Law note · Nepal

Privacy Act, 2075, sensitive information and biometric data

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, ss.2(c)(6), 11(2)(f), 12(4)(e), 19(3), 27 stage IN FORCE in force since 2018-09-18 kind Sensitive categories binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that holds a voiceprint, faceprint, or other biometric identifier of a person in Nepal must have the person's consent before disclosing or publishing it to a third party, and must have consent or lawful authorization before recording a private conversation to derive it in the first place, though Nepal's Privacy Act does not treat biometric data as a heightened "sensitive information" category the way it treats caste, political affiliation, religion, health, or sexual orientation.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models

What we found

Section 2(c)(6) defines "personal information" to include a person's thumb impressions, fingerprints, retina of eye, blood group, or other biometric information. Section 11(2)(f) lists biological or biometric data and thumb impression as a protected "personal document" category, and section 12(4)(e) separately bars a third party from disclosing or publishing another person's biometric details without consent once held.

Section 19(3) restricts the act of recording a private conversation without consent or lawful authorization, with an express carve-out for a speech or statement made publicly; it does not itself govern what may be done with a recording once lawfully obtained.

Section 27's "sensitive information" list, the Act's one heightened-protection category, excludes biometric data entirely: caste/ethnicity/origin, political affiliation, religious faith, health, sexual orientation, and property details are listed, but biometric data is not among them. No dedicated biometric consent form, retention ceiling, or destruction-duty timeline exists.

← Back to the example  ·  Lint your app →