TRW KNOWLEDGE · LEGAL INFORMATION

Cybersecurity Laws in Bangladesh: The Ultimate Guide for 2026 and Beyond

A comprehensive 2026 guide to cybersecurity laws in Bangladesh, covering the Cyber Security Act 2023, the new PDPA 2026, and legal compliance for businesses and employees.
Originally published 29 July 2026
2026 updateThis article retains its original publication date. Its structure, internal navigation and general information have been refreshed for 2026; current primary sources and advice should be checked before acting on any specific matter.

Cybersecurity Laws in Bangladesh: The Ultimate Guide for 2026 and Beyond

In the rapidly evolving digital landscape of the 21st century, Bangladesh has emerged as a significant player in the global technology sector. With the government's visionary "Smart Bangladesh 2041" initiative, the nation is undergoing a profound digital transformation that touches every aspect of social, economic, and administrative life. However, this increased connectivity brings with it a surge in sophisticated cyber threats, ranging from data breaches and identity theft to state-sponsored cyber espionage and AI-driven disinformation. Consequently, understanding the cybersecurity laws in Bangladesh has become a non-negotiable requirement for individuals, startups, and multinational corporations alike.The legal framework governing the digital realm in Bangladesh is not static; it is a dynamic and often complex set of regulations that has seen significant shifts over the last decade. From the initial Information and Communication Technology (ICT) Act of 2006 to the widely debated Digital Security Act (DSA) of 2018, and the current transition toward the Cyber Security Act (CSA) of 2023 and the upcoming Personal Data Protection Act (PDPA) of 2026, the legislative trajectory reflects the nation's struggle to balance national security with individual liberties. This comprehensive guide provides an in-depth analysis of the current legal status, compliance requirements, and the future of digital safety in Bangladesh.

The Evolution of Digital Legislation in Bangladesh

To understand the current state of cybersecurity laws in Bangladesh, one must first look at the historical progression of its legal instruments. The journey began with the Information and Communication Technology (ICT) Act, 2006. This was the first major step toward recognizing electronic records and digital signatures, providing a basic framework for punishing cybercrimes like hacking and unauthorized access. However, as the digital economy grew, the ICT Act was found to be insufficient in addressing modern complexities.In 2018, the Digital Security Act (DSA) was enacted, replacing several sections of the ICT Act. The DSA was designed to be a comprehensive shield against cyber terrorism and digital crimes. However, it faced significant international and domestic criticism due to its broad definitions and sections that were perceived as tools for suppressing freedom of expression. Specifically, sections related to "propaganda against the liberation war" and "hurting religious sentiments" were often cited in legal challenges.Recognizing the need for reform and alignment with international standards, the government repealed the DSA and introduced the Cyber Security Act (CSA) in 2023. The CSA aimed to soften some of the harsher penalties of the DSA, converting several non-bailable offenses into bailable ones and focusing more on the technical aspects of cybersecurity rather than content regulation. As we move through 2026, further refinements and new acts like the PDPA are defining the next generation of legal compliance.

The Cyber Security Act (CSA) 2023: Key Provisions

The Cyber Security Act of 2023 remains the primary legislative pillar for digital safety. It defines the roles of the National Cyber Security Agency and sets the parameters for investigating and prosecuting cyber-related offenses. For businesses operating in Bangladesh, understanding the following sections is critical:
  • Cyber Terrorism (Section 27): This section deals with activities that threaten the integrity, security, or sovereignty of the state through digital means. It carries heavy penalties, reflecting the government's zero-tolerance policy toward threats against critical information infrastructure.
  • Hacking and Unauthorized Access (Section 17-19): These sections criminalize the act of entering a computer system without authorization, damaging digital data, or disrupting network services. For corporations, this underscores the importance of robust firewalls and access control protocols.
  • Identity Theft and Fraud (Section 24): With the rise of phishing and social engineering, identity theft has become a rampant issue. The CSA provides specific penalties for using someone else's digital identity for fraudulent purposes.
  • Data Interception (Section 26): Unauthorized interception of data during transmission is a serious offense. This is particularly relevant for telecommunications and ISP providers who must ensure the privacy of their users' communications.
FeatureDigital Security Act (2018)Cyber Security Act (2023)
Bail StatusMajority of sections were non-bailable.Many sections converted to bailable.
Penalty for DefamationIncluded imprisonment.Primarily focuses on fines.
Regulatory FocusContent and Speech.Infrastructure and Technical Security.

The 2026 Regulatory Shift: PDPA and AI Governance

As of mid-2026, the most significant development in the cybersecurity laws in Bangladesh is the full implementation of the Personal Data Protection Act (PDPA) 2026. Unlike previous laws that focused on "crimes," the PDPA is a regulatory framework designed to protect the privacy rights of citizens. It introduces concepts similar to the EU's GDPR, such as:
  • Data Sovereignty: Requirements for certain types of sensitive personal data to be stored within the geographical boundaries of Bangladesh.
  • Right to be Forgotten: Citizens now have the legal right to request the deletion of their personal data from commercial databases under specific conditions.
  • Mandatory Data Protection Officers (DPOs): Organizations handling large volumes of data are now required by law to appoint a DPO to oversee compliance. This role is not merely administrative; the DPO acts as a bridge between the organization and the regulatory Agency, ensuring that data processing activities are audited annually.
  • Data Classification Standards: The PDPA 2026 introduces a three-tier classification system for data: General, Sensitive, and Critical. Critical data, which includes information related to national security and large-scale financial transactions, is subject to the highest level of scrutiny and localization requirements.

Cross-Border Data Transfers

One of the most complex areas of the cybersecurity laws in Bangladesh involves the transfer of data across national borders. For multinational corporations (MNCs) and international service providers, the 2026 regulations clarify that data can be transferred outside Bangladesh only if the recipient country provides an "equivalent level of protection." This necessitates the use of Standard Contractual Clauses (SCCs) and, in some cases, explicit authorization from the Data Protection Authority. Companies must conduct a Transfer Impact Assessment (TIA) before initiating such transfers to ensure that the privacy rights of Bangladeshi citizens are not compromised in the destination jurisdiction.Furthermore, the Cyber Security Act 2026 amendments have introduced specific clauses regarding Artificial Intelligence. These include penalties for the creation and dissemination of "Deepfakes" intended to incite social unrest or commit fraud. The law now requires AI developers to implement "digital watermarking" on synthetic media to ensure transparency. This is a direct response to the global rise in AI-generated misinformation, and Bangladesh is among the first few nations in South Asia to codify these technical requirements into law. The amendments also address "Algorithmic Accountability," requiring companies to ensure that their AI systems do not produce discriminatory outcomes in employment or financial lending.
"The transition to the PDPA 2026 represents a paradigm shift from a reactive, crime-based approach to a proactive, rights-based approach in Bangladesh's digital governance." — TRW Law Firm Legal Analysis.

Impact on Technology Companies and Employment

The intersection of technology and employment law is a critical area for HR departments and tech startups. Under the current cybersecurity laws in Bangladesh, employers have a dual responsibility: protecting their company's digital assets and ensuring the privacy of their employees.

1. Employee Monitoring and Privacy

While employers have a legitimate interest in monitoring company-issued devices to prevent data leaks, the PDPA 2026 restricts excessive surveillance. Monitoring must be "proportionate" and "necessary." Companies are advised to have clear, written policies in their employment contracts regarding the extent of digital monitoring to avoid legal disputes.

2. Vicarious Liability and Corporate Accountability

In certain cases, a company can be held vicariously liable for the cybercrimes committed by its employees if it can be proven that the company lacked adequate security protocols or failed to provide necessary training. The legal theory of Respondeat Superior is increasingly applied in the digital context. If an employee uses company infrastructure to launch a DDoS attack or steal data, and the company is found to have "grossly negligent" security measures, the corporate entity itself may face fines that could reach into the millions of BDT. This makes regular cybersecurity audits and employee training programs a legal necessity rather than just a best practice. The CSA 2023 specifically mentions that directors and managers can be held responsible unless they can prove the offense was committed without their knowledge or that they exercised all due diligence to prevent it.

3. Cybersecurity in Fintech and Mobile Financial Services (MFS)

Bangladesh has seen a revolution in Mobile Financial Services (MFS) with platforms like bKash, Nagad, and Rocket. Consequently, the cybersecurity laws in Bangladesh have carved out specific regulations for the Fintech sector. The Bangladesh Bank (the central bank) issues regular circulars that complement the CSA. These regulations mandate "Security by Design" for all financial applications, requiring end-to-end encryption and robust KYC (Know Your Customer) processes. Any Fintech company failing to report a security breach that affects consumer funds faces immediate suspension of their operating license, highlighting the critical nature of compliance in this sector.

3. Termination for Cyber Breaches

A significant breach of cybersecurity protocols by an employee can be grounds for termination under the Bangladesh Labour Act, read in conjunction with the CSA. However, the process must follow due legal procedure, including a proper internal investigation and a show-cause notice, to withstand judicial scrutiny.

Step-by-Step Compliance Guide for Organizations

Navigating the cybersecurity laws in Bangladesh requires a structured approach. Organizations should follow these steps to ensure they remain on the right side of the law:
  1. Inventory of Data: Identify what personal and sensitive data you collect, where it is stored, and who has access to it. This is the foundation of PDPA compliance.
  2. Update Privacy Policies: Ensure your website and internal documents clearly state how data is handled, in accordance with the 2026 standards.
  3. Implement Technical Safeguards: Use industry-standard encryption, multi-factor authentication (MFA), and regular penetration testing to protect your systems.
  4. Establish a Breach Response Plan: The law now mandates reporting significant data breaches to the National Cyber Security Agency within 72 hours. Having a pre-defined plan is essential.
  5. Legal Consultation: Given the complexities of the 2026 amendments, regular consultations with a specialized technology law firm in Bangladesh are highly recommended.

Important Legal Considerations and Warnings

While this guide provides an overview of the current legal landscape, it is vital to note that cybersecurity laws in Bangladesh are subject to rapid change. The interpretation of the Cyber Security Act 2023 and the PDPA 2026 by the courts is still evolving. Therefore, for cyber and employment topics especially, one must avoid asserting current law, penalties, or filing routes as absolute without checking the most recent official gazettes and circulars from the Ministry of Posts, Telecommunications and Information Technology.For instance, specific wage rates for IT professionals, procedural deadlines for filing cybercrime complaints, and the exact status of certain amendments can change through administrative orders. Always verify with current official materials or seek professional legal advice before making significant business decisions based on these regulations.

How TRW Law Firm Can Help

Tahmidur Rahman Remura Wahid (TRW) Law Firm is at the forefront of technology and cyber law in Bangladesh. Our multi-disciplinary team combines deep legal expertise with a thorough understanding of the digital economy. We assist clients with:
  • Drafting and reviewing IT-compliant employment contracts and internal policies.
  • Representing clients in cybercrime litigation and regulatory disputes.
  • Guiding startups through the complexities of data localization and PDPA 2026 compliance.
  • Conducting legal audits of cybersecurity frameworks to identify potential liabilities.
With offices in Dhaka and global reach, we provide the strategic counsel needed to thrive in a secure digital environment. For professional assistance, you can contact TRW Law Firm directly or book a consultation with our experts.

Professional Legal Support

If you are facing a cybersecurity challenge or need to ensure your business is compliant with the latest regulations, our team is here to help. Reach out to us at info@trw.org for a detailed assessment of your legal needs.

Frequently Asked Questions (FAQ)

Q1: What is the main difference between the Digital Security Act and the Cyber Security Act?
A: The Cyber Security Act (2023) repealed the DSA (2018) to reduce the number of non-bailable offenses and shift the focus from content regulation to technical security and infrastructure protection.Q2: Is data localization mandatory under the PDPA 2026?
A: Yes, for certain categories of "sensitive personal data" as defined by the government, the PDPA 2026 requires storage on servers located within Bangladesh, though exceptions may apply for specific international transactions.Q3: What are the penalties for deepfake creation under the new 2026 laws?
A: The 2026 amendments introduce stiff fines and potential imprisonment for creating deepfakes intended to deceive, defraud, or incite public disorder, especially if they target national security or public figures.Q4: How long do I have to report a data breach in Bangladesh?
A: Under the current regulatory guidelines, significant data breaches must be reported to the relevant authorities within 72 hours of discovery.Q5: Can an employee be fired for a cybersecurity mistake?
A: Yes, if the mistake constitutes "misconduct" under the Labour Act or a violation of a signed cybersecurity policy, though the employer must follow the standard disciplinary process including a show-cause notice.Q6: Does the law apply to foreign companies without a physical office in Bangladesh?
A: Yes, the CSA and PDPA have extraterritorial jurisdiction. If a foreign company processes the data of Bangladeshi citizens or provides digital services within the country, they are legally bound by these regulations.Q7: What is the role of the National Cyber Security Agency?
A: The Agency is the primary regulatory body responsible for implementing the CSA, overseeing critical information infrastructure, and responding to national-level cyber threats.

Conclusion

The cybersecurity laws in Bangladesh represent a critical frontier in the nation's development. As we navigate the complexities of 2026, the emphasis has clearly shifted toward data privacy, AI governance, and robust infrastructure protection. For businesses, staying compliant is not just about avoiding penalties; it is about building trust with customers and partners in an increasingly digital world. While the legal journey is complex, with the right information and professional guidance, organizations can turn these challenges into opportunities for growth and innovation.For more information on our firm and our expertise in other areas, please visit our Our Firm page, explore our Practice Areas, or see our full range of Services. If you have immediate concerns, visit our Contact page to get in touch with our team.

Using this information carefully

Administrative practice, searchable records, forms and filing requirements can change. Before relying on a search result or preparing a filing, confirm the current process through the relevant official register or office. A clear record of the search terms, date, source and result can assist with later review, while any material rights, deadlines or dispute issues should be considered in light of the specific facts.

Using this information carefully

Administrative practice, searchable records, forms and filing requirements can change. Before relying on a search result or preparing a filing, confirm the current process through the relevant official register or office. A clear record of the search terms, date, source and result can assist with later review, while any material rights, deadlines or dispute issues should be considered in light of the specific facts.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org
WhatsApp