Database

Browse Database

BANGLADESH

N/A

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringement
Section 37 of the repealed Cyber Security Act stipulated that a service provider would not be held liable under the Act or any associated regulations for enabling access to data or information, provided that it could demonstrate either a lack of knowledge regarding the relevant offence or breach, or that it had undertaken all reasonable efforts to prevent it. However, reports indicated that, even when this provision was in force, it failed to provide sufficient protection for intermediaries with respect to user-generated content. The Cyber Security Act has now been repealed by the Cyber Protection Ordinance, 2025, which does not include this explicit safe-harbour clause in the same form. Consequently, the current framework provides even less express protection for intermediaries in this regard.
Coverage Internet intermediaries

BANGLADESH

Since December 2020

Pillar Intermediary liability  |  Indicator User identity requirement
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
According to Section 33 of the "Regulatory and Licensing Guideline for Internet Service Providers (ISPs) in Bangladesh", ISPs are required to verify the identities of their Wi-Fi subscribers.
Coverage Internet Service Providers (ISPs)

BANGLADESH

Reported in 2015, last reported in 2024

BANGLADESH

Since February 2019

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Approval Procedure of Payment System Operator (PSO)/Payment Service Provider (PSP)
As stipulated in Section 4.2 of the "Approval Procedure of Payment System Operator (PSO)/Payment Service Provider (PSP)", payment service providers are required to establish a technological infrastructure within Bangladesh. According to Annexure-B, this infrastructure comprises hardware, software, network communication, integration with banks and other institutions, as well as additional components. It is reported that, due to local banks and government regulations, foreign online transaction platforms such as PayPal cannot operate in the country, which negatively affects the expansion of e-commerce.
Coverage Payment service providers

BANGLADESH

Since May 2025

Pillar Intermediary liability  |  Indicator Monitoring requirement
Cyber Protection Ordinance, 2025 - Ordinance No. 25 of 2025 (সাইবার সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ২৫ নং অধ্যাদেশ)
It has been reported that some provisions of the Cyber Security Act of 2023 categorise the mere transmission of certain content as an offence, and that their broad scope could impose liability on intermediaries even in the absence of malicious intent. In the absence of an explicit mens rea requirement, a service provider transmitting such content without criminal intent could still have been prosecuted. These provisions included Section 21, which criminalised the dissemination of online propaganda, Section 28, which penalised the publication of content deemed to offend religious values or sentiments, and Section 29, which criminalised the dissemination of defamatory material online or in any electronic format. The Cyber Security Act has since been repealed and replaced by the Cyber Protection Ordinance, 2025, Ordinance No. 25 of 2025. However, it is not clear whether the new Ordinance retains equivalent requirements in the same form
Coverage Internet intermediaries

BANGLADESH

Since June 2023, last amended in August 2025

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Guidelines to Establish Digital Bank (ডিজিটাল ব্যাংক প্রতিষ্ঠার নির্দেশিকা)
Section 10.1 of the Guidelines to Establish Digital Bank stipulates that digital banks shall maintain at least a Tier III data centre and a disaster recovery site, each located in a different seismic zone. Section 10.2 further provides that, although digital banks may utilise cloud services, the physical location of such cloud infrastructure must be within Bangladesh's territory.
Coverage Digital banks

BANGLADESH

Reported in 2020, last reported in 2025

Pillar Content access  |  Indicator Blocking or filtering of commercial web content
Blocking of commercial web content
Reports indicate that authorities have blocked certain websites, news outlets, social media platforms, and communication services, particularly during periods of political tension. Notably, several news media websites, including Manab Zamin, Samakal, Jamuna Television, and Voice of America (VOA) Bangla, were rendered inaccessible in the lead-up to and during the general elections in Bangladesh in January 2024. In addition, in July 2024, authorities restricted access to major social media and communication platforms, including Facebook, YouTube, WhatsApp, and Signal. Similar restrictions were reimposed in August 2024. Additionally, reports suggest that the Sweden-based website Netra News has remained inaccessible since 2020.
Coverage Websites, news outlets, social media and communication platforms

BANGLADESH

Since November 2025, entry into force in November 2025

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
Section 29 of the Data Protection Ordinance provides that personal data, including public or open personal data, internal personal data, confidential personal data, and limited personal data as defined in the Schedule, may be transferred abroad subject to the conditions set out in Section 29 itself. Such transfers are permitted where the consent of the relevant data subject has been obtained, where the transfer is necessary for the exchange of goods or services under a contract to which the data subject is a party, or where, with the consent of the data subject, the transfer relates to matters concerning the data subject’s interests, such as business, education, emigration, or immigration. Also, personal data that is lawfully transferable may be transferred only to countries that possess appropriate technological and infrastructural safeguards for the storage of personal data, as prescribed by regulation. In cases involving the cross‑border transfer of large volumes of sensitive personally identifiable data, notification to the competent authorities is mandatory. For the purposes of this section, sensitive personally identifiable data refers to data whose large‑scale cross‑border transfer may pose risks to national sovereignty, national security, or financial stability, including government‑issued unique identification numbers such as national identity card numbers, passport numbers, and taxpayer or TIN or PAN numbers; biometric identifiers such as fingerprints, facial recognition data, and iris scans; genetic or DNA‑related information; and records of criminal convictions or criminal history.
Coverage Horizontal

BANGLADESH

N/A

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Bangladesh has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal

BANGLADESH

Since November 2025

Pillar Domestic data policies  |  Indicator Framework for data protection
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Data Protection Ordinance establishes a comprehensive framework for data protection in Bangladesh, although the competent authority has yet to be constituted. Section 1.3 stipulates that, with the exception of section 23 and sections 31 to 46, the Ordinance shall enter into force immediately. The excepted provisions are to come into operation on such date as the Government may determine by notification in the Official Gazette, following the expiry of 18 months from the date of promulgation of the Ordinance. The provisions subject to deferred commencement primarily concern the appointment of the chief data officer, the mechanisms for lodging complaints, and the imposition of administrative penalties.
Other relevant legislation includes the Cybersecurity Ordinance 2025, the Information and Communication Technology Act 2006, the Telecommunications Act 2001, the Contract Act 1872, the Consumers’ Rights Protection Act, the Penal Code 1860, and the Copyright Act 2000.
Coverage Horizontal

BANGLADESH

Since December 2020

Pillar Domestic data policies  |  Indicator Minimum period for data retention
BTRC Regulatory and Licensing Guideline For Internet Service Provider (ISP) in Bangladesh
According to Clause 25.4 of the "Regulatory and Licensing Guideline for Internet Service Providers (ISPs) in Bangladesh", licensees are required to maintain individual user history records, system failure records, Simple Network Management Protocol (SNMP) traffic data, and bandwidth utilisation records as daily logs for a minimum period of three months. These records must be made available upon request by the Bangladesh Telecommunication Regulatory Commission or any relevant law enforcement agency.
The 2025 Telecommunications Network and Licensing Policy introduced migration of ISP licences into the Fixed Telecom Service Providers (FTSPs)/District FTSP framework, but it does not expressly repeal the 2020 ISP Guideline, and existing licensees may complete their current licensing terms.
Coverage Internet Service Providers (ISPs)

BANGLADESH

Since July 2021

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Digital Commerce Operation Guidelines, 2021 (ডিজিটাল কমার্স পরিচালনা নির্দেশিকা -২০২১)
In accordance with Section 3.1.14 of the Digital Commerce Operation Guidelines, all information pertaining to the operations of digital commerce platforms must be retained for a minimum of 6 years and made available to any government authority upon request.
Coverage Digital commerce platforms

BANGLADESH

Since February 2024

Pillar Domestic data policies  |  Indicator Minimum period for data retention
BTRC Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh
Pursuant to Section 25.02 of the Bangladesh Telecommunication Regulatory Commission (BTRC) Regulatory and Licensing Guidelines for Cellular Mobile Services in Bangladesh, licensees must preserve Call Detail Records (CDRs), Transaction Detail Records (TDRs), system logs or audit trails relating to CDR changes, network traffic data, IN and HLR dumps, QoS and KPI reports with underlying data, official correspondence with BTRC, statements, reports, and related records for two years, for scrutiny by BTRC, as directed by the Commission, or as required by the National Telecommunication Monitoring Centre (NTMC) under the law.
Licensees must also retain third-party VAS/CP logs for the same two-year period relating to activation, deactivation, and service usage. Where call records would otherwise be deleted after 2 years, the licensee must retain any specific CDR upon instruction from BTRC or law enforcement agencies. In addition, licensees must record and store data session logs or information, including IP addresses, for six months, for scrutiny by, or as directed by, the Commission. Records not subject to a retention instruction may be deleted without prior permission.
Coverage Mobile services providers

BANGLADESH

Since November 2025

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Protection Ordinance, 2025 - Ordinance No. 61 of 2025 (ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ৬১ নং অধ্যাদেশ)
The Personal Data Protection Ordinance 2025 establishes a DPO-equivalent requirement under Art. 23, requiring "significant" data controllers to appoint qualified Chief Data Officers (the word "significant" is not defined in the law). The Chief Data Officer represents the controller before the Authority, reports significant matters, serves as the contact point for the exercise of data-subject rights, receives complaints concerning the misuse or ineffective management of sensitive personal data, and supports remedial action.
However, this requirement is not yet enforceable. Section 1(3) provides that Section 23, together with Sections 31–46, does not enter into force immediately. These provisions will only come into force after 18 months from the promulgation of the Ordinance and on such date as the Government may appoint by notification in the Official Gazette.
Coverage Horizontal

BANGLADESH

Since October 2025

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Cyber Protection Ordinance, 2025 - Ordinance No. 25 of 2025 (সাইবার সুরক্ষা অধ্যাদেশ, ২০২৫ - ২০২৫ সনের ২৫ নং অধ্যাদেশ)
Section 35 of the Cyber Protection Ordinance, 2025 grants police officers the authority to seize computers and related hardware without requiring a warrant.
Coverage Horizontal

Report issue     Report new measure