TRW Knowledge / Cybersecurity, digital evidence & response
Cybercrime in Bangladesh: Reporting, Evidence and the 2026 Legal Framework
This guide provides general, source-grounded information on cybercrime reporting, digital evidence and the legal instruments that may be relevant in Bangladesh. It does not describe a single “Cyber Crime Act Bangladesh” or treat earlier legislation as automatically current. The appropriate legal route depends on the facts, the official text in force, the institution involved and any rela
TRW Knowledge / Legal guidance
Cybercrime reporting, electronic evidence and incident response / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Introduction
This guide provides general, source-grounded information on cybercrime reporting, digital evidence and the legal instruments that may be relevant in Bangladesh. It does not describe a single “Cyber Crime Act Bangladesh” or treat earlier legislation as automatically current. The appropriate legal route depends on the facts, the official text in force, the institution involved and any related contractual or regulatory obligation.The historical URL and original publication date are retained for continuity. This discussion is reviewed for 2026 to distinguish electronic-record law, cyber-security legislation and personal-data protection. It is not legal advice for a particular incident.Scope and purpose of this guide
The digital environment continues to evolve rapidly. This guide summarises the main statutory instruments commonly relied on in cybercrime matters in Bangladesh, describes typical categories of alleged wrongdoing, and sets out practical steps that victims and organisations commonly follow. The guide also identifies procedural and evidential issues that regularly arise in investigations and litigation. Where matters are time-sensitive or fact-specific, this guide directs readers to relevant authorities and to qualified advisers.Current legal context: keep the instruments distinct
The official Bangladesh Laws database lists separate instruments that may matter to a digital incident. The Information and Communication Technology Act, 2006 addresses legal recognition and security for information and communication technology, including electronic records and electronic signatures. It is not a catch-all statute for every cyber incident.The official database separately records the Cyber Security Act, 2023, whose preamble states that it repealed the Digital Security Act, 2018. The official entry for the Cyber Security Ordinance, 2025 states that it repeals the Cyber Security Act, 2023. That sequence is material: legacy labels should not be presented as a simple current answer without checking the primary source and any applicable rule.Where personal data is implicated, the official database also lists the Personal Data Protection Ordinance, 2025. Its official purpose includes protecting personal data and lawful processing with consent. The exact obligations and processes applicable to a matter must be verified from operative materials and the facts.Common categories of alleged cyber offences
The following categories are frequently encountered in complaints and investigations in Bangladesh. These labels are descriptive and are used here for clarity; actual charges or causes of action will depend on the statutory provisions invoked by authorities or by civil claimants.- Unauthorized access (hacking): Access to computer systems, networks or devices without lawful authorisation or exceeding authorised access.
- Data theft and unauthorised disclosure: Exfiltration, copying or sharing of personal, commercial or sensitive data without consent or lawful basis.
- Online harassment and cyberbullying: Use of digital platforms to harass, threaten or intimidate an individual.
- Online defamation: Publication of false statements online alleged to harm a person's reputation.
- Sexual exploitation of minors and illegal content: Distribution, possession or facilitation of child sexual exploitation material and other proscribed content.
Enforcement agencies and official reporting routes
Alleged cyber offences in Bangladesh may be investigated by local police units, specialist cyber units and other government authorities depending on the matter. Where a criminal offence is alleged, police remain the primary investigating agency in many cases. For information about official reporting routes and online complaint facilities, readers can consult the relevant law enforcement pages; for example, some reporting information is available from the Bangladesh Police cybercrime pages (see Bangladesh Police: Cyber Crime).Because authorities’ procedures and contact points can change, complainants should verify current reporting channels on official government websites or by contacting the relevant police station or cybercrime cell directly before filing a formal complaint.Practical step-by-step process for individuals and organisations
The following steps set out common actions taken by those who believe they have been affected by a cyber incident. These steps are descriptive of practice and not prescriptive legal requirements; specific circumstances may require different procedures.- Preserve and document evidence: As soon as it is safe to do so, preserve copies or records of relevant material: screenshots, emails, chat logs, system logs, timestamps, IP information where available, device identifiers and any other contextual records. Maintain an evidence log describing when and how each item was obtained. Avoid altering or deleting original sources where possible.
- Isolate affected systems: Where a live compromise is suspected, consider isolating affected devices or accounts to limit further loss. Where possible, take forensic images of affected systems before rebooting or cleaning them; if you have internal IT capacity or an external forensic service, coordinate this work to preserve chain of custody.
- Report to authorities: If the incident appears to constitute a criminal offence, the usual route is to lodge a formal complaint with the local police or the designated cybercrime unit and to provide the documented evidence. Authorities may issue instructions about evidence preservation and may request further cooperation.
- Consider civil remedies and notifications: In some cases, there may be civil remedies such as injunctive relief, claims for damages, or statutory notice requirements (for example in the context of data protection obligations). Entities that process personal data should consider any notification obligations under applicable law or contractual duties to affected individuals or service providers.
- Engage legal and technical advisers: Seek advice from legal practitioners with relevant experience and qualified technical professionals for incident response and forensic analysis. Advisers can help with reporting strategy, liaison with authorities and preservation of privilege where applicable.
- Follow up and review: Monitor the progress of any investigation and document all communications with authorities, platforms and other parties. Conduct a post-incident review to identify lessons and to strengthen policies, controls and employee training.
Evidence, privilege and data access considerations
Digital evidence presents common practical challenges: logs may be held by third-party service providers, ephemeral messages may be deleted quickly, and cross-border data flows can complicate access. When seeking records from service providers, consider both criminal and civil routes: police requests and letters of request can sometimes obtain evidence from providers, while civil preservation orders or court proceedings may be required to compel disclosure in other cases.Legal privilege may apply to communications with external counsel and to forensic work carried out under legal advice in certain circumstances; whether privilege attaches to particular reports or to communications with technical advisers will depend on the facts and applicable law. Parties should take care to structure incident response communications to preserve privilege where that is intended.Common practical and procedural pitfalls
Practitioners and victims commonly encounter avoidable difficulties. The following list highlights recurring issues:- Delay in reporting: Delays can result in the loss of volatile evidence and can complicate investigation. Prompt preservation of logs and contemporaneous documentation assists investigators and advisers.
- Inadvertent evidence loss: Restarting or using compromised devices without taking forensic images may overwrite evidence. Seek technical guidance before taking forensic steps where possible.
- Public statements: Uncontrolled public statements can affect subsequent civil or criminal proceedings. Consider legal advice before issuing public communications about an incident.
- Lack of coordination between responders: Multiple agencies, service providers and internal teams may be involved. Clear allocation of responsibilities and a single point of contact can reduce confusion.
- Assuming uniform platform processes: Different platforms have different notice-and-takedown, preservation and disclosure procedures. Check provider-specific requirements early in the process.
Interplay with data protection and sectoral compliance
Cyber incidents often raise parallel compliance issues under data protection, financial regulation and sector-specific rules. Organisations should consider whether statutory or contractual notification obligations arise, and whether regulatory authorities in a particular sector should be informed. Where personal data is involved, preservation of a clear record of the incident, decisions about notifications and the legal basis for any disclosure are central to sound compliance practice.Criminal penalties, civil remedies and standards of proof
Potential criminal sanctions, administrative penalties or civil remedies depend on the statutory provision at issue and the facts established by evidence. Criminal prosecutions require proof beyond a reasonable doubt of the elements of the alleged offence; civil claims require a lower standard of proof. It is important to recognise that the availability and scope of remedies is legally determined and fact-sensitive; parties should seek specific legal advice about potential sanctions and remedies in their circumstances.2026 update
The legal description in this article has been corrected for accuracy. The official Bangladesh Laws database lists the Cyber Security Ordinance, 2025 as repealing the Cyber Security Act, 2023. The 2023 Act’s official preamble refers to repeal of the Digital Security Act, 2018. These instruments are distinct from the Information and Communication Technology Act, 2006 and the Personal Data Protection Ordinance, 2025.An organisation or individual should not rely on a historical label alone when deciding whether to report, preserve evidence, notify an affected party, approach a platform or respond to an authority. Check the current official text, any sector-specific requirement and the case-specific facts before taking a legal position.Cooperation with international authorities and cross-border evidence
Many cyber incidents have cross-border elements: data stored overseas, service providers based in other jurisdictions, or actors located abroad. Mutual legal assistance processes, international police cooperation and bilateral arrangements may be needed to obtain evidence. The timeframes and requirements for cross-border evidence requests vary; parties should factor international procedural timelines into their investigation plans and seek assistance from advisers experienced in cross-border digital evidence matters.Working with online platforms and intermediaries
When content is hosted by a social media platform, cloud provider or another intermediary, platforms commonly offer notice-and-takedown procedures and forms for reporting abuse, illegal content or account compromises. Preservation requests or emergency disclosures may be available in some cases. Document the platform’s response and retain copies of correspondence. For matters requiring urgent preservation of evidence, coordinated requests from counsel or law enforcement can be more effective than informal requests from private individuals.Role of in-house teams and external advisers
Organisations should have incident response plans that set out contact points, evidence-preservation steps and criteria for engaging external counsel and forensic experts. External legal advisers can assist with scoping legal risks, communicating with authorities and seeking privileged forensic work where appropriate. For sensitive incidents, involving advisers early can help preserve legal options.Practical checklist for immediate action
Immediate practical steps to consider following discovery of a cyber incident:- Preserve evidence (screenshots, logs, backups) and create an evidence log;
- Isolate affected systems to prevent further spread, while preserving images where practical;
- Record and secure relevant accounts and credentials;
- Document the sequence of events and persons involved in the response;
- Consider whether police or regulator reporting is required and, if so, prepare the complaint with supporting evidence;
- Engage specialist forensic and legal advisers as necessary;
- Plan communications internally and externally, and seek legal input before public statements.
When to seek tailored legal advice
Legal advice should generally be sought when any of the following apply:- Potential criminal conduct is involved or there is an ongoing threat;
- Significant amounts of personal or commercial data have been exposed;
- There is a regulatory or contractual notification obligation;
- Third-party service providers or cross-border data issues complicate access to evidence;
- There is a risk of civil claims or criminal charges against the organisation or individuals.
Resources and contact points
Official government and law enforcement websites provide current guidance and reporting channels; for example, law enforcement cybercrime pages may list local reporting procedures and contact details. Where legal or technical assistance is required, organisations commonly engage specialised advisers and forensic firms. For organisational information about corporate structure, practice areas and how to contact advisers, consult relevant pages on TRW’s site, such as Our Firm, Our Practices, Services, and the contact page at Contact. For inquiries that touch on financial and regulatory issues, related practice pages include Financial Services Regulatory and for dispute resolution matters see Arbitration.Case handling: coordination and documentation
Effective coordination among legal counsel, forensic teams, communications advisers and senior management reduces risk. Keep a central repository of all incident-related materials and maintain an incident log that records decisions, timelines and communications with third parties and authorities. Well-documented files support regulatory responses and potential litigation.Five practical FAQs
Is there one current Cyber Crime Act in Bangladesh?
The official Bangladesh Laws database lists distinct instruments. The Cyber Security Ordinance, 2025 states that it repeals the Cyber Security Act, 2023; the 2023 Act’s preamble refers to repeal of the Digital Security Act, 2018. Electronic records and signatures are addressed separately in the Information and Communication Technology Act, 2006. The applicable provision depends on the facts and official text in force.What should I do first after a suspected cyber incident?
Preserve available evidence, document a timeline, protect affected accounts or systems where safe to do so, and avoid altering original material. Reporting and notification steps depend on the incident, current official requirements, contractual commitments and any relevant regulator.Where can a suspected cybercrime be reported?
Reporting options can depend on the incident and relevant authority. Bangladesh Police publishes cybercrime information, but official channels and contact details can change. Verify the current channel directly with the relevant government authority or police station before filing a formal complaint.Does a cyber incident always trigger a data-protection notification?
No universal conclusion should be assumed. Where personal data is involved, analyse the Personal Data Protection Ordinance, 2025, any later official instrument, the facts and contractual or sectoral duties. Record the decision-making process and obtain tailored advice where the risk is material.Can civil remedies be relevant as well as criminal processes?
Depending on the facts, a matter may raise contractual, injunctive, damages or other civil questions alongside a criminal report. The availability of a remedy is fact- and law-specific; preserve evidence and seek advice before choosing a route.Official materials and next steps
For authoritative statutory text, consult the Bangladesh Laws entries for the Information and Communication Technology Act, 2006, Cyber Security Ordinance, 2025 and Personal Data Protection Ordinance, 2025. Check later official instruments and relevant authority guidance before acting.Conclusion and next steps
Cyber incidents present a blend of technical, evidential and legal challenges. Prompt evidence preservation, careful coordination with technical and legal advisers, and a clear reporting strategy improve the prospects for a satisfactory outcome. Because outcomes depend on statutory interpretation and factual development, parties should consult qualified advisers to determine appropriate steps in their specific circumstances.If you require assistance or wish to discuss a particular matter, you may first review organisational information at https://trw.org/our-firm/ and our practice descriptions at https://trw.org/our-practices/. For direct enquiries, please use https://trw.org/services/ or our contact page: https://trw.org/contact/.Book a meeting using the following link: Book consultation or contact us by email at info@trw.org.Bring the facts.
We bring direction.
For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.