Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Comprehensive regime
What it requires →
Chapter 21 imposes a general consent-for-collection duty (s.384: express written permission of the subject, unless permitted or required by law), a non-disclosure duty absent authorization or legal requirement (s.385), and a duty to delete or destroy obsolete personal information, including sensitive personal data (s.386), on "a person" generally.
Chapter 17 imposes a fuller set of duties specifically on an ICT and Media facility or service provider and vendor: a duty to respect and protect privacy (s.336), a mandatory published privacy policy disclosing data types, sources, purposes, use, disclosure recipients, and opt-out options (ss.337-338), collection and use limited to what a reasonable person would consider appropriate (s.339), storage and use limited to the intended purpose (s.340), no disclosure to affiliates or third parties beyond the transaction absent written authorization (s.341), and continuing responsibility, with contractual binding, for personal data a provider transfers to a third party (ss.342-343).
No phased-commencement language was found for these chapters; this instrument is not recorded as currently in effect for lack of a confirmed primary commencement date, though the chapters function as operative law in practice.
Data subject rights
What it requires →
Section 338(3) requires an ICT and Media facility or service provider and vendor to let users or consumers review and, when necessary, have their information amended or removed. Section 340 requires information to be removed or withdrawn upon a user's request. These rights run specifically against an ICT/Media provider under Chapter 17; no equivalent named right was found running against a general Chapter 21 data handler. No express portability right was found.
Enforcement supervision
What it requires →
Issued by BICMA under section 58 of the ICM Act as a binding code of practice for licensed Telecom Service Providers and other ICT service providers operating critical information infrastructure, in force since 10 October 2024.
Section 8.6 requires a licensee to establish and communicate a topic-specific policy on privacy and protection of Personally Identifiable Information (PII), to implement procedures for preserving that privacy, and to put in place appropriate technical and organizational measures, expressly deferring compliance to "relevant legislation and regulations" (the ICM Act's own Chapter 21 duties).
The Code does not itself define "PII" or name biometric data, and its incident-response requirement (s.12.1) requires only that a licensee's Incident Response Plan include a reporting structure aligned with "its reporting obligations under the Act and any other laws and regulations"; it creates no independent breach-notification threshold, recipient, or timeline of its own.
Found through an independent search of the official bicma.gov.bt domain (which, unlike nab.gov.bt and parliament.bt, is TLS-reachable) while attempting to source the ICM Act 2018 itself at a government publisher; it is a genuinely separate, more recent, government-issued instrument, not a republication of the ICM Act.
What it requires →
The Bhutan InfoComm and Media Authority (BICMA), the unified telecom, broadcast, media, and ICT regulator this Act establishes, is the supervisory authority for the whole Act, including Chapters 17, 21, and 22, though its specific enforcement powers over the Chapter 21/17 civil-obligation provisions were not independently traced beyond Chapter 22's own offence sections.
Section 387 ("Failure to protect data") makes a person possessing, dealing with, or handling personal data, including sensitive personal data, who is negligent in implementing reasonable security practices and thereby causes wrongful loss or gain, liable to pay court-determined compensation to the victim, a genuine private right of action in substance.
Section 388 ("Unlawful Disclosure of data or information") separately makes it an offence to disclose another's personal data without consent or in breach of a lawful contract, intending or knowing it likely to cause wrongful loss or gain; its exact penalty tier was not confirmed this pass due to an extraction artifact at a page break.
Sensitive categories
What it requires →
Definitions item (89) lists biometric information as a Sensitive Personal Data or Information category, alongside password, financial information, physical/physiological/mental health condition, sexual orientation, medical records, and a residual "other information legally deemed to be private" category.
The item's own proviso carves information that is freely available or accessible in the public domain, or available under another existing national law, out of the sensitive-personal-information classification, though this does not obviously rescue a voiceprint or faceprint derived from public material, since the derived identifier is a distinct data element from its source recording.
No standalone definition of "biometric information" exists; the term is not otherwise defined, and neither "voice" nor "voiceprint" nor "facial image" appears anywhere in the Act as its own named term. Creating and storing an identity-linked voiceprint or faceprint would be handling Sensitive Personal Data, triggering Chapter 21's consent, non-disclosure, and destruction duties, and, where done by an ICT/media provider, Chapter 17's fuller duties.