Data Protection & Privacy | Bangladesh

by tahmidrahman1995@gmail.com | Sep 8, 2026

Technology, IP & DataPractice areaBangladesh · Cross-border

Data Protection &
Privacy

Bangladesh-related personal-data questions can arise when a product, workforce process, supplier arrangement or digital service is designed, changed or scaled. This page outlines the legal and commercial questions that may arise under the Personal Data Protection Act, 2026, including privacy governance and international data transfers.
FocusTechnology, IP & Data
Page typePractice
information
Initial routeStart with
context

The starting point

Questions to frame
early

A clear view of the data lifecycle, organisational roles and Bangladesh connection can help identify where the legal position may need closer assessment. The answer will depend on the relevant facts, statutory exceptions and developing regulatory detail.

01

Does the processing connect with Bangladesh?

The PDPA can extend beyond processing carried out in Bangladesh. Location, recipients, services, monitoring activity and the position of the individual concerned may all be relevant.
02

How are purpose and responsibility defined?

The statutory distinction between a data fiduciary and a processor makes the purpose of processing, instructions, systems and contractual allocation important starting points.
03

Could a transfer alter the analysis?

Cloud hosting, remote access and group-wide systems can raise questions about data classification, sensitivity, destination safeguards, contractual context and future prescribed procedures.

A focused conversation

Areas for legal
assessment

The following workstreams illustrate the issues that may be relevant where personal data is collected, used, stored, shared or made accessible across borders. They are general information, not a conclusion on any organisation’s legal position.

01 · Potential question

Scope and data mapping

An assessment may consider processing purposes, personal-data categories, systems, recipients, retention points, organisational roles and the nature of the Bangladesh connection.
02 · Potential question

Notices, consent and processing grounds

Privacy notices, consent pathways, withdrawal mechanisms, stated purposes and documented processing grounds may need to be considered together rather than as isolated formalities.
03 · Potential question

Sensitive and children’s data

Genetic, biometric, health, belief, union, criminal and real-time geolocation information are among statutory examples of sensitive personal data. Children’s data can raise separate consent and prescribed-procedure questions.
04 · Potential question

Processor and vendor arrangements

Cloud, software, outsourcing and other supplier arrangements may require attention to processing instructions, confidentiality, security, assistance, escalation, records, deletion and audit-related terms.
05 · Potential question

Individual-rights processes

Access, correction, completion, portability, withdrawal, objection and deletion requests may call for verification, triage, documentation and response pathways that account for statutory exceptions and later regulatory detail.
06 · Potential question

International transfers and remote access

A cross-border assessment may examine data classification, transfer basis, consent or contractual context, scale, sensitivity, destination safeguards and the role of forthcoming regulations or standard operating procedures.
07 · Potential question

Security and breach governance

Appropriate technical and organisational measures, internal escalation, contractual notices and record preservation may be relevant where security concerns or a potential personal-data breach are identified.
08 · Potential question

Regulatory readiness

Designation, audit and Chief Data Officer questions require careful treatment because the statutory framework reserves elements for regulatory detail and later commencement.

Bangladesh context

Bangladesh privacy
framework

The Personal Data Protection Act, 2026 provides Bangladesh’s comprehensive statutory framework for personal-data processing. It addresses territorial reach, roles, processing grounds, transparency, security, retention, records, individual rights, transfers and administrative mechanisms. The Act refers to the National Data Management Authority established under the National Data Management Act, 2026. Parts of the operating framework remain dependent on commencement notices, rules, regulations, standard operating procedures and institutional implementation.

Laws of Bangladesh

Bangladesh connection and organisational roles

The PDPA addresses specified Bangladesh-connected processing and certain foreign processing linked to goods or services, monitoring or profiling involving a person in Bangladesh. It distinguishes a data fiduciary from a processor, so the facts and role allocation require close attention.Read source
Laws of Bangladesh

Transfers are not a one-size-fits-all question

The Act permits the Government to classify personal data and sets conditions for transfers abroad. It identifies certain transfer bases while reserving procedures, technology and tools for further regulations and standard operating procedures.Read source
Laws of Bangladesh

Authority framework and implementation

The PDPA assigns specified implementation, guidance, coordination, direction and inspection functions to the National Data Management Authority. The companion statute establishes the Authority and its wider data-management framework.Read source

Questions, not prescriptions

What may
matter.

These answers are general information. The applicable route always depends on the facts, documents and current legal position.

Can Bangladesh’s Personal Data Protection Act affect an organisation outside Bangladesh?
The Act includes specified foreign processing connected with supplying goods or services to, or monitoring or profiling, a data subject in Bangladesh. Whether it applies in a particular situation remains dependent on the facts and the statutory framework.
What should be considered before using a processor or transferring personal data outside Bangladesh?
Relevant questions may include the parties’ roles, purpose, processing basis, contract terms, data classification, security, transfer conditions and any prescribed procedures. The Act does not support a blanket statement that every overseas transfer is either prohibited or unrestricted.
What if a potential personal-data breach is identified?
The issue may require prompt governance assessment, including internal escalation, preservation, contractual notices and the conditional question of notification to the Authority. The Act refers to notification where a breach may cause significant harm, while the form, manner and timing are to be prescribed.

Begin with context

Discuss a data-protection
question

For a Bangladesh-related or cross-border data-protection question, please share only non-confidential context in an initial enquiry.

Legal information only. This proposed page provides general information about Bangladesh-related data-protection and privacy issues as of 8 September 2026. It is not legal advice, does not address every applicable law or factual situation, and should not be relied upon instead of advice on a specific situation. Laws, rules, regulations, official guidance and commencement notices may change. Contacting TRW & Co or using this website does not establish a professional relationship. Please do not send confidential information, personal data, credentials or incident evidence through an initial website enquiry.
Legal status: the statutory text, Gazette commencement notices, rules, regulations, standard operating procedures and Authority guidance may alter the operational position. The provision on Chief Data Officers, and provisions on complaints, fines and compensation, await later commencement under the Act.