TRW Knowledge / Technology, data & IP
Legal Framework for E‑Commerce in Bangladesh: 2026 Practical Overview and Compliance Guide
This article provides a practical, legally cautious overview of the laws and regulatory guidance commonly relevant to commercial online activity in Bangladesh in 2026. It is written to help entrepreneurs, in‑house counsel, compliance officers and advisers identify the principal statutes, common regulatory touchpoints and typical operational compliance steps. This text is explanatory and

2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Introduction
This article provides a practical, legally cautious overview of the laws and regulatory guidance commonly relevant to commercial online activity in Bangladesh in 2026. It is written to help entrepreneurs, in‑house counsel, compliance officers and advisers identify the principal statutes, common regulatory touchpoints and typical operational compliance steps. This text is explanatory and does not constitute legal advice; readers should obtain context‑specific legal advice before relying on it.Scope and purpose of this overview
The e‑commerce sector brings together aspects of contract law, consumer protection, payments regulation, and cybersecurity. This overview summarises the principal statutory instruments and regulatory guidance frequently relied upon in practice, outlines practical steps for market entrants and operational teams, and highlights typical compliance pitfalls. Where relevant, links are provided to official sources and to practice pages for additional advisory services.Primary laws and regulatory instruments
The regulatory environment for online commerce in Bangladesh is multi‑layered. The legislation most commonly cited in commercial and compliance work includes:- Electronic Transactions Act, 2001 (ETA 2001) — legal recognition of electronic records, electronic signatures and rules for electronic contracts.
- Digital Security Act, 2018 (DSA 2018) — provisions addressing computer‑related offences, data compromise and certain online conduct; this statute has been applied in a range of contexts affecting online platforms.
- Consumer Rights Protection Act, 2009 (CRPA 2009) — consumer protection obligations that can apply to sellers operating through electronic marketplaces, including prohibitions on unfair trade practices.
- Guidelines and circulars issued by Bangladesh Bank relevant to electronic payments and payment service providers.
- Sectoral regulations and licensing requirements where specific goods or services are sold online (for example, health products, financial services or telecommunications).
- Administrative procedures and decisions issued by agencies exercising enforcement functions in the cyber and consumer protection space.
Key legal concepts relevant to online commerce
Electronic contracts and signatures
The ETA 2001 establishes that electronic records and electronic signatures may be recognised in legal transactions, subject to statutory qualifications and any required formalities under other laws. Practically, businesses should consider clear terms on how contracts are formed online (clickwrap, browsewrap, order confirmations) and whether any particular transaction requires a physical signature or statutory registration under a different law.Data, privacy and cybersecurity
Data protection in Bangladesh is currently shaped by a combination of sectoral rules, the DSA 2018 and applicable contract/privacy practices. The DSA 2018 contains provisions that criminalise certain unauthorised access or misuse of digital systems and data. Entities handling personal data should adopt reasonable security measures, maintain documented policies on data handling and consider contractual protections with service providers. For cross‑border data flows, compliance with applicable contractual and regulatory controls should be verified.Consumer protection and unfair trade practices
The CRPA 2009 sets out consumer rights and protections against misleading or unfair trade practices. For online sellers this commonly translates into obligations to display accurate product information, clearly disclose prices and charges (including delivery and return costs), and honour statutory remedies such as returns and refunds where applicable. Platform operators may also have intermediary considerations depending on their role (marketplace vs. reseller).Payments and electronic money
Banking and payments regulation plays a central role for e‑commerce. Bangladesh Bank has issued operational guidelines for electronic payments and for digital financial service providers; these instruments address aspects such as customer authentication, transaction monitoring and anti‑money laundering measures. Businesses that integrate payment gateways or act as payment service providers need to consider licensing, compliance reporting and contractual requirements with banks and payment processors.Practical compliance checklist for e‑commerce operators
The following checklist summarises common compliance steps that are typically relevant to commercial online operations. This list is illustrative and should be adapted to the facts of each business.- Entity registration and licensing: confirm that the business is lawfully registered in the appropriate jurisdiction and that any sectoral licences required for the goods or services offered are in place.
- Commercial and consumer terms: prepare clear terms of service, website terms, sales contracts, and a privacy policy that address service scope, delivery, cancellations, refunds and applicable law and jurisdiction.
- Data governance: maintain a data inventory, adopt reasonable technical and organisational measures for data security, and document retention and deletion policies.
- Payments compliance: verify that payment arrangements comply with Bangladesh Bank guidance, contractual obligations to payment service providers, and applicable AML/KYC requirements.
- Cybersecurity and incident response: implement access controls, encryption where appropriate, vulnerability management and a written incident response plan that identifies escalation paths and notification obligations.
- Consumer dispute handling: establish accessible dispute and refund processes and keep records of consumer complaints and resolutions.
- Third‑party contracts: ensure supplier and service provider agreements (hosting, logistics, payment gateways) allocate responsibility for security, data protection and continuity.
Operational considerations and common pitfalls
Operators often face recurring compliance issues. Typical examples include:- Lack of clear terms and inadequate consumer disclosures, which can create downstream disputes.
- Insufficient data security controls for customer personal data, increasing the risk of breaches and regulatory scrutiny.
- Failure to align payment flows with banking guidance, which can cause operational disruption or additional compliance burdens.
- Inadequate contractual protections with logistics and technology vendors, leaving platform operators exposed to liability for third‑party failures.
Practical steps to prepare for regulatory interactions
If a business anticipates an interaction with a regulator, typical preparatory steps include:- Assemble a legal and compliance file summarising applicable licences, policies, contracts and recent incident reports.
- Prepare a factual chronology of any relevant events and a summary of remedial steps taken.
- Designate a single point of contact for regulator communications and maintain a record of all correspondence.
- Suspend or remediate services if required to prevent further harm, in consultation with counsel.
2026 update
By mid‑2026 the commercial and regulatory environment remains subject to active discussion. Stakeholders continue to examine clarity on data protection and privacy frameworks, the scope of intermediary liability for platforms, and finer points of electronic evidence admissibility. In 2024 and thereafter, the government announced measures and public consultations aimed at strengthening consumer protections for online transactions; these initiatives may influence future regulatory or legislative changes.Because proposals, consultations and rule‑making can evolve, businesses should consult primary sources for the latest status. Official sources to consult include regulators such as Bangladesh Bank (for payments guidance) at https://www.bb.org.bd/, and formal notices published in the government gazette. For interpretation and application to specific facts, seek tailored legal advice.Regulatory authorities and official resources
Relevant authorities and resources that businesses commonly consult include:- Bangladesh Bank (for payments and digital financial service guidance) — https://www.bb.org.bd/.
- Sectoral ministries or departments for regulated products (for example pharmaceuticals, food safety, or financial services).
- The administrative offices or departments that receive consumer complaints under the Consumer Rights Protection Act.
Drafting and contractual best practices
Contract drafting for e‑commerce operations should address:- Formation of contract: how orders are accepted, the point at which a binding contract arises, and confirmation mechanisms.
- Allocation of risk for delivery, returns, refunds and defective goods.
- Data processing and security obligations between controllers and processors.
- Indemnities and limitation of liability that reflect applicable mandatory consumer protections (note that certain consumer rights cannot be waived by contract).
- Dispute resolution mechanisms and applicable law; consider operational implications of chosen forums for cross‑border transactions.
Enforcement trends and litigation considerations
Enforcement can take multiple forms: administrative action, criminal prosecution under cyber or digital security statutes, civil claims by consumers or commercial counterparties, and regulatory sanctions. When assessing enforcement risk, consider the following:- Nature of the alleged conduct (for example, deceptive advertising vs. data breach).
- Whether statutory offences under the DSA 2018 or other laws are implicated.
- Potential cross‑border considerations where data or services involve foreign jurisdictions.
Practical examples (illustrative, non‑exhaustive)
Example A: An online retailer expanding into Bangladesh should check whether product categories require registration or pre‑approval, ensure tax registration is in place, implement clear return policies and integrate a payments solution that complies with Bangladesh Bank guidance.Example B: A technology platform hosting third‑party sellers should identify whether it acts as a marketplace intermediary or as a principal seller, and allocate contractual responsibilities accordingly for product safety, consumer refunds and dispute handling.These examples are illustrative only; the appropriate measures depend on the exact business model and commercial arrangements.Data breach preparedness
Preparations for a possible data breach include maintaining an incident response plan, identifying internal and external notification obligations (including to customers and, where applicable, regulators), and documenting remediation steps. Because notification obligations and procedures can vary by sector and the nature of the personal data involved, consult counsel to determine specific obligations.Engaging advisers and when to seek tailored advice
Given the complexity and fact‑sensitive nature of regulatory obligations, businesses should consider seeking specialist legal and compliance advice in the following circumstances:- Before launching a new payments integration or acting as a payment service provider.
- When handling sensitive personal data or large volumes of customer data.
- After receiving a regulatory notice, administrative summons or criminal complaint related to online activity.
- When entering contracts that allocate complex cross‑border risk (data transfers, platform liability, intellectual property).
Step‑by‑step compliance programme checklist
- Map the business model and identify all applicable legal regimes (contract law, consumer law, payments, product regulation, data/security).
- Document all data flows and third‑party service providers (hosting, payment gateways, logistics).
- Draft or update customer‑facing documents (terms, privacy policy, returns policy) and ensure visibility on the site and at point of sale.
- Establish operational controls: KYC for sellers or users where required, transaction monitoring, and incident response capabilities.
- Train staff on consumer complaint handling and data protection basics, and maintain records of complaints and remediation measures.
- Undertake periodic legal and security audits and update policies to reflect legal or regulatory changes.
Five practical frequently asked questions
Q: What is the Electronic Transactions Act 2001?
A: The Electronic Transactions Act 2001 establishes legal recognition for electronic records and electronic signatures in Bangladesh and sets out conceptual rules for electronic contracts; whether an electronic method is sufficient in a particular case depends on the statutory requirements applicable to the transaction and should be confirmed with legal advice.Q: How does the Consumer Rights Protection Act 2009 affect e‑commerce businesses?
A: The Consumer Rights Protection Act 2009 imposes statutory consumer protections that apply to sellers, including requirements to avoid unfair trade practices and to provide certain remedies; businesses should ensure product descriptions, pricing and returns policies are consistent with consumer protection obligations and obtain advice on sector‑specific rules.Q: What are the penalties for non‑compliance with e‑commerce regulations?
A: Penalties depend on the law and the facts and can include administrative sanctions, fines, civil liability to consumers, and, in some cases, criminal penalties; the appropriate response should be guided by counsel and may involve remediation and engagement with the relevant authority.Q: Is cybersecurity important for e‑commerce businesses?
A: Yes; implementing reasonable cybersecurity measures helps protect customer data and reduce operational risk. The adequacy of measures is fact‑dependent and should be assessed against contemporary industry practices and any applicable regulatory guidance.Q: How can I ensure my e‑commerce business is compliant with current laws?
A: Regular legal review, monitoring of regulatory updates, documented policies and, where appropriate, consultation with qualified legal advisers are the practical steps to maintain compliance; bespoke legal advice is recommended for specific transactions or complex compliance issues.Additional resources and internal advisory pages
Further information on related practice areas and services can be found on TRW pages that discuss firm services and specialist teams, including: https://trw.org/our-practices/, https://trw.org/services/, https://trw.org/our-firm/, and compliance‑related pages such as https://trw.org/financial-services-regulatory-lawyers/. For contact and engagement, see https://trw.org/contact/.Concluding observations
The legal framework that governs e‑commerce in Bangladesh touches multiple areas of law. Businesses should adopt a cautious, documented approach, combining clear consumer‑facing terms, reasonable data security measures, compliant payment arrangements and contractual risk allocation with suppliers and platforms. Because legal obligations and enforcement priorities can be fact‑specific and may evolve, obtain tailored legal advice before taking action on material compliance matters.Call to action: For case‑specific assistance, Book consultation or email info@trw.org.Bring the facts.
We bring direction.
For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.