TRW KNOWLEDGE · LEGAL INFORMATION
Bangladesh Computer Crime Act: Expert Legal Guide
This guide explains the legal framework commonly described as the Bangladesh computer crime regime, outlines typical categories of offences and penalty ranges, and offers practical steps for evidence preservation and risk reduction for individuals and organisations operating in Bangladesh's digital environment.
Introduction
The pace of digital change has made computer-related wrongdoing a routine legal and operational risk for people, organisations and public institutions. This article provides an accessible, source-grounded legal-information overview of the law often referred to as the Bangladesh computer crime framework. It explains how offences are commonly classified, what practical steps victims and organisations may take, and how cyber-related matters interact with other legal areas. The content is intended to inform decision-making and to help readers frame questions for legal advisers and technical specialists.How this guide is structured
The guide proceeds in discrete sections: a short explanation of the statutory context, a practical table summarising typical categories of computer‑related offences and associated penalty ranges that are commonly found in public summaries, a step‑by‑step outline of investigative stages, guidance on evidence preservation,notes on organisational risk reduction, interactions with other practice areas and a Frequently Asked Questions section. Where appropriate, the text signposts relevant institutional pages and internal practice descriptions such as /our-firm/, /our-practices/ and service pages under /services/. For advice specific to a dispute or suspected offence, consult a qualified lawyer and technical specialist via your usual contacts or through our /contact/ route.Statutory context: what to expect
In Bangladesh and comparable jurisdictions, legislation addressing computer misuse and related harms defines a set of offences (for example, unauthorised access, unauthorised interference with data, misuse of data, offences involving communications, and more serious conduct such as cyber-enabled terrorism). These statutory frameworks are typically used alongside general criminal law, data protection and sector‑specific regulations. Readers should understand that statutory texts, amendments, implementing rules and judicial interpretation together shape how an offence is investigated and prosecuted.Key offence categories and typical penalty ranges
The table below summarises common offence categories and penalty ranges that are often cited in public summaries of Bangladesh's computer‑crime legislation and related commentary. The entries are presented as informational examples rather than an exhaustive or definitive legal statement; any case-specific question should be considered against the applicable statutory text, official guidance and recent case law.| Offence category | Typical description | Penalty ranges (public summaries) |
|---|---|---|
| Unauthorised access | Accessing a computer, system or account without the owner’s permission. | Imprisonment and/or fines; public summaries commonly reference short‑term custodial periods for less severe conduct. |
| Data theft / unauthorised copying | Taking, copying or transferring protected or sensitive data without lawful authority. | Significant custodial terms and/or higher fines in public summaries for aggravated or repeated conduct. |
| Cyber harassment / communications offences | Using digital communication to intimidate, threaten or harass individuals. | Custodial sentences and/or fines; severity depends on content, persistence and harm caused. |
| Cyber‑enabled national security offences | Using computer systems to plan, assist or carry out terrorist acts or threats to public safety. | Severe penalties, including long custodial sentences in public reporting for the gravest forms of conduct. |
How investigations typically progress
While procedures vary, investigations frequently follow an observable pattern: initial report, preliminary assessment, evidence preservation and technical forensics, specialist interviews, charging decisions and, if applicable, court proceedings. The presence of digital evidence usually means agencies and technical specialists will seek seized devices, network logs and cloud records. That evidence may require careful forensic handling to preserve chain of custody and to make it admissible in court.Step-by-step practical guide for victims and organisations
The following steps are general practice guidance designed to help people and organisations respond promptly and coherently to suspected computer crime. They are high-level; specific circumstances will change the recommended actions.- Contain the incident: limit further access to affected systems to prevent escalation and data loss.
- Document everything: keep a contemporaneous log of what you observe, times and any communications. Screenshots, server logs and preservation notices can be important.
- Preserve evidence: where possible, avoid powering down devices or altering files; capture forensic images and metadata through qualified technical specialists.
- Notify appropriate internal teams: inform IT security, compliance and senior management in line with internal policies under /our-practices/ and operational plans.
- Seek legal and technical advice early: lawyers and forensic investigators can align investigative steps with legal requirements (for example, searches, warrants and preservation notices).
- Consider external reporting: depending on the nature of the incident, public authorities or specialised cyber units may need to be notified.
- Plan for communications: prepare factual, measured messages for affected stakeholders, regulators, or third parties in coordination with legal counsel.
Preserving digital evidence: practical pointers
Digital evidence is fragile and easy to alter. Practical preservation principles include isolation (take affected devices off shared networks where possible), acquisition (use forensically sound imaging tools), verification (hashing and logging), and documentation (who handled the device, when and why). Do not attempt advanced forensic work without qualified tools and personnel; accidental changes can undermine evidence integrity. Where relevant, coordinate with third parties that may hold data, such as cloud providers or telecoms, and consider preservation notices to preserve logs pending legal process.Organisational risk-reduction and compliance measures
Preventive measures reduce the likelihood and impact of computer‑related incidents. Typical elements of a coherent programme include governance and policy, technical controls, staff awareness and incident‑response planning. Governance ties cyber risk into corporate decision‑making and should clarify roles and responsibilities for investigations and reporting. Technical controls include multi‑factor authentication, timely patching, network segmentation and logging. Training and simulated incidents help staff recognise phishing and social engineering. Incident response plans should define thresholds for notification, external support and the roles of legal and technical advisers.How computer‑crime issues intersect with other legal areas
Cyber incidents commonly implicate other legal domains. Examples include employment law when internal staff conduct is at issue (consult specialist teams such as /employment-and-labor-lawyers/), financial regulation where customer assets or transactional systems are affected (see practice areas such as /financial-services-regulatory-lawyers/), and tax or cross‑border compliance in matters involving data transfers and reporting across borders (teams like /foreign-direct-investment-lawyers/ and /tax-lawyers/ may be relevant in specialised circumstances). Complex disputes may lead to courtroom work that interacts with national registry and cause lists, including reference materials such as the /supreme-court-bangladesh-cause-list/ for public dockets.Common mistakes to avoid
Typical errors that complicate resolution include: delaying reporting, unintentionally altering or destroying evidence, failing to engage technical expertise early, over‑communicating details publicly without counsel, and neglecting to coordinate internal stakeholders. Organisations should treat suspected incidents with a balance of urgency and control: respond quickly, but in a way that preserves legal options and evidential value.Working with counsel and technical specialists
When counsel are instructed, they typically coordinate legal strategy, communications with authorities and privileged legal work, while technical specialists carry out forensic acquisition, triage and remediation. Legal advisers can also help evaluate regulatory notification obligations and cross‑border data transfer constraints; multidisciplinary coordination is often essential in complex matters. Our firm’s practice descriptions under /our-practices/ and service pages under /services/ outline how legal and technical teams can be aligned in high‑risk incidents.Practical considerations for small businesses and individuals
Small entities and individuals should prioritise baseline measures: maintain updated backups stored offline, use strong unique passwords and multi‑factor authentication where available, and implement routinely audited update and patch processes. Individuals who suspect harassment or identity misuse should preserve communications and consider reporting to local law enforcement; commercial or institutional incidents should be escalated to the organisation's security team and legal counsel.Brief legal‑information disclaimer
This article provides general legal information about computer‑related offences and practical steps commonly taken in Bangladesh. It is not legal advice and does not create a lawyer‑client relationship. For advice about a specific situation, consult an appropriately qualified lawyer who can consider the full facts and applicable law.A practical preparation step is to create a concise chronology and document index. The chronology can identify relevant communications, notices, applications, filings, contracts, approvals, payments, deadlines and decisions. The index can identify the current version of each record, its source, the responsible party and any matter that still requires confirmation. This helps distinguish established facts from assumptions and focuses attention on the decision that needs to be made.It can also be useful to identify the immediate practical question, the person or authority able to confirm an uncertain point, and the date by which a response may be needed. Maintaining a clear record of these points can reduce avoidable delay and support more focused communication with relevant stakeholders. General legal information cannot determine the appropriate next step for a particular matter; the current facts and legal position should be considered together before action is taken.Frequently Asked Questions
Q: What types of conduct are most commonly investigated as computer crimes?
A: Investigations frequently focus on unauthorised access to systems, data theft, interference with computer systems or data, and online communications that form part of harassment or extortion. In some cases, digital tools are used in conjunction with other criminal activity, and investigators assess the full context. The specific statutory labels and investigative thresholds will depend on the governing legislation and prosecutorial guidance.Q: If my organisation discovers a breach, when should we notify authorities?
A: Notification timing depends on the nature and severity of the breach, any applicable regulatory requirements and contractual obligations. Early coordination with legal counsel helps determine whether a matter should be reported to law enforcement, sector regulators, or other entities. Prompt preservation of evidence and a measured disclosure strategy protect legal and commercial interests.Q: Can digital communications and social media posts be used as evidence?
A: Yes. Messages, posts, logs and metadata can form critical evidence, but their evidential value depends on how they were captured, preserved and authenticated. Forensic processes that document chain of custody, create verified copies (hashing) and preserve original metadata strengthen the reliability of digital evidence.Q: What protections are available for reporters or whistleblowers in cyber incidents?
A: Protections for reporters or whistleblowers vary by context and the specific regulatory framework. Some laws provide specific safeguards for good‑faith reporting; others protect employment rights. Legal advice can help clarify protections and the safest way to disclose information internally or to authorities.Q: How do cross‑border data flows affect investigations?
A: Cross‑border elements add complexity. Data stored with foreign cloud providers or held on servers in other jurisdictions may require legal process to obtain. Cooperation mechanisms between authorities and contractual provisions with service providers are often relevant. Legal counsel can assess mutual legal assistance options and the bounds of provider cooperation in specific cases.Q: What steps should executives take immediately after learning of a suspected incident?
A: Senior leaders should ensure that an incident response plan is activated, that relevant internal teams (IT, legal, compliance and communications) are notified, and that no action is taken that could compromise evidence. Engaging external forensic and legal advisers early helps coordinate technical containment with legal preservation and reporting requirements.Q: When might civil remedies be available in addition to criminal prosecution?
A: Civil remedies such as injunctions, damages claims or contractual relief may be available where harm can be demonstrated and parties identified. Civil and criminal proceedings can run in parallel or independently; the availability and desirability of civil action will depend on evidential strength, reputational considerations and strategic objectives.Q: How can organisations align cyber security with broader legal compliance?
A: Organisations that integrate cyber security governance with legal, privacy and compliance functions achieve more consistent outcomes. Regular risk assessments, clear policies, incident playbooks and cross‑functional drills enhance readiness. Legal teams should be involved in drafting policies and preparing for likely regulatory expectations.Further reading and internal resources
Readers seeking more information about how cyber matters relate to other practice areas can consult related internal pages and practice descriptions such as /our-firm/, /our-practices/ and specific pages under /services/. Where incidents implicate employment matters, see /employment-and-labor-lawyers/; for financial sector issues, see /financial-services-regulatory-lawyers/; and for matters with cross‑border or investment aspects, see /foreign-direct-investment-lawyers/ and /tax-lawyers/. For public court dockets that may be relevant to high‑profile matters, consult the listings such as /supreme-court-bangladesh-cause-list/. To arrange a discussion with legal and technical advisors, use the /contact/ page to request an initial engagement.CONTINUE EXPLORINGConnected
Connected
legal insight.
Let’s discuss
the detail.
For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org