TRW Knowledge / Technology, data & IP
Understanding Bangladesh Online Privacy Law (2026): A Practical Guide for Organisations
This guide explains the principal legal and practical considerations for organisations operating in or with links to Bangladesh when handling personal data online. It summarises the principal statutory instruments that affect online privacy, identifies common compliance steps and practical risk-management measures, and sets out approaches to breach response, contracts with third parties,

2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Introduction
This guide explains the principal legal and practical considerations for organisations operating in or with links to Bangladesh when handling personal data online. It summarises the principal statutory instruments that affect online privacy, identifies common compliance steps and practical risk-management measures, and sets out approaches to breach response, contracts with third parties, and cross-border transfers. The material is explanatory and not a substitute for case-specific legal advice; organisations should consult a qualified adviser for decisions that turn on particular facts or evolving law.Scope and purpose of this guide
The guide is intended for in-house counsel, compliance officers, data protection officers, business leaders and advisers who need an overview of the regulatory landscape as it stood in mid-2026 and practical steps that frequently arise in compliance programmes. It uses cautious language where the underlying public record is not definitive and directs readers to official authorities or to advisers where appropriate.Legal framework in Bangladesh: principal instruments and regulators
There is no single consolidated code labelled a "data protection act" in force in Bangladesh equivalent to some other jurisdictions’ statutes. Instead, online privacy and data protection in practice are affected by multiple statutes, regulations and regulatory instruments. Key sources include:- the Information and Communication Technology Act, 2006 (ICT Act) as amended;
- the Digital Security Act, 2018; and
- rules, licences and directions issued by the Bangladesh Telecommunication Regulatory Commission (BTRC) and other sectoral regulators.
Regulatory roles and overlap
Several public bodies may exercise overlapping functions relevant to online privacy: telecommunications regulators (such as the BTRC) often regulate carriers and service providers; law enforcement and intelligence agencies have roles in national security and criminal enforcement; and sectoral regulators may set sector-specific obligations (for financial services, health, education and so forth). Overlap can create both coverage and enforcement complexity. Organisations should map which regulator(s) have primary jurisdiction for their operations and maintain contemporaneous records of the licences, terms and conditions, and statutory obligations that apply to their services.Key substantive themes and common provisions
Published instruments and regulatory practice commonly address the following themes. The summary below is explanatory and not exhaustive:- Consent and lawful basis for processing. Many instruments and best-practice frameworks refer to the need for an appropriate legal basis for collecting and using personal data, commonly including consent in consumer-facing contexts and contractual or statutory bases in commercial or public-sector contexts. The precise form and evidential requirements for consent are not fixed by a single statutory code and may depend on context.
- Purpose limitation and data minimisation. Organisations are generally expected to limit collection to what is necessary for declared purposes and to avoid indefinite retention unless required by law or contract.
- Security and technical safeguards. There is an expectation that reasonable technical and organisational measures (for example, access controls, encryption and patching regimes) will be applied to protect stored and transmitted data; the appropriate standard is context-specific.
- Access and individual rights. Instruments and administrative practice recognise individuals’ interests in accessing personal data held about them and, in certain contexts, correcting or updating that data; the scope and procedures for such requests may be set by specific rules or agency guidance.
- Data sharing and third parties. Transfers to third-party processors or controllers are generally subject to contractual and, in some cases, statutory constraints; due diligence and contractual protections (including confidentiality and security covenants) are frequently recommended.
Practical steps: a compliance-oriented process
Organisations commonly follow a structured programme to reduce legal and operational risks. A practical compliance framework often includes the following steps; each step should be adapted to the organisation’s size, sector and risk profile.1. Map data flows and business purposes
Document what personal data the organisation collects, how and from whom it is collected, the purposes for processing, where data flows (including cross-border transfers), and how long data is retained. Mapping highlights high-risk processing and clarifies which contractual and regulatory obligations apply.2. Review legal bases and notice mechanisms
Assess whether the organisation has an appropriate legal basis for each processing activity and whether privacy notices are clear, accessible and accurate for the likely audience. For consent-based processing, record how consent is obtained, evidenced and withdrawn.3. Implement proportionate security measures
Adopt technical and organisational measures that correspond to the sensitivity of the data and the scale of processing. Examples include role-based access controls, encryption for data at rest and in transit, multi-factor authentication for privileged accounts, secure development practices and incident logging. Where an organisation is unable to meet particular technical standards, it should document the reasons and mitigation measures.4. Contractual risk management for third parties
Use written agreements with processors and other third parties that: allocate responsibilities for compliance; require appropriate security measures; address sub-processing; specify audit and reporting rights; and include breach-notification obligations. Standard contractual terms can be adapted to the factual context but should be reviewed by counsel.5. Prepare breach response plans and exercises
Maintain an incident response plan with defined roles, escalation thresholds and external communication templates. Regular tabletop exercises and periodic technical testing (for example, penetration testing) help confirm that the plan is realistic. The plan should address obligations to report incidents to regulators, law enforcement or affected individuals, as applicable.6. Training, policies and governance
Deploy role-appropriate training for employees and contractors, maintain an up-to-date privacy policy and internal data handling procedures, and designate responsible individuals (for example, a data protection officer or a compliance lead) with sufficient authority and resources to implement the programme.7. Audit and continuous improvement
Regularly audit data handling practices, update risk assessments in response to changes in law or practice, and remediate identified gaps. Audits should review contractual compliance by processors, retention practices, and adherence to documented procedures.Sector-specific considerations
Different sectors may face additional requirements or heightened scrutiny. Examples commonly encountered include:- Financial services: obligations to safeguard customer data intersect with financial regulation; some financial-sector rules prescribe specific retention or reporting obligations.
- Healthcare: health and medical data are usually treated as more sensitive and may attract additional confidentiality duties.
- Telecommunications and internet service providers: licensing terms from the BTRC or other regulators may impose record-keeping or interception-related obligations.
Cross-border transfers and international considerations
Cross-border data transfers raise practical and legal issues. Where personal data is sent outside Bangladesh, organisations should identify the legal basis for transfer, ensure appropriate contractual and technical safeguards, and evaluate whether local permits, notices or approvals are required. When foreign jurisdictions are involved, organisations should also consider the interaction of Bangladeshi requirements with foreign laws applicable to the recipient. Transfer mechanisms and adequacy assessments evolve over time; bespoke legal advice is advisable for transfers that raise regulatory or commercial risk.Data breach identification and response
Not every cybersecurity incident is a reportable personal-data breach, but organisations should assume that incidents affecting personal data might have regulatory implications. A pragmatic response sequence typically includes:- initial containment and preservation of evidence;
- internal assessment to determine the nature and scope of the incident;
- notification of affected stakeholders and regulators where required by law or contract;
- remediation to address vulnerabilities and prevent recurrence; and
- post-incident review and follow-up (including possible reporting to customers or partners).
Enforcement and penalties: a cautious summary
Enforcement approaches and potential sanctions under statutes such as the ICT Act or the Digital Security Act can include administrative fines, criminal penalties or other corrective measures. The available remedies and the procedures for enforcement depend on the particular statutory provisions invoked and the prosecuting authority. Because enforcement regimes may be amended or interpreted through case law or regulatory practice, organisations should not rely on this guide as a definitive statement of potential sanctions and should consult counsel for an up-to-date assessment of regulatory risk.Contracts, procurement and supply-chain management
Data protection obligations should be reflected in procurement and contract processes. Recommended contract features include:- clear allocation of responsibilities between data controllers and processors;
- processor security and confidentiality obligations and sub-processor controls;
- audit rights and compliance reporting obligations;
- data return/deletion obligations on contract termination; and
- clauses addressing cross-border transfers and applicable law/dispute-resolution mechanisms (recognising that choice of law can affect enforcement and remedies).
Record-keeping and documentation
Maintaining contemporaneous documentation of processing activities, risk assessments, incident logs, consent records and contractual arrangements is a practical control and may be essential if an organisation must demonstrate compliance to a regulator or a counterparty. Documentation should be proportionate and retained according to the organisation’s retention policy and legal obligations.Common pitfalls and how to avoid them
Repeated issues in compliance programmes include:- Insufficient consent documentation. Organisations sometimes rely on implied consent or fail to record explicit consent where it would be prudent to do so.
- Weak supplier management. Contracts that lack clear security and sub-processing requirements expose organisations to third-party risk.
- Poorly scoped retention policies. Keeping data indefinitely without a lawful or business purpose increases exposure to risk.
- Overreliance on technical fixes. Technical controls are necessary but should be accompanied by process, training and governance measures.
2026 update
As of mid-2026, public discussion in Bangladesh has continued about potential legislative and regulatory developments affecting data protection and online privacy. Proposals and consultations have been reported in public sources; organisations should treat any draft proposals as subject to change. Where official amendments are enacted by Parliament or regulators issue binding rules, those texts should be the primary source for compliance obligations.Readers should consult official sources for enacted texts and current guidance. The BTRC publishes regulatory information on its website (https://www.btrc.gov.bd/); for legislative texts, consult the Government Gazette or the official parliamentary resources. If a proposed amendment is relevant to your business model, obtain tailored legal advice before implementing operational changes in reliance on draft or proposed rules.Drafting an organisational privacy policy: suggested elements
Privacy policies should be concise, transparent and written with the intended audience in mind. Typical sections include:- what categories of personal data are collected;
- purposes for processing;
- legal bases for processing (where applicable);
- data retention periods or criteria used to determine retention;
- details of recipients or categories of recipients (including third-party processors and cross-border recipients);
- data subject rights and how to exercise them; and
- contact details for privacy queries (for example, an email address or an internal contact point).
Training and organisational culture
Privacy compliance is not purely a legal exercise. Regular training calibrated to job functions helps reduce human error and promotes a culture of accountability. Training topics can include secure handling of personal data, recognising phishing attempts, appropriate use of cloud services, and the process for reporting suspected incidents.When to seek specialist legal advice
Certain circumstances commonly warrant early legal involvement, including:- complex cross-border transfers or international group structures;
- significant security incidents or suspected breaches that may trigger regulatory reporting;
- novel processing activities involving sensitive personal data, biometrics, AI/automated decision-making, or large-scale profiling;
- disputes with regulators, affected individuals, or commercial counterparties about data handling;
- drafting or negotiating large-scale outsourcing or cloud services arrangements.
Practical compliance checklist
- Map your personal-data inventory and data flows.
- Update privacy notices and obtain documented lawful bases for processing.
- Review and update contracts with processors and vendors.
- Ensure proportionate security controls commensurate with risk.
- Put in place an incident response plan and exercise it periodically.
- Train staff and maintain role-based access controls.
- Maintain retention schedules and documented disposal procedures.
- Schedule periodic audits and remediate identified gaps.
Five practical FAQs
Q: What does the Bangladesh online privacy law cover?
A: The legal framework in Bangladesh relevant to online privacy generally covers the collection, use, storage and sharing of personal data, and includes obligations on consent, security and respect for individual rights as implemented across statutes and regulatory instruments; organisations should review the particular statutory texts and regulatory guidance that apply to their activities and seek tailored advice for specific compliance questions.Q: How can organisations ensure compliance with the law?
A: Organisations commonly ensure compliance by mapping data flows, documenting legal bases and privacy notices, contracting with processors, implementing appropriate technical and organisational measures, training staff, and conducting audits; where statutory obligations or sectoral rules apply, seek legal advice to align practices with the applicable requirements.Q: What are the penalties for non-compliance?
A: Penalties can include administrative fines, criminal sanctions, regulatory enforcement measures or civil liabilities depending on the statutory provision and facts; because enforcement regimes and penalties can change, organisations should not assume the scope or magnitude of sanctions without up-to-date legal advice.Q: Are there any exceptions to the law?
A: Certain exceptions may apply, for example for national security, law enforcement or other matters specified by statute; the availability and scope of any exception depend on the relevant legal text and should be assessed with legal counsel rather than assumed.Q: When should we seek tailored legal advice on privacy matters?
A: Seek tailored advice when you face cross-border transfers, suspected breaches, novel processing involving sensitive data or AI, regulatory investigations, or complex contractual arrangements; early legal input helps preserve privilege and frame an effective compliance response.Useful organisational resources
Internal stakeholders should coordinate across legal, IT, procurement and business units. External resources that organisations frequently consult include regulator publications (for example the BTRC website at https://www.btrc.gov.bd/) and professional guidance on security standards. For commercial or regulatory matters that require legal support, TRW’s pages on services and firm information may be a point of contact: see https://trw.org/services/, https://trw.org/our-practices/, https://trw.org/our-firm/ and https://trw.org/contact/.Document retention and evidence preservation
When a regulator inquiry or litigation is reasonably anticipated, organisations should issue hold notices and preserve potentially relevant records in line with legal advice. Retention policies should balance business needs, legal obligations and privacy considerations; disposal processes should be defensible and documented.Data protection by design and default
Embedding privacy considerations early in project lifecycles reduces downstream compliance costs. Practical measures include minimising collected data, defaulting to privacy-friendly settings, anonymising or pseudonymising data where possible, and incorporating privacy impact assessments for high-risk processing.Conclusion
Maintaining compliance with online privacy obligations in Bangladesh requires attention to multiple instruments, sectoral rules and evolving regulatory practice. Organisations should adopt proportionate governance, technical safeguards and contractual protections, and they should obtain tailored legal advice for complex or high-risk matters. The guidance above is explanatory and does not constitute legal advice for any particular fact pattern.Book consultation or contact us by email at info@trw.org if you require tailored advice or assistance implementing a compliance programme.Bring the facts.
We bring direction.
For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.