TRW Law Firm·Dhaka · London · Dubai · Singapore

Practice Areas

Litigation & Disputes

Explore this practice
People

Experience when it matters most.

Meet the lawyers and professionals behind TRW’s advice, advocacy and commercial judgement.

Insights

Perspective for the decisions ahead.

Follow legal developments, market change and TRW announcements.

The Firm

TRW Law Firm.
Clear in purpose.

TRW Law Firm is a full-service international law firm based in Dhaka.

TRW KNOWLEDGE · LEGAL INFORMATION

Compliance With Cyber Law Bangladesh

Navigate the complex landscape of cyber law in Bangladesh with our 2026 guide. Learn about the ICT Act, Cyber Security Act, and essential compliance steps for businesses.
Originally published 29 July 2026
2026 updateThis article retains its original publication date. Its structure, internal navigation and general information have been refreshed for 2026; current primary sources and advice should be checked before acting on any specific matter.

Introduction: The Digital Frontier and Legal Responsibility

As Bangladesh undergoes a rapid digital transformation under the "Smart Bangladesh 2041" vision, the intersection of technology and law has become a focal point for businesses and individuals alike. The proliferation of digital services, from mobile financial systems to complex e-commerce platforms, has necessitated a robust legal framework to ensure security, privacy, and trust. Compliance with cyber law in Bangladesh is no longer an optional consideration for enterprises; it is a fundamental requirement for operational legitimacy and risk management.In this comprehensive guide, we explore the intricate landscape of cyber regulations in Bangladesh, providing a detailed roadmap for organizations to navigate the complexities of digital compliance. From the foundational Information and Communication Technology (ICT) Act to the recent shifts in security legislation, understanding these laws is critical for any entity operating in the country's burgeoning digital economy.

The Evolution of Cyber Legislation in Bangladesh

The journey of cyber law in Bangladesh began in earnest with the enactment of the Information and Communication Technology (ICT) Act, 2006. This landmark legislation provided the first comprehensive legal framework for electronic transactions, digital signatures, and the prevention of cybercrimes. Over the years, the Act has been amended to address emerging threats, reflecting the dynamic nature of the digital environment.Following the ICT Act, the government introduced the Digital Security Act (DSA) in 2018, which aimed to enhance national cybersecurity. However, due to various challenges and the need for a more balanced approach between security and freedom of expression, the DSA was recently replaced by the Cyber Security Act (CSA), 2023. This transition marks a significant shift in how cyber offenses are categorized and penalized, emphasizing a more nuanced legal approach to digital safety.
"The evolution of cyber laws in Bangladesh reflects a growing recognition of the digital realm as a critical infrastructure that requires both protection and progressive regulation to foster innovation."

Key Regulatory Authorities and Their Roles

Ensuring compliance requires an understanding of the various government bodies that oversee digital activities in Bangladesh. The Bangladesh Telecommunication Regulatory Commission (BTRC) is the primary regulator for telecommunications and internet services. It issues licenses to Internet Service Providers (ISPs) and monitors online content to ensure adherence to national standards.Additionally, the Digital Security Agency, established under the Ministry of Posts, Telecommunications, and Information Technology, plays a vital role in coordinating cybersecurity efforts across the country. This agency is responsible for managing the National Computer Emergency Response Team (CERT) and providing guidelines for critical information infrastructure (CII) protection.
AuthorityPrimary ResponsibilityKey Functions
BTRCTelecommunications RegulationLicensing, Spectrum Management, Content Monitoring
Digital Security AgencyNational CybersecurityCII Protection, Incident Response, Policy Development
Cyber TribunalJudicial EnforcementTrial of Cybercrimes, Legal Adjudication

Core Provisions of the ICT Act and CSA

The ICT Act, 2006 remains a cornerstone of digital law, particularly regarding the legal recognition of electronic records and digital signatures. Section 6 of the Act establishes that where any law requires information to be in writing or in typewritten form, such requirement is satisfied if the information is rendered or made available in an electronic form and is accessible for subsequent reference.The Cyber Security Act, 2023, on the other hand, focuses heavily on the prevention of cyber-attacks and the protection of digital systems. It outlines various offenses, including unauthorized access to computer systems, digital fraud, and the spreading of harmful content. While the source record indicates that penalties can include imprisonment for up to 14 years and significant fines, it is essential to consult current official gazettes for the most up-to-date information on specific sentencing guidelines and amendments.For businesses, compliance involves adhering to strict standards for data integrity and system security. The law mandates that entities handling sensitive information must implement "reasonable security practices" to prevent unauthorized access or disclosure. Failure to do so can result in both criminal liability and civil suits for damages.

Data Protection and Privacy: The Emerging Landscape

One of the most critical aspects of compliance with cyber law in Bangladesh is data protection. Currently, the legal requirements for data privacy are scattered across various sections of the ICT Act and BTRC guidelines. However, the government is in the process of finalizing a dedicated Data Protection Act (DPA), which is expected to introduce a more centralized and rigorous regime for personal data processing.Key requirements for data protection under the current and proposed frameworks include:
  • Consent: Organizations must obtain explicit consent from individuals before collecting or processing their personal data.
  • Purpose Limitation: Data should only be collected for specified, legitimate purposes and not processed in a manner incompatible with those purposes.
  • Data Security: Implementing technical and organizational measures to protect data against unauthorized access, loss, or destruction.
  • Rights of Data Subjects: Ensuring that individuals have the right to access, correct, and delete their personal information.
Given the evolving nature of data privacy laws, it is highly recommended that businesses proactively align their practices with international standards such as the GDPR, while closely monitoring local legislative updates from the Ministry of Law and Justice.

Compliance Requirements for E-commerce and Fintech

The e-commerce and fintech sectors are subject to additional layers of regulation due to the sensitive nature of financial transactions and consumer data. The National Digital Commerce Policy and the BTRC's regulations for mobile financial services (MFS) set out specific requirements for these industries.Compliance for digital commerce includes ensuring the security of payment gateways, providing clear terms of service, and establishing robust mechanisms for consumer grievance redressal. For fintech companies, adherence to anti-money laundering (AML) and know-your-customer (KYC) regulations is paramount, requiring sophisticated digital verification systems that comply with both cyber and banking laws.

Cybercrimes and Legal Consequences: A Word of Caution

The legal framework in Bangladesh categorizes a wide range of activities as cybercrimes. These include hacking, digital forgery, identity theft, and the publication of offensive or false information. The penalties for these offenses can be severe, often involving both hefty fines and lengthy prison terms.However, it is important to note that the application of these laws can be complex, and judicial interpretations may vary. For cyber and employment topics especially, it is critical to avoid asserting current law, penalties, or filing routes without direct support from the most recent official records. Where uncertainty exists regarding procedural deadlines or administrative contacts, current official materials from the relevant ministries must be checked to ensure accuracy.Legal professionals at TRW Law Firm emphasize that "proactive compliance is the best defense against the significant legal and reputational risks associated with cybercrimes."

Step-by-Step Guide to Achieving Compliance

For organizations looking to strengthen their legal standing in the digital space, the following step-by-step process is recommended:
  1. Conduct a Comprehensive Audit: Evaluate all digital assets, data processing workflows, and security protocols to identify gaps in compliance.
  2. Implement Robust Security Infrastructure: Deploy advanced technical measures such as end-to-end encryption, multi-factor authentication (MFA), and intrusion detection systems.
  3. Develop Internal Policies: Create clear, written policies for data handling, employee use of technology, and incident response.
  4. Training and Awareness: Regularly educate employees on cybersecurity best practices and their legal obligations under the ICT Act and CSA.
  5. Engagement with Legal Counsel: Work with specialized technology lawyers to stay updated on legislative changes and to represent the firm in case of legal disputes.

The Role of the Cyber Tribunal and Specialized Courts

Adjudication of cyber-related disputes in Bangladesh is primarily handled by the Cyber Tribunal, located in Dhaka. This specialized court was established to handle cases arising under the ICT Act and now the CSA. The tribunal is equipped with the technical understanding necessary to evaluate digital evidence, which is often more complex than traditional physical evidence.The legal process in the Cyber Tribunal involves specific rules for the admissibility of electronic records. Under the Evidence Act of Bangladesh (as amended), electronic records are admissible in court, provided they meet certain criteria for integrity and authenticity. Understanding these evidentiary requirements is crucial for both prosecution and defense in cybercrime cases.

International Standards and the Bangladesh Framework

As Bangladesh integrates more deeply into the global economy, the alignment of its cyber laws with international standards has become a priority. Many Bangladeshi companies, particularly those in the IT and outsourcing sectors, must comply with international frameworks like the General Data Protection Regulation (GDPR) of the EU to serve global clients.While the local framework is unique to the country's needs, there is a clear trend toward adopting principles found in international conventions, such as the Budapest Convention on Cybercrime. Businesses that adopt high international standards for cybersecurity and data privacy often find themselves better prepared for local compliance requirements as they evolve.

Challenges in Cyber Law Enforcement

Despite the robust legal framework, several challenges remain in the effective enforcement of cyber laws in Bangladesh. One of the primary issues is the borderless nature of cyberspace, which creates jurisdictional complexities when crimes are committed by actors outside the country. International legal cooperation and mutual legal assistance treaties (MLATs) are essential tools for addressing these cross-border threats.Another challenge is the rapid pace of technological change, which often outstrips the ability of legislation to keep up. Emerging technologies such as Artificial Intelligence (AI), Blockchain, and the Internet of Things (IoT) present new legal questions that the current framework may not fully address. Stakeholders are encouraged to participate in public consultations on new regulations to ensure they are practical and forward-looking.

The Future of Cyber Law: AI and Emerging Technologies

Looking ahead, the legal landscape in Bangladesh is set to expand into new areas of technology regulation. The government has already begun drafting guidelines for the ethical use of AI and is exploring the legal implications of blockchain technology in the financial sector. These developments will likely lead to new compliance requirements for tech-driven startups and established enterprises alike.Organizations should stay informed about these trends and consider the legal implications of adopting new technologies early in their development cycle. "Legal by design" is a concept that is gaining traction, where compliance and security are integrated into the very architecture of new digital products and services.

How TRW Law Firm Can Assist in Your Compliance Journey

Navigating the complexities of compliance with cyber law in Bangladesh requires specialized legal expertise. At Tahmidur Rahman Remura Wahid (TRW) Law Firm, our technology and cyber law practice group is dedicated to helping clients protect their digital interests and ensure full legal compliance.Our services include:
  • Regulatory Compliance Audits: Comprehensive reviews of your digital operations to ensure adherence to the ICT Act, CSA, and BTRC guidelines.
  • Policy Drafting: Creating customized data protection, privacy, and cybersecurity policies for your organization.
  • Litigation and Dispute Resolution: Representing clients in the Cyber Tribunal and other judicial forums for cyber-related cases.
  • Advisory on Emerging Tech: Providing legal guidance on the implementation of AI, blockchain, and other advanced technologies.
We are committed to providing our clients with the clarity and defense they need in an increasingly complex digital world. For more information about our firm and our team of legal experts, please visit our Our Firm and Our Practices pages.

Conclusion: A Proactive Approach to Digital Safety

In conclusion, compliance with cyber law in Bangladesh is an ongoing process that requires vigilance, expertise, and a proactive mindset. As the legal framework continues to evolve, businesses and individuals must stay informed and adapt their practices to ensure they remain on the right side of the law. By prioritizing cybersecurity and data protection, organizations can not only mitigate legal risks but also build lasting trust with their customers and partners.For professional legal assistance tailored to your specific needs, we invite you to contact us or visit our Services page to learn more about how we can support your digital journey.

Get in Touch with TRW Law Firm

If you have questions regarding cyber law compliance or need immediate legal assistance, please contact our expert team:

Using this information carefully

Administrative practice, searchable records, forms and filing requirements can change. Before relying on a search result or preparing a filing, confirm the current process through the relevant official register or office. A clear record of the search terms, date, source and result can assist with later review, while any material rights, deadlines or dispute issues should be considered in light of the specific facts.

Using this information carefully

Administrative practice, searchable records, forms and filing requirements can change. Before relying on a search result or preparing a filing, confirm the current process through the relevant official register or office. A clear record of the search terms, date, source and result can assist with later review, while any material rights, deadlines or dispute issues should be considered in light of the specific facts.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org