Law note · Bhutan
Cybersecurity Code of Practice for ICT/Telecommunications Service Providers, privacy and PII duty
What it requires
- A Telecom Service Provider or other ICT service provider with critical information infrastructure in Bhutan must establish and communicate a privacy and PII-protection policy, implement procedures to preserve that privacy, including for a biometric identifier such as a voiceprint or faceprint handled as PII, and put in place appropriate technical and organizational measures, consistent with its reporting obligations under the Information, Communications and Media Act of Bhutan 2018.
When LexLint raises it
crawls_webprocesses_biometricsprocesses_voice
What we found
Issued by BICMA under section 58 of the ICM Act as a binding code of practice for licensed Telecom Service Providers and other ICT service providers operating critical information infrastructure, in force since 10 October 2024.
Section 8.6 requires a licensee to establish and communicate a topic-specific policy on privacy and protection of Personally Identifiable Information (PII), to implement procedures for preserving that privacy, and to put in place appropriate technical and organizational measures, expressly deferring compliance to "relevant legislation and regulations" (the ICM Act's own Chapter 21 duties).
The Code does not itself define "PII" or name biometric data, and its incident-response requirement (s.12.1) requires only that a licensee's Incident Response Plan include a reporting structure aligned with "its reporting obligations under the Act and any other laws and regulations"; it creates no independent breach-notification threshold, recipient, or timeline of its own.
Found through an independent search of the official bicma.gov.bt domain (which, unlike nab.gov.bt and parliament.bt, is TLS-reachable) while attempting to source the ICM Act 2018 itself at a government publisher; it is a genuinely separate, more recent, government-issued instrument, not a republication of the ICM Act.