Law / Bangladesh

Bangladesh

privacy

Bangladesh's Personal Data Protection Act, 2026 (Act No. 63 of 2026) was enacted by Parliament 10 April 2026, repealing and replacing the Personal Data Protection Ordinance, 2025 (Ordinance No. 61 of 2025) and its 2026 amending Ordinance.

By its own section 1(3), the Act is deemed to have come into force retroactively on 6 November 2025, the date the original Ordinance was gazetted, for every chapter except section 23 (mandatory Chief Data Officer appointment) and the complaint, penalty, and appeal chapter (sections 31 to 35).

So the lawful-basis, sensitive-data, data-subject-rights, retention, breach-notification, and cross-border-transfer duties already bind private data fiduciaries today, while no complaint mechanism, administrative fine, or Authority-ordered compensation is currently operative. Biometric data, defined to include facial image and voiceprint by name, is an express Sensitive Personal Data category carrying a heightened lawful-basis bar under section 7.

13 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Act, 2026, breach notification duties

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, s.20 stage RECENT in force 10 months effective 2025-11-06 binds public and private bodies source official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), via an Internet Archive capture since the official portal serves no HTTPS
What it requires

Section 20(1) requires a Data Fiduciary to notify the Authority of a personal data breach, in the form, manner, and time prescribed by regulation, whenever the breach creates a possibility of significant harm to the affected data principal. Section 20(2) lists factors, nature of breach, affected-principal categories and counts, contact details, and mitigation steps, that the Authority considers in gauging severity, again by regulation not yet located.

No statutory deadline (no 72 hour figure) appears in the Act itself, and no separate duty to notify the affected data principal directly was found in the sections read.

Comprehensive regime

Personal Data Protection Act, 2026, comprehensive regime and lawful basis

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.5, 8, 18 stage RECENT in force 10 months effective 2025-11-06 binds public and private bodies source official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), via an Internet Archive capture since the official portal serves no HTTPS
What it requires

Section 5 requires a Data Fiduciary to have a lawful basis before processing personal data: voluntary, specific, clear, revocable consent (s.5(2)), or one of seven enumerated legitimate-interest grounds without consent (contract performance, pre-contractual steps, legal-claims necessity, vital interests, employment/labor/social-security legal duties, the data principal's own voluntary public disclosure, or preventing harm from unreasonably withheld consent).

A Data Fiduciary determines purpose and means and remains liable for a Processor's processing (s.8). Section 18 bars retaining data beyond what the purpose requires, subject to a scientific, historical, statistical-research, or public-interest exception. In force since 6 November 2025, deemed retroactively by the Act's own commencement clause.

Cross border transfer

Personal Data Protection Act, 2026, cross-border transfer of personal data

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.29, 30 stage RECENT in force 10 months effective 2025-11-06 binds public and private bodies source official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), via an Internet Archive capture since the official portal serves no HTTPS
What it requires

Section 29(1) empowers the Government to classify personal data into four tiers by Schedule (public/open, internal, confidential, restricted). Transfer abroad is permitted with the data principal's consent, under a contract to which they are party involving goods or services, or with consent for their business, education, or travel/migration interests (s.29(3)), and the destination must have adequate technology and safeguards for personal-data storage per regulation (s.29(4)).

Bulk cross-border transfer of sensitive personally identifiable data, including a biometric identifier such as a fingerprint, facial-recognition data, or iris scan, requires mandatory notification to the Authority where it could threaten sovereignty, national security, or financial stability (s.29(6)).

No blanket data-localization mandate appears in the enacted text, correcting the amendment-ordinance stage's residency mandate, which industry comment reports was removed in the revision that became this Act.

Enforcement supervision

Personal Data Protection Act, 2026, complaints, penalties and appeals

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.31-38 stage IMMINENT commencement not set binds public and private bodies source official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), via an Internet Archive capture since the official portal serves no HTTPS
What it requires

Once operative, a data principal or any person with reason to believe a rights violation occurred may file a complaint with the National Data Management Authority (s.31); the Authority may impose an administrative fine of up to BDT 2,500,000 for a rights violation (s.32) and separately up to BDT 2,500,000 for a security or protection failure (s.33), with factors for setting the fine listed at s.34, plus compensation to the complaining data principal in addition to the fine (s.35).

Section 36 lets the Authority fine individual company officials personally implicated in a rights-violation complaint. Appeal against an Authority fine or compensation order runs to the Tribunal established under section 68 of the Information and Communication Technology Act, within 30 days (s.37).

None of this is currently operative: sections 23 and 31 to 35 are excluded from the Act's own retroactive commencement deeming and await a separate Government gazette notification, expected roughly 18 months after the Act's gazetted predecessor (a date not yet reached or notified as of this document's as_of_date).

No standalone private civil right of action (a direct court suit) was found; the only individual remedy is the Authority's own compensation power under section 35, and that too is deferred.

Sensitive categories

Personal Data Protection Act, 2026, sensitive personal data and biometric data

cite Personal Data Protection Act, 2026, Act No. 63 of 2026, s.2(21), s.2(14), s.7 stage RECENT in force 10 months effective 2025-11-06 binds public and private bodies source official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), via an Internet Archive capture since the official portal serves no HTTPS
What it requires

Biometric Data is defined (definitions item 14) as personal data created through measurement or technical processing of a person's physical, physiological or behavioral characteristics, capable of uniquely identifying a specific person, expressly naming DNA, blood group, fingerprint, facial image, iris scan, voiceprint, and gait pattern as examples.

It is one of the enumerated Sensitive Personal Data categories (item 21), alongside genetic data, ethnic and community data, political or religious belief, trade union membership, health data, sexual orientation, criminal-record data, and real-time geolocation data.

Section 7 processing conditions for sensitive data are narrower than the ordinary section 5(3) legitimate-interest grounds: specific consent, contract necessity, an employment or social-security legal duty, a health worker's treatment duty or life or health emergency, a duty imposed by law, or the data principal's own voluntary public disclosure of the data.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.