🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
BD · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 10 sources retrieved model claude-sonnet-5 ·

Bangladesh

BD schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 10 claims · 10 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
10Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), read with the National Data Governance and Interoperability Authority Ordinance 2025
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberCore regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.

Sub-modules (5)

Regulator And AuthorityGreen

NDGIA is named as the enforcement and guidance-issuing body for the Ordinance.

Claims: CLM-BD-1a2b3c4d

Act And InstrumentsAmber

Instrument progressed from presidential ordinance to parliamentary enactment within 2026.

Claims: CLM-BD-2b3c4d5e, CLM-BD-3c4d5e6f

Material ScopeRed

No confirmed definition of covered personal data / processing scope retrieved.

Absence provenance: not recorded. Searched: not recorded.

Territorial ScopeRed

No confirmed extraterritorial application provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Regulator Registration And FilingRed

No confirmed controller registration/filing regime retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative95 words

Bangladesh's data protection landscape moved from a decade of draft bills (2022 Draft Data Protection Act, 2023 ICT Department drafts) into a live instrument: the Data Protection Ordinance, 2025. The Ordinance was promulgated by presidential ordinance and, per later reporting, subsequently enacted into statute by Parliament. Supervisory authority sits with the newly created National Data Governance and Interoperability Authority (NDGIA), established under a companion National Data Governance and Interoperability Authority Ordinance 2025. Material scope, territorial scope, and registration/filing obligations could not be confirmed from accessible sources (primary Bangla-language text not independently retrieved; secondary commentary paywalled).

Sources and claims (3)
  1. ConfirmedDataGuidanceThe National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.
  2. ProbableDataGuidanceThe President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.
  3. ProbableDataGuidanceParliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.

#

Only a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.

Sub-modules (4)

Lawful BasesRed

Only a general 'consent-based' characterisation is evidenced; no enumerated Art 6-style lawful basis list confirmed.

Claims: CLM-BD-4d5e6f7a

Special CategoriesRed

No confirmed sensitive/special-category data regime retrieved for the 2025 Ordinance.

Absence provenance: not recorded. Searched: not recorded.

Pseudonymisation And AnonymisationRed

No confirmed pseudonymisation/anonymisation safe-harbour provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative39 words

Independent academic analysis characterises the Bangladesh Data Protection Ordinance (PDPO) as establishing consent-based and rights-oriented processing mechanisms, but the enumerated lawful bases, consent standards, special-category rules, and pseudonymisation/anonymisation safe harbours could not be independently confirmed from accessible primary text.

Sources and claims (1)
  1. UncertainarXivAcademic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).

#

Only a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.

Sub-modules (5)

Access RightRed

General 'rights-oriented' characterisation only; no confirmed access-request mechanism.

Claims: CLM-BD-5e6f7a8b

Rectification And ErasureRed

No confirmed rectification/erasure right retrieved.

Absence provenance: not recorded. Searched: not recorded.

Restriction And ObjectionRed

No confirmed restriction/objection right retrieved.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

No confirmed portability right retrieved.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

No confirmed statutory response deadline retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative31 words

Secondary academic commentary characterises the Ordinance as establishing 'rights-oriented' mechanisms for data subjects, but specific rights (access, rectification/erasure, restriction/objection, portability) and statutory response deadlines could not be confirmed from accessible sources.

Sources and claims (1)
  1. UncertainarXivAcademic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.

#

Breach notification obligation confirmed; other accountability sub-modules unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberBreach notification obligation confirmed; other accountability sub-modules unconfirmed.

Sub-modules (7)

Accountability And DpiaRed

No confirmed DPIA trigger or accountability-principle text retrieved.

Absence provenance: not recorded. Searched: not recorded.

Dpo RequirementsRed

No confirmed DPO appointment threshold retrieved.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

No confirmed records-of-processing obligation retrieved.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No confirmed joint-controller provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresRed

No confirmed detailed technical/organisational security-measures standard retrieved beyond general breach-notification coverage.

Absence provenance: not recorded. Searched: not recorded.

Breach NotificationGreen

Breach notification obligation confirmed as within the Ordinance's scope, enforced by NDGIA.

Claims: CLM-BD-6f7a8b9c

Retention And DisposalRed

No confirmed retention-limit or disposal-duty provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative41 words

Secondary guidance confirms the Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, enforced by the NDGIA. DPIA triggers, DPO appointment thresholds, ROPA requirements, joint-controller rules, detailed security-measure standards, and retention/disposal duties could not be confirmed from accessible sources.

Sources and claims (1)
  1. ConfirmedDataGuidanceThe Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.

#

No confirmed transfer mechanism, adequacy status, or localisation mandate located in accessible sources.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedNo confirmed transfer mechanism, adequacy status, or localisation mandate located in accessible sources.

Sub-modules (6)

Transfer MechanismsRed

No confirmed transfer mechanism retrieved.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

No adequacy decision received by Bangladesh from another regime confirmed.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

No adequacy decision granted by Bangladesh to another regime confirmed.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC/BCR mechanism confirmed.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No TIA requirement confirmed.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No confirmed data-localisation mandate under the 2025 Ordinance retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative48 words

No transfer-mechanism detail (adequacy, SCCs, BCRs, derogations), adequacy decisions received or granted, transfer-impact-assessment requirement, or data-localisation mandate could be confirmed for the Data Protection Ordinance, 2025 from accessible sources. Earlier (pre-2025) draft bills reportedly raised cross-border transfer concerns per industry commentary, but underlying text was not independently accessible.

#

Telecom sectoral carve-out confirmed via academic source; other sectoral overlays unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), overlaid by sectoral telecommunications and cybersecurity law
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberTelecom sectoral carve-out confirmed via academic source; other sectoral overlays unconfirmed.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed Bangladesh Bank or financial-sector data-protection overlay retrieved (source paywalled).

Absence provenance: not recorded. Searched: not recorded.

Health Sector OverlayRed

No confirmed health-sector data-protection overlay retrieved.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyAmber

Telecom interception powers confirmed as a sectoral carve-out operating alongside the data protection framework.

Claims: CLM-BD-7a8b9c0d

Employment DataRed

No confirmed employment-data-specific regime retrieved.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

No confirmed credit-scoring regime retrieved.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

No confirmed education-sector data rules retrieved.

Absence provenance: not recorded. Searched: not recorded.

InsuranceRed

No confirmed insurance-sector data rules retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative44 words

The clearest confirmed sectoral overlay is telecommunications: the Bangladesh Telecommunication Regulation Act empowers interception of communications on national-security/public-order grounds, operating through sectoral law rather than the data protection framework. Financial-sector, health-sector, employment, credit-scoring, education, and insurance overlays could not be confirmed from accessible sources.

Sources and claims (1)
  1. ConfirmedarXivThe Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.

#

No adtech/commercial-privacy-specific provisions located in this research pass.

Traffic-light rationale — RedNo adtech/commercial-privacy-specific provisions located in this research pass.

Sub-modules (6)

Cookies And TrackersRed

No confirmed cookie/tracker consent regime retrieved.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsRed

No confirmed dark-pattern prohibition retrieved.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

No confirmed opt-out signal recognition (e.g., GPC) retrieved.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No confirmed clean-room/data-collaboration rule retrieved.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingRed

No confirmed cross-context-advertising rule retrieved.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingRed

No confirmed direct-marketing consent/suppression rule retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative24 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising provision, or direct-marketing consent/suppression rule could be confirmed for Bangladesh from accessible sources.

#

Surveillance carve-out confirmed via academic source; other sub-modules unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), overlaid by the Cyber Security Ordinance 2025
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberSurveillance carve-out confirmed via academic source; other sub-modules unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right retrieved.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsRed

No confirmed AI-specific risk-assessment requirement retrieved.

Absence provenance: not recorded. Searched: not recorded.

Biometric RegimeRed

No confirmed biometric-data-specific regime (facial recognition, NID biometrics) retrieved beyond general Ordinance coverage.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataRed

No confirmed genetic-data regime retrieved.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

Cyber Security Ordinance 2025 interception powers confirmed as operating outside the Ordinance's consent-based safeguards.

Claims: CLM-BD-8b9c0d1e

Category narrative59 words

The confirmed finding in this module is a state-surveillance carve-out: the Cyber Security Ordinance 2025 permits interception of, or access to, traffic data on a 'reason to believe' evidentiary threshold, operating outside the consent-based safeguards of the Data Protection Ordinance. Profiling restrictions, ADM transparency, AI-specific risk assessments, biometric regime, and genetic-data regime could not be confirmed from accessible sources.

Sources and claims (1)
  1. ConfirmedarXivThe Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.

#

No children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.

Traffic-light rationale — RedNo children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.

Sub-modules (5)

Age VerificationRed

No confirmed age-of-consent or age-verification provision retrieved.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansRed

No confirmed minor-profiling ban retrieved.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsRed

No confirmed education-settings-specific rule retrieved.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No confirmed dependent-adults protection retrieved.

Absence provenance: not recorded. Searched: not recorded.

Category narrative23 words

No age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults protection could be confirmed for Bangladesh's data protection framework from accessible sources.

#

Regulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberRegulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

NDGIA's enforcement/guidance role confirmed; specific maximum penalty amounts unconfirmed.

Claims: CLM-BD-9c0d1e2f

Enforcement Activity IndexRed

No confirmed enforcement actions or decisions retrieved.

Absence provenance: not recorded. Searched: not recorded.

Regulator Funding And CapacityRed

No confirmed funding/headcount data retrieved.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism retrieved.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionRed

No confirmed private right of action retrieved.

Absence provenance: not recorded. Searched: not recorded.

Recent Developments 180DAmber

Within the past 180 days, the framework moved from presidential ordinance to full parliamentary enactment.

Claims: CLM-BD-0d1e2f3a

Category narrative57 words

The NDGIA is confirmed as the body responsible for enforcing the Data Protection Ordinance, 2025, and the framework's most significant recent development is its own legislative progression: presidential promulgation followed by parliamentary enactment within the past 180 days. Maximum penalties, enforcement-activity track record, regulator funding/capacity, collective-redress mechanisms, and private-right-of-action availability could not be confirmed from accessible sources.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.
  2. ProbableDataGuidanceBangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Bangladesh
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 10 claim(s), 19 source(s) in the cumulative register.