Law note · Bangladesh

Personal Data Protection Act, 2026, breach notification duties

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, s.20 stage RECENT in force 10 months effective 2025-11-06 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a personal data breach in Bangladesh, including one involving a biometric identifier, must notify the Authority in the form, manner and time a regulation prescribes whenever the breach creates a possibility of significant harm to an affected data principal; no separate statutory duty to notify the affected individual directly was found.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Section 20(1) requires a Data Fiduciary to notify the Authority of a personal data breach, in the form, manner, and time prescribed by regulation, whenever the breach creates a possibility of significant harm to the affected data principal. Section 20(2) lists factors, nature of breach, affected-principal categories and counts, contact details, and mitigation steps, that the Authority considers in gauging severity, again by regulation not yet located.

No statutory deadline (no 72 hour figure) appears in the Act itself, and no separate duty to notify the affected data principal directly was found in the sections read.

← Back to the example  ·  Lint your app →