Law / Bangladesh

Bangladesh

9 of 11 named instruments researched to a stage, across four of the six areas of law we track: 8 in force and 1 enacted but not yet in force. As of 18 September 2026.

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (153 words)

Bangladesh has no general AI-risk, AI-transparency, or AI-governance statute. The ICT Division circulated a National AI Policy 2024 (Draft) under the pre-transition government, and the interim government has since circulated its own National AI Policy 2026-2030 (Draft, Version 2.0, February 2026), proposing risk-based obligations such as algorithmic impact assessments and a human-review right for automated decisions; neither draft has been adopted by cabinet or gazetted, so neither binds anyone.

The Cyber Security Act, 2026 (Act No. 81 of 2026) is the one enacted statute reaching AI conduct directly: it criminalises sending, publishing, or broadcasting sexual-harassment, blackmail, revenge-pornography, digital child-sexual-abuse-material, or sextortion content that is created or edited by artificial intelligence, binding any person regardless of sector.

Bangladesh's general personal-data statute, the Personal Data Protection Act, 2026, is researched under this jurisdiction's privacy topic rather than here, because a duty attaching to personal data is filed there whatever the technology used to process it.

AI prohibited practices

Cyber Security Act, 2026, AI-generated sexual content and CSAM ban

Cyber Security Act 2026, Act No. 81 of 2026, s.25 (offence and punishment relating to sexual harassment, blackmail, or publication of obscene content)official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 6, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1710.html

In force since 21 May 2025. Binds public and private bodies.

What this law does

Section 25(1) makes it an offence for any person, through a website or other digital or electronic medium, intentionally or knowingly to send, publish, or broadcast, or threaten to send, publish, or broadcast, any information, video, audio-visual footage, still image, or graphics that is captured, edited, or created or edited by artificial intelligence, and displayable, where it was created for, obtained for, or preserved for the purpose of blackmail, sexual harassment, revenge pornography, digital child-sexual-abuse material, or sextortion, and is harmful or intimidating.

Section 25(2) sets the base penalty at up to two years' imprisonment, or a fine of up to BDT 1,000,000, or both; section 25(3) raises it to up to five years' imprisonment, or a fine of up to BDT 2,000,000, or both, where the victim is a woman or a child under eighteen.

The Act's own commencement clause deems it, including this section, to have come into force on 21 May 2025, the date its immediate predecessor, the Cyber Security Ordinance 2025, took effect; that Ordinance had itself replaced the Cyber Security Act, 2023.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (139 words)

Bangladesh's Personal Data Protection Act, 2026 (Act No. 63 of 2026) was enacted by Parliament 10 April 2026, repealing and replacing the Personal Data Protection Ordinance, 2025 (Ordinance No. 61 of 2025) and its 2026 amending Ordinance.

By its own section 1(3), the Act is deemed to have come into force retroactively on 6 November 2025, the date the original Ordinance was gazetted, for every chapter except section 23 (mandatory Chief Data Officer appointment) and the complaint, penalty, and appeal chapter (sections 31 to 35).

So the lawful-basis, sensitive-data, data-subject-rights, retention, breach-notification, and cross-border-transfer duties already bind private data fiduciaries today, while no complaint mechanism, administrative fine, or Authority-ordered compensation is currently operative. Biometric data, defined to include facial image and voiceprint by name, is an express Sensitive Personal Data category carrying a heightened lawful-basis bar under section 7.

Breach notification

Personal Data Protection Act, 2026, breach notification duties

Personal Data Protection Act, 2026, Act No. 63 of 2026, s.20official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 29, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1692.html

In force 11 months, effective 6 November 2025. Binds public and private bodies.

What this law does

Section 20(1) requires a Data Fiduciary to notify the Authority of a personal data breach, in the form, manner, and time prescribed by regulation, whenever the breach creates a possibility of significant harm to the affected data principal. Section 20(2) lists factors, nature of breach, affected-principal categories and counts, contact details, and mitigation steps, that the Authority considers in gauging severity, again by regulation not yet located.

No statutory deadline (no 72 hour figure) appears in the Act itself, and no separate duty to notify the affected data principal directly was found in the sections read.

What it requires

Comprehensive regime

Personal Data Protection Act, 2026, comprehensive regime and lawful basis

Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.5, 8, 18official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 29, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1692.html

In force 11 months, effective 6 November 2025. Binds public and private bodies.

What this law does

Section 5 requires a Data Fiduciary to have a lawful basis before processing personal data: voluntary, specific, clear, revocable consent (s.5(2)), or one of seven enumerated legitimate-interest grounds without consent (contract performance, pre-contractual steps, legal-claims necessity, vital interests, employment/labor/social-security legal duties, the data principal's own voluntary public disclosure, or preventing harm from unreasonably withheld consent).

A Data Fiduciary determines purpose and means and remains liable for a Processor's processing (s.8). Section 18 bars retaining data beyond what the purpose requires, subject to a scientific, historical, statistical-research, or public-interest exception. In force since 6 November 2025, deemed retroactively by the Act's own commencement clause.

What it requires

Cross border transfer

Personal Data Protection Act, 2026, cross-border transfer of personal data

Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.29, 30official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 29, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1692.html

In force 11 months, effective 6 November 2025. Binds public and private bodies.

What this law does

Section 29(1) empowers the Government to classify personal data into four tiers by Schedule (public/open, internal, confidential, restricted). Transfer abroad is permitted with the data principal's consent, under a contract to which they are party involving goods or services, or with consent for their business, education, or travel/migration interests (s.29(3)), and the destination must have adequate technology and safeguards for personal-data storage per regulation (s.29(4)).

Bulk cross-border transfer of sensitive personally identifiable data, including a biometric identifier such as a fingerprint, facial-recognition data, or iris scan, requires mandatory notification to the Authority where it could threaten sovereignty, national security, or financial stability (s.29(6)).

No blanket data-localization mandate appears in the enacted text, correcting the amendment-ordinance stage's residency mandate, which industry comment reports was removed in the revision that became this Act.

What it requires

Enforcement supervision

Personal Data Protection Act, 2026, complaints, penalties and appeals

Personal Data Protection Act, 2026, Act No. 63 of 2026, ss.31-38official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 29, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1692.html

Commencement not set. Binds public and private bodies.

What this law does

Once operative, a data principal or any person with reason to believe a rights violation occurred may file a complaint with the National Data Management Authority (s.31); the Authority may impose an administrative fine of up to BDT 2,500,000 for a rights violation (s.32) and separately up to BDT 2,500,000 for a security or protection failure (s.33), with factors for setting the fine listed at s.34, plus compensation to the complaining data principal in addition to the fine (s.35).

Section 36 lets the Authority fine individual company officials personally implicated in a rights-violation complaint. Appeal against an Authority fine or compensation order runs to the Tribunal established under section 68 of the Information and Communication Technology Act, within 30 days (s.37).

None of this is currently operative: sections 23 and 31 to 35 are excluded from the Act's own retroactive commencement deeming and await a separate Government gazette notification, expected roughly 18 months after the Act's gazetted predecessor (a date not yet reached or notified as of the date shown). No standalone private civil right of action (a direct court suit) was found; the only individual remedy is the Authority's own compensation power under section 35, and that too is deferred.

What it requires

Sensitive categories

Personal Data Protection Act, 2026, sensitive personal data and biometric data

Personal Data Protection Act, 2026, Act No. 63 of 2026, s.2(21), s.2(14), s.7official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 29, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1692.html

In force 11 months, effective 6 November 2025. Binds public and private bodies.

What this law does

Biometric Data is defined (definitions item 14) as personal data created through measurement or technical processing of a person's physical, physiological or behavioral characteristics, capable of uniquely identifying a specific person, expressly naming DNA, blood group, fingerprint, facial image, iris scan, voiceprint, and gait pattern as examples.

It is one of the enumerated Sensitive Personal Data categories (item 21), alongside genetic data, ethnic and community data, political or religious belief, trade union membership, health data, sexual orientation, criminal-record data, and real-time geolocation data.

Section 7 processing conditions for sensitive data are narrower than the ordinary section 5(3) legitimate-interest grounds: specific consent, contract necessity, an employment or social-security legal duty, a health worker's treatment duty or life or health emergency, a duty imposed by law, or the data principal's own voluntary public disclosure of the data.

What it requires

Scraping law2 instruments, 2 in force

Research summary (253 words)

Bangladesh has no scraping-specific statute, so general law governs each dimension separately.

The Cyber Security Act, 2026 criminalises illegal entry into a computer, digital device, computer system, or network (s.18), but the Act does not define "illegal entry" against a security-measure-bypass test the way some other jurisdictions' computer-misuse statutes do, so whether reading a public, unauthenticated page falls within it is not addressed by the text read; no reported Bangladeshi case on the point has been located.

No Bangladeshi court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper has been located.

The Copyright Act, 2023 lists a database among the categories of protected "work" (s.2(11)), defining it as an electronically or otherwise systematically arranged collection of original works reflecting the compiler's own intellectual expression (s.2(16)), an originality-based standard rather than an investment-based sui generis extraction right; Bangladesh has not enacted a text-and-data-mining exception, and the Act's general reproduction exception for a literary work (s.70) leaves its purpose and conditions to be set by Rules not otherwise identified.

This jurisdiction's privacy-topic research into the Personal Data Protection Act, 2026 found no general exemption in the Act for personal data that is publicly accessible, so scraping personal data from a public Bangladeshi website remains subject to the Act's lawful-basis, retention, and cross-border-transfer duties, with a narrower lawful-basis test for a biometric or other sensitive-data category.

No Bangladeshi statute or reported case establishing a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigning legal weight to a robots.txt directive, has been located.

Computer misuse

Cyber Security Act, 2026, unauthorised access to a computer system

Cyber Security Act, 2026, Act No. 81 of 2026, s.18 (illegal entry into computer, digital device, computer system or network)official statute text, Bangladesh Laws (bdlaws.minlaw.gov.bd)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 6, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1710.html

In force since 21 May 2025. Binds public and private bodies.

What this law does

Section 18(1)(a) makes it an offence for a person intentionally to gain illegal entry into a computer, digital device, computer system, or computer network, or to assist another to do so, punishable by up to one year's imprisonment or a fine of up to BDT 1,000,000, or both. Section 18(1)(b) raises the offence, and the penalty to up to two years or BDT 2,000,000, where the illegal entry is for the purpose of committing an offence.

Section 18(1)(c) raises it further, to up to five years or BDT 5,000,000, where the illegal entry (described as hacking) results in theft, destruction, cancellation, or alteration of information from a data store, in a diminution of its value or utility, or in an artificial intelligence agent generating new data through that access.

The Act does not define "illegal entry" by reference to defeating a security measure or exceeding an authorisation, so the provision's reach over a scraper reading a public, unauthenticated page is not addressed by the text read.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (312 words)

Bangladesh's Cyber Security Act, 2026 (Act No. 81 of 2026, deemed retroactively in force from 21 May 2025) creates a National Cyber Security Agency and, under it, a National Computer Emergency Response Team that any government, private, or autonomous organization or institution must inform without delay after a cyber incident.

This profile flags that duty inclusively because the Act states it in general terms rather than through a licensed or sector-specific status, reaching an ordinary software distributor the same way it reaches a bank or a ministry.

The Act separately lets the Government designate a computer system, network, or information infrastructure as Critical Information Infrastructure (CII) by gazette notification, and binds each designated CII to maintain its own incident-response team, submit an annual infrastructure audit to the National Cyber Security Council, and accept the Agency's ongoing monitoring and inspection; because CII status is a government designation no declared LexLint activity can express, this profile defers that regime rather than filing it as an instrument.

The Act's own offence for unauthorized access to a computer system or to a CII binds the intruding person, software developer, or artificial intelligence tool user rather than the operator, and is recorded on this jurisdiction's scraping row instead.

No provision of the Act sets security requirements a software product or connected device must meet before going to market, creates a licensing or certification regime reaching an ordinary cybersecurity service provider, or states a general reasonable-security duty with no sector gate; its only accreditation scheme recognizes digital forensic and ICT testing laboratories, a government-lab quality-control function rather than a private-sector duty.

The Personal Data Protection Act, 2026 carries its own security-of-processing and breach-notification provisions and stays on this jurisdiction's privacy row; Bangladesh Bank separately maintains its own ICT-security directives for banks and financial institutions, a licensed-sector regime this profile defers on the same ground as the CII rows.

Vulnerability and incident reporting

Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident

Cyber Security Act, 2026 (Act No. 81 of 2026), s. 9Official text of the Cyber Security Act, 2026, Bangladesh Laws (bdlaws.minlaw.gov.bd), Bengali original mirrored via the Wayback Machine

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 6, 2026. Publisher's page: http://bdlaws.minlaw.gov.bd/act-details-1710.html

In force since 21 May 2025. Binds public and private bodies.

What this law does

The Agency maintains a National Computer Emergency Response Team and a National Security Operation Center, and every entity the Government designates as Critical Information Infrastructure must maintain its own Computer Emergency Response Team or Computer Incident Response Team and Security Operation Center.

Any government, private, or autonomous organization or institution that experiences a cyber incident must, without delay, inform the National Computer Emergency Response Team under the Agency. The Act names no fixed number of hours or days for that notification. No provision of the Act states a penalty specific to a failure to give this notification.

The Act's own offences for unauthorized access to a computer system or to Critical Information Infrastructure bind the person, software developer, or artificial intelligence tool user who intrudes, and are recorded on this jurisdiction's scraping row.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.