Law / Bhutan

Bhutan

privacy

Bhutan has no standalone, dedicated data-protection Act, but the Information, Communications and Media Act of Bhutan 2018 (ICMA) carries a real personal-data regime across three chapters: Chapter 21 (data protection duties on any person: consent for collection, non-disclosure, destruction of obsolete data), Chapter 17 (fuller privacy duties, including a mandatory privacy policy, purpose and storage limitation, and security, specifically on ICT and media facility or service providers and vendors), and Chapter 22 (offences and penalties, including a court-ordered compensation remedy for a negligent data-security failure).

Biometric information is expressly listed as a Sensitive Personal Data category, which the derivation seed had not recorded, and information freely available or accessible in the public domain is carved out of that sensitive-category classification specifically, not out of the Act's personal-data coverage generally, confirming rather than correcting the seed's assessment that no general public-domain carve-out exists.

A reviewer pass independently confirmed the government's own domains for the ICM Act text (nab.gov.bt, parliament.bt) remain TLS-unreachable, so the Act is still sourced to a journalist-federation mirror, and separately located a genuinely additional, government-issued instrument the research pass missed: BICMA's Cybersecurity Code of Practice for ICT/Telecommunications Service Providers (in force since 10 October 2024, hosted on the TLS-valid bicma.gov.bt), whose section 8.6 imposes a PII privacy-policy and technical-safeguards duty on licensed Telecom and ICT providers, issued under ICMA s.58.

The Bhutan National Digital Identity Act 2023, described in secondary summaries as biometric-enabled, could not be obtained in readable primary text despite five attempts across two government domains and a Wayback Machine snapshot, all genuine infrastructure failures; it is the highest-priority follow-up gap for this jurisdiction. The Royal Monetary Authority's financial-sector data-privacy guidelines were also not independently verified this pass.

10 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Information, Communications and Media Act of Bhutan 2018, data protection and privacy duties

cite Information, Communications and Media Act of Bhutan 2018, ss.336-337, 339-343, 384-386 stage IMMINENT commencement not set binds public and private bodies source official Act text
What it requires

Chapter 21 imposes a general consent-for-collection duty (s.384: express written permission of the subject, unless permitted or required by law), a non-disclosure duty absent authorization or legal requirement (s.385), and a duty to delete or destroy obsolete personal information, including sensitive personal data (s.386), on "a person" generally.

Chapter 17 imposes a fuller set of duties specifically on an ICT and Media facility or service provider and vendor: a duty to respect and protect privacy (s.336), a mandatory published privacy policy disclosing data types, sources, purposes, use, disclosure recipients, and opt-out options (ss.337-338), collection and use limited to what a reasonable person would consider appropriate (s.339), storage and use limited to the intended purpose (s.340), no disclosure to affiliates or third parties beyond the transaction absent written authorization (s.341), and continuing responsibility, with contractual binding, for personal data a provider transfers to a third party (ss.342-343).

No phased-commencement language was found for these chapters; this instrument is not recorded as currently in effect for lack of a confirmed primary commencement date, though the chapters function as operative law in practice.

Data subject rights

Information, Communications and Media Act of Bhutan 2018, user review and removal rights

cite Information, Communications and Media Act of Bhutan 2018, ss.338(3), 340 stage IMMINENT commencement not set binds private bodies source official Act text
What it requires

Section 338(3) requires an ICT and Media facility or service provider and vendor to let users or consumers review and, when necessary, have their information amended or removed. Section 340 requires information to be removed or withdrawn upon a user's request. These rights run specifically against an ICT/Media provider under Chapter 17; no equivalent named right was found running against a general Chapter 21 data handler. No express portability right was found.

Enforcement supervision

Cybersecurity Code of Practice for ICT/Telecommunications Service Providers, privacy and PII duty

cite Cybersecurity Code of Practice for ICT/Telecommunications Service Providers (issued under Information, Communications and Media Act of… Bhutan 2018, s.58), s.8.6 stage IN FORCE in force since 2024-10-10 binds private bodies source official regulatory text, Bhutan InfoComm and Media Authority (BICMA)
What it requires

Issued by BICMA under section 58 of the ICM Act as a binding code of practice for licensed Telecom Service Providers and other ICT service providers operating critical information infrastructure, in force since 10 October 2024.

Section 8.6 requires a licensee to establish and communicate a topic-specific policy on privacy and protection of Personally Identifiable Information (PII), to implement procedures for preserving that privacy, and to put in place appropriate technical and organizational measures, expressly deferring compliance to "relevant legislation and regulations" (the ICM Act's own Chapter 21 duties).

The Code does not itself define "PII" or name biometric data, and its incident-response requirement (s.12.1) requires only that a licensee's Incident Response Plan include a reporting structure aligned with "its reporting obligations under the Act and any other laws and regulations"; it creates no independent breach-notification threshold, recipient, or timeline of its own.

Found through an independent search of the official bicma.gov.bt domain (which, unlike nab.gov.bt and parliament.bt, is TLS-reachable) while attempting to source the ICM Act 2018 itself at a government publisher; it is a genuinely separate, more recent, government-issued instrument, not a republication of the ICM Act.

Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures

cite Information, Communications and Media Act of Bhutan 2018, ss.387-388 stage IMMINENT commencement not set binds public and private bodies source official Act text
What it requires

The Bhutan InfoComm and Media Authority (BICMA), the unified telecom, broadcast, media, and ICT regulator this Act establishes, is the supervisory authority for the whole Act, including Chapters 17, 21, and 22, though its specific enforcement powers over the Chapter 21/17 civil-obligation provisions were not independently traced beyond Chapter 22's own offence sections.

Section 387 ("Failure to protect data") makes a person possessing, dealing with, or handling personal data, including sensitive personal data, who is negligent in implementing reasonable security practices and thereby causes wrongful loss or gain, liable to pay court-determined compensation to the victim, a genuine private right of action in substance.

Section 388 ("Unlawful Disclosure of data or information") separately makes it an offence to disclose another's personal data without consent or in breach of a lawful contract, intending or knowing it likely to cause wrongful loss or gain; its exact penalty tier was not confirmed this pass due to an extraction artifact at a page break.

Sensitive categories

Information, Communications and Media Act of Bhutan 2018, sensitive personal data and biometric information

cite Information, Communications and Media Act of Bhutan 2018, definitions clause, item 89(f) stage IMMINENT commencement not set binds public and private bodies source official Act text
What it requires

Definitions item (89) lists biometric information as a Sensitive Personal Data or Information category, alongside password, financial information, physical/physiological/mental health condition, sexual orientation, medical records, and a residual "other information legally deemed to be private" category.

The item's own proviso carves information that is freely available or accessible in the public domain, or available under another existing national law, out of the sensitive-personal-information classification, though this does not obviously rescue a voiceprint or faceprint derived from public material, since the derived identifier is a distinct data element from its source recording.

No standalone definition of "biometric information" exists; the term is not otherwise defined, and neither "voice" nor "voiceprint" nor "facial image" appears anywhere in the Act as its own named term. Creating and storing an identity-linked voiceprint or faceprint would be handling Sensitive Personal Data, triggering Chapter 21's consent, non-disclosure, and destruction duties, and, where done by an ICT/media provider, Chapter 17's fuller duties.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.