Law note · Bhutan
Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures
What it requires
- An app that negligently fails to implement reasonable security practices for personal data of a person in Bhutan, including a biometric identifier, and thereby causes wrongful loss or gain, is liable to pay court-determined compensation to the victim, and unlawfully disclosing another's personal data without consent is a separate offence under section 388.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- Yes
What we found
The Bhutan InfoComm and Media Authority (BICMA), the unified telecom, broadcast, media, and ICT regulator this Act establishes, is the supervisory authority for the whole Act, including Chapters 17, 21, and 22, though its specific enforcement powers over the Chapter 21/17 civil-obligation provisions were not independently traced beyond Chapter 22's own offence sections.
Section 387 ("Failure to protect data") makes a person possessing, dealing with, or handling personal data, including sensitive personal data, who is negligent in implementing reasonable security practices and thereby causes wrongful loss or gain, liable to pay court-determined compensation to the victim, a genuine private right of action in substance.
Section 388 ("Unlawful Disclosure of data or information") separately makes it an offence to disclose another's personal data without consent or in breach of a lawful contract, intending or knowing it likely to cause wrongful loss or gain; its exact penalty tier was not confirmed this pass due to an extraction artifact at a page break.
Primary source
official Act text
via a journalist-federation mirror of the government-issued PDF (samsn.ifj.org), since the government's own hosting domains had live TLS failures this pass