Law / Bhutan

Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures

Information, Communications and Media Act of Bhutan 2018, ss.387-388

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 8 January 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • An app that negligently fails to implement reasonable security practices for personal data of a person in Bhutan, including a biometric identifier, and thereby causes wrongful loss or gain, is liable to pay court-determined compensation to the victim, and unlawfully disclosing another's personal data without consent is a separate offence under section 388.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

ICMA s.388 (Unlawful Disclosure of data or information) grades the offence a misdemeanour. Under the Penal Code of Bhutan 2004 (as amended by the Penal Code (Amendment) Act of Bhutan 2011 and 2021), Chapter 3 (Sentencing) s.12, a misdemeanour carries imprisonment of a minimum of one year and a maximum of less than three years; a second conviction for the same offence is enhanced to a felony of the fourth degree under Penal Code s.15(c). ICMA s.387 (Failure to protect data, the negligent security-failure provision) carries no criminal offence grading of its own, only court-determined civil compensation to the victim.

Who enforces it

Enforcement body

Bhutan InfoComm and Media Authority (BICMA), created by this Act, is the sector's general regulator, but a Chapter 22 offence such as s.388 is enforced as an ordinary crime: ICMA ss.443-444 route the investigative search-and-seizure power through a Court-issued warrant under the Civil and Criminal Procedure Code of Bhutan, and it is the Courts of Bhutan, not BICMA, that adjudicate the offence and determine the compensation award under ss.387-388.

What it reaches

Obligation class

Security, Consent

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Bhutan InfoComm and Media Authority (BICMA), the unified telecom, broadcast, media, and ICT regulator this Act establishes, is the supervisory authority for the whole Act, including Chapters 17, 21, and 22, though its specific enforcement powers over the Chapter 21/17 civil-obligation provisions were not independently traced beyond Chapter 22's own offence sections.

Section 387 ("Failure to protect data") makes a person possessing, dealing with, or handling personal data, including sensitive personal data, who is negligent in implementing reasonable security practices and thereby causes wrongful loss or gain, liable to pay court-determined compensation to the victim, a genuine private right of action in substance.

Section 388 ("Unlawful Disclosure of data or information") separately makes it an offence to disclose another's personal data without consent or in breach of a lawful contract, intending or knowing it likely to cause wrongful loss or gain; its exact penalty tier is not confirmed due to an extraction artifact at a page break.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official Act text
via a journalist-federation mirror of the government-issued PDF (samsn.ifj.org), since the government's own hosting domains serve live TLS failures

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app