TRW Knowledge / Technology, data & IP

Internet Privacy Laws in Bangladesh: 2026 Guide for Organisations and Individuals

This article provides an explanatory overview of the legal framework relevant to internet privacy in Bangladesh as of 2026, practical compliance steps for organisations and individuals, and directions on when to seek context-specific legal advice. The text is intended for information and planning; it does not substitute for specialist advice tailored to particular facts.

Originally published 09 July 2026

Technology, data and digital commerce / Bangladesh
2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
This article provides an explanatory overview of the legal framework relevant to internet privacy in Bangladesh as of 2026, practical compliance steps for organisations and individuals, and directions on when to seek context-specific legal advice. The text is intended for information and planning; it does not substitute for specialist advice tailored to particular facts.

Scope and purpose

Internet privacy covers a range of legal and operational issues that arise when personal information is collected, stored, processed or disclosed using internet-connected systems. In Bangladesh the current legal landscape is composed of multiple statutes and regulatory instruments rather than a single consolidated data protection law. This article summarises those primary sources, discusses commonly encountered compliance tasks, highlights practical risk-management measures, and summarises recent policy activity through mid-2026.As of 2026, no single, comprehensive Personal Data Protection Act was in force that consolidated all privacy rules into one statutory regime. Instead, internet privacy issues are addressed through several laws and administrative frameworks. The principal instruments commonly relied upon by practitioners include:
  • Information and Communication Technology (ICT) Act, 2006 — contains provisions aimed at cybercrime and electronic transactions; certain sections have been used in proceedings concerning unlawful access and misuse of electronic data.
  • Right to Information Act, 2009 — establishes limited rights of access to information held by public authorities and thereby interacts with privacy considerations where disclosure by a public body intersects with personal data protection interests.
These instruments interact with sectoral rules or licensing conditions that may be issued by regulators such as the Bangladesh Telecommunication Regulatory Commission (BTRC) and other sector regulators. For regulator material, consult the relevant authority directly (for example, the BTRC website at https://www.btrc.gov.bd/). Do not rely on this article to establish the current text or interpretation of any statutory provision; seek a copy of the relevant statute and up-to-date comment from qualified counsel.The following themes commonly arise in privacy reviews and compliance programmes. Each point describes the legal concept and practical actions organisations frequently adopt to manage risk.

1. Lawful basis and consent

Where personal information is collected via internet platforms, organisations should identify the lawful basis for processing. In several jurisdictions lawful bases can include consent, performance of a contract, legal obligation, and legitimate interests. In Bangladesh, practitioners typically document the justification for collecting personal data (for example, service delivery or statutory reporting), and where reliance is placed on consent they ensure the consent mechanism is clear, auditable and revocable.

2. Purpose limitation and data minimisation

Organisations should record and limit the purposes for which they collect personal data and avoid collecting information that is not necessary to those purposes. Data minimisation reduces exposure in the event of a breach and simplifies retention and deletion obligations.

3. Security measures and breach response

Technical and organisational measures commonly adopted include encryption of data at rest and in transit, access controls, logging and monitoring, patch management, vulnerability testing, and incident response playbooks. Entities should design and test a data-breach response plan that defines internal roles, notification timelines, containment steps and communication strategies. Where a statutory or contractual obligation requires reporting to a regulator or affected individuals, organisations should prepare templates and escalation pathways. Because obligations and reporting thresholds can vary, confirm applicable reporting requirements with counsel and relevant regulators.

4. Contracts and third-party processing

Contracts with processors and sub-processors should set out processing purpose, security expectations, confidentiality requirements, audit rights and instructions from the controller. Where personal data is transferred to third parties (including cloud providers and overseas processors), the contract should address cross-border transfer safeguards and the party responsibilities in the event of a regulatory inquiry or security incident.

5. Data retention and deletion

Retention policies should specify retention periods by data category, the legal or business basis for the retention period, and deletion procedures. Implementing automated deletion where practicable reduces long-term risk. Retention obligations may be affected by sectoral laws or litigation holds; consult advisers before deleting records that may be subject to legal preservation requirements.

6. Rights of data subjects and access requests

Individuals may exercise rights such as access, rectification, deletion, or objection depending on the legal framework and the nature of the data. Organisations should have documented procedures for logging and responding to data-subject requests within the applicable timeframes, verifying identity appropriately and protecting third-party rights when fulfilling requests.

Practical step-by-step compliance guide

The following sequence is a commonly used starting point for organisations preparing or updating privacy compliance programmes. It is presented as general guidance and should be adapted to the organisation’s size, sector and risk profile.
  1. Map data flows: Identify categories of personal data collected, processing purposes, storage locations, and transfers to internal teams or external service providers.
  2. Assess legal bases and applicable laws: Determine the statutory basis for each processing activity and identify sectoral or cross-border rules that apply; document any assumptions.
  3. Prepare or update privacy notices: Draft concise privacy notices that explain what data is collected, why, with whom it is shared, retention periods, and how individuals may exercise available rights.
  4. Obtain and manage consent where needed: Implement consent capture mechanisms that are granular (where appropriate), auditable, and allow withdrawal.
  5. Implement contractual safeguards: Update contracts with vendors and partners to address security obligations, breach notification and processor-controller responsibilities.
  6. Deploy security controls: Apply encryption, access controls, logging, secure development practices, and endpoint protection aligned to the organisation’s threat model.
  7. Train staff: Provide role-based training for those who handle personal data and general awareness for all employees about phishing and data-handling protocols.
  8. Test and audit: Perform periodic audits, vulnerability assessments, and tabletop exercises for incident response.
  9. Maintain records: Keep written records of processing activities and decisions, including dataflow diagrams and DPIAs where risks are high.
  10. Review and update: Review policies and technical controls after significant changes in processing or law and update privacy notices accordingly.

Sector-specific considerations

Some sectors face additional legal and regulatory expectations:
  • Financial services: Entities operating payment systems or handling financial data should consider applicable banking and payment-sector rules, AML obligations, and any regulator guidance on electronic payment platforms; consult specialist advisers such as those listed under our financial services regulatory practice (https://trw.org/financial-services-regulatory-lawyers/).
  • Health and biometric data: Health-related and biometric data are sensitive categories that typically require heightened safeguards and, where applicable, explicit consent or specific legal authorisation.
  • Employment: Employee data is processed under a mixture of employment law obligations and privacy expectations; transparency, limited access and secure storage are essential.
  • Cross-border operations: International transfers may raise additional compliance requirements; formal transfer mechanisms, transport-layer protections and contractual terms are practical tools to manage cross-border risk.

Enforcement, penalties and dispute pathways

Enforcement can arise under criminal or civil regimes depending on the facts and the statutory provisions engaged. Some provisions of the ICT Act and the Digital Security Act may attract criminal penalties for specified offences involving unauthorised access, data breaches, or misuse of electronic information. Administrative or contractual remedies (including fines under licensing conditions) are also possible.Because enforcement practices and prosecutorial priorities can change, organisations should not assume a fixed enforcement approach; instead, maintain robust compliance and incident-response procedures and consult legal counsel immediately if subject to an investigation or notice.

Data transfers and international considerations

When personal data is transferred outside Bangladesh, organisations should assess applicable restrictions or requirements. Practical measures include contractual protections, strong encryption, and choice of data storage and processing locations. If transfers are governed by contractual clauses or regulatory guidance, document the legal basis and technical safeguards. Engage counsel for transfers involving jurisdictions with differing data protection regimes or where export controls and cross-border data flow restrictions may apply.

Privacy by design and technology considerations

Embedding privacy into system design reduced long-term operational and legal risk. Common privacy-by-design techniques include:
  • Data minimisation and pseudonymisation.
  • Privileged access controls and privileged identity management.
  • Secure default configurations and privacy-preserving analytics.
  • Segregation of test and production environments.
When procuring third-party software or cloud services, require vendors to provide security documentation and attestations (for example, SOC reports or equivalent), and verify that those attestations cover the relevant processing activities.

Common mistakes and how to avoid them

  • Insufficient documentation: Failing to document processing activities, lawful bases or consents increases exposure; keep clear records.
  • Inadequate contractual terms: Third-party contracts that lack processor obligations and cybersecurity commitments create uncertainty—update templates accordingly.
  • Weak access control: Overly broad internal access rights lead to unnecessary exposure—apply least privilege principles.
  • Outdated policies: Policies that are not reviewed after business changes or legal updates cease to reflect current practice; schedule regular reviews.
  • Ignoring regulatory guidance: Failure to review regulator guidance can result in missed compliance steps—consult BTRC or other sector regulators as needed (BTRC).
Bangladesh’s technology-law framework should be described precisely. The official Bangladesh Laws database lists the Information and Communication Technology Act, 2006, which addresses legal recognition and security for information and communication technology, including electronic records and signatures. It is distinct from cyber-security and personal-data instruments.The same official database lists the Cyber Security Ordinance, 2025, whose official preamble states that it repeals the Cyber Security Act, 2023. It separately lists the Personal Data Protection Ordinance, 2025, addressing protection of personal data and lawful processing with consent. The relevant statutory text, any later instrument and applicable sectoral requirement must be checked against the facts before a legal position is taken.

2026 update

In 2024–2026 there was increased public discussion in Bangladesh about a consolidated Personal Data Protection Act. As of the publication date of this article (2026-07-09T08:03:23), such an act had not yet been enacted as a single, fully implemented statutory regime that supersedes or replaces existing provisions. Draft proposals and policy statements have been reported in public consultations, but the legal status of any proposed law may change. Practitioners and organisations should verify the current status of legislative proposals directly with official sources or qualified advisers before relying on any one interpretation. For official notices and regulatory materials, consult the relevant ministry or regulator and the BTRC website at https://www.btrc.gov.bd/.

When to conduct a Data Protection Impact Assessment (DPIA)

A DPIA is appropriate where processing is likely to result in a high risk to individuals’ rights and freedoms. Examples include large-scale processing of sensitive data, systematic monitoring of public areas, or extensive profiling that affects people’s legal or significant interests. A DPIA should document the processing, assess risks, identify mitigation measures, and record decision-making. Even where not legally required, a DPIA can demonstrate that the organisation has considered privacy risks as part of its governance obligations.

Practical checklist for a new or updating organisation

Use this checklist as a starting point for internal governance meetings:
  • Map personal data and flows across systems and third parties.
  • Identify legal bases and any sectoral rules that apply.
  • Publish or update privacy notices and consent mechanisms.
  • Ensure contracts with processors include security and notification clauses.
  • Implement or verify encryption and access controls.
  • Train staff on phishing, secure handling and incident reporting.
  • Prepare an incident response plan with communication templates.
  • Schedule periodic audits and tabletop exercises.
  • Review retention and deletion policies against legal holds.
  • Plan for cross-border transfer safeguards where applicable.

How TRW can assist (scope of services)

For organisations seeking external support, legal advisers commonly provide services such as legal-gap analysis, drafting or reviewing privacy notices and contracts, preparing incident-response playbooks, and conducting staff training. For regulatory or sector-specific matters, multidisciplinary teams frequently combine legal analysis with technical and organisational assessments. TRW offers advisory services on privacy and regulatory matters and lists practices and services on its website; see our practice information at https://trw.org/our-practices/ and our services overview at https://trw.org/services/. To discuss an engagement, use our contact page at https://trw.org/contact/ or reach specialist teams via practice pages such as https://trw.org/financial-services-regulatory-lawyers/.

Five practical scenarios and suggested first steps

These scenarios illustrate typical first-step actions. They are not prescriptions; engage counsel for tailored advice.

Scenario A — New online marketplace

First steps: map seller and buyer data, document lawful basis for processing, implement privacy notice and seller agreements, secure payment-data handling, and review vendor contracts.

Scenario B — Health-tech application

First steps: treat health data as sensitive, minimise collection, encrypt sensitive fields, implement robust access controls, and consider whether explicit consent or statutory authorisation is required.

Scenario C — Cross-border SaaS provider

First steps: document cross-border flows, implement contractual safeguards with cloud providers, review encryption-at-rest and in-transit practices, and assess export-control constraints where relevant.

Scenario D — Data breach requiring notification

First steps: activate incident response, contain and preserve evidence, evaluate scope of affected data, consider notification obligations to affected individuals and regulators, and engage legal counsel immediately.

Scenario E — Employee data review

First steps: map employee categories and access, ensure lawful bases for monitoring or background checks, apply least-privilege access, and update employment privacy notices and retention rules.

Frequently asked questions

Q: What are the main internet privacy laws in Bangladesh?

A: The primary statutes commonly applied to internet Consult the text of each statute and current regulator guidance for the latest position and seek specific legal advice for particular matters.

Q: How can an organisation ensure compliance with internet privacy laws?

A: Organisations typically map data flows, document lawful bases for processing, implement clear privacy notices and consent mechanisms where needed, adopt technical and organisational security controls, update contracts with processors, and carry out regular audits; tailored steps depend on sector and processing activities and should be confirmed with advisers.

Q: What happens if an organisation violates internet privacy laws?

A: Consequences may include criminal or administrative penalties under applicable statutes, contractual liabilities, civil claims, and reputational harm; the specific consequences depend on the statute and facts, and organisations should obtain immediate legal advice if they face an enforcement action or potential claim.

Q: Are there any upcoming changes to internet privacy laws in Bangladesh?

A: Through 2024–2026 there have been public consultations and policy discussions concerning a possible Personal Data Protection Act, but any proposed law should be verified against official sources for its current status; consult the relevant ministry or regulator and qualified counsel for updates.

Q: How can TRW Law Firm assist with internet privacy compliance?

A: Legal advisers can provide gap analyses, draft privacy notices and processor contracts, assist with incident response and DPIAs, and perform training; for tailored assistance contact TRW through its practice pages or use the contact link provided earlier to arrange a consultation.

Next steps and governance

Organisations should treat privacy governance as an ongoing programme involving legal, IT, security and operational stakeholders. Board-level oversight of privacy risk, periodic reporting, and alignment between legal advice and technical implementation reduce the likelihood of regulatory or operational failures. Where external certification or independent assurance is appropriate, procure recognised audits and retain evidence of remediation activities.

Concluding remarks

Internet privacy in Bangladesh remains a developing area of law and practice. Organisations and individuals should take a risk-based, documented approach to privacy and data security, remain attentive to regulatory developments, and obtain legal advice tailored to the particular facts of any proposed processing activity or enforcement matter. This article is explanatory and does not constitute legal advice.Book consultation or contact us by email at info@trw.org to discuss context-specific questions or to arrange a compliance review.Source note: This 2026 review uses the official titles above. Historical labels in the URL are retained for continuity only and should not be treated as a statement of the current legal framework.

Bring the facts.
We bring direction.

For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.
WhatsApp