Law note · Nepal

Privacy Act, 2075, general privacy and collection regime

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, ss.1(2), 12(3), 23, 24, 26(1) stage IN FORCE in force since 2018-09-18 kind Comprehensive regime binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that collects, uses, or discloses the personal information of an individual in Nepal, including a voiceprint, faceprint, or other biometric identifier, must have the person's consent or fall within a statutory exception before collecting it, and a body corporate must limit use to its stated purpose and obtain consent before using the information for another purpose.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

What we found

The Act sets no General Data Protection Regulation (GDPR)-style enumerated lawful-basis list; each chapter instead states a "no one shall do X without consent" rule for its own subject matter, with scattered exceptions (court order, authorized-official demand, criminal investigation, public-interest research). Section 23(1) restricts collection to an official authorized under law or a person that official permits, a public-sector-centric default.

Section 12(3) (purpose limitation) and section 26(1) (consent to use) both expressly name "a public body or body corporate," so those two duties bind private entities directly. There is no formal controller/processor allocation and no registration regime. In force immediately from authentication.

← Back to the example  ·  Lint your app →