Law note · Bangladesh
Personal Data Protection Act, 2026, cross-border transfer of personal data
What it requires
- An app transferring the personal data of a person in Bangladesh abroad, including a biometric identifier, must have the data principal's consent or a qualifying contract or personal-interest ground, and must notify the Authority before a bulk cross-border transfer of sensitive personally identifiable data such as fingerprint, facial-recognition, or iris data where it could threaten sovereignty, national security, or financial stability.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
Section 29(1) empowers the Government to classify personal data into four tiers by Schedule (public/open, internal, confidential, restricted). Transfer abroad is permitted with the data principal's consent, under a contract to which they are party involving goods or services, or with consent for their business, education, or travel/migration interests (s.29(3)), and the destination must have adequate technology and safeguards for personal-data storage per regulation (s.29(4)).
Bulk cross-border transfer of sensitive personally identifiable data, including a biometric identifier such as a fingerprint, facial-recognition data, or iris scan, requires mandatory notification to the Authority where it could threaten sovereignty, national security, or financial stability (s.29(6)).
No blanket data-localization mandate appears in the enacted text, correcting the amendment-ordinance stage's residency mandate, which industry comment reports was removed in the revision that became this Act.