BANGLADESH
Reported in 2024
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Supplier Declaration of Conformity not allowed for foreign businesses
It is reported that Bangladesh currently lacks a comprehensive type-approval system, governed by a dedicated law, to regulate the approval of telecommunication and radio equipment. Consequently, manufacturers and importers are required to obtain a "No Objection Certificate "(NOC) to import such devices. This certificate is issued upon the request of a licensed local importer and serves as confirmation that the equipment complies with at least the country’s fundamental regulatory requirements. To obtain the certificate, applicants must submit product specifications and test reports to the Bangladesh Telecommunication Regulatory Commission (BTRC), yet in-country testing is not required. An acceptable CE report is required for the issuance of a BTRC NOC in Bangladesh.
Coverage Electronic products
BANGLADESH
Since July 2021
Pillar Online sales and transactions |
Indicator Licensing scheme for e-commerce providers
Digital Commerce Operation Guidelines, 2021 (ডিজিটাল কমার্স পরিচালনা নির্দেশিকা -২০২১)
Pursuant to Section 3.1.18 of the Digital Commerce Operation Guidelines, all foreign digital commerce platforms conducting business in Bangladesh must register in the country and obtain the necessary approvals from the relevant authorities. In addition, in accordance with Section 3.1.13, measures shall be undertaken to ensure that all digital commerce platforms are progressively mandated to acquire a Unique Business Identification Number (UBID). Additionally, as stipulated in Section 3.1.9, the implementation of digital wallets, gift cards, cash vouchers, or other payment alternatives shall not be permitted without the Central Bank's approval.
Coverage Digital commerce platforms
Sources
- https://web.archive.org/web/20250318191931/https://mincom.gov.bd/sites/default/files/files/mincom.portal.gov.bd/notices/60120aa2_5245_442f_ac7a_369485877e2e/2065-Comerce-04%20July%202021(11245-11252)....
- https://web.archive.org/web/20250331211654/https://www.thedailystar.net/law-our-rights/news/overview-the-digital-commerce-operation-guidelines-2021-2128871
- https://web.archive.org/web/20260219155602/https://www.dpp.gov.bd/upload_file/gazettes/45356_29094.pdf
- Show more...
BANGLADESH
Reported in 2022, last reported in 2024
Pillar Online sales and transactions |
Indicator Restrictions on online payments
Reported restrictions on Internet Banking Fund Transfer (IBFT) transactions
It is reported that limitations have been imposed on both individual and institutional Internet Banking Fund Transfer (IBFT) transactions. For individual users, the maximum permissible amount per transaction is 300,000 taka (approx. USD 2,500), with a maximum transaction frequency of 10 times per day, not exceeding a total of 1,000,000 taka (approx. USD 8,000) per day. For corporate entities, the transaction limit is 500,000 taka (approx. USD 4,000) per transaction, with a maximum frequency of 20 transactions per day and a daily limit of 2,500,000 taka (approx. USD 21,000).
Coverage Horizontal
BANGLADESH
Reported in 2022, last reported in 2025
Pillar Online sales and transactions |
Indicator Restrictions on online payments
Reported transfer limits in mobile financial services
Reports indicate a daily transfer limit of Tk 50,000 (approx. USD 400) between mobile financial service accounts and bank accounts, and a monthly limit of Tk 300,000 (approx. USD 2,500). The limit applies in both directions.
Coverage Horizontal
Sources
- http://web.archive.org/web/20250328182609/https://bdnews24.com/business/2f65caa2422a
- https://web.archive.org/web/20250327010204/https://www.thedailystar.net/business/news/bangladesh-bank-fixes-transfer-limit-bank-account-mfs-account-3064391
- https://web.archive.org/web/20250327010734/https://thefinancialexpress.com.bd/economy/bangladesh/bb-re-fixes-mfs-transaction-limit-1657024418
- Show more...
BANGLADESH
Since March 1947, last amended in September 2015
Pillar Online sales and transactions |
Indicator Restrictions on online payments
The Foreign Exchange Regulation Act, 1947 - Act No. VII of 1947 (বৈদেশিক মুদ্রা নিয়ন্ত্রণ আইন, ১৯৪৭ - ১৯৪৭ সালের ০৭ নং আইন)
Bangladesh maintains a highly stringent foreign exchange control regime. The country's foreign exchange laws are broadly applicable to any transaction involving foreign currency or the remittance of funds into or out of Bangladesh. No individual or entity is permitted to engage in foreign exchange dealings without obtaining prior authorisation from the central bank. Pursuant to Section 5 of the Foreign Exchange Regulation Act, 1947, no person in, or resident in, Bangladesh may, except under a general or special exemption granted by Bangladesh Bank, make payments to, or for the credit of, persons resident outside Bangladesh, place sums to their credit, or create or transfer payment rights in their favour. Separately, Section. 10 regulates the duties of persons entitled to receive foreign exchange or payments from persons resident outside Bangladesh. Reports indicate that these regulations affect the operations of fintech companies, preventing their customers from purchasing or selling products on e-commerce platforms using their preferred payment methods. Consequently, they must rely on intermediaries, such as friends, relatives, or agents, who possess access to foreign currency accounts or payment cards.
Coverage Horizontal
Sources
- http://bdlaws.minlaw.gov.bd/act-218/section-3338.html
- https://web.archive.org/web/20250917071726/https://practiceguides.chambers.com/practice-guides/comparison/1026/15058/23622-23623-23624-23625-23626-23627-23628-23629-23630-23631-23632
- https://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID4616435_code6251136.pdf?abstractid=4616435&mirid=1
- Show more...
BANGLADESH
Since November 2025, entry into force in November 2025
Pillar Cross-border data policies |
Indicator Conditional flow regime
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
Section 29 of the Data Protection Ordinance provides that personal data, including public or open personal data, internal personal data, confidential personal data, and limited personal data as defined in the Schedule, may be transferred abroad subject to the conditions set out in Section 29 itself. Such transfers are permitted where the consent of the relevant data subject has been obtained, where the transfer is necessary for the exchange of goods or services under a contract to which the data subject is a party, or where, with the consent of the data subject, the transfer relates to matters concerning the data subject’s interests, such as business, education, emigration, or immigration. Also, personal data that is lawfully transferable may be transferred only to countries that possess appropriate technological and infrastructural safeguards for the storage of personal data, as prescribed by regulation. In cases involving the cross‑border transfer of large volumes of sensitive personally identifiable data, notification to the competent authorities is mandatory. For the purposes of this section, sensitive personally identifiable data refers to data whose large‑scale cross‑border transfer may pose risks to national sovereignty, national security, or financial stability, including government‑issued unique identification numbers such as national identity card numbers, passport numbers, and taxpayer or TIN or PAN numbers; biometric identifiers such as fingerprints, facial recognition data, and iris scans; genetic or DNA‑related information; and records of criminal convictions or criminal history.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260505193319/http://bdlaws.minlaw.gov.bd/upload/act/2025-11-16-13-56-48-Ordinance-No.-61-of-2025.pdf
- https://web.archive.org/web/20260505193758/https://dpo-india.com/Resources/Privacy_Regulations_in_Asia_Pacific_Countries/Bangladesh-Personal-Data-Protection-Ordinance,2025(Ordinance.No.61-2025).pdf
- https://www.dataguidance.com/notes/bangladesh-privacy-overview
- Show more...
BANGLADESH
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Bangladesh has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
BANGLADESH
Since November 2025
Pillar Domestic data policies |
Indicator Framework for data protection
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Data Protection Ordinance establishes a comprehensive framework for data protection in Bangladesh, although the competent authority has yet to be constituted. Section 1.3 stipulates that, with the exception of section 23 and sections 31 to 46, the Ordinance shall enter into force immediately. The excepted provisions are to come into operation on such date as the Government may determine by notification in the Official Gazette, following the expiry of 18 months from the date of promulgation of the Ordinance. The provisions subject to deferred commencement primarily concern the appointment of the chief data officer, the mechanisms for lodging complaints, and the imposition of administrative penalties.
Other relevant legislation includes the Cybersecurity Ordinance 2025, the Information and Communication Technology Act 2006, the Telecommunications Act 2001, the Contract Act 1872, the Consumers’ Rights Protection Act, the Penal Code 1860, and the Copyright Act 2000.
Other relevant legislation includes the Cybersecurity Ordinance 2025, the Information and Communication Technology Act 2006, the Telecommunications Act 2001, the Contract Act 1872, the Consumers’ Rights Protection Act, the Penal Code 1860, and the Copyright Act 2000.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260505193319/http://bdlaws.minlaw.gov.bd/upload/act/2025-11-16-13-56-48-Ordinance-No.-61-of-2025.pdf
- https://web.archive.org/web/20260505193758/https://dpo-india.com/Resources/Privacy_Regulations_in_Asia_Pacific_Countries/Bangladesh-Personal-Data-Protection-Ordinance,2025(Ordinance.No.61-2025).pdf
- https://www.dataguidance.com/jurisdictions/bangladesh
- Show more...
BANGLADESH
Since December 2020
Pillar Domestic data policies |
Indicator Minimum period for data retention
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
According to Clause 25.4 of the "Regulatory and Licensing Guideline for Internet Service Providers (ISPs) in Bangladesh", licensees are required to maintain individual user history records, system failure records, Simple Network Management Protocol (SNMP) traffic data, and bandwidth utilisation records as daily logs for a minimum period of three months. These records must be made available upon request by the Bangladesh Telecommunication Regulatory Commission or any relevant law enforcement agency.
The 2025 Telecommunications Network and Licensing Policy introduced migration of ISP licences into the Fixed Telecom Service Providers (FTSPs)/District FTSP framework, but it does not expressly repeal the 2020 ISP Guideline, and existing licensees may complete their current licensing terms.
The 2025 Telecommunications Network and Licensing Policy introduced migration of ISP licences into the Fixed Telecom Service Providers (FTSPs)/District FTSP framework, but it does not expressly repeal the 2020 ISP Guideline, and existing licensees may complete their current licensing terms.
Coverage Internet Service Providers (ISPs)
Sources
- https://web.archive.org/web/20250227200236/https://lims.btrc.gov.bd/uploads/service_guideline/Regulatory%20and%20Licensing%20Guideline%20for%20Internet%20Service%20Provider%20(ISP)%20in%20Bangladesh.p...
- https://web.archive.org/web/20250219185057/https://today.thefinancialexpress.com.bd/print/isps-to-keep-records-of-users-for-one-year-1692638399?utm
- https://web.archive.org/web/20260429193452/https://objectstorage.ap-dcc-gazipur-1.oraclecloud15.com/n/axvjbnqprylg/b/V2Ministry/o/office-ptd/2024/12/dc545fba9f8b4a39851a4f3290f5573c.pdf
- Show more...
BANGLADESH
Since July 2021
Pillar Domestic data policies |
Indicator Minimum period for data retention
Digital Commerce Operation Guidelines, 2021 (ডিজিটাল কমার্স পরিচালনা নির্দেশিকা -২০২১)
In accordance with Section 3.1.14 of the Digital Commerce Operation Guidelines, all information pertaining to the operations of digital commerce platforms must be retained for a minimum of 6 years and made available to any government authority upon request.
Coverage Digital commerce platforms
Sources
- https://web.archive.org/web/20250318191931/https://mincom.gov.bd/sites/default/files/files/mincom.portal.gov.bd/notices/60120aa2_5245_442f_ac7a_369485877e2e/2065-Comerce-04%20July%202021(11245-11252)....
- https://web.archive.org/web/20250318192214/https://www.thedailystar.net/law-our-rights/law-analysis/news/marks-be-registered-trademarks-bangladesh-2123921
BANGLADESH
Since February 2024
Pillar Domestic data policies |
Indicator Minimum period for data retention
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh
Pursuant to Section 25.02 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, licensees must preserve Call Detail Records (CDRs), Transaction Detail Records (TDRs), system logs or audit trails relating to CDR changes, network traffic data, IN and HLR dumps, QoS and KPI reports with underlying data, official correspondence with BTRC, statements, reports, and related records for two years, for scrutiny by BTRC, as directed by the Commission, or as required by the National Telecommunication Monitoring Centre (NTMC) under the law.
Licensees must also retain third-party VAS/CP logs for the same two-year period relating to activation, deactivation, and service usage. Where call records would otherwise be deleted after 2 years, the licensee must retain any specific CDR upon instruction from BTRC or law enforcement agencies. In addition, licensees must record and store data session logs or information, including IP addresses, for six months, for scrutiny by, or as directed by, the Commission. Records not subject to a retention instruction may be deleted without prior permission.
Licensees must also retain third-party VAS/CP logs for the same two-year period relating to activation, deactivation, and service usage. Where call records would otherwise be deleted after 2 years, the licensee must retain any specific CDR upon instruction from BTRC or law enforcement agencies. In addition, licensees must record and store data session logs or information, including IP addresses, for six months, for scrutiny by, or as directed by, the Commission. Records not subject to a retention instruction may be deleted without prior permission.
Coverage Mobile services providers
BANGLADESH
Since November 2025
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Personal Data Protection Ordinance 2025 establishes a DPO-equivalent requirement under Art. 23, requiring "significant" data controllers to appoint qualified Chief Data Officers (the word "significant" is not defined in the law). The Chief Data Officer represents the controller before the Authority, reports significant matters, serves as the contact point for the exercise of data-subject rights, receives complaints concerning the misuse or ineffective management of sensitive personal data, and supports remedial action.
However, this requirement is not yet enforceable. Section 1(3) provides that Section 23, together with Sections 31–46, does not enter into force immediately. These provisions will only come into force after 18 months from the promulgation of the Ordinance and on such date as the Government may appoint by notification in the Official Gazette.
However, this requirement is not yet enforceable. Section 1(3) provides that Section 23, together with Sections 31–46, does not enter into force immediately. These provisions will only come into force after 18 months from the promulgation of the Ordinance and on such date as the Government may appoint by notification in the Official Gazette.
Coverage Horizontal
BANGLADESH
Since October 2025
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Cyber Protection Ordinance, 2025 - Ordinance No. 25 of 2025 (সাইবার সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ২৫ নং অধ্যাদেশ)
Section 35 of the Cyber Protection Ordinance, 2025 grants police officers the authority to seize computers and related hardware without requiring a warrant.
Coverage Horizontal
BANGLADESH
Since April 2001, as amended in February 2006
Since December 2020
Since February 2024
Since December 2020
Since February 2024
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Bangladesh Telecommunication Regulatory Authority Act, 2001 - Act No. 18 of 2001 (বাংলাদেশ টেলিযোগাযোগ নিয়ন্ত্রণ আইন, ২০০১ - ২০০১ সনের ১৮ নং আইন)
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024
Under Section 97A of the Telecommunication Regulatory Authority Act, the Ministry of Home Affairs may, on grounds of national security or public order and with ministerial approval, authorise intelligence, national security, investigative, or law enforcement bodies to record or collect user information relating to subscribers of telecommunications services. Telecommunications operators must provide full cooperation to the authority vested with these powers. This access obligation is reinforced in sector-specific licensing rules.
Section 33 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guideline for Internet Service Providers (ISP) in Bangladesh requires ISP operational systems to be compatible with lawful interception and to enable the identification of Wi-Fi subscribers.
Similarly, under Sections 25.03 and 25.05.01–25.05.02 of the BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024, cellular mobile licensees must provide connectivity and information to the BTRC Telecommunication Monitoring System (TMS), connect with the National Telecommunication Monitoring Centre (NTMC) lawful interception system, and provide access to CDR, IPDR, PDR, ETSAF data, customer and retailer information, call and radio-location information, recharge information, and other required data. Sections 25.07.01–25.07.02 further authorise BTRC, or its authorised representatives, to inspect licensees’ premises and take copies of records, documents, and other business information.
Section 33 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guideline for Internet Service Providers (ISP) in Bangladesh requires ISP operational systems to be compatible with lawful interception and to enable the identification of Wi-Fi subscribers.
Similarly, under Sections 25.03 and 25.05.01–25.05.02 of the BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024, cellular mobile licensees must provide connectivity and information to the BTRC Telecommunication Monitoring System (TMS), connect with the National Telecommunication Monitoring Centre (NTMC) lawful interception system, and provide access to CDR, IPDR, PDR, ETSAF data, customer and retailer information, call and radio-location information, recharge information, and other required data. Sections 25.07.01–25.07.02 further authorise BTRC, or its authorised representatives, to inspect licensees’ premises and take copies of records, documents, and other business information.
Coverage Telecommunications sector
Sources
- http://bdlaws.minlaw.gov.bd/act-857/section-33698.html
- http://web.archive.org/web/20250227181249/https://clfr.globalnetworkinitiative.org/country/bangladesh/
- https://web.archive.org/web/20250214202409/https://freedomhouse.org/country/bangladesh/freedom-net/2024
- https://web.archive.org/web/20250227200236/https://lims.btrc.gov.bd/uploads/service_guideline/Regulatory%20and%20Licensing%20Guideline%20for%20Internet%20Service%20Provider%20(ISP)%20in%20Bangladesh.p...
- https://web.archive.org/web/20260513133744/https://objectstorage.ap-dcc-gazipur-1.oraclecloud15.com/n/axvjbnqprylg/b/V2Ministry/o/office-btrc/2024/12/b022cff2b79b434b9f51d80dc48f4e39.pdf
- Show more...
BANGLADESH
Since October 2006, last amended in October 2018
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Information and Communication Technology Act, 2006 - Act No. 39 of 2006 (তথ্য ও যোগাযোগ প্রযুক্তি আইন, ২০০৬ - ২০০৬ সনের ৩৯ নং আইন)
Under Section 30 of the Information and Communication Technology Act, the ICT Controller—an officer appointed under this Act responsible for overseeing its implementation—is authorised to access any computer system, apparatus, data, or other material associated with a computer system for the purpose of conducting or facilitating a search to obtain information contained within or accessible to the system. The ICT Controller may, by order, require any individual responsible for, or otherwise involved in the operation of, the computer system, data apparatus, or related material to provide such reasonable technical and other assistance as they deem necessary.
In addition, under Section 46, if the ICT Controller determines that it is necessary or expedient in the interests of the sovereignty, integrity, or security of Bangladesh, international relations, public order, or for the prevention of incitement to commit a legally recognised offence, they may direct any government law enforcement agency to intercept information transmitted through any computer resource. Additionally, they may instruct the subscriber or any individual responsible for a computer resource to provide all necessary assistance in decrypting the relevant information.
Pursuant to Section 29, the ICT Controller or an authorised officer possesses the same authority as that conferred upon a Civil Court under the Code of Civil Procedure of Bangladesh. These powers encompass the authority to conduct "discovery and inspection" as well as to "compel the production of any document."
In addition, under Section 46, if the ICT Controller determines that it is necessary or expedient in the interests of the sovereignty, integrity, or security of Bangladesh, international relations, public order, or for the prevention of incitement to commit a legally recognised offence, they may direct any government law enforcement agency to intercept information transmitted through any computer resource. Additionally, they may instruct the subscriber or any individual responsible for a computer resource to provide all necessary assistance in decrypting the relevant information.
Pursuant to Section 29, the ICT Controller or an authorised officer possesses the same authority as that conferred upon a Civil Court under the Code of Civil Procedure of Bangladesh. These powers encompass the authority to conduct "discovery and inspection" as well as to "compel the production of any document."
Coverage Horizontal
Sources
- https://web.archive.org/web/20250725235924/https://cyrilla.org/entity/dqctnkcxm0w?file=1588594729616gl43oin1uvb.pdf&page=1
- https://web.archive.org/web/20260212134736/http://bdlaws.minlaw.gov.bd/act-details-950.html
- http://web.archive.org/web/20250227181249/https://clfr.globalnetworkinitiative.org/country/bangladesh/
- https://web.archive.org/web/20250326174902/https://ustr.gov/sites/default/files/2024%20NTE%20Report.pdf
- Show more...
