Cybersecurity Code of Practice for ICT/Telecommunications Service Providers, privacy and PII duty
Cybersecurity Code of Practice for ICT/Telecommunications Service Providers (issued under Information, Communications and Media Act of… Bhutan 2018, s.58), s.8.6
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 10 October 2024.
An enforcement supervision rule binding private bodies.
As of 30 August 2026.
What it requires
- A Telecom Service Provider or other ICT service provider with critical information infrastructure in Bhutan must establish and communicate a privacy and PII-protection policy, implement procedures to preserve that privacy, including for a biometric identifier such as a voiceprint or faceprint handled as PII, and put in place appropriate technical and organizational measures, consistent with its reporting obligations under the Information, Communications and Media Act of Bhutan 2018.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Issued by BICMA under section 58 of the ICM Act as a binding code of practice for licensed Telecom Service Providers and other ICT service providers operating critical information infrastructure, in force since 10 October 2024.
Section 8.6 requires a licensee to establish and communicate a topic-specific policy on privacy and protection of Personally Identifiable Information (PII), to implement procedures for preserving that privacy, and to put in place appropriate technical and organizational measures, expressly deferring compliance to "relevant legislation and regulations" (the ICM Act's own Chapter 21 duties).
The Code does not itself define "PII" or name biometric data, and its incident-response requirement (s.12.1) requires only that a licensee's Incident Response Plan include a reporting structure aligned with "its reporting obligations under the Act and any other laws and regulations"; it creates no independent breach-notification threshold, recipient, or timeline of its own. It is a separate, more recent, government-issued instrument, not a republication of the ICM Act.
When LexLint raises it
crawls_webprocesses_biometricsprocesses_voiceprovides_telecom_services
Read the law
official regulatory text, Bhutan InfoComm and Media Authority (BICMA)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.