{
 "jurisdiction_id": "BD",
 "jurisdiction": "Bangladesh",
 "url": "https://dataprotection.gi/jurisdictions/bangladesh/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 10,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.",
   "claims": [
    {
     "statement": "The National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bangladesh-data-breach-1",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/bangladesh-president-bangladesh-enacts-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Parliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/bangladesh-parliament-bangladesh-enacts-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Only a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.",
   "claims": [
    {
     "statement": "Academic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2603.22637",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Only a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.",
   "claims": [
    {
     "statement": "Academic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2603.22637",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification obligation confirmed; other accountability sub-modules unconfirmed.",
   "claims": [
    {
     "statement": "The Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bangladesh-data-breach-1",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No confirmed transfer mechanism, adequacy status, or localisation mandate located in accessible sources.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecom sectoral carve-out confirmed via academic source; other sectoral overlays unconfirmed.",
   "claims": [
    {
     "statement": "The Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2603.22637",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No adtech/commercial-privacy-specific provisions located in this research pass.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Surveillance carve-out confirmed via academic source; other sub-modules unconfirmed.",
   "claims": [
    {
     "statement": "The Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2603.22637",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "No children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bangladesh/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.",
   "claims": [
    {
     "statement": "The National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bangladesh-data-breach-1",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Bangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/bangladesh-parliament-bangladesh-enacts-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}