Law note · Bangladesh
Personal Data Protection Act, 2026, breach notification duties
cite Personal Data Protection Act, 2026, Act No. 63 of 2026, s.20
stage RECENT in force 10 months
effective 2025-11-06
kind Breach notification
binds public and private bodies
reviewed 2026-08-29
What it requires
- An app that suffers a personal data breach in Bangladesh, including one involving a biometric identifier, must notify the Authority in the form, manner and time a regulation prescribes whenever the breach creates a possibility of significant harm to an affected data principal; no separate statutory duty to notify the affected individual directly was found.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Section 20(1) requires a Data Fiduciary to notify the Authority of a personal data breach, in the form, manner, and time prescribed by regulation, whenever the breach creates a possibility of significant harm to the affected data principal. Section 20(2) lists factors, nature of breach, affected-principal categories and counts, contact details, and mitigation steps, that the Authority considers in gauging severity, again by regulation not yet located.
No statutory deadline (no 72 hour figure) appears in the Act itself, and no separate duty to notify the affected data principal directly was found in the sections read.