Law / Nepal

Nepal

privacy

Nepal's Privacy Act, 2075 (2018) was authenticated 18 September 2018 and came into force immediately under its own section 1(2). It is a privacy tort and confidentiality code, not a General Data Protection Regulation (GDPR)-shaped comprehensive regime: twelve chapters each protect privacy of a distinct subject matter, backed by a single uniform criminal penalty and court-based compensation rather than administrative fines.

Scope varies provision by provision between duties running to "a public body," "a public body or body corporate," and "no one"; the private-sector reach must be read clause by clause rather than assumed uniform. Biometric information is protected as ordinary personal information and, separately, as a non-disclosure-without-consent category, but section 27 affirmatively excludes it from the Act's one heightened "sensitive information" tier, a deliberate omission rather than an absent concept.

The Data Act, 2079 (2022), reported by secondary sources to be a separate data-governance statute establishing a National Data Council and a not-yet-fully-operational Data Protection Authority, was not obtained in primary text this pass and is not authored here; its cross-border and other posture remains unconfirmed.

12 instruments named 4 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Privacy Act, 2075, general privacy and collection regime

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, ss.1(2), 12(3), 23, 24, 26(1) stage IN FORCE in force since 2018-09-18 binds public and private bodies source official English translation, Nepal Law Commission
What it requires

The Act sets no General Data Protection Regulation (GDPR)-style enumerated lawful-basis list; each chapter instead states a "no one shall do X without consent" rule for its own subject matter, with scattered exceptions (court order, authorized-official demand, criminal investigation, public-interest research). Section 23(1) restricts collection to an official authorized under law or a person that official permits, a public-sector-centric default.

Section 12(3) (purpose limitation) and section 26(1) (consent to use) both expressly name "a public body or body corporate," so those two duties bind private entities directly. There is no formal controller/processor allocation and no registration regime. In force immediately from authentication.

Data subject rights

Privacy Act, 2075, correction right

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, s.28 stage IN FORCE in force since 2018-09-18 binds government bodies source official English translation, Nepal Law Commission
What it requires

Section 28 is the sole rights-like provision located: a right to apply to the concerned public body to correct information the person believes is wrong or not fact-based, with the public body deciding after inquiry whether to correct it. The right does not run against a private body corporate on its face. No express right of access, erasure, portability, or objection was found anywhere in the sections read, a materially thinner rights catalog than this batch's other South Asian jurisdictions.

Enforcement supervision

Privacy Act, 2075, enforcement and compensation

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, ss.29-32 stage IN FORCE in force since 2018-09-18 binds public and private bodies source official English translation, Nepal Law Commission
What it requires

No Data Protection Authority or equivalent regulator is established by this Act; enforcement runs through the District Court. An aggrieved person may file a complaint within three months of the offending act, except for a defined subset of more serious offences, including a section 27(1) sensitive-information violation and a section 23 unauthorized-collection violation, where the Government of Nepal itself becomes the plaintiff.

Penalty is a single uniform band across every offence, imprisonment up to three years or a fine up to NPR 30,000, or both. Section 31 gives a genuine, court-mediated private right of action: a person harmed by an offence or other act under the Act may complain directly to the District Court for compensation, and the court shall order reasonable compensation paid by the offender if it finds compensation warranted.

Sensitive categories

Privacy Act, 2075, sensitive information and biometric data

cite Privacy Act, 2075 (2018), Act Number 14 of 2075, ss.2(c)(6), 11(2)(f), 12(4)(e), 19(3), 27 stage IN FORCE in force since 2018-09-18 binds public and private bodies source official English translation, Nepal Law Commission
What it requires

Section 2(c)(6) defines "personal information" to include a person's thumb impressions, fingerprints, retina of eye, blood group, or other biometric information. Section 11(2)(f) lists biological or biometric data and thumb impression as a protected "personal document" category, and section 12(4)(e) separately bars a third party from disclosing or publishing another person's biometric details without consent once held.

Section 19(3) restricts the act of recording a private conversation without consent or lawful authorization, with an express carve-out for a speech or statement made publicly; it does not itself govern what may be done with a recording once lawfully obtained.

Section 27's "sensitive information" list, the Act's one heightened-protection category, excludes biometric data entirely: caste/ethnicity/origin, political affiliation, religious faith, health, sexual orientation, and property details are listed, but biometric data is not among them. No dedicated biometric consent form, retention ceiling, or destruction-duty timeline exists.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.