BANGLADESH
Since November 2025
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Personal Data Protection Ordinance 2025 establishes a DPO-equivalent requirement under Art. 23, requiring "significant" data controllers to appoint qualified Chief Data Officers (the word "significant" is not defined in the law). The Chief Data Officer represents the controller before the Authority, reports significant matters, serves as the contact point for the exercise of data-subject rights, receives complaints concerning the misuse or ineffective management of sensitive personal data, and supports remedial action.
However, this requirement is not yet enforceable. Section 1(3) provides that Section 23, together with Sections 31–46, does not enter into force immediately. These provisions will only come into force after 18 months from the promulgation of the Ordinance and on such date as the Government may appoint by notification in the Official Gazette.
However, this requirement is not yet enforceable. Section 1(3) provides that Section 23, together with Sections 31–46, does not enter into force immediately. These provisions will only come into force after 18 months from the promulgation of the Ordinance and on such date as the Government may appoint by notification in the Official Gazette.
Coverage Horizontal
BANGLADESH
Since October 2025
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Cyber Protection Ordinance, 2025 - Ordinance No. 25 of 2025 (সাইবার সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ২৫ নং অধ্যাদেশ)
Section 35 of the Cyber Protection Ordinance, 2025 grants police officers the authority to seize computers and related hardware without requiring a warrant.
Coverage Horizontal
BANGLADESH
Since April 2001, as amended in February 2006
Since December 2020
Since February 2024
Since December 2020
Since February 2024
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Bangladesh Telecommunication Regulatory Authority Act, 2001 - Act No. 18 of 2001 (বাংলাদেশ টেলিযোগাযোগ নিয়ন্ত্রণ আইন, ২০০১ - ২০০১ সনের ১৮ নং আইন)
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024
Under Section 97A of the Telecommunication Regulatory Authority Act, the Ministry of Home Affairs may, on grounds of national security or public order and with ministerial approval, authorise intelligence, national security, investigative, or law enforcement bodies to record or collect user information relating to subscribers of telecommunications services. Telecommunications operators must provide full cooperation to the authority vested with these powers. This access obligation is reinforced in sector-specific licensing rules.
Section 33 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guideline for Internet Service Providers (ISP) in Bangladesh requires ISP operational systems to be compatible with lawful interception and to enable the identification of Wi-Fi subscribers.
Similarly, under Sections 25.03 and 25.05.01–25.05.02 of the BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024, cellular mobile licensees must provide connectivity and information to the BTRC Telecommunication Monitoring System (TMS), connect with the National Telecommunication Monitoring Centre (NTMC) lawful interception system, and provide access to CDR, IPDR, PDR, ETSAF data, customer and retailer information, call and radio-location information, recharge information, and other required data. Sections 25.07.01–25.07.02 further authorise BTRC, or its authorised representatives, to inspect licensees’ premises and take copies of records, documents, and other business information.
Section 33 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guideline for Internet Service Providers (ISP) in Bangladesh requires ISP operational systems to be compatible with lawful interception and to enable the identification of Wi-Fi subscribers.
Similarly, under Sections 25.03 and 25.05.01–25.05.02 of the BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, 2024, cellular mobile licensees must provide connectivity and information to the BTRC Telecommunication Monitoring System (TMS), connect with the National Telecommunication Monitoring Centre (NTMC) lawful interception system, and provide access to CDR, IPDR, PDR, ETSAF data, customer and retailer information, call and radio-location information, recharge information, and other required data. Sections 25.07.01–25.07.02 further authorise BTRC, or its authorised representatives, to inspect licensees’ premises and take copies of records, documents, and other business information.
Coverage Telecommunications sector
Sources
- http://bdlaws.minlaw.gov.bd/act-857/section-33698.html
- http://web.archive.org/web/20250227181249/https://clfr.globalnetworkinitiative.org/country/bangladesh/
- https://web.archive.org/web/20250214202409/https://freedomhouse.org/country/bangladesh/freedom-net/2024
- https://web.archive.org/web/20250227200236/https://lims.btrc.gov.bd/uploads/service_guideline/Regulatory%20and%20Licensing%20Guideline%20for%20Internet%20Service%20Provider%20(ISP)%20in%20Bangladesh.p...
- https://web.archive.org/web/20260513133744/https://objectstorage.ap-dcc-gazipur-1.oraclecloud15.com/n/axvjbnqprylg/b/V2Ministry/o/office-btrc/2024/12/b022cff2b79b434b9f51d80dc48f4e39.pdf
- Show more...
BANGLADESH
Since October 2006, last amended in October 2018
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Information and Communication Technology Act, 2006 - Act No. 39 of 2006 (তথ্য ও যোগাযোগ প্রযুক্তি আইন, ২০০৬ - ২০০৬ সনের ৩৯ নং আইন)
Under Section 30 of the Information and Communication Technology Act, the ICT Controller—an officer appointed under this Act responsible for overseeing its implementation—is authorised to access any computer system, apparatus, data, or other material associated with a computer system for the purpose of conducting or facilitating a search to obtain information contained within or accessible to the system. The ICT Controller may, by order, require any individual responsible for, or otherwise involved in the operation of, the computer system, data apparatus, or related material to provide such reasonable technical and other assistance as they deem necessary.
In addition, under Section 46, if the ICT Controller determines that it is necessary or expedient in the interests of the sovereignty, integrity, or security of Bangladesh, international relations, public order, or for the prevention of incitement to commit a legally recognised offence, they may direct any government law enforcement agency to intercept information transmitted through any computer resource. Additionally, they may instruct the subscriber or any individual responsible for a computer resource to provide all necessary assistance in decrypting the relevant information.
Pursuant to Section 29, the ICT Controller or an authorised officer possesses the same authority as that conferred upon a Civil Court under the Code of Civil Procedure of Bangladesh. These powers encompass the authority to conduct "discovery and inspection" as well as to "compel the production of any document."
In addition, under Section 46, if the ICT Controller determines that it is necessary or expedient in the interests of the sovereignty, integrity, or security of Bangladesh, international relations, public order, or for the prevention of incitement to commit a legally recognised offence, they may direct any government law enforcement agency to intercept information transmitted through any computer resource. Additionally, they may instruct the subscriber or any individual responsible for a computer resource to provide all necessary assistance in decrypting the relevant information.
Pursuant to Section 29, the ICT Controller or an authorised officer possesses the same authority as that conferred upon a Civil Court under the Code of Civil Procedure of Bangladesh. These powers encompass the authority to conduct "discovery and inspection" as well as to "compel the production of any document."
Coverage Horizontal
Sources
- https://web.archive.org/web/20250725235924/https://cyrilla.org/entity/dqctnkcxm0w?file=1588594729616gl43oin1uvb.pdf&page=1
- https://web.archive.org/web/20260212134736/http://bdlaws.minlaw.gov.bd/act-details-950.html
- http://web.archive.org/web/20250227181249/https://clfr.globalnetworkinitiative.org/country/bangladesh/
- https://web.archive.org/web/20250326174902/https://ustr.gov/sites/default/files/2024%20NTE%20Report.pdf
- Show more...
BANGLADESH
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
Bangladesh's legal framework and jurisprudence lack a comprehensive provision on intermediary liability for copyright infringement. Section 82 of the Copyright Act 2023 merely states that if it is determined that the copyright or other rights of a work’s creator or legal licensee have been infringed by a network service provider or any other third party, the creator, legal licensee, network service provider, or third party must, upon receiving a written objection, remove all copies of the disputed work from any medium under their control as soon as possible and notify the complainant in writing. Failure to comply renders the network service provider, institution, individual, or third party liable for copyright infringement. For this section, a "service provider" is defined as a network, individual, or institution that disseminates, publishes, or broadcasts content through any medium, including information technology, the Internet, and digital platforms.
Coverage Internet intermediaries
BANGLADESH
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringement
Section 37 of the repealed Cyber Security Act stipulated that a service provider would not be held liable under the Act or any associated regulations for enabling access to data or information, provided that it could demonstrate either a lack of knowledge regarding the relevant offence or breach, or that it had undertaken all reasonable efforts to prevent it. However, reports indicated that, even when this provision was in force, it failed to provide sufficient protection for intermediaries with respect to user-generated content. The Cyber Security Act has now been repealed by the Cyber Protection Ordinance, 2025, which does not include this explicit safe-harbour clause in the same form. Consequently, the current framework provides even less express protection for intermediaries in this regard.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20250227234510/http://bdlaws.minlaw.gov.bd/upload/act/2023-10-16-13-54-10-Act-No.-39-of-2023.pdf
- https://web.archive.org/web/20250227234302/https://aicasia.org/download/784
- https://web.archive.org/web/20260320223338/https://www.dpp.gov.bd/upload_file/gazettes/57587_41613.pdf
- Show more...
BANGLADESH
Since December 2020
Pillar Intermediary liability |
Indicator User identity requirement
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
According to Section 33 of the "Regulatory and Licensing Guideline for Internet Service Providers (ISPs) in Bangladesh", ISPs are required to verify the identities of their Wi-Fi subscribers.
Coverage Internet Service Providers (ISPs)
BANGLADESH
Reported in 2015, last reported in 2024
Pillar Intermediary liability |
Indicator User identity requirement
Identity requirement for SIM cards
It is reported that mobile network operators must collect and validate users' personal information and proof of identity to sell SIM cards. This also includes biometric registration.
Coverage Horizontal
Sources
- https://web.archive.org/web/20250221013459/https://www.gsma.com/mobilefordevelopment/wp-content/uploads/2021/04/Digital-Identity-Access-to-Mobile-Services-and-Proof-of-Identity-2021_SPREADs.pdf
- https://www.comparitech.com/blog/vpn-privacy/sim-card-registration-laws/
- https://web.archive.org/web/20250221013639/https://freedomhouse.org/country/bangladesh/freedom-net/2024
- https://web.archive.org/web/20250221013646/https://advox.globalvoices.org/2015/12/22/bangladesh-will-demand-biometric-data-from-all-sim-card-users/
- Show more...
BANGLADESH
Since February 2019
Pillar Cross-border data policies |
Indicator Infrastructure requirement
Approval Procedure of Payment System Operator (PSO)/Payment Service Provider (PSP)
As stipulated in Section 4.2 of the "Approval Procedure of Payment System Operator (PSO)/Payment Service Provider (PSP)", payment service providers are required to establish a technological infrastructure within Bangladesh. According to Annexure-B, this infrastructure comprises hardware, software, network communication, integration with banks and other institutions, as well as additional components. It is reported that, due to local banks and government regulations, foreign online transaction platforms such as PayPal cannot operate in the country, which negatively affects the expansion of e-commerce.
Coverage Payment service providers
Sources
- https://web.archive.org/web/20250328235806/https://bb.org.bd/aboutus/regulationguideline/psd/pso_psp_03022019.pdf
- https://web.archive.org/web/20250329000852/https://legalseba.com/bd-licenses/how-to-obtain-a-pso-and-psp-license-in-bangladesh/
- https://web.archive.org/web/20250327000050/https://www.trade.gov/country-commercial-guides/bangladesh-ecommerce
- Show more...
BANGLADESH
Since May 2025
Pillar Intermediary liability |
Indicator Monitoring requirement
Cyber Protection Ordinance, 2025 - Ordinance No. 25 of 2025 (সাইবার সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ২৫ নং অধ্যাদেশ)
It has been reported that some provisions of the Cyber Security Act of 2023 categorise the mere transmission of certain content as an offence, and that their broad scope could impose liability on intermediaries even in the absence of malicious intent. In the absence of an explicit mens rea requirement, a service provider transmitting such content without criminal intent could still have been prosecuted. These provisions included Section 21, which criminalised the dissemination of online propaganda, Section 28, which penalised the publication of content deemed to offend religious values or sentiments, and Section 29, which criminalised the dissemination of defamatory material online or in any electronic format. The Cyber Security Act has since been repealed and replaced by the Cyber Protection Ordinance, 2025, Ordinance No. 25 of 2025. However, it is not clear whether the new Ordinance retains equivalent requirements in the same form
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20260320223338/https://www.dpp.gov.bd/upload_file/gazettes/57587_41613.pdf
- https://web.archive.org/web/20260312072212/http://bdlaws.minlaw.gov.bd/act-1538.html
- https://web.archive.org/web/20250227234302/https://aicasia.org/download/784
- https://web.archive.org/web/20250221013639/https://freedomhouse.org/country/bangladesh/freedom-net/2024
- Show more...
BANGLADESH
Since June 2023, last amended in August 2025
Pillar Cross-border data policies |
Indicator Infrastructure requirement
Guidelines to Establish Digital Bank (ডিজিটাল ব্যাংক প্রতিষ্ঠার নির্দেশিকা)
Section 10.1 of the Guidelines to Establish Digital Bank stipulates that digital banks shall maintain at least a Tier III data centre and a disaster recovery site, each located in a different seismic zone. Section 10.2 further provides that, although digital banks may utilise cloud services, the physical location of such cloud infrastructure must be within Bangladesh's territory.
Coverage Digital banks
BANGLADESH
Reported in 2020, last reported in 2025
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Blocking of commercial web content
Reports indicate that authorities have blocked certain websites, news outlets, social media platforms, and communication services, particularly during periods of political tension. Notably, several news media websites, including Manab Zamin, Samakal, Jamuna Television, and Voice of America (VOA) Bangla, were rendered inaccessible in the lead-up to and during the general elections in Bangladesh in January 2024. In addition, in July 2024, authorities restricted access to major social media and communication platforms, including Facebook, YouTube, WhatsApp, and Signal. Similar restrictions were reimposed in August 2024. Additionally, reports suggest that the Sweden-based website Netra News has remained inaccessible since 2020.
Coverage Websites, news outlets, social media and communication platforms
Sources
- https://web.archive.org/web/20260320221551/https://freedomhouse.org/country/bangladesh/freedom-net/2025
- https://web.archive.org/web/20250214202409/https://freedomhouse.org/country/bangladesh/freedom-net/2024
- https://web.archive.org/web/20250214202442/https://www.state.gov/reports/2023-country-reports-on-human-rights-practices/bangladesh/
- https://web.archive.org/web/20250214202512/https://www.state.gov/reports/2021-country-reports-on-human-rights-practices/bangladesh
- Show more...
BANGLADESH
Since November 2025, entry into force in November 2025
Pillar Cross-border data policies |
Indicator Conditional flow regime
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
Section 29 of the Data Protection Ordinance provides that personal data, including public or open personal data, internal personal data, confidential personal data, and limited personal data as defined in the Schedule, may be transferred abroad subject to the conditions set out in Section 29 itself. Such transfers are permitted where the consent of the relevant data subject has been obtained, where the transfer is necessary for the exchange of goods or services under a contract to which the data subject is a party, or where, with the consent of the data subject, the transfer relates to matters concerning the data subject’s interests, such as business, education, emigration, or immigration. Also, personal data that is lawfully transferable may be transferred only to countries that possess appropriate technological and infrastructural safeguards for the storage of personal data, as prescribed by regulation. In cases involving the cross‑border transfer of large volumes of sensitive personally identifiable data, notification to the competent authorities is mandatory. For the purposes of this section, sensitive personally identifiable data refers to data whose large‑scale cross‑border transfer may pose risks to national sovereignty, national security, or financial stability, including government‑issued unique identification numbers such as national identity card numbers, passport numbers, and taxpayer or TIN or PAN numbers; biometric identifiers such as fingerprints, facial recognition data, and iris scans; genetic or DNA‑related information; and records of criminal convictions or criminal history.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260505193319/http://bdlaws.minlaw.gov.bd/upload/act/2025-11-16-13-56-48-Ordinance-No.-61-of-2025.pdf
- https://web.archive.org/web/20260505193758/https://dpo-india.com/Resources/Privacy_Regulations_in_Asia_Pacific_Countries/Bangladesh-Personal-Data-Protection-Ordinance,2025(Ordinance.No.61-2025).pdf
- https://www.dataguidance.com/notes/bangladesh-privacy-overview
- Show more...
BANGLADESH
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Bangladesh has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
BANGLADESH
Since November 2025
Pillar Domestic data policies |
Indicator Framework for data protection
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Data Protection Ordinance establishes a comprehensive framework for data protection in Bangladesh, although the competent authority has yet to be constituted. Section 1.3 stipulates that, with the exception of section 23 and sections 31 to 46, the Ordinance shall enter into force immediately. The excepted provisions are to come into operation on such date as the Government may determine by notification in the Official Gazette, following the expiry of 18 months from the date of promulgation of the Ordinance. The provisions subject to deferred commencement primarily concern the appointment of the chief data officer, the mechanisms for lodging complaints, and the imposition of administrative penalties.
Other relevant legislation includes the Cybersecurity Ordinance 2025, the Information and Communication Technology Act 2006, the Telecommunications Act 2001, the Contract Act 1872, the Consumers’ Rights Protection Act, the Penal Code 1860, and the Copyright Act 2000.
Other relevant legislation includes the Cybersecurity Ordinance 2025, the Information and Communication Technology Act 2006, the Telecommunications Act 2001, the Contract Act 1872, the Consumers’ Rights Protection Act, the Penal Code 1860, and the Copyright Act 2000.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260505193319/http://bdlaws.minlaw.gov.bd/upload/act/2025-11-16-13-56-48-Ordinance-No.-61-of-2025.pdf
- https://web.archive.org/web/20260505193758/https://dpo-india.com/Resources/Privacy_Regulations_in_Asia_Pacific_Countries/Bangladesh-Personal-Data-Protection-Ordinance,2025(Ordinance.No.61-2025).pdf
- https://www.dataguidance.com/jurisdictions/bangladesh
- Show more...
