TRW Knowledge / Technology, data & IP
Bangladesh Information Technology Act: Compliance Guide and Legal Considerations (2026)
This article provides an expanded, practical and legally cautious overview of the Bangladesh Information Technology Act for 2026. It summarises core subject areas frequently encountered by businesses and individuals operating in Bangladesh’s digital environment, explains common compliance steps, and identifies issues that commonly require tailored legal advice. It is a general guide and
TRW Knowledge / Legal guidance
Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Introduction
This article provides an expanded, practical and legally cautious overview of the Bangladesh Information Technology Act for 2026. It summarises core subject areas frequently encountered by businesses and individuals operating in Bangladesh’s digital environment, explains common compliance steps, and identifies issues that commonly require tailored legal advice. It is a general guide and not a substitute for case-specific legal counsel.Scope and purpose of this guide
The guide focuses on the Act as it applies to electronic transactions, cybersecurity, data handling and intellectual property in digital contexts. It aims to help readers understand the Act’s typical applications and to identify areas where organisational policies or contracts may need attention. It does not offer a legal opinion about any particular fact pattern. Where precision is required about statutory language, regulatory instruments or recent government instruments, readers should consult the text of the Act, relevant regulations and an appropriately qualified adviser.Context and historical note
The Bangladesh Information Technology Act and related measures were introduced to provide a legal framework for electronic commerce, cybersecurity and related digital activities. The Act’s original enactment and subsequent regulatory developments reflect an ongoing attempt to align law with technological change. For matters of statutory interpretation and up-to-date legislative history, consult the official gazette and the relevant regulatory body; for technical guidance on implementation, consult recognised government technical bodies such as the Bangladesh Computer Council at https://www.bcc.gov.bd/.Core legal areas addressed by the Act
The Act and its ancillary instruments typically cover the following subject areas. The scope of each item can vary with amendments and implementing regulations.Electronic transactions and signatures
Many provisions provide legal recognition for electronic records and electronic signatures, subject to rules about reliability, authenticity and admissibility. Organisations should assess what classes of electronic evidence they rely on (contracts, logs, records) and whether the forms of electronic signature used will satisfy evidentiary and contractual requirements in anticipated disputes.Cybercrime and enforcement
Provisions commonly define a range of cyber-enabled offences (for example, unauthorised access, data interference, misuse of credentials) and set out investigative and enforcement mechanisms. Criminal definitions and procedures tend to be specific; potential liability can implicate both corporate entities and individuals. Because penalties and procedural rules may change over time, consult the statute and prosecutors’ guidance in relation to specific conduct.Data protection and privacy
The Act refers to responsibilities for collection, storage and processing of personal data and often requires reasonable security measures. The degree of regulatory prescription and the rights afforded to data subjects vary between jurisdictions and over time. Entities that process personal data should map data flows, identify legal bases for processing, implement security measures proportionate to risk and document those measures. Where a comprehensive data protection law or supplementary regulations apply, compliance requires reviewing the full set of statutory and regulatory instruments.Intellectual property in digital environments
Protections for copyright, trademarks and other intellectual property rights continue to apply to digital content. The Act or accompanying rules may include procedures for takedown requests, liability of intermediaries and remedial mechanisms. Rights-holders and service providers should consider contractual allocations of risk and notice-and-takedown procedures to manage infringement claims while respecting due process and applicable law.Regulatory and supervisory arrangements
The statute may identify or permit the creation of regulatory authorities or designate existing bodies to oversee compliance, issue licences and investigate offences. When a regulatory authority is empowered to produce subordinate rules, those rules can materially affect operational compliance: licence conditions, reporting obligations and technical standards can be introduced through delegated instruments. Confirm the current regulator and any applicable delegated instruments before relying on a particular regulatory interpretation.Who is affected
The Act typically applies to natural and legal persons who create, store, process, transmit or host electronic information within the jurisdictional scope of Bangladesh, as well as to operators of ICT systems and intermediaries. Cross-border activities can raise additional compliance requirements — for example, data export restrictions, cross-border investigative assistance or obligations on service providers with a significant local presence. Assessments of applicability should consider the nature of services, user base, and contractual terms with counterparties.Key terms that frequently require operational definition
Organisations should clarify the following terms in policy documents and contracts:- "Electronic signature" — the technical types accepted and the thresholds for reliability.
- "Personal data" or "sensitive personal data" — what categories are included and whether special protections apply.
- "Intermediary" — which service providers qualify and what immunities or duties apply.
- "Unauthorized access" — the factual elements that constitute the offence.
- "Critical information infrastructure" — if the statute or regulations define systems that attract enhanced protection.
Step-by-step practical compliance approach
The following is a structured, practical approach to assessing and improving compliance. It is descriptive rather than prescriptive and should be adapted to the size and risk profile of your organisation.1. Legal and operational mapping
Identify legal instruments that may apply: the Act itself, subordinate regulations, sectoral licences and any data protection law or guidelines. Map organisational technology, data flows and contractual relationships (including cloud and cross-border suppliers). This mapping should include what data is collected, where it is stored, who has access, and contractual terms governing third-party processors.2. Risk assessment
Conduct a risk assessment that links legal risks (criminal liability, regulatory fines, contractual exposure) to technical and organisational vulnerabilities (weak access controls, inadequate logging, lack of incident response). Prioritise risks where the legal and operational consequences overlap, such as risks of data breach affecting regulated personal data.3. Security and controls
Design and implement technical and organisational measures to address identified risks. Typical measures include access controls, encryption in transit and at rest, multi-factor authentication for privileged access, secure development practices and regular patching. Maintain written policies and evidence of implementation; many regulatory regimes expect not only technical measures but also records demonstrating active compliance efforts.4. Contractual safeguards
Review contracts with vendors, cloud providers and customers to allocate responsibilities for security, incident notification, data returns and liability. Where third-party processors handle personal data, ensure contracts include documented instructions, confidentiality obligations and appropriate technical and organisational safeguards. Avoid relying on informal assurances when the law requires contractual commitments.5. Governance, training and awareness
Appoint responsible persons for IT governance and data protection tasks. Provide role-specific training for IT, security, legal and operations teams, and general awareness training for staff who handle personal data or sensitive systems. Document training content and attendance to evidence ongoing governance efforts.6. Documentation and record-keeping
Maintain clear records of policies, data inventories, security assessments, penetration test results and incident response plans. If lawful audits or investigations occur, documented processes will be crucial to demonstrate compliance steps and mitigation efforts. Retention policies should align with statutory retention periods and business needs.7. Incident response and notification
Develop an incident response plan that describes detection, containment, investigation, notification and remediation. Identify legal thresholds for notification to regulators, affected individuals and contractual counterparties. Tailor the plan to reflect the organisation's reliance on external forensic experts and legal advisers.8. Periodic review and adaptation
Regulatory environments and technology change. Schedule periodic reviews of compliance posture, incorporate lessons from incidents, and adapt governance when new regulations or authoritative guidance are issued. Consider independent audits where appropriate to provide objective assurance.Practical examples of common compliance issues
- Failure to maintain adequate logs and audit trails, which can impede investigations and undermine assertions about the provenance of electronic records.
- Undertaking cross-border transfers without reviewing the legal basis and contractual protections for data exports.
- Using weak authentication for privileged accounts, increasing the risk of unauthorised access.
- Relying on oral assurances from third-party suppliers rather than documented contractual warranties for data handling practices.
Cross-border and international considerations
Where processing activities cross borders, consider export rules, mutual legal assistance frameworks, and whether foreign law compels disclosure of local data when hosted abroad. Commercial contracts should address jurisdictional questions, data localisation concerns and the law that governs dispute resolution. The interplay between domestic enforcement and international mutual assistance can be complex; for cross-border operations, obtain tailored advice.Regulatory enforcement and investigatory process
Authorities empowered to investigate computer-related offences may use search, seizure and other investigatory powers. Compliance steps such as documented policies, rapid notification mechanisms and preserved evidence can affect the course and outcome of investigations. If a matter attracts enforcement attention, organisations should consider preserving evidence and seeking legal advice promptly to manage privilege, disclosure and procedural protections.2026 update
This section summarises trends and developments relevant in 2026. It is an explanatory update rather than an exhaustive or definitive statement about legislative change. Where the underlying record does not confirm a specific amendment, this section frames developments as proposed, emerging or under consideration and directs readers to the official sources listed below for verification.Proposed enhancements to cybersecurity rules
Policymakers internationally, and in Bangladesh, have signalled heightened attention to cybersecurity resilience. Proposed measures commonly include higher standards for critical infrastructure, clearer incident notification timelines and enhanced powers for regulators to set technical standards. Organisations should monitor official notices and review technical standards issued by relevant authorities before making compliance decisions.Consideration of AI and emerging technologies
As artificial intelligence systems are deployed in services and decision-making, regulators are exploring how existing legal frameworks address accountability, transparency and privacy risks. Where automated decision-making affects individuals, organisations should document design choices, data inputs, testing procedures and potential impact assessments. Where specific regulatory guidance on AI exists, treat it as an important compliance input.Enforcement trends and penalties
Enforcement emphasis globally has shifted toward imposing accountability on both technical and governance failures. Entities should be prepared for increased scrutiny of governance frameworks, data protection practices and vendor management. Precise penalties depend on statutory text and case law; consult official guidance or legal counsel for case-specific risk evaluation.Where to monitor official developments
Monitor the official websites of relevant Bangladeshi authorities and the official gazette for proposed or enacted regulations. For technical standards and implementation guidance, bodies such as the Bangladesh Computer Council publish material that may assist technical compliance. For regulatory actions or enforcement notices, consult the relevant regulator’s publications. This article does not substitute for checking official sources in real time.Practical compliance checklist (high level)
- Map data flows and classify personal/sensitive data.
- Review and update contracts with processors and cloud providers.
- Implement or verify multi-factor authentication and privileged access controls.
- Document incident response and ensure notification thresholds are clear.
- Maintain records of security assessments and training activities.
- Assess the need for data localisation or specific licences for regulated services.
Common mistakes and how to avoid them
Common recurring errors include relying on undocumented practices, failing to update policies to reflect system changes, inadequate employee training, and neglecting to conduct contractual reviews for third-party processors. Avoid these by creating a repeatable compliance program with ownership, timelines and regular review cycles.When to seek tailored legal advice
Seek context-specific legal counsel when:- There is uncertainty about the applicability of offences or regulatory requirements to particular operations.
- An incident may attract criminal investigation or significant regulatory attention.
- Contracts with processors or customers involve complex cross-border data flows.
- You need to design compliance programmes that will be scrutinised in litigation, regulatory review or transactional due diligence.
Practical interactions with other TRW services
For organisations seeking transactional, regulatory or dispute-related support, consider linking compliance workstreams with broader legal services. Examples of related practice areas at TRW are provided for reference and may be helpful when seeking integrated advice: our practices, services, corporate and commercial teams and dispute resolution specialists such as those listed on leading arbitration lawyer. For firm-level or contact details see our firm and contact.Documentation examples and model records
Maintain clear documentation of the following as part of a defensible compliance posture:- Data inventory and processing records.
- Security assessment reports, pen-test summaries and remediation logs.
- Incident response logs, root-cause analysis and communications to stakeholders.
- Training materials and attendance records.
- Contracts with processors, including technical and organisational safeguards.
Practical note on evidence preservation
Where an incident has occurred or is suspected, organisations should preserve relevant logs, backups and custody chains while seeking legal advice. Avoid making public statements that could prejudice regulatory or criminal processes without counsel; tailored advice assists in balancing legal obligations with operational disclosure needs.Five practical FAQs
The five questions and answers below address common procedural concerns. They are general explanations and do not replace personalised legal advice.Q: What is the main purpose of the Bangladesh Information Technology Act?
A: The Act is intended to provide a statutory framework for recognising electronic transactions, addressing cyber-enabled offences and setting out obligations related to digital information; its application to a particular situation depends on the statute’s language and any implementing regulations, so seek specific advice if you need an authoritative determination.Q: How does the Act protect personal data?
A: The Act contains provisions that impose responsibilities on data handlers to implement appropriate security measures for personal data; the exact scope and required safeguards may be influenced by regulations and sector-specific rules, so organisations should map processing activities and consult guidance to confirm applicable measures.Q: What are the penalties for cybercrimes under the Act?
A: The Act sets out offences and penalties that can include fines or imprisonment depending on the nature and severity of the conduct; because penalties and enforcement approaches may change, review the current statutory text and obtain legal advice when assessing risk in a specific matter.Q: How can businesses ensure compliance with the Act?
A: Businesses can improve compliance by conducting legal and technical audits, implementing proportionate security measures, training staff, documenting processing activities, and updating contracts with service providers; consult legal and technical advisers to tailor measures to your organisation’s risk profile.Q: What recent changes have been proposed to the Act?
A: Proposals discussed in public fora include strengthening cybersecurity provisions, addressing emerging technologies such as AI, and reviewing penalties for cyber offences; because proposals may be revised or not adopted, verify the current legislative position with the official gazette or a qualified adviser before acting on any presumed change.Resources and official sources
For authoritative texts and updates, consult the official gazette and the websites of relevant regulatory and technical bodies. The Bangladesh Computer Council may publish technical guidance relevant to implementation: https://www.bcc.gov.bd/. For regulatory notices and sectoral licences, consult the webpages of the applicable regulator. This article does not substitute for checking those sources in real time.Conclusion and next steps
The Bangladesh Information Technology Act establishes a legal framework that interfaces with technical, contractual and governance questions faced by organisations in the digital economy. Use the steps and checklist above to assess where targeted improvements are needed and obtain tailored legal and technical advice for matters that raise enforcement, litigation or complex cross-border issues.To discuss how these considerations apply to your organisation, contact our team via https://trw.org/contact/ or review our practice areas at https://trw.org/our-practices/ and services at https://trw.org/services/. For enquiries about arbitration or cross-border dispute resolution, see https://trw.org/leading-arbitration-lawyer/. For firm information, visit https://trw.org/our-firm/.Book consultation or email info@trw.org to arrange a discussion about your specific situation.Bring the facts.
We bring direction.
For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.