TRW Knowledge / Technology, data & IP

E‑Commerce in Bangladesh: Legal Guide for 2026

This article provides a cautious, practice‑oriented overview of the legal and regulatory considerations relevant to operating an e‑commerce business in Bangladesh in 2026. It summarises primary statutory frameworks, common compliance requirements, practical steps for market entry and ongoing operations, and the types of regulatory risks businesses commonly face. Nothing in this publicati

Originally published 19 June 2026

Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
This article provides a cautious, practice‑oriented overview of the legal and regulatory considerations relevant to operating an e‑commerce business in Bangladesh in 2026. It summarises primary statutory frameworks, common compliance requirements, practical steps for market entry and ongoing operations, and the types of regulatory risks businesses commonly face. Nothing in this publication is legal advice; readers should obtain tailored guidance from a qualified adviser for matters specific to their facts.

Overview

Over the last decade, Bangladesh's online marketplace has expanded significantly. Greater internet access, increased mobile adoption and new payment technologies have amplified commercial opportunities while also drawing regulatory attention to issues such as consumer protection, data security, taxation and electronic transaction integrity. This guide organises the principal legal considerations that operators, investors and advisers typically assess when launching or operating e‑commerce services in Bangladesh.Multiple statutes and subordinate instruments intersect in this area. The principal laws commonly engaged in e‑commerce matters include:
  • Digital Security Act, 2018 — addresses offences and obligations concerning digital systems and information security;
  • Information and Communication Technology Act, 2006 — provides a legal basis for electronic transactions and certain cyber offences (note: some provisions have been amended or superseded and may be read together with later instruments);
  • Consumer Rights Protection Act, 2009 — establishes consumer protections relevant to online sales, advertising and remedies; and
  • Tax and VAT laws and attendant rules — including obligations under the Income Tax Ordinance and VAT legislation that apply to digital sales, platform operators and service providers.
These laws do not operate in isolation: sectoral regulators, administrative guidance and contractual terms also shape obligations. For example, registration and licensing requirements involve the Registrar of Joint Stock Companies and Firms (RJSC) and municipal trade licensing authorities, while tax authorities administer TIN and VAT registration. Where the precise application of a statute depends on particular facts, obtain specific legal advice and verify requirements with the official regulator.

Key regulatory actors

  • Registrar of Joint Stock Companies and Firms (RJSC) — corporate registration and business entity records (see the RJSC website for registration processes: https://www.roc.gov.bd/).
  • National Board of Revenue (NBR) — tax and VAT administration.
  • Sectoral regulators or authorities — depending on the service (for example, payment service providers and banking interfaces may implicate the Bangladesh Bank regulatory framework).
  • Law enforcement and prosecutorial bodies — enforcement of cyber security and criminal offences under the Digital Security Act and other laws.

2026 update

Regulatory attention to e‑commerce continued into 2024–2026. Stakeholders should be aware that: (a) the government and regulators have signalled work on clarifying tax treatment of digital goods and services; (b) guidance and enforcement relating to data security and digital offences remain active; and (c) some administrative practices around registration, tax collection and payment gateway approvals have been updated by regulators since 2023.These observations are descriptive and not exhaustive. For a definitive position on current rules and any recent amendments in 2026, consult the text of the relevant statutes and the websites or published circulars of the specific regulators or seek advice from a qualified local lawyer or tax adviser.

Registration and structuring

Decisions on entity form and registration affect taxation, compliance burdens and commercial relationships. Common steps include:
  1. Choosing an entity type (private limited company, public limited company, partnership, sole proprietorship) appropriate to the business strategy and financing plan;
  2. Registering the chosen entity with the RJSC and obtaining attendant documents such as a certificate of incorporation and memorandum and articles; visit the RJSC site for procedure and forms: https://www.roc.gov.bd/;
  3. Securing required local trade licenses and municipal permits where a physical presence or warehousing is involved;
  4. Registering for tax identification (TIN) and, where thresholds are met, VAT registration with the National Board of Revenue;
  5. Ensuring any regulated activities (for example, financial services or payment processing) have the necessary approvals from sectoral regulators.
Because registration and licensing requirements can vary by location and activity, businesses should identify which permits are material to their operations and confirm current procedures with the relevant authorities.

Data protection and cybersecurity

Data security is a central compliance concern for e‑commerce operators. The Digital Security Act addresses a range of digital offences and includes provisions that bear on how organisations collect, store and process personal data. Key practical considerations include:
  • Mapping personal data flows — identify what categories of personal data you collect, the lawful basis for processing, storage locations and retention periods;
  • Technical and organisational measures — implement proportionate security controls (access controls, encryption, secure development practices, incident response procedures) and keep records of those measures;
  • Privacy notices and terms — publish clear information for users about data collection, use, retention and rights (subject access, correction and deletion where applicable);
  • Third‑party vendors — conduct vendor due diligence and reflect security and compliance obligations in contracts with payment gateways, cloud providers and fulfilment partners;
  • Incident reporting — establish internal procedures to detect, contain and report incidents, bearing in mind that some incidents could trigger law enforcement or regulatory notifications.
Technical and legal advice should be obtained to tailor data protection measures to the volume and sensitivity of the data processed.

Consumer protection and platform obligations

The Consumer Rights Protection Act sets out general duties and remedies aimed at preventing misleading conduct and ensuring fair treatment of consumers. For online sellers and platforms, practical implications typically include:
  • Transparent pricing and clear disclosure of total costs, including taxes, shipping and fees;
  • Clear return, refund and cancellation policies, including any statutory remedies that may apply;
  • Labelling and product safety information where applicable;
  • Accessible and timely customer service channels, and a record of communications that may be relevant in a dispute;
  • Mechanisms to address consumer complaints and escalate unresolved matters to appropriate dispute resolution forums.
Operators should avoid assumptions about how statutory consumer remedies apply to a particular product or service without tailored advice.

Payment gateways, settlement and financial compliance

Integration with payment gateways raises regulatory, contractual and technical considerations. Key topics are:
  • Selection of a payment service provider that has the necessary approvals and contractual arrangements for settlement and chargebacks;
  • Compliance with anti‑money laundering (AML) and know‑your‑customer (KYC) rules where these apply to the payment flows or beneficiary accounts;
  • Allocation of liability for fraud, unauthorised transactions and data breaches in contracts with payment service providers;
  • Reconciliation and recordkeeping to support tax reporting and customer refunds.
Given the interplay between banking regulation and digital payments, consult regulators or qualified advisers about the regulatory status of a proposed gateway or wallet arrangement.

Taxation and VAT

Tax obligations for e‑commerce businesses can include corporate income tax, withholding taxes, and value added tax (VAT) or similar indirect taxes. Practical matters to consider:
  • Registration for tax (TIN) and for VAT when the taxable turnover threshold is exceeded;
  • Determination of the place of supply for VAT purposes for digital goods and cross‑border services;
  • Appropriate collection and remittance of VAT on sales to consumers, and documentation to support input tax claims where relevant;
  • Recordkeeping to support income tax compliance and to respond to any tax authority enquiries.
Tax treatment may turn on transactional facts and cross‑border elements; consult a qualified tax adviser for precise treatment and for planning to address VAT or withholding tax exposure.

Contracts, website terms and marketplace arrangements

Contractual documentation limits commercial and regulatory risk. Consider the following documents and features:
  • Terms of service and acceptable use policies that set out the contractual relationship with users;
  • Privacy policies describing data practices and the rights of data subjects;
  • Supplier and vendor agreements (including fulfilment, logistics and returns handling);
  • Marketplace agreements that allocate responsibilities between platform operators and third‑party sellers; and
  • Dispute resolution clauses (including jurisdiction, governing law and arbitration provisions) that reflect enforceability constraints in cross‑border disputes.
Drafting should be informed by the applicable law and the intended allocation of commercial risks; plain language and conspicuous disclosures help reduce disputes and regulatory attention.

Dispute resolution and enforcement risk

E‑commerce disputes may involve consumer complaints, intellectual property claims, payment disputes and regulatory enforcement. Consider establishing:
  • Internal complaint handling procedures and timeframes for response;
  • Escalation pathways for potential enforcement matters; and
  • Alternative dispute resolution mechanisms, where suitable, to manage costs and timelines.
When enforcement action is threatened or commenced, obtain legal advice promptly to understand procedural rights, potential remedies and the practical steps to mitigate risk.

Practical step‑by‑step checklist for market entry

The following checklist outlines typical steps for launching commerce operations in Bangladesh. It is indicative and should be adapted to your business model and regulatory environment.
  1. Decide on a business model (direct retailer, marketplace operator, platform for services) and select an entity type;
  2. Register the business with RJSC and obtain required permits and municipal trade licenses (https://www.roc.gov.bd/);
  3. Register for TIN and, if required, VAT with the National Board of Revenue;
  4. Draft website and platform terms, privacy policy and returns policy; publish conspicuously on the website;
  5. Engage vetted payment gateways and put in place contracts allocating liability and responsibilities;
  6. Implement data security measures proportionate to the personal data processed and maintain incident response procedures;
  7. Set up customer support and complaint handling processes consistent with consumer protection expectations;
  8. Maintain transaction records, stock and tax documentation to meet statutory retention and audit requirements;
  9. Monitor regulatory developments and update policies and contracts as required.

Common mistakes and how to avoid them

Operators commonly make several avoidable errors that attract regulatory attention or commercial disputes:
  • Neglecting data security: failing to implement basic controls and incident response plans;
  • Inadequate consumer disclosures: unclear pricing, terms or refund policies that provoke complaints or enforcement action;
  • Failure to register or to account for VAT and tax obligations in pricing and reporting;
  • Insufficient vendor contracts that leave platform operators exposed to liability for third‑party seller conduct;
  • Failure to keep accurate transactional records and reconciliation documents, which complicates tax compliance and dispute resolution.
Addressing these areas early reduces operational risk and assists in demonstrating good faith in regulatory interactions.

Cross‑border sales and international considerations

Cross‑border e‑commerce raises additional considerations, including customs, withholding taxes, differing consumer protection regimes and cross‑border data transfers. Key points:
  • Determine customs duties and import regulations that apply to goods sold from abroad into Bangladesh;
  • Consider whether the business presence in Bangladesh triggers permanent establishment or other tax nexus concerns;
  • Consider contractual and operational measures for cross‑border fulfilment, returns and dispute management;
  • Review data transfer arrangements and whether additional safeguards are required when data moves across borders.
Cross‑border arrangements are fact‑sensitive; businesses should obtain cross‑disciplinary advice covering tax, customs, corporate and data protection law.

Engaging advisors and in‑house compliance functions

Many e‑commerce operators engage external advisers for entity formation, tax registration, drafting of standard terms and data protection risk assessments. Larger operators commonly create an in‑house compliance function that monitors regulatory changes, oversees vendor due diligence and manages incident response. Where an operator needs specialist tax support, consider the practice group pages for guidance on service scope such as https://trw.org/tax-lawyers/. For regulatory and licensing queries, relevant practice areas are summarised at https://trw.org/our-practices/ and services at https://trw.org/services/.Consider retaining legal counsel in the following circumstances:
  • During entity selection and registration, to ensure alignment with commercial and tax objectives;
  • When drafting terms of service, supplier contracts and privacy policies;
  • Before launching payment integrations or wallets that may raise regulatory questions;
  • In the event of a data breach, regulatory inquiry or potential criminal allegation under digital security laws;
  • When dealing with cross‑border supply chains and tax planning that may create nexus issues.
Early engagement of advisers can reduce the likelihood of enforcement action and costly operational disruption.

How TRW Law Firm can assist (scope of services)

Legal services commonly sought by e‑commerce clients include company formation assistance and corporate documentation, drafting of website terms and supplier contracts, data protection strategy and incident response planning, and tax and VAT advice. For information about the firm’s practice areas and contact points, see https://trw.org/our-firm/, https://trw.org/our-practices/ and https://trw.org/services/. For assistance with tax-specific matters, see https://trw.org/tax-lawyers/ and for regulatory or disputes work consider https://trw.org/leading-arbitration-lawyer/. Contact details are available at https://trw.org/contact/. Readers should note that the selection of a legal services provider should reflect the client’s particular needs and that this article is not a substitute for tailored legal advice.

Practical compliance checklist

Use this checklist as an initial control framework; adapt it to the business model and risk profile.
  • Entity registration and local trade licences: complete and retain certificates;
  • TIN and VAT registration: monitor turnover thresholds and register timely;
  • Terms, privacy policy and returns policy: publish and review annually or after material system changes;
  • Payment contracts: verify KYC/AML provisions and chargeback processes;
  • Data security: maintain basic technical safeguards and an incident response playbook;
  • Recordkeeping: ensure transaction, inventory and tax records are accurate and retrievable;
  • Staff training: run periodic training on customer service, fraud prevention and privacy obligations;
  • Vendor due diligence: document security and compliance obligations in written contracts.

Frequently asked questions

Q: What are the primary laws that govern e‑commerce in Bangladesh?

A: The primary statutes include the Digital Security Act, the ICT Act, the Consumer Rights Protection Act, and tax and VAT laws; their interaction can be complex and you should consult the official texts or a qualified adviser for application to specific situations.

Q: Is registration required to operate an e‑commerce business in Bangladesh?

A: Businesses offering goods or services online generally need to register with the Registrar of Joint Stock Companies and Firms (RJSC) and obtain other local permits; check with RJSC (https://www.roc.gov.bd/) and seek advice on your factual circumstances.

Q: What consumer protection requirements apply to e‑commerce platforms?

A: Platforms should provide transparent pricing, clear return and refund policies, and accessible customer support in line with the Consumer Rights Protection Act; specifics depend on the transaction and you should obtain tailored advice.

Q: What steps should I take to protect customer data and comply with data‑related laws?

A: Implement proportionate technical and organisational measures, maintain records of processing, and review obligations under the Digital Security Act and other guidance; consult a data protection specialist for detailed steps relevant to your operations.

Q: What are the consequences of non‑compliance and when should I seek legal advice?

A: Non‑compliance can lead to regulatory enforcement, fines, and reputational harm; seek legal advice promptly when you face enforcement risk or complex regulatory questions.

Next steps and further resources

This guide is intended as a practical starting point. For official procedural steps on company registration consult the RJSC website at https://www.roc.gov.bd/. For tax registration and VAT guidance consult the National Board of Revenue. For assistance with structuring, regulatory compliance, tax or dispute matters, consider engaging experienced advisers early in planning and before launch.

Contact and call to action

If you would like to discuss specific questions about your proposed operations or require assistance with regulatory or contractual work, please contact the firm via our contact page at https://trw.org/contact/. To arrange a consultation, Book consultation or write to info@trw.org. The information in this article is general in nature and does not constitute legal advice; for advice tailored to your circumstances consult a qualified lawyer.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.