Law note · Bhutan
Information, Communications and Media Act of Bhutan 2018, sensitive personal data and biometric information
What it requires
- An app that derives a voiceprint, faceprint, or other biometric identifier from a person in Bhutan must treat it as Sensitive Personal Data or Information and obtain the subject's express written permission before collecting it, unless the information is itself freely available or accessible in the public domain.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_models
What we found
Definitions item (89) lists biometric information as a Sensitive Personal Data or Information category, alongside password, financial information, physical/physiological/mental health condition, sexual orientation, medical records, and a residual "other information legally deemed to be private" category.
The item's own proviso carves information that is freely available or accessible in the public domain, or available under another existing national law, out of the sensitive-personal-information classification, though this does not obviously rescue a voiceprint or faceprint derived from public material, since the derived identifier is a distinct data element from its source recording.
No standalone definition of "biometric information" exists; the term is not otherwise defined, and neither "voice" nor "voiceprint" nor "facial image" appears anywhere in the Act as its own named term. Creating and storing an identity-linked voiceprint or faceprint would be handling Sensitive Personal Data, triggering Chapter 21's consent, non-disclosure, and destruction duties, and, where done by an ICT/media provider, Chapter 17's fuller duties.
Primary source
official Act text
via a journalist-federation mirror of the government-issued PDF (samsn.ifj.org), since the government's own hosting domains had live TLS failures this pass