Law / Bhutan

Bhutan

10 of 12 named instruments researched to a stage, across five of the six areas of law we track: 10 in force. As of 16 September 2026.

When they take effect10 of 10 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 7 instruments (7 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (243 words)

Bhutan has no binding AI-transparency, AI-risk, or AI-training statute.

The Bhutan National AI Strategy 2025, published by the Government Technology Agency, sets a decade-long, Gross National Happiness-oriented policy vision across eight sectors and calls, under its Governance and Regulations enabler, for a future national AI governing body, ethical guidelines, and a review of existing legal instruments including the Information, Communications and Media Act, but the Strategy states no legally enforceable rule of its own and creates no binding duty.

A 2024 Guideline for Generative Artificial Intelligence Usage in the Civil Service, issued jointly by the Government Technology Agency and the Royal Civil Service Commission, asks civil servants to apply human oversight to AI outputs, be transparent about AI use in public communications, and take care before sharing sensitive data with external AI tools, but it binds only the civil service and is not legislation.

The National Digital Identity Act of Bhutan 2023 is described in secondary sources as establishing a biometric-enabled digital identity wallet; its text is not reproduced in any copy located at the two government domains that would carry it, one of which serves an expired TLS certificate, so its content is not described here.

The Information, Communications and Media Act of Bhutan 2018 does bind any person to a criminal prohibition on creating, publishing, or distributing obscene or sexually explicit material depicting a child, in a provision broad enough on its own terms to reach a synthetic or AI-generated depiction.

AI prohibited practices

Information, Communications and Media Act of Bhutan 2018, obscene communications depicting children

Information, Communications and Media Act of Bhutan 2018, s.424official Act text

In force since 8 January 2018. Binds public and private bodies.

What this law does

Section 424 makes it a felony of the fourth degree for a person to publish, distribute, or transmit an obscene communication or material depicting children engaged in a sexually explicit act, or to create text or digital images, collect, seek, browse, download, advertise, promote, exchange, or distribute material in any form depicting children in an obscene, indecent, or sexually explicit manner, or to record own or another's abuse of a child in a sexually explicit act.

The offence's second limb criminalises creating a digital image or text depicting a child in that manner without requiring that the depicted child be a real, identifiable person, so on the section's own text it reaches a computer-generated or AI-synthesized depiction of a child in the same terms as one derived from a real photograph.

What it requires

Privacy law5 instruments, 5 in force

Research summary (228 words)

Bhutan has no standalone, dedicated data-protection Act, but the Information, Communications and Media Act of Bhutan 2018 (ICMA) carries a real personal-data regime across three chapters: Chapter 21 (data protection duties on any person: consent for collection, non-disclosure, destruction of obsolete data), Chapter 17 (fuller privacy duties, including a mandatory privacy policy, purpose and storage limitation, and security, specifically on ICT and media facility or service providers and vendors), and Chapter 22 (offences and penalties, including a court-ordered compensation remedy for a negligent data-security failure).

Biometric information is expressly listed as a Sensitive Personal Data category, and information freely available or accessible in the public domain is carved out of that sensitive-category classification specifically, not out of the Act's personal-data coverage generally, so no general public-domain carve-out exists. The Act's text is cited from a journalist-federation copy of the official print.

A further government-issued instrument applies alongside it: BICMA's Cybersecurity Code of Practice for ICT/Telecommunications Service Providers (in force since 10 October 2024, hosted on the TLS-valid bicma.gov.bt), whose section 8.6 imposes a PII privacy-policy and technical-safeguards duty on licensed Telecom and ICT providers, issued under ICMA s.58.

The Bhutan National Digital Identity Act 2023, described in secondary summaries as biometric-enabled, has not been located in readable primary text, so its contents are not established here. The Royal Monetary Authority's financial-sector data-privacy guidelines were also not independently verified.

Comprehensive regime

Information, Communications and Media Act of Bhutan 2018, data protection and privacy duties

Information, Communications and Media Act of Bhutan 2018, ss.336-337, 339-343, 384-386official Act text

In force since 8 January 2018. Binds public and private bodies.

What this law does

Chapter 21 imposes a general consent-for-collection duty (s.384: express written permission of the subject, unless permitted or required by law), a non-disclosure duty absent authorization or legal requirement (s.385), and a duty to delete or destroy obsolete personal information, including sensitive personal data (s.386), on "a person" generally.

Chapter 17 imposes a fuller set of duties specifically on an ICT and Media facility or service provider and vendor: a duty to respect and protect privacy (s.336), a mandatory published privacy policy disclosing data types, sources, purposes, use, disclosure recipients, and opt-out options (ss.337-338), collection and use limited to what a reasonable person would consider appropriate (s.339), storage and use limited to the intended purpose (s.340), no disclosure to affiliates or third parties beyond the transaction absent written authorization (s.341), and continuing responsibility, with contractual binding, for personal data a provider transfers to a third party (ss.342-343).

No phased-commencement language was found for these chapters; this instrument is not recorded as currently in effect for lack of a confirmed primary commencement date, though the chapters function as operative law in practice. The Act's own Section 2 ("Commencement") sets a single, whole-Act date rather than a chapter-by-chapter schedule: "This Act comes into force on the 22nd Day of the 11th month of the Fire Female Bird Year corresponding to 8th Day of the January 2018."

What it requires

Data subject rights

Information, Communications and Media Act of Bhutan 2018, user review and removal rights

Information, Communications and Media Act of Bhutan 2018, ss.338(3), 340official Act text

In force since 8 January 2018. Binds private bodies.

What this law does

Section 338(3) requires an ICT and Media facility or service provider and vendor to let users or consumers review and, when necessary, have their information amended or removed. Section 340 requires information to be removed or withdrawn upon a user's request. These rights run specifically against an ICT/Media provider under Chapter 17; no equivalent named right was found running against a general Chapter 21 data handler. No express portability right was found.

What it requires

Enforcement supervision

Cybersecurity Code of Practice for ICT/Telecommunications Service Providers, privacy and PII duty

Cybersecurity Code of Practice for ICT/Telecommunications Service Providers (issued under Information, Communications and Media Act of… Bhutan 2018, s.58), s.8.6official regulatory text, Bhutan InfoComm and Media Authority (BICMA)

In force since 10 October 2024. Binds private bodies.

What this law does

Issued by BICMA under section 58 of the ICM Act as a binding code of practice for licensed Telecom Service Providers and other ICT service providers operating critical information infrastructure, in force since 10 October 2024.

Section 8.6 requires a licensee to establish and communicate a topic-specific policy on privacy and protection of Personally Identifiable Information (PII), to implement procedures for preserving that privacy, and to put in place appropriate technical and organizational measures, expressly deferring compliance to "relevant legislation and regulations" (the ICM Act's own Chapter 21 duties).

The Code does not itself define "PII" or name biometric data, and its incident-response requirement (s.12.1) requires only that a licensee's Incident Response Plan include a reporting structure aligned with "its reporting obligations under the Act and any other laws and regulations"; it creates no independent breach-notification threshold, recipient, or timeline of its own. It is a separate, more recent, government-issued instrument, not a republication of the ICM Act.

What it requires

Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures

Information, Communications and Media Act of Bhutan 2018, ss.387-388official Act text

In force since 8 January 2018. Binds public and private bodies.

What this law does

The Bhutan InfoComm and Media Authority (BICMA), the unified telecom, broadcast, media, and ICT regulator this Act establishes, is the supervisory authority for the whole Act, including Chapters 17, 21, and 22, though its specific enforcement powers over the Chapter 21/17 civil-obligation provisions were not independently traced beyond Chapter 22's own offence sections.

Section 387 ("Failure to protect data") makes a person possessing, dealing with, or handling personal data, including sensitive personal data, who is negligent in implementing reasonable security practices and thereby causes wrongful loss or gain, liable to pay court-determined compensation to the victim, a genuine private right of action in substance.

Section 388 ("Unlawful Disclosure of data or information") separately makes it an offence to disclose another's personal data without consent or in breach of a lawful contract, intending or knowing it likely to cause wrongful loss or gain; its exact penalty tier is not confirmed due to an extraction artifact at a page break.

What it requires

Sensitive categories

Information, Communications and Media Act of Bhutan 2018, sensitive personal data and biometric information

Information, Communications and Media Act of Bhutan 2018, definitions clause, item 89(f)official Act text

In force since 8 January 2018. Binds public and private bodies.

What this law does

Definitions item (89) lists biometric information as a Sensitive Personal Data or Information category, alongside password, financial information, physical/physiological/mental health condition, sexual orientation, medical records, and a residual "other information legally deemed to be private" category.

The item's own proviso carves information that is freely available or accessible in the public domain, or available under another existing national law, out of the sensitive-personal-information classification, though this does not obviously rescue a voiceprint or faceprint derived from public material, since the derived identifier is a distinct data element from its source recording.

No standalone definition of "biometric information" exists; the term is not otherwise defined, and neither "voice" nor "voiceprint" nor "facial image" appears anywhere in the Act as its own named term. Creating and storing an identity-linked voiceprint or faceprint would be handling Sensitive Personal Data, triggering Chapter 21's consent, non-disclosure, and destruction duties, and, where done by an ICT/media provider, Chapter 17's fuller duties.

What it requires

Scraping law1 instrument, 1 in force

Research summary (241 words)

Bhutan has no scraping-specific statute, so general law governs each dimension separately.

The Information, Communications and Media Act of Bhutan 2018 (ICMA) makes unauthorized access to a computer, computer system, network, or computer, content, or traffic data a standalone felony of the fourth degree carrying court-ordered compensation (s.416), separately from a broader tampering offence keyed to intent to cause loss, gain, or damage (s.415); neither section defines what makes access "unauthorized", so it is unclear whether reading a public, unauthenticated page without agreement or technical circumvention falls within either provision, and no reported case has tested the point.

No Bhutanese court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright Act of the Kingdom of Bhutan, 2001 permits quotation and reproduction for informatory purposes subject to a fair-practice test, but it excludes a database from its personal-use reproduction exception and predates the concept of a text-and-data-mining exception, so training a model on scraped copyrighted Bhutanese text has no dedicated exception to rest on.

The Act confers no sui generis database right. The ICMA's data-protection duties (researched separately as this jurisdiction's privacy law) are not expressly limited to information from a non-public source, so they extend in principle to personal data collected by scraping a public page.

No Bhutanese statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Information, Communications and Media Act of Bhutan 2018, unauthorized access and tampering with computer systems

Information, Communications and Media Act of Bhutan 2018, ss.415-416official Act text

In force since 8 January 2018. Binds public and private bodies.

What this law does

Section 415 makes it an offence, keyed to intent to cause or knowledge that it is likely to cause wrongful loss, gain, or damage, to access a computer, computer system, network, or computer, content, or traffic data and thereby cause a stoppage or denial of service, delete or alter data, diminish a system's value or utility, or introduce a computer contaminant; the section labels this "tampering with computer material", punishable under the Penal Code of Bhutan.

Section 416 separately makes unauthorized access to a computer, computer system, network, or computer, content, or traffic data an offence in its own right, without requiring the loss, gain, or damage element of section 415, graded a felony of the fourth degree with court-determined compensation to the victim.

What it requires

Age gating law1 instrument, 1 in force

Research summary (193 words)

Bhutan has no adult-content age-verification statute, no social-media minor-access restriction, and no app-store age-verification requirement.

The Information, Communications and Media Act of Bhutan 2018 (ICMA) does impose an age-appropriate design duty of the kind this topic tracks: an ICT and Media facility, service provider, or vendor must keep a communication addressed to, or of particular interest to, children age-appropriate, take reasonable steps to shield children from offensive communications and from being drawn into business transactions, and refrain from advertisements that exploit a child's vulnerabilities.

The same chapter also bars an ICT or media provider from collecting or disclosing a child's personal information without a parent's or guardian's express, verifiable consent; that duty attaches to personal data rather than to content or advertising, so it is treated as this jurisdiction's data-protection law rather than as an age-appropriate design duty in its own right.

Bhutan's film classification regime, under which the National Film Commission certifies a film for unrestricted, child-unaccompanied, or adults-only exhibition (ICMA ss.254-256, 408-409), is a physical-exhibition censorship scheme rather than an age-verification or age-gating duty on an online or digital service, so it is noted here without being recorded as an instrument.

Age-appropriate design code

Information, Communications and Media Act of Bhutan 2018, protection of children in communications

Information, Communications and Media Act of Bhutan 2018, ss.348-349, 351official Act text

In force since 8 January 2018. Binds private bodies.

What this law does

Section 348 requires that a communication addressed to children, or likely to be of particular interest to children, be age-appropriate, and prohibits exploiting the credulity, lack of experience, or sense of loyalty of children. Section 349 requires an ICT and Media facility or service provider and vendor to take all reasonable steps to prevent offensive communications being delivered to children and to prevent children from being drawn into conducting business transactions of any kind.

Section 351 bars an advertisement, in any form, that is aimed at taking advantage of a child's vulnerabilities. A separate provision in the same chapter, section 350, additionally bars an ICT or media provider from collecting or disclosing a child's personal information without a parent's or guardian's express, verifiable consent; because that duty attaches to personal data rather than to content or advertising, it is not carried on this instrument.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (279 words)

Bhutan has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act of the Kingdom of Bhutan, 2001 is what reaches an aggregator's reproduction of news content.

Its quotation provision permits reproducing a short part of a published work as a quotation, with source and author attribution, subject to a fair-practice and extent-justified test, and carries no headline-length or short-extract cap of its own beyond that test; a separate informatory-purposes provision permits a newspaper or periodical to reproduce another newspaper or periodical's article on current economic, political, or religious topics unless the original rightsholder has expressly reserved that right, and this is the clause most directly relevant to a news aggregator's own reproduction, since the other two clauses reach only excerpts of an event and speeches delivered in public.

No reported Bhutanese decision applies the quotation exception to a systematic news aggregator rather than to a single quotation in another work. Neighbouring rights under the Act (Part III) protect performers, sound-recording producers, and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or reported Bhutanese decision addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been located.

The Act excludes a database from its general personal-use reproduction exception and predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists, and the Act confers no sui generis database right of its own.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.