Technology, IP & DataPractice areaBangladesh · Cross-border
Data Protection &
Privacy
information
context
The starting point
Questions to frame
early
A clear view of the data lifecycle, organisational roles and Bangladesh connection can help identify where the legal position may need closer assessment. The answer will depend on the relevant facts, statutory exceptions and developing regulatory detail.
Does the processing connect with Bangladesh?
The PDPA can extend beyond processing carried out in Bangladesh. Location, recipients, services, monitoring activity and the position of the individual concerned may all be relevant.How are purpose and responsibility defined?
The statutory distinction between a data fiduciary and a processor makes the purpose of processing, instructions, systems and contractual allocation important starting points.Could a transfer alter the analysis?
Cloud hosting, remote access and group-wide systems can raise questions about data classification, sensitivity, destination safeguards, contractual context and future prescribed procedures.A focused conversation
Areas for legal
assessment
The following workstreams illustrate the issues that may be relevant where personal data is collected, used, stored, shared or made accessible across borders. They are general information, not a conclusion on any organisation’s legal position.
Scope and data mapping
An assessment may consider processing purposes, personal-data categories, systems, recipients, retention points, organisational roles and the nature of the Bangladesh connection.Notices, consent and processing grounds
Privacy notices, consent pathways, withdrawal mechanisms, stated purposes and documented processing grounds may need to be considered together rather than as isolated formalities.Sensitive and children’s data
Genetic, biometric, health, belief, union, criminal and real-time geolocation information are among statutory examples of sensitive personal data. Children’s data can raise separate consent and prescribed-procedure questions.Processor and vendor arrangements
Cloud, software, outsourcing and other supplier arrangements may require attention to processing instructions, confidentiality, security, assistance, escalation, records, deletion and audit-related terms.Individual-rights processes
Access, correction, completion, portability, withdrawal, objection and deletion requests may call for verification, triage, documentation and response pathways that account for statutory exceptions and later regulatory detail.International transfers and remote access
A cross-border assessment may examine data classification, transfer basis, consent or contractual context, scale, sensitivity, destination safeguards and the role of forthcoming regulations or standard operating procedures.Security and breach governance
Appropriate technical and organisational measures, internal escalation, contractual notices and record preservation may be relevant where security concerns or a potential personal-data breach are identified.Regulatory readiness
Designation, audit and Chief Data Officer questions require careful treatment because the statutory framework reserves elements for regulatory detail and later commencement.Bangladesh context
Bangladesh privacy
framework
The Personal Data Protection Act, 2026 provides Bangladesh’s comprehensive statutory framework for personal-data processing. It addresses territorial reach, roles, processing grounds, transparency, security, retention, records, individual rights, transfers and administrative mechanisms. The Act refers to the National Data Management Authority established under the National Data Management Act, 2026. Parts of the operating framework remain dependent on commencement notices, rules, regulations, standard operating procedures and institutional implementation.
Bangladesh connection and organisational roles
The PDPA addresses specified Bangladesh-connected processing and certain foreign processing linked to goods or services, monitoring or profiling involving a person in Bangladesh. It distinguishes a data fiduciary from a processor, so the facts and role allocation require close attention.Read sourceTransfers are not a one-size-fits-all question
The Act permits the Government to classify personal data and sets conditions for transfers abroad. It identifies certain transfer bases while reserving procedures, technology and tools for further regulations and standard operating procedures.Read sourceAuthority framework and implementation
The PDPA assigns specified implementation, guidance, coordination, direction and inspection functions to the National Data Management Authority. The companion statute establishes the Authority and its wider data-management framework.Read sourceQuestions, not prescriptions
What may
matter.
These answers are general information. The applicable route always depends on the facts, documents and current legal position.
Can Bangladesh’s Personal Data Protection Act affect an organisation outside Bangladesh?
What should be considered before using a processor or transferring personal data outside Bangladesh?
What if a potential personal-data breach is identified?
Begin with context
Discuss a data-protection
question
For a Bangladesh-related or cross-border data-protection question, please share only non-confidential context in an initial enquiry.