TRW KNOWLEDGE · LEGAL INFORMATION
Cybercrime Laws in Bangladesh: A Comprehensive Legal Overview (2026)
This article explains the principal statutes, common offence types, evidentiary considerations, corporate responsibilities and risk-reduction practices relevant to cybercrime in Bangladesh. It summarises the statutory framework and practical issues that individuals and organisations commonly face, and points to institutional and professional resources for further information.
Introduction
Digital connectivity has expanded rapidly in Bangladesh, bringing social and economic benefits while also increasing exposure to unlawful online activity. This article provides legal information about the statutory framework that addresses cybercrime in Bangladesh, explains commonly encountered categories of offending behaviour, identifies evidentiary and investigatory issues that arise in cyber matters, and outlines steps organisations and individuals can take to reduce risk. The material is intended to inform decision‑making; it is not legal advice.Statutory Framework: Primary Sources
The legal framework most frequently cited in discussions of cybercrime in Bangladesh comprises the Information and Communication Technology Act (ICT Act), certain provisions of the Bangladesh Penal Code and the Evidence Act. The ICT Act, originally enacted in 2006 and amended subsequently, provides definitions and offence provisions targeted at conduct involving computers and electronic communications. The Penal Code supplies general criminal offences that can apply to actions conducted online, while the Evidence Act governs admissibility of electronic records and related evidential matters.| Law | Year enacted / notable update | Key focus areas |
|---|---|---|
| Information and Communication Technology (ICT) Act | 2006; amended in 2013 (noting ongoing discussion about additional changes) | Computer-related offences, electronic signatures, electronic records, privacy-related offences |
| Bangladesh Penal Code | 1860 | General criminal offences potentially engaged by online conduct (fraud, coercion, defamation, etc.) |
| Evidence Act | 1872 | Admissibility and authentication of electronic evidence and records |
Core Offence Categories and Representative Statutory Sections
Several sections of the statutory framework have been used to address digital offences. These provisions are often read together with general criminal law. Representative categories include:Unauthorized access and hacking
Provisions that penalise unauthorised access to computer systems or networks target conduct commonly described as hacking. Such provisions are intended to capture persons who circumvent security or use credentials they are not permitted to use. In assessing a matter, authorities and courts consider the presence or absence of consent, the manner of access, and whether the access was associated with further harmful acts such as data theft or system disruption.Publication of false or harmful electronic content
Laws addressing the publication of false information or content that harms reputation or public order can apply where material is created, hosted or shared electronically. These provisions are fact‑specific and commonly require analysis of intent, truthfulness of the statement, and the public interest in the expression.Identity theft, impersonation and misuse of personal information
Statutory provisions addressing misuse of personal data, identity impersonation and related offences operate to deter and punish appropriation of another person’s identity or personal information for deceitful or harmful purposes. In digital contexts, matters often involve fraudulent transactions, social engineering, or creation of false profiles.Privacy violations and intimate images
Certain provisions of the ICT Act and related law criminalise electronic intrusion into private communications or distribution of intimate materials without consent. These provisions reflect concerns about dignity, autonomy and privacy in the digital sphere. Courts and investigators typically balance privacy claims with competing rights and consider the technical means by which material was obtained or distributed.Evidentiary Issues and the Electronic Record
Handling digital evidence raises technical and legal challenges. The Evidence Act includes mechanisms for admitting electronic records, but effective use of evidence in cyber matters requires careful attention to preservation, chain of custody, integrity and authentication. Technical metadata, logs, backups and system images can be critical, as can expert analysis of devices and networks. Practical constraints—such as volatility of data, encryption, and cross‑border storage—make early forensic preservation important from a fact‑gathering perspective.Preservation and chain of custody
Preservation means taking steps to prevent alteration, deletion or loss of potentially relevant digital material. Chain of custody documentation should identify each person who handled media, the times and places of transfers and the method of storage. Where official powers are employed to seize devices, statutory limits and procedural safeguards apply; where private actors undertake preservation, care must be taken to avoid actions that could prejudice later use of evidence.Authentication and expert evidence
Establishing that a record is what it purports to be commonly requires technical explanation. Courts may rely on expert witnesses to explain how logs were created, how a device stores timestamps, or how network evidence links activity to a user or machine. Experts should describe methods, tools and limitations transparently to assist fact‑finders in weighing complex technical material.Enforcement, Investigation and Interagency Roles
Law enforcement agencies with cyber units typically lead criminal investigations involving serious online offences. Investigations may involve specialised units within police forces, regulatory bodies where sectoral harms arise, and prosecutors who must evaluate sufficiency of evidence. In some matters private parties initiate civil processes or administrative complaints; overlapping avenues can arise depending on the nature of the harm.Cross‑agency coordination
Because cyber incidents can engage data protection considerations, financial regulators, telecommunications authorities and law enforcement, coordination among agencies is often required. International cooperation is also common where servers, service providers or actors are located outside national borders. In cross‑border matters, mutual legal assistance, preservation orders and internationally recognised protocols are tools that may be used; their application depends on the facts and the engagement of relevant authorities.Corporate and Institutional Obligations
Organisations that operate systems, collect personal data, process payments or provide online services are subject to obligations that bear on cyber risk. While statutory instruments establish criminal prohibitions, organisations face separate responsibilities to implement reasonable security measures, protect customer data and respond to incidents. Expectations are informed by statutory obligations, regulatory guidance in specific sectors, contractual duties and industry best practice.Governance, risk management and incident response
Corporate governance processes should assign responsibility for cyber risk, document policies and ensure oversight of security investments. Effective incident response plans set out roles, communication protocols, and steps for containment, investigation and restoration. Plans that integrate legal, technical and communications advice are more likely to support coherent decision‑making during an incident and to preserve legal options.Third‑party relationships and supply chain risk
Vendors, cloud providers and other third parties are common nodes in incident chains. Contractual arrangements should allocate responsibility for security, incident notification and cooperation during investigations. Operational due diligence and periodic review of vendor security posture reduce exposure to supply‑chain compromises.Risk‑Reduction Measures: Technical and Organisational
Reduction of cyber risk proceeds through layered controls: technical measures, governance, training and monitoring. Commonly recommended measures include patch management, multi‑factor authentication, network segregation, secure backup strategies, encryption at rest and in transit, and regular security testing. Human factors such as phishing susceptibility highlight the need for staff training and clearly defined escalation pathways for suspected incidents.Data minimisation and access controls
Limiting the collection and retention of personal data to what is necessary reduces exposure in the event of a breach. Role‑based access controls and periodic reviews of privileged accounts can prevent unnecessary access and limit damage if credentials are compromised.Regulatory Considerations and Sectoral Contexts
Sectoral regulators can impose supplementary expectations—for example, financial regulators may require stronger protections for payment systems and customer data, while telecommunications regulators may oversee aspects of network security. Entities should be alert to sector‑specific guidance and consult specialist advisers where regulatory obligations intersect with cyber incidents.For organisations seeking practice information or firm resources, see pages such as /our-firm/, /our-practices/, and the /services/ overview. Where disputes implicate specialised regulatory regimes it may also be relevant to consult area pages such as /financial-services-regulatory-lawyers/ or /employment-and-labor-lawyers/. Matters requiring cross‑border litigation or arbitration may engage resources including /leading-arbitration-lawyer/ and, for Supreme Court matters, listings such as /supreme-court-bangladesh-cause-list/. For procedural contact points and practice queries, a firm’s /contact/ page identifies how to request further information.Cross‑Border Issues and International Cooperation
Many investigations encounter cross‑border questions: servers, accounts or suspects may be in other jurisdictions; evidence may be held by foreign commercial providers; and enforcement may require international assistance. Mutual legal assistance treaties, preservation requests to foreign providers, and bilateral cooperation between investigative agencies are mechanisms commonly used in these contexts. The practical effectiveness of these tools depends on the legal frameworks of the states involved and on available diplomatic and law enforcement channels.Recent Developments and Legislative Trends (2024–2025)
In recent years there has been heightened legislative and policy attention to ransomware, large‑scale data breaches and emerging forms of online abuse. Discussion about strengthening penalties, clarifying definitions and improving investigative capacity has continued. Proposed amendments and regulatory initiatives have been part of public debate; stakeholders have emphasised the need to align legal tools with technical realities while guarding fundamental safeguards such as privacy, due process and freedom of expression. Practitioners and organisations should monitor official legislative updates and regulatory guidance for authoritative details.Practical Considerations for Individuals
Individuals who encounter suspected cybercrime should prioritise preservation of evidence without taking steps that might themselves contravene law or compromise safety. Simple actions such as taking screenshots, saving relevant messages, recording dates/times and noting account identifiers can be useful for later review. Where there are threats to safety, extortion, or financial loss, timely engagement with appropriate authorities is important. Individuals should consider seeking informed legal and technical advice tailored to the specifics of the incident.Checklist for Organisations Responding to a Cyber Incident
- Activate incident response team and follow documented incident response plan.
- Preserve system images, logs and backups; avoid changes that could alter evidential material.
- Isolate affected systems to prevent further spread while maintaining evidence integrity.
- Notify internal stakeholders (legal, compliance, communications, senior management).
- Consider obligations to regulators, customers and contractual counterparties and prepare factual timelines.
- Engage qualified forensic and legal advisers to assess scope, origin and legal implications.
- Document all decisions, communications and remediation steps for audit and potential legal processes.
Privacy, Free Expression and Proportionality
Responses to cyber threats operate within broader legal limits. Measures to investigate and prevent harm must respect privacy protections, lawful process and proportionality. Where enforcement powers are exercised, procedural safeguards and judicial oversight play a role in protecting individual rights. Similarly, restrictions on speech in digital spaces are evaluated against standards that consider necessity and proportionality in democratic society.How Legal Advisers and Specialists Can Assist
Specialist advisers can help interpret how statutory provisions apply to particular facts, evaluate evidential options, coordinate with technical experts and communicate with regulators. Legal advisers can also assist organisations with drafting and reviewing policies, contracts and incident response plans, and with designing compliance programmes that align with sectoral expectations. Firm resources and practice pages such as /our-practices/ describe commonly available practice areas without constituting a recommendation of any particular piece of advice.Legal‑Information Disclaimer
The content of this article is intended to provide general legal information about cybercrime laws in Bangladesh as of the date published. It does not create a solicitor–client relationship, and it is not a substitute for personalised legal advice. Because legal frameworks and factual circumstances differ, readers should consult a qualified lawyer for advice specific to their situation.For broader context on TRW’s work across criminal-law information, banking, financial-regulatory, foreign-investment and dispute matters, readers can explore TRW Law Firm, its practice areas, the firm’s legal services, and the appropriate route to contact the team. These resources provide general information and do not replace advice on a particular record, transaction, regulatory question or current legal position.FAQ
What types of conduct are typically investigated as cybercrime?
Investigations often focus on unauthorised access to systems, theft of data, online fraud, dissemination of harmful or false content, identity misuse, and offences involving privacy violations such as non-consensual sharing of intimate images. The classification of conduct depends on statutory definitions and factual context; identical technical acts may give rise to different legal characterisations depending on intent, effect and the presence of aggravating factors.Can ordinary criminal offences apply to online behaviour?
Yes. General criminal offences under the Penal Code—such as fraud, extortion, defamation, or criminal intimidation—can be engaged when those acts are committed using electronic means. Prosecutors and investigators commonly rely on a combination of statute‑specific cyber provisions and traditional offences to address complex incidents.How is electronic evidence treated in court proceedings?
Electronic records are admissible subject to authentication and relevance requirements. Courts examine chain of custody, integrity of the record, expert evidence explaining technical provenance, and any indicia of tampering. Where electronic evidence is central, courts often rely on expert testimony to interpret metadata, logs and system behaviour for a non‑technical factfinder.What obligations do businesses have after a data breach?
Businesses may have obligations under sectoral regulations, contractual commitments and general duties to protect customer data. These obligations can include preserving evidence, notifying affected parties or regulators where applicable, and taking remedial steps to secure systems. Obligations vary by sector and the nature of the data involved; organisations should review applicable legal requirements and industry guidance relevant to their operations.Are there specific rules for cross‑border evidence gathering?
Cross‑border evidence gathering often involves formal mechanisms such as mutual legal assistance or preservation orders to secure data held by foreign service providers. Practical options depend on treaties, bilateral arrangements, and the willingness of foreign authorities to cooperate. Private preservation requests and service provider channels (e.g., specialist legal processes provided by global platforms) can sometimes be useful interim tools but do not replace formal legal cooperation when required.What steps can individuals take immediately after experiencing cyber harm?
Individuals should preserve relevant information (screenshots, emails, transaction records), change compromised passwords, consider securing accounts with multi‑factor authentication, and report offences to the appropriate authorities if there is loss, extortion or threat to safety. Where financial loss or identity theft is involved, affected persons should monitor accounts and consider notifying financial institutions. Seeking legal and technical advice is advisable if harm is significant or complex.How should organisations approach vendor risk related to cybersecurity?
Organisations should assess vendor security practices during procurement, include contractual protections (security standards, notification obligations, audit rights, and cooperation clauses), require timely incident notification, and periodically reassess vendor posture. Where vendors process personal data, contractual terms should address data protection responsibilities and delineate assistance in responding to incidents.Conclusion
Cybercrime law in Bangladesh encompasses statutory provisions targeted at electronic offences, supplemented by general criminal law and evidentiary rules relevant to digital material. Responding effectively to cyber incidents requires coordination among technical, legal and organisational actors; preservation and authentication of digital evidence; attention to cross‑border issues; and proportionate respect for privacy and expression. Staying informed about legislative and regulatory developments, and engaging suitably experienced advisers where matters are serious or complex, helps individuals and organisations manage risk and protect rights.CONTINUE EXPLORINGConnected
Connected
legal insight.
Let’s discuss
the detail.
For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org