TRW Knowledge / Technology, data & IP

Data Protection in Bangladesh: Legal Framework and Practical Compliance Guide (2026)

Data protection obligations in Bangladesh are evolving. This article explains the principal statutes, regulatory actors, common compliance issues and practical steps organisations should consider in 2026. It is explanatory and not a substitute for legal advice; organisations should consult an appropriately qualified adviser about their specific circumstances.

Originally published 19 June 2026

Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Data protection obligations in Bangladesh are evolving. This article explains the principal statutes, regulatory actors, common compliance issues and practical steps organisations should consider in 2026. It is explanatory and not a substitute for legal advice; organisations should consult an appropriately qualified adviser about their specific circumstances.

Overview

Bangladesh’s regulatory landscape for personal data involves multiple instruments and authorities. The Digital Security Act, 2018 includes provisions relevant to data privacy and cybersecurity, while regulatory bodies such as the Bangladesh Telecommunication Regulatory Commission (BTRC) and the Bangladesh Computer Council (BCC) publish rules, standards and guidance that can affect handling of personal information. A proposed Data Protection Bill has been discussed for several years; readers should confirm its current status with official sources before relying on its provisions.

2026 update

As of the original publication date in 2026, commentators continue to track the proposed Data Protection Bill and other regulatory activity. Because legislative and regulatory processes are time sensitive, interested parties should verify the latest position with the national legislature, the BTRC, the BCC or other official authorities such as the Ministry of Posts, Telecommunications and Information Technology. The BTRC publishes sectoral regulatory materials at https://www.btrc.gov.bd; this link is provided for reference and should not be read as proof of any legal proposition in this article.

Primary laws and regulatory actors

The applicable framework in Bangladesh may include:
  • Digital Security Act, 2018: contains provisions addressing computer systems, unauthorised access and certain privacy-related offences; parts of the statute can affect how personal data is handled by private sector and public actors.
  • Sectoral rules and directions: regulatory bodies, notably the Bangladesh Telecommunication Regulatory Commission (BTRC) and the Bangladesh Computer Council (BCC), issue rules, sectoral standards and guidance that affect telecommunication, internet service providers and public digital systems.
  • Draft or proposed legislation: a Data Protection Bill has been proposed to create a comprehensive personal data protection regime; its final text and legal effect depend on the legislative process and any implementing regulations.
These sources interact with other legal areas such as contract law, consumer protection, employment law and sector-specific regulation (for example, financial services). Entities handling personal data should consider the intersection of multiple legal obligations.Although the exact requirements depend on any final law and sectoral instruments, common principles that appear across comparative frameworks and that are relevant for organisations operating in Bangladesh include:

Lawful basis for processing and consent

Organisations should identify and document a lawful basis for processing personal data. Where consent is relied upon, it should be informed, freely given, specific and capable of withdrawal. Consent mechanisms must be designed to reflect the purpose of processing and the nature of the data subject relationship. In many contexts, other bases (contractual necessity, compliance with legal obligations, legitimate interests or statutory powers) may be appropriate; organisations should record their choice and rationale.

Data minimisation and purpose limitation

Collect only personal data that is necessary for a specified, explicit purpose and avoid retaining data longer than required for that purpose. Purpose limitation means processing should be compatible with the purpose communicated to data subjects or otherwise authorised under law.

Data subject rights

Rights commonly associated with modern data protection laws include access, rectification, erasure (subject to legal retention duties), restriction of processing, objection and data portability in some regimes. Organisations should build procedures to receive, verify and respond to requests from data subjects promptly and within any statutory time limits.

Technical and organisational security

Appropriate technical and organisational measures should protect personal data against unauthorised access, alteration, deletion, accidental loss or disclosure. Measures commonly recommended include access controls, encryption, secure development and configuration management, logging, vulnerability management and secure backup strategies. The precise level of security should be proportionate to the risk associated with processing.

Data breach notification

Entities should operate an incident response process that identifies, contains and remediates data security incidents. Where notification to authorities or to affected individuals is required by law, timeliness and accuracy are essential. Organisations should take legal advice to determine any notification thresholds and applicable timelines for particular incidents.

Cross-border transfers

International transfers of personal data may trigger additional legal requirements. Transfer safeguards can include contractual protections, approved binding corporate rules, or other mechanisms permitted by the relevant law. Organisations should assess the lawfulness of transfers and document the legal basis for cross-border data flows.

Special categories of data

Sensitive categories of information (for example, health data, biometric identifiers, religious or political affiliation) generally call for heightened protection and may be subject to stricter processing conditions or prohibitions. When processing sensitive data, consider whether special legal authorization or explicit consent is necessary and implement stricter technical controls and governance oversight.

Sectoral considerations

Certain sectors face additional expectations or regulatory requirements that affect data handling:

Telecommunications and internet services

Operators in the telecom sector should monitor any BTRC directions concerning retention of traffic data, lawful interception, user privacy and data localisation. Compliance may require specific record-keeping practices and technical capabilities.

Financial services

Financial institutions must reconcile data protection requirements with anti-money laundering (AML), know-your-customer (KYC) and reporting obligations. Sectoral regulators may publish supervisory guidance addressing the balance between privacy and financial regulatory duties. For related legal services, see TRW’s practice description at https://trw.org/financial-services-regulatory-lawyers/.

Employment

Employers collecting employee personal data should consider employment law, payroll regulation and social security obligations alongside privacy duties; workplace monitoring and biometric systems require particular care and proportionate justification.

Practical compliance steps: a structured approach

The following stepwise approach can help organisations identify and reduce data protection risk. None of the steps below is a substitute for legal advice tailored to an organisation’s activities.

1. Data mapping and inventory

Catalogue the personal data you collect, process and store, including subject categories, data elements, purpose(s), legal basis, data flows, storage locations and retention periods. Include third parties, subprocessors and cross-border transfers in the map.

2. Risk assessment and DPIAs

Assess processing risks to individuals and carry out Data Protection Impact Assessments (DPIAs) for processing likely to result in high risk (for example, large-scale processing of sensitive data or systematic monitoring). Document mitigations and decisions.

3. Policies, records and contracts

Develop written policies (privacy policy, data retention policy, acceptable use, vendor management), internal records of processing activities, and contract clauses to govern processor-subprocessor relationships. Ensure standard contractual terms reflect security obligations and liability allocation.

4. Consent and notice

Design privacy notices that clearly explain processing activities, legal bases and data subject rights. Implement consent mechanisms where appropriate and keep records of consent. Ensure mechanisms for withdrawing consent are accessible.

5. Technical controls and secure design

Apply technical controls consistent with identified risks: encryption for data at rest and in transit where appropriate, role-based access controls, multifactor authentication, secure coding practices and vulnerability testing. For cloud deployments, document shared responsibility models with providers.

6. Vendor due diligence and contracts

Assess third-party service providers for their data protection maturity. Use contractual safeguards to require processors to implement security measures and to cooperate with incident response. Ensure right-to-audit or certification requirements where feasible.

7. Incident response and breach notification

Establish an incident response plan that identifies responsibilities, escalation paths and communication templates. Define criteria that trigger regulatory notification and notification to affected data subjects. Test the plan with tabletop exercises.

8. Training and governance

Deliver role-specific training for staff who handle personal data and establish an accountability framework (data protection officer or privacy lead, governance committee, board reporting). Maintain an awareness programme for ongoing compliance.

9. Regular audits and continuous improvement

Perform periodic audits of processing activities, technical security and vendor compliance. Update data mapping, DPIAs and policies when business processes change. Maintain documented evidence of compliance efforts.

Cross-border and international considerations

Organisations with international operations should consider the compatibility of Bangladeshi obligations with foreign laws such as the EU General Data Protection Regulation (GDPR) or other jurisdictions' regimes. Where an organisation is subject to multiple legal regimes, mapping applicable law by processing activity and jurisdiction is essential. Contractual, technical and organisational measures may be required to minimise conflicts and ensure lawful transfers.Regulatory enforcement approaches vary by authority and the relevant instrument. Penalties for non-compliance can include administrative fines, orders to cease processing, injunctive relief and reputational consequences. Criminal sanctions may apply under statutes that criminalise specific acts involving computer systems or communications. Because enforcement outcomes depend on facts and applicable law, organisations should seek legal advice promptly when an incident or dispute arises.

Common compliance pitfalls

The following issues frequently cause problems in practice:
  • Relying on consent where there is a clear imbalance of power or where another legal basis would be more appropriate.
  • Retaining data longer than necessary without a defensible retention policy or schedule.
  • Failing to document processing activities and risk assessments.
  • Neglecting contractual protection for processors and subcontractors.
  • Insufficient incident response planning and failure to test the response process.
Addressing these areas proactively reduces legal risk and improves operational resilience.Given the diversity of processing activities and potential legal consequences, organisations should consider seeking bespoke advice in circumstances such as:
  • Designing or deploying systems that process large volumes of personal data, sensitive categories, or biometric information;
  • Planning transfers of personal data outside Bangladesh or integrating multinational data flows;
  • Responding to a substantial data breach or regulatory inquiry;
  • Structuring contracts with cloud providers, processors or cross-border vendors; and
  • Assessing sector-specific regulatory obligations (for example, financial, telecom or health sectors).
Legal and technical advisers can help tailor a compliance programme to the organisation’s risk profile and operational constraints.

Practical checklist for board and senior management

Boards and senior management should ensure oversight and accountability for data protection by considering the following actions:
  • Confirm that data protection is part of enterprise risk management and that senior responsibility is assigned.
  • Approve a data protection policy and allocate resources to implement it.
  • Require periodic reporting on DPIAs, incidents and audit findings.
  • Ensure capital expenditure for security improvements is considered in budgeting decisions.

Resources and further reading

Useful sources for up-to-date information include official regulator sites and published guidance documents. For regulatory materials affecting telecom and information infrastructure, consult the BTRC at https://www.btrc.gov.bd. For organisational assistance and legal services offered by TRW, see our practice descriptions at https://trw.org/our-practices/ and service pages at https://trw.org/services/. General information about the firm is available at https://trw.org/our-firm/, and contact details are at https://trw.org/contact/.

Five practical compliance scenarios

Scenario 1 — New customer onboarding for an online service

When designing onboarding, limit data collection to what is necessary for the service, describe the purpose clearly in notices, and implement mechanisms for verifying and responding to subject requests. If identity verification involves sensitive identifiers, escalate to a DPIA and consider stronger authentication and retention policies.

Scenario 2 — Using a cloud provider for personal data

Establish a data processing agreement that identifies roles, security measures, subprocessors and incident reporting obligations. Verify the provider’s certifications and clarify the provider’s responsibilities for backups and recovery.

Scenario 3 — Data transfer to analytics or marketing vendors outside Bangladesh

Document the legal basis for transfer, implement contractual safeguards and evaluate whether any additional regulatory approvals or notices are required. Consider pseudonymisation and minimisation techniques before transfer.

Scenario 4 — Responding to a suspected breach

Activate the incident response plan, contain the incident, preserve relevant logs and evidence, evaluate notification obligations and take steps to remediate and prevent recurrence. Engage legal counsel early to assess regulatory and contractual reporting duties.

Scenario 5 — Employee monitoring and workplace data

Balance business needs with privacy expectations, provide clear policies and notices to staff, minimise collection and retain data only as needed for lawful employment administration. Consult labour and privacy advisers before deploying monitoring technologies.

Frequently Asked Questions

Q: What are the main objectives of data protection laws in Bangladesh?

A: The primary objectives are to protect individuals' personal data, enable the exercise of privacy rights and establish legal rules for organisations that collect or process personal information; for specific legal conclusions or application to particular activities, consult a qualified adviser.

Q: Who is responsible for enforcing data protection laws in Bangladesh?

A: Enforcement depends on the statute and sectoral rules; regulatory bodies such as the Bangladesh Telecommunication Regulatory Commission (BTRC) and the Bangladesh Computer Council (BCC) have relevant regulatory or supervisory roles in particular areas, but organisations should verify the applicable authority for their activities.

Q: How can individuals protect their personal data?

A: Individuals can protect their data by understanding their rights, exercising available access and correction remedies, using privacy settings on platforms, and being cautious when providing consent or sharing sensitive information; where individual rights are disputed, seek advice from a qualified legal adviser.

Q: What are the potential penalties for non-compliance with data protection laws?

A: Penalties vary by instrument and may include administrative sanctions, fines, orders to cease processing or criminal liability in certain circumstances; the exact consequences depend on the law and facts of each case and should be assessed with legal counsel.

Q: Is there a deadline for organisations to comply with the new Data Protection Bill?

A: Any compliance deadlines will depend on the final enacted text and effective dates of the Data Protection Bill and its regulations; organisations should monitor official announcements and seek tailored advice to determine specific timelines for their operations.

Next steps and practical assistance

Entities wishing to progress their compliance programme should consider an initial diagnostic: data mapping, a gap analysis against applicable standards, and a prioritised remediation plan. For legal support and to discuss a tailored approach, contact TRW via our services page at https://trw.org/services/ or visit our firm information page at https://trw.org/our-firm/. For enquiries regarding specific practice areas, see https://trw.org/our-practices/ and for direct contact information use https://trw.org/contact/.If you would like to discuss a particular compliance matter with legal advisers, please use the following options: Book consultation or email info@trw.org. Engaging legal counsel early will help ensure any programme aligns with current law and operational needs.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.
WhatsApp