TRW Knowledge / Technology, data & IP

Bangladesh Data Protection Law: Practical Guide for Organisations (2026)

This guide provides an explanatory overview of the legal and practical issues organisations should consider when processing personal data in Bangladesh as of 2026. It is intended to summarise common legal concepts, compliance measures and practical steps; it does not constitute legal advice. For application to specific facts, consult a qualified adviser.

Originally published 09 July 2026

Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
This guide provides an explanatory overview of the legal and practical issues organisations should consider when processing personal data in Bangladesh as of 2026. It is intended to summarise common legal concepts, compliance measures and practical steps; it does not constitute legal advice. For application to specific facts, consult a qualified adviser.

Introduction

Data protection is a cross-cutting legal issue for businesses, public bodies and non-profit entities. In Bangladesh, the regulatory environment has been developing in recent years. This guide summarises the principal elements that commonly appear in modern data protection frameworks and sets out practical measures organisations typically consider to reduce legal and operational risk. Where the status of legislation or regulation is time-sensitive, readers should confirm the current position with the relevant government authority or a lawyer.Bangladesh’s technology-law framework should be described precisely. The official Bangladesh Laws database lists the Information and Communication Technology Act, 2006, which addresses legal recognition and security for information and communication technology, including electronic records and signatures. It is distinct from cyber-security and personal-data instruments.The same official database lists the Cyber Security Ordinance, 2025, whose official preamble states that it repeals the Cyber Security Act, 2023. It separately lists the Personal Data Protection Ordinance, 2025, addressing protection of personal data and lawful processing with consent. The relevant statutory text, any later instrument and applicable sectoral requirement must be checked against the facts before a legal position is taken.

2026 update

As of mid-2026, public debate and administrative activity continue around consolidation of data protection rules in Bangladesh. Some provisions that commonly appear in recent legislative drafts in other jurisdictions — for example, explicit data subject rights (access, rectification and erasure), obligations on data controllers and processors, breach notification duties, and rules for cross-border transfers — are reflected in draft proposals and policy statements seen in public materials. Whether, when and in what form a final consolidated Data Protection Act will be enacted and implemented is a matter for the legislature and relevant administrative authorities. Readers should consult notices published by the Ministry of Posts, Telecommunications and Information Technology and other competent bodies for authoritative updates (for example, https://mpt.gov.bd/).

Scope and interaction with existing laws

Organisations in Bangladesh typically must consider multiple statutes and regulatory instruments when assessing privacy and data protection obligations. Historically relevant instruments have included the Information and Communication Technology Act, 2006 and the earlier digital-security legislation (now requiring current-text verification), along with sectoral rules administered by regulatory bodies. A consolidated data protection statute, if enacted, is likely to sit alongside — and interact with — existing laws governing cybercrime, telecommunications, employment, banking and other regulated activities.

Key practical point

Do not treat a single document as definitive without checking the current official sources. Where statutory consolidation occurs, transitional provisions may affect obligations and compliance timelines.

Core principles that commonly appear in modern data protection frameworks

The following principles summarise concepts frequently adopted in data protection laws internationally and often found in legislative drafts. Use this list as a framework for internal review rather than as a substitute for statutory language:
  • Lawfulness, fairness and transparency — processing should have a lawful basis and individuals should be informed.
  • Purpose limitation — personal data should be collected for specified, explicit and legitimate purposes.
  • Data minimisation — only data necessary for the purpose should be processed.
  • Accuracy — reasonable steps should be taken to keep data accurate and up to date.
  • Storage limitation — personal data should be retained only as long as necessary for the purpose.
  • Integrity and confidentiality — appropriate technical and organisational measures should protect data.
  • Accountability — controllers should be able to demonstrate compliance with applicable obligations.

Typical rights of data subjects

Drafts and modern data protection laws commonly provide individuals (data subjects) with a range of rights. Organisations should map incoming requests and have procedures that allow timely handling of rights requests while verifying the requester’s identity. Common rights include:
  • Right of access — to confirm whether personal data is being processed and to receive a copy of personal data subject to applicable exemptions.
  • Right to rectification — to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) — subject to legal limits such as retention obligations or legitimate interests.
  • Right to restriction of processing — to suspend processing in certain circumstances.
  • Right to data portability — to receive personal data in a structured, commonly used format where technically feasible and where a lawful basis exists.
  • Right to object — to certain processing, particularly for direct marketing or where processing is based on legitimate interests.
Practical note: rights are often subject to verification, exemptions and procedural conditions (for example, time limits and fee rules). Adopt a documented procedure for managing rights requests, including identity checks, response timelines and escalation.

Controller and processor obligations

Modern regimes distinguish between controllers (entities that determine purposes and means of processing) and processors (entities that process personal data on behalf of a controller). Typical obligations placed on controllers and processors include:
  • Maintaining records of processing activities (scope, categories of data, retention periods, legal bases).
  • Implementing appropriate technical and organisational security measures (encryption, access control, logging, secure disposal).
  • Carrying out data protection impact assessments (DPIAs) where processing is likely to result in high risk to individuals.
  • Ensuring contracts with processors contain required clauses (instructions, security measures, sub-processing rules, assistance with rights requests).
  • Designating contact points for data protection matters (internal or public-facing).

Practical checklist for contracts with vendors

  1. Identify the role (controller, joint controller, processor).
  2. Define permitted purposes and technical measures.
  3. Set breach notification timing and cooperation obligations.
  4. Include audit and inspection rights consistent with local law.
  5. Specify sub-processor rules and liability allocation.

Data breach notification and incident response

Many modern data protection laws require controllers to notify a designated authority and, where appropriate, affected individuals about personal data breaches within a specified timeframe unless the breach is unlikely to result in risk to rights and freedoms. Even where statutory time limits differ or are not yet finalised domestically, organisations should have an incident response plan that includes:
  • Internal escalation pathways and roles.
  • Criteria for deciding whether external notification is required.
  • Prepared communications for regulators, affected individuals and media (fact-based, without speculation).
  • Legal and technical steps to contain and remediate the incident.
Because statutory notification requirements vary, consult the relevant authority or counsel before issuing formal notices to ensure compliance with timing and content obligations.

Cross-border transfers and international considerations

Cross-border data transfers are commonly regulated to ensure that data leaving a jurisdiction continues to receive an adequate level of protection. Possible mechanisms for lawful transfers include adequacy decisions by the relevant authority, contractual safeguards, binding corporate rules and approved standard contractual clauses. If your organisation transfers personal data outside Bangladesh, consider:
  • Mapping data flows — know what data leaves the country, where it goes and why.
  • Assessing the legal basis for each transfer and whether specific authorisations are required.
  • Implementing contractual protections that reflect applicable law; review vendor terms for compatibility with local requirements.
  • Monitoring developments in other jurisdictions that affect data transfer mechanisms.
Note: do not assume a particular transfer mechanism is acceptable without checking current official guidance and any implementing regulations.

Sector-specific issues

Certain sectors — for example, financial services, healthcare and telecommunications — may be subject to additional confidentiality, retention and reporting obligations under sectoral laws and regulator rules. Organisations in regulated sectors should coordinate privacy compliance with sectoral regulatory teams. TRW’s practice pages discuss regulatory and sector experience in more detail (see https://trw.org/our-practices/ and https://trw.org/financial-services-regulatory-lawyers/).

Employment and HR data

Processing employee data raises specific issues, including lawful bases for processing, monitoring at work, access to records, and the intersection of labour law and data protection. Typical employer steps include:
  • Documenting lawful bases for processing payroll, benefits, health and performance data.
  • Limiting access to HR data and maintaining retention schedules aligned with labour law.
  • Providing employees with privacy notices and avenues to exercise rights.
Where employment law imposes conflicting requirements, seek tailored legal advice to reconcile obligations.

Data protection by design and by default

Embedding privacy considerations into projects, procurement and system design reduces later compliance costs and operational risk. Practical measures include minimisation of data collection, pseudonymisation, privacy-friendly default settings and security testing as part of development lifecycles. Document design decisions to support accountability.

Data protection impact assessments (DPIAs)

DPIAs are structured evaluations of high-risk processing operations. Typical DPIA elements are:
  • A description of the processing operations and purpose.
  • An assessment of necessity and proportionality.
  • An assessment of risks to individuals’ rights and freedoms.
  • Measures envisaged to address risks, including safeguards and mechanisms to ensure protection.
Carrying out DPIAs for new projects that involve large-scale or sensitive processing is a prudent step even where legislation does not explicitly require one.

Record-keeping and demonstrable compliance

Organisations should maintain records of processing activities that demonstrate how data protection principles are applied. Records typically include:
  • Categories of personal data and recipients.
  • Retention periods and deletion schedules.
  • Legal bases for processing.
  • Details of security measures and DPIAs.
Well-maintained records assist with internal governance and with responding to supervisory authority enquiries or data subject requests.

Enforcement and penalties: a cautious approach

Enforcement frameworks in different jurisdictions may include administrative fines, requirements to cease processing, civil liability or criminal sanctions in particular circumstances. Do not infer specific penalties unless they are set out in statute or regulation; verify through official sources and legal counsel. The practical implication is the same: failure to adopt reasonable measures can lead to financial, operational and reputational consequences.

Practical, step-by-step compliance guide

The following structured approach is commonly used by organisations preparing for comprehensive data protection obligations:
  1. Governance and inventory: appoint responsibility (data protection lead or committee) and create an inventory of processing activities.
  2. Risk assessment: prioritise processing activities that involve sensitive data, large datasets or cross-border transfers.
  3. Policies and procedures: draft privacy notices, data retention policies, vendor and data breach procedures.
  4. Contracting: update supplier and customer contracts to reflect data protection responsibilities.
  5. Technical controls: implement encryption, access control, monitoring and secure backup systems.
  6. Training: provide role-specific training for staff who handle personal data.
  7. Testing and audits: conduct periodic audits and penetration testing as appropriate.
  8. Continuous improvement: monitor legal developments and update controls and documentation.

Common compliance mistakes to avoid

Organisations commonly fall into a few avoidable traps:
  • Underestimating the scope of personal data — metadata and identifiers in logs can be personal data.
  • Failing to document decision-making and lawful bases for processing.
  • Relying on verbal assurances from vendors instead of written contractual commitments.
  • Neglecting retention schedules — keeping data indefinitely increases risk.
  • Treating security as solely an IT issue rather than a cross-functional responsibility.

Addressing cross-border vendor relationships

When contracting with vendors outside Bangladesh, ensure contracts require sufficient protections, describe subprocessors and include cooperation obligations for incident response and rights requests. If a legislative framework introduces specific transfer mechanisms or approval procedures, update documentation promptly to reflect those requirements.

Interplay with other regulatory requirements

Data protection compliance should be integrated with broader regulatory obligations (for example, anti-money laundering, tax reporting and consumer protection). Work with regulatory teams and external counsel to harmonise obligations and avoid conflicting duties.

Practical examples of internal controls

  • Role-based access control to sensitive datasets with quarterly access reviews.
  • Automated retention workflows that flag data for review prior to deletion.
  • Template clauses for customer and supplier contracts covering permitted purposes and security measures.
  • Pre-approved DPIA templates for new projects involving profiling or automated decision-making.
Consider obtaining tailored legal advice in at least the following circumstances:
  • When interpreting statutory obligations or when a new statute or regulation is published.
  • Where processing carries a high risk to individuals’ rights and freedoms (sensitive categories, systematic profiling, large-scale public data).
  • When responding to regulator enquiries, investigations or enforcement actions.
  • For drafting or negotiating complex cross-border data transfer agreements and binding corporate rules.

Practical resources and internal training

Develop role-specific training modules for staff who handle personal data and produce concise quick-reference guidance for managers. If needed, law firms and consulting providers can provide templates and delivery of training programs. For organisational governance materials and to understand advisory services available from TRW, see https://trw.org/services/ and https://trw.org/our-firm/.

Regulatory contacts and official sources

For official publications and guidance, consult the websites of relevant Bangladeshi authorities. One source visitors commonly consult for policy publications is the Ministry of Posts, Telecommunications and Information Technology (https://mpt.gov.bd/). Do not treat any third-party commentary as a substitute for official text or independent legal advice.

Record retention and deletion practices

Adopt a documented retention schedule that aligns with legal obligations and business needs. Retention policies should identify categories of records, retention periods, legal bases for retention and deletion procedures. Maintain an audit trail of deletions where practicable.

Handling regulator enquiries and investigations

If an authority contacts your organisation, act promptly: assemble requested documentation, designate an internal point of contact and consider contemporaneous legal advice. Preserve relevant evidence and avoid unilateral public statements without counsel review.

Example compliance timeline for a mid-size organisation

Below is an illustrative timeline for organisations implementing a baseline compliance programme; adapt timing to organisational size and complexity:
  • Weeks 1–4: Inventory and risk assessment.
  • Weeks 5–8: Policy drafting (privacy notice, retention, incident response) and initial vendor contract review.
  • Weeks 9–12: Implement technical controls, role-based access and secure backups.
  • Months 4–6: Staff training and desktop incident response testing; begin DPIAs for priority projects.
  • Ongoing: Quarterly reviews, audits and updates to documentation.

Practical considerations for small businesses and startups

Smaller organisations should prioritise proportionate measures: inventory, clear privacy notice, minimal data collection, and selecting reputable vendors with appropriate security. Consider appointing an external data protection adviser on a retainer basis for periodic reviews.

Five practical FAQs

Q: What is the purpose of the Bangladesh data protection law?

A: The primary purpose, as in many modern data protection frameworks, is to protect individuals’ personal data and privacy rights while providing a regulatory structure for organisations that collect and process personal data; organisations should review the relevant statutory text and official guidance to confirm the current scope and obligations.

Q: Who is affected by the Bangladesh data protection law?

A: Entities that process the personal data of individuals in Bangladesh — including local organisations and foreign entities offering goods or services to individuals in Bangladesh — are commonly within the scope of such laws; confirm the territorial and material scope against the final statutory text and administrative guidance.

Q: What are the penalties for non-compliance with the Bangladesh data protection law?

A: Potential enforcement measures typically range from administrative orders to civil or criminal sanctions depending on statutory provisions; consult the enacted legislation and official guidance or obtain legal advice for information about specific penalties and enforcement procedures.

Q: How can organisations ensure compliance with the law?

A: Organisations can adopt a structured programme: conduct a processing inventory, implement appropriate policies and technical controls, train staff, document decisions and maintain vendor contracts that address data protection; tailored legal advice is advisable for complex issues.

Q: What should I do if my personal data is mishandled?

A: If you believe your personal data has been mishandled, consider preserving evidence, reporting the incident to the relevant authority and seeking legal advice to understand available remedies and next steps; timelines and procedures for complaints depend on the applicable statutory framework and administrative guidance.

Next steps and practical help

Organisations that wish to take concrete next steps typically begin with an internal audit and a prioritised remediation plan. For assistance with implementation, policy drafting, vendor contract clauses and incident response planning, external legal or consulting resources can provide project-based or retained support. To learn about services that may be relevant to regulatory and transactional issues, see https://trw.org/services/ and https://trw.org/our-practices/.

Concluding remarks and a caution

Data protection law is an evolving area. This guide sets out common features and practical measures that organisations often find useful, but it is not a substitute for professional advice tailored to your factual circumstances. Confirm the current status of any proposed or enacted provisions with official sources and counsel.ContactIf you require more detailed, context-specific guidance, you may wish to contact a specialist adviser. For queries about related regulatory matters, corporate arrangements or sector-specific obligations, TRW provides services detailed at https://trw.org/our-firm/ and sector pages such as https://trw.org/financial-services-regulatory-lawyers/ and https://trw.org/tax-lawyers/.To arrange an initial discussion, please use the booking link or email the firm directly: Book consultation or info@trw.org.Source note: This 2026 review uses the official titles above. Historical labels in the URL are retained for continuity only and should not be treated as a statement of the current legal framework.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.