Information, Communications and Media Act of Bhutan 2018, data protection and privacy duties
Information, Communications and Media Act of Bhutan 2018, ss.336-337, 339-343, 384-386
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 8 January 2018.
A comprehensive regime rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Bhutan, including a voiceprint, faceprint, or other biometric identifier, must obtain the subject's express written permission before collecting it and must not disclose it to a third party without authorization. An ICT or media service provider or vendor must additionally publish a privacy policy, limit collection and use to what is reasonably appropriate, store and use data only for its intended purpose, and remain responsible for data it transfers to a third party.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Chapter 21 imposes a general consent-for-collection duty (s.384: express written permission of the subject, unless permitted or required by law), a non-disclosure duty absent authorization or legal requirement (s.385), and a duty to delete or destroy obsolete personal information, including sensitive personal data (s.386), on "a person" generally.
Chapter 17 imposes a fuller set of duties specifically on an ICT and Media facility or service provider and vendor: a duty to respect and protect privacy (s.336), a mandatory published privacy policy disclosing data types, sources, purposes, use, disclosure recipients, and opt-out options (ss.337-338), collection and use limited to what a reasonable person would consider appropriate (s.339), storage and use limited to the intended purpose (s.340), no disclosure to affiliates or third parties beyond the transaction absent written authorization (s.341), and continuing responsibility, with contractual binding, for personal data a provider transfers to a third party (ss.342-343).
No phased-commencement language was found for these chapters; this instrument is not recorded as currently in effect for lack of a confirmed primary commencement date, though the chapters function as operative law in practice. The Act's own Section 2 ("Commencement") sets a single, whole-Act date rather than a chapter-by-chapter schedule: "This Act comes into force on the 22nd Day of the 11th month of the Fire Female Bird Year corresponding to 8th Day of the January 2018."
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official Act text
via a journalist-federation mirror of the government-issued PDF (samsn.ifj.org), since the government's own hosting domains serve live TLS failures
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.