Bangladesh has, for the first time, recognised citizens as the legal owners of their personal data, putting unauthorised collection or use under criminal penalty.
The Personal Data Protection Ordinance 2025 and the National Data Governance Ordinance 2025 were published in the gazette, the ICT Division said on Sunday.
Under the new laws, anyone collecting, storing, using or sharing personal data without explicit consent can face up to seven years in jail, a Tk 20 lakh fine or both.
Citizens’ consent must be clear, specific and voluntary. It can be withdrawn at any time, requiring immediate stoppage of data use. Citizens can access, correct or delete their data and object to automated processing.
Financial, health, genetic, biometric, religious, political, legal, trade union and sexual orientation data are now classified as sensitive, requiring higher protection.
Children’s data collection will require parental consent, while online tracking, profiling and targeted advertising aimed at children are now banned.
A new regulator, the National Data Governance Authority, will oversee compliance, audit data handlers, investigate breaches, resolve complaints and enforce penalties. It will also secure government software and databases, preserve source codes and dismantle vendor lock and software lock dependencies.
A National Responsible Data Exchange framework will enable supervised data sharing between public and private entities under minimum compliance standards. A unified digital identity system will also be rolled out.
Corporate violations will carry personal accountability for directors and responsible executives, unless proven that adequate safeguards existed. All data breaches must be immediately reported to the authority.
Cross-border data transfers will only be allowed to countries or organisations that uphold protections equal to Bangladesh’s, reinforcing data sovereignty.
Certain provisions will take effect after 18 months, giving institutions time for infrastructure upgrades, workforce training and compliance adjustments.
“Data business anarchy ends today,” said Chief Adviser’s Special Assistant for Posts, Telecommunications and ICT Faiz Ahmad Taiyeb on Sunday.
“The earlier law, introduced a decade after the General Data Protection Regulation, failed to protect people’s data,” he said.
“Foundational changes are being made in platform liability, sensitive data protection and the way data is collected, stored and exchanged,” he said.
“Unregulated trade and dark-web sale of personal data are now illegal,” he added, recalling mass breaches during the Bangladesh Awami League tenure.
“No digital business can operate anymore by violating data sovereignty,” he said.
The law comes amid rapid growth of mobile payments, e-commerce, digital identity, online banking and digital health services, sectors that previously operated without a unified data protection shield.
The new framework aligns Bangladesh with global benchmarks including the European Union’s General Data Protection Regulation, India’s 2023 data law and frameworks used in Singapore, Japan, South Korea and Thailand.




