and Communication Technology Act, 2006, the Cyber Security Ordinance, 2025, and the Personal Data Protection Ordinance, 2025. Check the current official text, any amending instrument and any relevant sector guidance before acting.Book consultation or email info@trw.org to discuss an electronic-record, technology-contract, cyber-security or data-governance question.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.
WhatsApp