Law note · Bangladesh

Personal Data Protection Act, 2026, cross-border transfer of personal data

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.29, 30 stage RECENT in force 10 months effective 2025-11-06 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of a person in Bangladesh abroad, including a biometric identifier, must have the data principal's consent or a qualifying contract or personal-interest ground, and must notify the Authority before a bulk cross-border transfer of sensitive personally identifiable data such as fingerprint, facial-recognition, or iris data where it could threaten sovereignty, national security, or financial stability.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Section 29(1) empowers the Government to classify personal data into four tiers by Schedule (public/open, internal, confidential, restricted). Transfer abroad is permitted with the data principal's consent, under a contract to which they are party involving goods or services, or with consent for their business, education, or travel/migration interests (s.29(3)), and the destination must have adequate technology and safeguards for personal-data storage per regulation (s.29(4)).

Bulk cross-border transfer of sensitive personally identifiable data, including a biometric identifier such as a fingerprint, facial-recognition data, or iris scan, requires mandatory notification to the Authority where it could threaten sovereignty, national security, or financial stability (s.29(6)).

No blanket data-localization mandate appears in the enacted text, correcting the amendment-ordinance stage's residency mandate, which industry comment reports was removed in the revision that became this Act.

← Back to the example  ·  Lint your app →