TRW Law Firm·Dhaka · London · Dubai · Singapore

Practice Areas

Litigation & Disputes

Explore this practice
People

Experience when it matters most.

Meet the lawyers and professionals behind TRW’s advice, advocacy and commercial judgement.

Insights

Perspective for the decisions ahead.

Follow legal developments, market change and TRW announcements.

The Firm

TRW Law Firm.
Clear in purpose.

TRW Law Firm is a full-service international law firm based in Dhaka.

TRW Knowledge / Technology, data & IP

Bangladesh Cybercrime Legal Framework: Practical Guide and 2026 Update

This article explains the legal framework that applies to cybercrime in Bangladesh as of 2026, how enforcement typically operates, and practical steps individuals and organisations can take when digital incidents occur. The coverage is explanatory and does not substitute for legal advice tailored to a particular situation; readers should consult the primary legislation, official authorit

Originally published 19 June 2026

Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.

Introduction

This article explains the legal framework that applies to cybercrime in Bangladesh as of 2026, how enforcement typically operates, and practical steps individuals and organisations can take when digital incidents occur. The coverage is explanatory and does not substitute for legal advice tailored to a particular situation; readers should consult the primary legislation, official authorities, or qualified counsel for case-specific guidance.

Scope and primary sources

The principal statutory instrument commonly relied on for criminal conduct carried out by digital means is the Digital Security Act, 2018. Other legal instruments that remain relevant to online conduct are the Information and Communication Technology (ICT) Act, 2006, the Penal Code, 1860 and the Evidence Act, 1872. These laws interact in practice: the Digital Security Act provides provisions that address offences occurring in digital environments, the Penal Code supplies general criminal offences, and the Evidence Act governs admissibility and treatment of evidence. Where statutory text is determinative, readers should consult the official legislation and gazette notice for the most current wording.

Principal categories of offences

Legislative instruments and public summaries commonly identify several recurring categories of cyber-related misconduct. In broad terms, and without concluding legal characterisations, these categories include:
  • Unauthorized access to computer systems or networks (commonly described as "hacking");
  • Acquisition, copying or disclosure of data without lawful authority (often referred to as data theft or unlawful data access);
  • Use of digital communications to threaten, harass or defame individuals (online harassment and related conduct);
  • Dissemination of false or misleading information online that may affect public order or individual rights (sometimes characterised in public materials as misinformation or disinformation); and
  • Digital fraud, identity misuse and financial schemes facilitated by electronic means.
The statutory texts contain definitions, offence elements and penalties. Where a legal or factual dispute exists about whether particular conduct falls within an offence, that question depends on statutory interpretation and the facts of the case; readers should consult the legislative provisions themselves and seek legal advice for application to specific incidents.

Penalties and remedies: cautious overview

Public summaries of the applicable laws describe a range of penalties, which historically have included fines and terms of imprisonment for certain offences. Media reporting and tertiary sources have reported examples of maximum custodial terms for selected offences, but any particular situation requires reference to the relevant provision in the applicable statute and, where relevant, to subsequent amendments and judicial decisions. For definitive statements about penalties in a given case, consult the text of the Digital Security Act, the Penal Code, and the official gazette or an authorised legal database.

Jurisdiction and enforcement agencies

Law enforcement agencies with responsibilities for investigating cyber-related offences include units within the police that focus on cyber incidents and the Criminal Investigation Department (CID). The Bangladesh Police maintains an online presence for public information about police services; it can be an initial point of contact for reporting an incident: https://www.police.gov.bd/ . In practice, complex digital investigations frequently involve dedicated cybercrime investigation units and may require technical support from forensic specialists, private cybersecurity providers, or relevant government IT authorities.

Evidence, preservation and admissibility

Digital evidence presents particular legal and technical challenges. Key principles that recur in practice are:
  • Preserve evidence promptly: retain original devices, take forensic images where appropriate, and keep logs of what is done to preserve chain of custody;
  • Avoid alteration of data: do not alter, delete or overwrite files or logs unless under professional direction; inadvertent changes can affect admissibility;
  • Document steps taken: maintain a contemporaneous record of all actions taken in relation to the incident (who did what, when and why); and
  • Use qualified forensic practitioners: where forensic analysis is necessary, engage persons who can provide methodology and provenance statements that will be acceptable in court or regulatory proceedings.
The Evidence Act, 1872 governs admissibility issues and provides evidentiary rules that courts apply. The precise treatment of electronic evidence can turn on statutory provisions, evidentiary practice, and judicial assessment of authenticity and reliability.

Reporting and investigation: practical steps

The following steps describe an operational approach that is used in many digital-incident scenarios. This description is explanatory and not prescriptive; organisations and individuals should tailor responses to their circumstances, statutory obligations, sectoral regulations, and contractual duties.
  1. Immediate technical containment: Limit further access or damage by isolating affected devices or systems where feasible. These actions should be coordinated with IT and legal advisors to preserve evidence.
  2. Document the incident: Capture screenshots, metadata, email headers, server logs, timestamps and any other artefacts that show the incident and actions taken.
  3. Engage forensic and cybersecurity expertise: Use independent or accredited forensic analysts to secure and analyse data; ask for written reports that explain methods and findings.
  4. File a police report: Where a criminal offence is suspected, file a formal report with the local police station or the specialised cyber unit. Keep an official copy and a reference number for follow-up.
  5. Notify specialised enforcement units: If necessary, inform the Criminal Investigation Department (CID) or the police cybercrime unit for specialist handling of the matter.
  6. Consider civil remedies and regulatory notifications: Decide whether to pursue civil relief (injunctions, damages) or to make regulatory notifications; requirements will vary by sector and by contractual undertakings.
  7. Follow up: Maintain regular contact with investigators and retain counsel to protect legal rights and to coordinate any disclosure obligations.
When reporting to law enforcement, provide a clear chronology, copies of preserved evidence, and contact details for technical persons who can explain logs or forensic findings.

Interactions with internet service providers and intermediaries

Service providers and intermediaries frequently play a central role in investigations—by supplying logs, blocking material, or taking down content under lawful process. Where providers are located in other jurisdictions or under different legal regimes, cooperation may require formal mutual legal assistance or preservation requests. Organisations should consider including incident-response clauses and cooperation protocols in third-party contracts so that service-level expectations are clear before an incident occurs.

Cross-border and mutual assistance considerations

Cyber incidents often involve actors, infrastructure or data located outside Bangladesh. Cross-border evidence gathering and enforcement can involve:
  • Mutual legal assistance treaties or letters rogatory;
  • International cooperation through police liaison channels; and
  • Coordination with foreign service providers subject to other jurisdictions' legal processes.
Cross-border processes can be slow and constrained by differing legal standards for evidence, privacy protections and procedural safeguards. Legal advice is essential where foreign cooperation or data transfer is contemplated.

Practical risk-reduction measures for organisations

Proactive measures reduce the likelihood and impact of incidents. Commonly recommended actions include:
  • Maintain up-to-date incident response plans that set out legal and technical responsibilities;
  • Train employees on phishing, credential hygiene and secure remote access;
  • Apply technical controls: logging, multi-factor authentication, network segmentation and regular patching;
  • Conduct periodic penetration testing and tabletop exercises that include legal and PR stakeholders; and
  • Establish contracts with forensic and incident-response providers so they can be quickly engaged when needed.
These measures do not eliminate risk but can materially reduce the likelihood of successful attacks and improve detection and response times.

Common procedural pitfalls

Investigations and prosecutions can be undermined by common mistakes, including:
  • Failing to preserve evidence promptly or allowing uncontrolled access to affected systems;
  • Not engaging forensic expertise early, which can affect the quality of analysis and admissibility of evidence;
  • Overly public commentary that prejudices investigations or civil litigation;
  • Missing statutory or contractual notification obligations because of uncertainty about who must be informed; and
  • Assuming that informal requests to foreign providers will result in rapid cooperation without formal legal process.
Given these pitfalls, legal and technical coordination at an early stage is usually critical.

2026 update

Observers and public sources indicate continued legislative and administrative attention to cybercrime issues in Bangladesh through 2024–2026. Reported themes in recent public discussion include measures intended to strengthen investigative capacity, training for law enforcement, and awareness-raising for the public. Where summaries refer to "increased penalties" or operational changes, readers should verify those reports against the official statutory text and government publications. For current procedural guidance or to confirm amendments, consult the official legislation or authorised government notices and consider obtaining tailored legal advice.

How TRW Law Firm can assist

When a digital-incident affects legal rights or business operations, law firms typically provide a combination of services such as advising on reporting strategy, coordinating with forensic experts, drafting formal complaints and civil claims where available, and representing clients in court or regulatory proceedings. TRW provides practice information and contact points on its website regarding firm organisation, practice areas and services: https://trw.org/our-firm/ , https://trw.org/our-practices/ , https://trw.org/services/ and https://trw.org/contact/ . Readers should treat such material as introductory and obtain advice specific to their facts.

Sector-specific considerations

Different sectors — for example, financial services, telecommunications, or media — face particular regulatory overlays. Where sectoral laws apply, obligations such as data handling, mandatory reporting, or consumer protection duties may affect how an incident must be handled. For regulated financial activities, specialist regulatory advice may be required; TRW has practice pages that explain regulatory services relevant to financial services and taxation: https://trw.org/financial-services-regulatory-lawyers/ and https://trw.org/tax-lawyers/ .

When to involve counsel

Counsel should be engaged early where there is any risk of criminal investigation, regulatory action, or civil exposure. Legal advisers can help to:
  • Assess whether conduct amounts to a reportable offence, and advise on the benefits and risks of reporting;
  • Protect privilege and advise on what technical communications may be privileged;
  • Manage disclosure obligations in litigation or regulatory proceedings; and
  • Coordinate external communications to minimise legal risk while preserving relationships with stakeholders.

Practical checklist for immediate response

Below is a short checklist to consider in the first 72 hours after detection. This is a general checklist and should be adapted to the incident and applicable law.
  1. Isolate affected systems if that will not destroy evidence.
  2. Engage IT and forensic responders to image and document affected systems.
  3. Notify internal legal counsel and relevant executives.
  4. Collect and preserve logs, email headers and other relevant metadata.
  5. Decide whether to notify police or regulatory authorities, and prepare factual materials to support any report.
  6. Consider communications to affected parties and prepare a holding statement that protects legal interests.

Five practical frequently asked questions

Q: What types of cybercrimes are recognised under the Bangladesh cybercrime legal framework?

A: The statutory framework and related materials commonly describe offences such as unauthorised access to computer systems, unlawful acquisition or disclosure of data, online harassment and the dissemination of false information; whether particular conduct meets any statutory offence requires reference to the specific legislative provision and factual analysis, so seek case-specific legal advice.

Q: How can I report a cybercrime in Bangladesh?

A: Reporting is typically initiated by documenting the incident, filing a police report at the local police station or through a specialised cyber unit, and, where necessary, notifying the CID or other specialised investigators; preserve evidence first and consult counsel to coordinate reporting strategy.

Q: What penalties apply for cybercrime offences in Bangladesh?

A: Penalties described in public summaries include fines and custodial sentences for certain offences, but precise penalties depend on the applicable statutory provision and any amendments or judicial interpretations; confirm the current statutory text or consult qualified counsel for definitive information.

Q: Can I seek legal representation for cybercrime cases?

A: Yes. Engaging legal representation early is advisable where criminal, regulatory or civil exposure is possible; lawyers can coordinate with technical specialists, advise on reporting, and represent clients in subsequent proceedings.

Q: What role does TRW Law Firm play in cybercrime cases?

A: TRW can provide legal advice on reporting strategy, assist in interactions with law enforcement and regulators, coordinate with forensic specialists, and represent clients in civil and criminal proceedings; readers should contact the firm to discuss the specifics of their case.

Reporting contacts and official sources

For law enforcement reporting, the Bangladesh Police website is a public contact point: https://www.police.gov.bd/ . For legislative text, consult the official government publications or authorised legal databases that publish acts and amendments. For any specific question about how a statutory provision applies, obtain legal advice or consult the text of the relevant statute as published in the official gazette.

Concluding remarks

The legal framework addressing cyber-related conduct in Bangladesh comprises multiple statutes and procedural rules that must be read together and applied to the facts of each case. Effective management of cyber incidents requires coordination between technical responders, legal advisers and law enforcement. This article provides a practical overview and does not substitute for legal advice tailored to the facts of an individual matter.For further information about the firm’s practice areas and how we work with clients on cyber-incident matters, see https://trw.org/our-practices/ and https://trw.org/services/ . For queries about regulatory or sector-specific issues, refer to https://trw.org/financial-services-regulatory-lawyers/ and https://trw.org/tax-lawyers/ . To discuss a particular incident, visit https://trw.org/contact/ .Book consultation or email info@trw.org to arrange a confidential discussion.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.