Most businesses operating in Bangladesh collect far more personal data than they realize — a customer's phone number for delivery, a NID copy for KYC, a saved card for repeat checkout. Until recently, how that data was stored and protected was mostly left to individual judgment. That is no longer the position: Bangladesh now has a comprehensive data protection law, and businesses that treat this as a systems problem will have a much easier time than those who wait to be told.
Where the law actually stands. The framework arrived by ordinance first, then statute. The Personal Data Protection Ordinance, 2025 was gazetted on 6 November 2025 — alongside a companion data governance ordinance — was then amended by Ordinance No. 23 of 2026 in February 2026, and became the Personal Data Protection Act on 15 April 2026. So the operative question for a business is no longer “is this coming?” but “does our system already do what it requires?”
It is worth reading the criticism alongside the law. The Daily Star's analysis, “Why Bangladesh's new data protection law may fail to protect your data” , argues the Act constrains private companies considerably more than it constrains the state. For a business owner that is not a reason to relax — it is the opposite. The obligations that landed hardest landed on you.
If your company is not in Bangladesh, this may still be your problem. The Act attaches to where the processing happens, not to where the company is registered. A brand running a Dhaka support desk, a BPO floor, a back-office finance team, or an outsourced development team that touches production data is having personal data processed in Bangladesh on its behalf — and the obligations follow the data. The practical consequence is contractual: if a vendor in Bangladesh handles your customer records, the questions below belong in your agreement with them and in your due diligence, not in a compliance file you assume they keep on their own. That is worth settling before work starts, alongside NDA and IP ownership terms.
This guide covers what the Personal Data Protection Act generally requires from a business's software and data handling practices, who it typically affects, and how to prepare. It is written as general, practical orientation for business owners — whether you operate from Bangladesh or merely process data there — and not as legal advice.
Important: specific obligations, thresholds, and enforcement timelines are set by the law and its regulator. Always verify your business's exact requirements with a licensed legal advisor — this article explains the general direction, not your specific legal obligation.
What Data Protection Compliance Actually Means for a Business
In practical terms, it means the systems that collect, store, and process customer data need to demonstrate a few things: that data was collected with proper consent, that it is stored securely, that it is only used for the purpose it was collected for, and that the business can respond appropriately if that data is ever breached or a customer asks what data is held about them.
Why This Matters Beyond Legal Risk
Data breaches are expensive regardless of regulation — lost customer trust, fraud liability, and incident response costs all exist whether or not a specific law is in force. A compliance framework mostly formalizes practices that were already good business sense: know what data you hold, protect it properly, and don't keep what you don't need.
Who This Generally Affects
E-commerce & Retail
Any business storing customer names, phone numbers, addresses, and order history for checkout or delivery is processing personal data at volume.
Fintech & Payment Platforms
Businesses handling financial data, transaction records, and payment credentials face the highest sensitivity tier and typically the strictest expectations.
Healthcare & HR Systems
Patient records and employee data (including biometric attendance data) are generally treated as especially sensitive categories requiring stronger safeguards — see our healthcare app architecture guide for how this applies to a patient-facing build.
Any SaaS or App Collecting Accounts
If your product has user sign-up, login, and a database of customer profiles, that database is personal data regardless of your industry.
Common Data Categories and Their Risk Level
| Data Category | Examples | Risk If Leaked |
|---|---|---|
| Customer identity data | Name, phone number, NID number, address | High — directly identifying |
| Transaction & financial data | Purchase history, payment records, invoices | High — financial harm if leaked |
| Account credentials | Passwords, login sessions, security questions | Critical — enables account takeover |
| Biometric data | Fingerprints, facial recognition data | Critical — cannot be reset if leaked |
| Marketing & behavioral data | Browsing history, ad preferences, purchase patterns | Medium — profiling risk |
What a Compliant System Actually Needs to Do
- Collect explicit, informed consent before storing personal data, and record when and how that consent was given.
- Encrypt sensitive data at rest and in transit, and restrict database access to only the roles that genuinely need it.
- Give the business a way to locate, export, or delete a specific customer's data on request, rather than data scattered across disconnected spreadsheets and systems.
- Maintain a breach detection and notification process, so an incident can be identified and reported within a reasonable window instead of discovered months later.
- Avoid retaining data indefinitely — define a retention policy and actually enforce it in the database, not just on paper.
Common Pitfalls Businesses Run Into
- Assuming a privacy policy on the website alone satisfies compliance, while the underlying database has no real access controls.
- Storing customer NID copies, payment details, or passwords in plain text because "it was faster to build that way."
- Having no clear internal owner for data protection decisions, so a breach response is improvised rather than planned.
- Treating this purely as a legal/paperwork exercise, when the actual gap is almost always in how the software itself handles data.
- Not confirming current requirements with a legal advisor, and instead relying on assumptions carried over from GDPR or other markets.
Sources
External references behind the figures and claims on this page. Rate bands and vendor pricing move — check the source before quoting a number.
- Govt issues gazettes of 2 landmark ordinances on data protection, governance
The Business Standard
The Personal Data Protection Ordinance, 2025 was gazetted on 6 November 2025.
- Personal Data Protection (Amendment) Ordinance, 2026 (Ordinance No. 23 of 2026)
Digital Policy Alert
The February 2026 amendment that preceded the permanent Act.
- Why Bangladesh’s new data protection law may fail to protect your data
The Daily Star
Analysis arguing the Act binds private companies more tightly than the state — which is why the obligations land on businesses.
Frequently Asked Questions
Obligations generally scale with the volume and sensitivity of personal data processed, not solely company size — a small e-commerce shop storing customer phone numbers and addresses still processes personal data. Confirm your specific obligations with a licensed legal advisor rather than assuming small scale means exemption.
It shares some concepts with GDPR and other regional data protection laws — consent, purpose limitation, breach notification — but it is a distinct Bangladeshi law with its own scope and enforcement body. Do not assume GDPR compliance automatically satisfies local requirements.
Broadly, any information that can identify a person — name, phone number, NID number, address, email, biometric data, and transaction history are all typical examples. Businesses often underestimate how much of their existing customer database already qualifies.
The risk is twofold: a data breach becomes both a security incident and a potential compliance failure. Retrofitting access controls and encryption after a breach is far more costly and reputationally damaging than building them in from the start.
This typically depends on the scale and sensitivity of data processed. Many SMEs will not need a full-time DPO, but should still assign clear internal ownership for data protection decisions and incident response. Confirm your specific threshold with a legal advisor.
Already Handling VAT Compliance? This Is the Next Layer
Businesses adapting their systems for NBR e-invoicing and digital VAT compliance are already touching the same customer and transaction database that data protection rules govern. It is worth reviewing both at once rather than treating them as separate projects.
Build Data Protection Into the System, Not Around It
Retrofitting proper access controls, encryption, and consent tracking onto an existing system after a breach is far costlier — in money and reputation — than building it in from the start. Confirm your specific obligations with a legal advisor, then make sure the software actually storing your customer data is built to hold up to scrutiny.
Want your systems audited or built with data protection in mind from day one? BengalTech Solutions builds custom software with proper access control and encryption architecture. Tell us about your setup.