TRW KNOWLEDGE · LEGAL INFORMATION

Cybersecurity Law in Bangladesh: A Comprehensive Legal Overview (2026)

This article explains the legal framework and practical compliance steps for organisations operating in Bangladesh’s digital environment. It summarises primary statutory sources, core obligations, governance approaches, and sector considerations, and sets out a practical incident response checklist and an FAQ to assist non-legal and legal readers in understanding cybersecurity duties.
Originally published 30 May 2026

Introduction

Maintaining a resilient digital environment has become an essential aspect of business and public administration. Organisations operating in Bangladesh must understand the statutory framework that shapes how data, systems and communications are protected, how incidents are handled, and how liability may arise. This overview aims to provide clear legal information about the principal statutory sources, commonly encountered obligations, practical risk-reduction measures, and governance topics relevant to boards, compliance teams and operational managers.

Core legal framework and regulatory actors

The primary statutory instrument commonly referenced in discussions about digital security in Bangladesh is the national Digital Security Act. Complementary statutes, regulatory instruments and sector-specific rules also influence responsibilities for digital safety and information integrity. Oversight and operational regulation involve multiple public bodies; among them, telecommunications regulation and other sectoral regulators exercise roles over service providers, infrastructure and permitted uses of networks. Organisations should also consider obligations under sectoral regimes such as financial services, taxation and employment law when assessing cyber-related risk.For firms seeking institutional context, information about practice areas and firm capabilities is available at /our-practices/ and institutional background is set out at /our-firm/. Practical services that can support compliance projects are described at /services/ and ways to reach advisers are at /contact/.

Scope and key legal concepts

When assessing obligations, it is important to identify which of an organisation’s activities fall within the statutory definitions used by the legislation: for example, whether particular data types qualify as personal information, whether systems meet the definition of critical infrastructure, and whether particular acts constitute unauthorised access or harmful interference. These definitions determine which duties and potential liabilities apply and whether specific regulatory reporting triggers are met.Common legal concepts that appear across instruments and guidance include duties to implement ‘‘reasonable’’ security measures, the prohibition of unauthorised access and dissemination of harmful code, limits on unlawful interception or disclosure, and obligations to assist or cooperate with lawful investigations. The precise contours of these concepts are shaped by statutory text, implementing rules and regulatory guidance; where certainty is required practitioners should consult primary sources and regulatory communications.

Core obligations likely to affect organisations

Although the precise requirements vary by statutory text and regulatory guidance, most organisations should expect the following types of obligations to be relevant when assessing compliance and risk:• Protecting personal and sensitive data through appropriate organisational and technical measures; this typically means access controls, encryption where feasible, secure backups and data minimisation practices.• Preventing and responding to unauthorised access, malware, denial-of-service attacks and related cybercrimes; responsibilities extend to preventing misuse of hosted services and to taking reasonable steps to secure devices and accounts.• Incident management, including internal escalation and potential notification to competent authorities where an incident meets statutory thresholds or regulatory reporting criteria.• Maintaining records that demonstrate compliance efforts, including policies, training logs, audit reports and evidence of remediation after incidents.

Governance, roles and internal accountability

Sound governance arranges responsibility for cyber risk in a way that board members, senior management and operational teams can exercise oversight and maintain accountability. Effective governance typically includes a named officer or committee for cyber risk, clear escalation pathways for incidents, and periodic board-level reporting. Integration with other compliance functions — for example, data protection, procurement, and corporate risk management — reduces duplication and supports coherent decision-making.Organisations with regulated activities should ensure governance arrangements coordinate with their sectoral compliance teams. For example, financial services firms should align cybersecurity governance with prudential, anti-money laundering and payment system resilience frameworks; advisers with relevant sector experience include those listed under /financial-services-regulatory-lawyers/.

Third-party risk and contractual controls

Third-party providers — cloud hosts, managed service providers, software vendors and supply chain partners — are a leading source of cyber risk. Contractual controls that allocate responsibility and set security standards are a practical tool to manage this exposure. Typical contractual clauses address data processing roles, security measures, audit rights, incident cooperation and exit arrangements for secure data return or deletion. Procurement teams should work closely with legal counsel and information-security teams to ensure contracts deliver operationally meaningful controls.

Technical and organisational measures (high-level)

A layered approach to security aligns with accepted practice and helps meet legal expectations about reasonable protection. Key technical measures commonly recommended include multi-factor authentication for privileged access, network segmentation, regular patching and vulnerability management, endpoint protection, secure configuration baselines and data encryption in transit and, where appropriate, at rest. Organisational measures include role-based access policies, background checks for sensitive roles, secure software development lifecycle practices and a formal vulnerability disclosure process.

Sector-specific considerations

Cyber obligations intersect with sectoral rules. In the financial sector, resilience and incident reporting may be subject to additional regulatory expectations; teams may find it helpful to coordinate with advisers experienced in the financial regulatory environment at /financial-services-regulatory-lawyers/. Employers have obligations under employment law and should coordinate cyber policies with human-resources practice; see guidance for employers at /employment-and-labor-lawyers/. Organisations engaged in cross-border investments or transactions should assess cyber-related due diligence in foreign direct investment contexts; subject-matter support is available at /foreign-direct-investment-lawyers/. For disputes that may require alternative dispute resolution or arbitration, parties often consider security and confidentiality requirements in advance; lawyers with experience as a /leading-arbitration-lawyer/ can assist with drafting and strategy.

Incident response and reporting

Incident response is an operational process that should be rehearsed and documented. A practical response plan identifies who will lead an incident, how evidence will be preserved, what internal communications protocols will be used, and when and how regulators, customers and counterparties will be notified. Notification thresholds and timing depend on statutory and regulatory criteria; where reporting is required, timely, accurate and proportionate information sharing reduces legal and operational risks.

Single practical checklist: Initial incident response checklist

  • Isolate affected systems to prevent further spread while preserving access logs and volatile evidence.
  • Activate the incident response team and confirm roles (Incident Lead, Forensics, Legal, Communications, HR, IT Operations).
  • Preserve copies of logs, snapshots and relevant system images in a forensically sound manner.
  • Assess immediate operational continuity needs and invoke contingency plans as required.
  • Document actions taken and decisions made in an incident register for later review and regulatory reporting.
  • Engage external forensic specialists if technical expertise is required to determine scope and impact.
  • Notify internal stakeholders and, where appropriate, prepare external notifications that comply with regulatory obligations.
  • Assess third-party involvement and inform contracted providers to coordinate containment and remediation.
  • Plan remedial actions, including patching, credential resets and restoration from verified backups.
  • After containment, conduct a post-incident review to identify root causes and implement improvements.

Compliance, audits and evidence

Regulatory expectations tend to emphasise demonstrable efforts to reduce risk. That means maintaining contemporaneous documentation: policies, implementation records, procurement decisions, audit reports, testing outcomes and training logs. Regular independent audits and penetration testing, when designed to be systematic and documented, provide evidence of ongoing due diligence. Organisations should maintain a documented schedule for review and update of policies so that regulators and stakeholders can see governance in practice.

Data transfers and cross-border considerations

Transfers of personal or sensitive data across borders raise additional considerations. Organisations should identify whether any cross-border movement of data engages specific statutory controls, contractual obligations or market-specific regulation. Where transfers are required, consider the legal basis for transfer, contractual safeguards and technical measures such as encryption. When in doubt, organisations should adopt a layered approach that combines contractual, technical and organisational measures to reduce risk.

Privacy impact and risk assessments

Data protection and security assessments, including privacy impact assessments (PIAs), help organisations identify risks at the design stage of projects and operations. PIAs document the decision-making process, the risks identified, and the mitigation steps taken. These assessments can be particularly important when deploying new technologies, processing particularly sensitive categories of data, or offering services that may be widely used by the public.

Common compliance pitfalls

Many organisations make similar mistakes when implementing cyber governance. Typical pitfalls include: relying solely on perimeter controls without addressing identity and endpoint protections; failing to update or test incident response plans; neglecting to include cybersecurity requirements in vendor contracts; and under-investing in staff training and awareness. Addressing these gaps requires a combination of technical investment and process improvement, backed by senior management commitment.

Enforcement, remedial measures and dispute considerations

Regulatory bodies and authorities may investigate incidents and alleged breaches. Outcomes can range from requirements to remediate identified deficiencies to administrative penalties where breaches of statutory requirements are found. Organisations involved in incidents should carefully manage communications and preserve evidence to support lawful defence or mitigation. Where incidents give rise to disputes, alternative dispute resolution or litigation may focus on contractual obligations, negligence or statutory compliance; relevant cause lists or hearing schedules can inform case planning, such as those published at /supreme-court-bangladesh-cause-list/.

Recent dynamics and anticipated trends (2024–2025)

The legal and regulatory landscape for cyber risk is evolving. Recent years have seen increased regulatory emphasis on data protection, incident transparency and resilience. Policymakers and regulators have signalled an interest in strengthening rules, clarifying reporting thresholds and encouraging sectoral coordination. Organisations should monitor formal rule-making, regulator guidance and judicial developments and update their compliance programmes accordingly.

Practical steps for first 90 days of a compliance programme

For an organisation beginning a compliance programme, a pragmatic 90-day plan can prioritise high-value actions. First, map data flows and critical systems to identify where most risk is concentrated. Second, conduct an initial risk and control assessment focused on high-impact scenarios. Third, implement immediate technical mitigations such as enforced multi-factor authentication and patching of critical vulnerabilities. Fourth, establish formal incident response roles and document initial policies. Finally, schedule external audit or penetration testing to validate the implemented controls and create a plan for remediation.

How to align legal, technical and operational teams

Bridging the gap between legal advisers, IT teams and operations requires clear communication protocols and shared objectives. Legal teams should translate statutory expectations into operational checkpoints that technologists can test and implement. IT and security teams should provide technical assessments in terms that enable legal teams to evaluate compliance risk. Regular cross-disciplinary meetings, shared dashboards and joint tabletop exercises are effective tools for building a coordinated approach.

When to seek external legal or technical advice

Organisations should consider external advice when they encounter significant incidents, when novel or ambiguous statutory questions arise, or when large-scale vendor or M&A transactions involve complex cyber risk. Firms may also seek specialist technical forensics to investigate intrusions and independent legal advice for regulatory engagement or dispute strategy. For tailored representation or regulatory navigation, practitioners with sector experience may assist; consider specialists listed under relevant practice routes.

Legal-information disclaimer

The content of this article is provided for general informational purposes and does not constitute legal advice. It describes legal concepts and practical approaches but is not a substitute for consulting an attorney on specific facts or regulatory questions. For tailored guidance, organisations should consult qualified counsel and technical advisers.

FAQ

Q: What statutes and sources should organisations consult first when assessing cyber obligations?

A: Organisations should begin with the primary statutory instrument governing digital security and related implementing rules. Complementary sources include sectoral regulation, telecommunications rules, and guidance issued by competent authorities. For a holistic view, organisations should also review contract terms, industry codes and relevant international standards used as benchmarks for technical practice.

Q: What constitutes a notifiable incident and when should authorities be informed?

A: Notifiable incidents are typically those that meet statutory thresholds set by applicable law or regulator guidance — for example, incidents that materially affect availability of services, breach significant volumes of personal data, or threaten national security or critical infrastructure. The timing and content of notifications depend on statutory language and regulator expectations; organisations should prepare internal criteria to identify notifiable events and consult counsel early in serious incidents to shape regulatory communications.

Q: How should organisations approach vendor and cloud contracts from a cybersecurity perspective?

A: Contracts should clearly allocate responsibilities for data protection, security controls, incident response cooperation, audit or inspection rights, sub-processor restrictions and secure exit mechanisms. Organisations should require minimum security standards, evidence of testing, and provisions allowing remediation or termination where material deficiencies are found. Pricing, liability caps and insurance arrangements should be negotiated in light of the residual risk after contractual protections.

Q: What evidence demonstrates compliance if a regulator opens an inquiry after an incident?

A: Useful evidence includes documented policies and standards, training records, audit results, penetration-testing reports, change-management records, incident logs and communications showing remedial actions taken. Contemporaneous documentation that evidences decision-making, risk assessments and prompt remedial work is often persuasive in demonstrating an organisation's intent and the reasonableness of its actions.

Q: How often should organisations test incident response plans and run exercises?

A: Best practice is to run tabletop exercises at least annually and to conduct more comprehensive technical simulations — such as red-team exercises or full-scale incident simulations — at regular intervals appropriate to the organisation’s risk profile, generally every one to three years. Testing frequency should increase where the threat environment or business operations change materially.

Q: Can employees’ actions create organisational liability for cybersecurity breaches?

A: Employee actions can be a source of risk, particularly where inadequate training, insufficient access controls or weak policies enable misuse or negligence. Organisations are expected to implement reasonable measures to prevent foreseeable misuse, including training, clear policies, monitoring and proportionate sanctions. Where employee misconduct is alleged, employers should preserve evidence and follow appropriate processes to respond and remedy systemic shortcomings.

Q: What role do data minimisation and retention policies play in cyber risk management?

A: Reducing the volume of stored personal or sensitive data reduces exposure in the event of a breach and simplifies protection efforts. Retention policies should be aligned with legal and operational requirements: keep data only as long as it is needed for its lawful purpose, and dispose of it securely when no longer required. Retention and minimisation are practical risk controls as well as governance measures that regulators increasingly expect to see documented.

Q: Who within the organisation should be involved in managing cyber risk?

A: Cyber risk is multi-disciplinary. Key participants include senior management and the board (for oversight), legal and compliance functions (for regulatory interpretation and reporting), IT and security teams (for technical controls), procurement (for contractual protections) and HR (for employee-related measures). External specialists can support forensics, technical testing and regulatory engagement when incidents or projects require extra capacity or expertise.For further sector-specific or transaction-focused support, practitioners commonly coordinate across relevant specialties such as those available at /tax-lawyers/ and the other practice routes noted above. Organisations preparing for regulatory engagement or complex cross-border questions are advised to seek tailored advice from counsel with relevant experience.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org