Introducing the Personal Data Protection Act, 2026
On April 10, 2026, the Parliament of Bangladesh enacted the long-awaited Personal Data Protection Act, 2026 (Act No. 63 of 2026). Replacing the temporary ordinances of 2025, this landmark legislation establishes a comprehensive legal framework governing the collection, processing, and storage of personal data. The law has been declared retrospectively effective from November 6, 2025, though administrative enforcement clauses (such as penalties and complaints) will be phased in over the coming months.
The PDPA 2026 represents a massive shift in how businesses handle customer data in Bangladesh, moving the country closer to international standards like the EU's GDPR.
Key Pillars of the Act
The Act defines specific rights for data subjects and heavy obligations for data controllers:
- Consent-Centric Processing: Organizations must obtain clear, unambiguous consent before collecting or processing any personal information.
- Extraterritorial Scope: The law applies to any entity processing the data of Bangladeshi citizens, regardless of whether the processing occurs inside or outside the country.
- Chief Data Officer (CDO) Requirement: All data controllers meeting specific criteria must appoint a certified Chief Data Officer to oversee compliance.
- Administrative Financial Penalties: The 2026 Act enforces fines up to 5% of a company's annual turnover or BDT 2.5 million to BDT 5 million, depending on the severity of the data breach.
A Compliance Checklist for Businesses
To avoid severe financial penalties, local and international businesses must act immediately:
1. Audit Your Data
Map out all the personal data your organization collects. Identify where it is stored, who has access, and whether you have explicit consent for each data point.
2. Implement Consent Management
Update your website privacy policies, mobile apps, and terms of service to include explicit consent pop-ups and options to opt-out.
3. Appoint a Chief Data Officer
Designate an executive or hire a professional to manage data protection audits, report breaches, and act as a liaison with the National Data Protection Authority.
4. Implement Encryption at Rest and in Transit
Under Section 23 of the Act, organizations must ensure the security, integrity, and confidentiality of personal data through strong encryption.
Compliance as a Business Advantage
Rather than viewing the PDPA 2026 as a regulatory burden, forward-thinking businesses should see it as an opportunity to build trust. Securing customer data builds brand loyalty and mitigates the severe reputational damage associated with a public data breach.
Oberon Services provides end-to-end compliance support. Contact us to begin your assessment.