Law note · Nepal
Privacy Act, 2075, general privacy and collection regime
What it requires
- An app that collects, uses, or discloses the personal information of an individual in Nepal, including a voiceprint, faceprint, or other biometric identifier, must have the person's consent or fall within a statutory exception before collecting it, and a body corporate must limit use to its stated purpose and obtain consent before using the information for another purpose.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
The Act sets no General Data Protection Regulation (GDPR)-style enumerated lawful-basis list; each chapter instead states a "no one shall do X without consent" rule for its own subject matter, with scattered exceptions (court order, authorized-official demand, criminal investigation, public-interest research). Section 23(1) restricts collection to an official authorized under law or a person that official permits, a public-sector-centric default.
Section 12(3) (purpose limitation) and section 26(1) (consent to use) both expressly name "a public body or body corporate," so those two duties bind private entities directly. There is no formal controller/processor allocation and no registration regime. In force immediately from authentication.