Bangladesh - Digital Security Act (2018)

Digital Security Act, 2018

Bangladesh

RAI-BD-NA-DIGSE20-2018
Effective: October 8, 2018
In Force(In Force)
ActCybersecurity and Model SecurityEnforcement and PenaltiesGovernance and Oversight
Export PDF

The Digital Security Act, 2018 (DSA) is a Bangladesh national statute enacted in 2018 to address cybercrime, digital harms, protection of critical information infrastructure and online offences. The Act defines offences related to hacking, digital espionage, false information, defamation, hurting religious sentiments and gives authorities powers for investigation, blocking, removal and prosecution.

Overview

The Digital Security Act, 2018 (DSA) is a national statute enacted by the Parliament of Bangladesh and published in the Government Gazette in October 2018. The DSA creates a legal framework to address crimes and harms that arise in digital environments — including unauthorised access, hacking, digital espionage, false information, content that affronts religious sentiments and acts that threaten the security of critical information infrastructure. The Act provides powers to designated investigative authorities, sets out penalties for specified offences and contemplates institutional arrangements for digital security governance. The authoritative text of the Act and its official publication are available via government sources such as the Government Press (Gazette) and official ICT Division / agency pages; see the Gazette record for October 2018 and the official English text. For the official gazette entry see Extraordinary Gazette (October 2018) — Digital Security Act, 2018, and for an authorised English text see the ICT Division’s published copy at The Authentic English Text of the DIGITAL SECURITY ACT, 2018 — DoICT.

Definitions

The Act defines core terms used throughout its provisions. Typical statutory definitions include "digital device", "computer", "computer network", "computer system", "information system", "critical information infrastructure (CII)", "service provider/intermediary", "publish", "broadcast", "offence", and "digital security agency/council". The DSA distinguishes between offences that target systems (for example unauthorised access/hacking or damaging CII) and offences that arise from content (for example publishing false information, defamation, or speech that may hurt religious sentiments). The statutory definitions form the basis for jurisdiction, scope of investigatory powers and intermediary obligations.

Governance and Institutional Framework

The DSA contemplates institutional mechanisms for national digital security and enforcement. It provides for the identification and protection of Critical Information Infrastructure (CII) and allocates responsibilities to government ministries, designated law-enforcement units and digital security agencies for oversight, investigation and maintenance of national digital security. The Act enables the government to issue rules and form agencies or councils to coordinate responses; subsequent implementing rules and agency-level guidance have been published by the ICT Division and national cybersecurity bodies. Official implementing instruments and agency guidance (for example the Digital Security Rules, 2020, and agency guidelines) can be found on the ICT Division and National Cyber Security Agency portals; see DoICT — law list and the National Cyber Security Agency’s law page at National Cyber Security Agency (NCSA) for official instrument links. The DSA grants specific operational powers to investigative units, and empowers authorities to require cooperation from service providers, order content removal or blocking and to designate certain systems as essential for national security.

Key Focus Areas

The DSA’s operative focus areas include (i) criminalisation of cyber-enabled conduct: unauthorised access, hacking, data theft and sabotage of information systems; (ii) content offences: publishing or circulating false, provocative or defamatory content online, hurting religious sentiments, contempt of the Liberation War and related offences; (iii) protection of critical information infrastructure: designation, access control and penalty for damage or interference; (iv) enforcement tools: investigatory powers, preservation orders, search and seizure of digital devices, interception subject to lawful authorisation; (v) intermediary and service-provider duties: cooperation, data preservation, and potential penalties for non-compliance; and (vi) remedies and adjudication: criminal penalties and processes for appeals. The Act therefore spans both cybersecurity (technical system protection) and regulation of online speech and content — a hybrid coverage that has produced debate regarding rights balance, procedural safeguards and proportionality.

Implementation Framework

Implementation of the DSA relies on regulations, agency guidelines and operational protocols. The Act authorises the government to issue rules; the Digital Security Rules and related administrative instruments establish procedures for investigation, designation of CII, appointing authorised officers and setting standards for data preservation and cooperation by service providers. Law enforcement units and digital security agencies (and where designated, a national Digital Security Agency or Council) are responsible for operationalising the Act’s investigatory and enforcement powers. Implementation also depends on coordination across ministries (Home Affairs, ICT/Science & Technology, Law) and public bodies responsible for communications infrastructure. Official implementing rules and agency guidance are available from the ICT Division and relevant agencies; see the Digital Security Rules, 2020 linked from the DoICT law list and agency pages such as BGD e-GOV CIRT — Acts for official instruments and downloads.

Monitoring and Evaluation

The Act provides for oversight and reporting by designated agencies and courts. Monitoring primarily occurs through law enforcement casework and administrative oversight of designated CII, while agency guidelines set monitoring protocols for audits, inspections and incident response. Evaluations of implementation — including frequency of content removal orders, prosecutions and designation of CII — are conducted through inter-agency channels and periodic reviews. Official agencies (e.g., ICT Division, National Cyber Security Agency and other authorised bodies) publish notices, rules and guidance to reflect evolving operational practice and to ensure compliance; those publications are available on respective agency sites.

Penalties, Liability, and Appeals

The DSA prescribes a range of criminal penalties and fines for listed offences, including imprisonment terms and monetary fines. Certain offences are designated non-bailable to reflect perceived gravity. The Act also sets out liability pathways for individuals and, in some cases, intermediary entities that fail to comply with lawful directions (for example, content removal or data preservation orders). Criminal prosecutions are subject to the general rules of criminal procedure and statutory appeal routes to higher courts; affected parties may seek remedies through judicial review and ordinary appellate procedures. Official text and the Gazette provide the precise wording for penalties and procedural provisions; consult the Government Gazette entry and the authorised English text for the statutory schedule of penalties.

Relationship to Other Instruments

The DSA operates alongside earlier and subsequent laws governing information and communications technology, criminal procedure and national security. It extends or supersedes provisions previously found in the Information and Communication Technology (ICT) Act in relation to digital offences, and interacts with sectoral laws (for example telecommunications, banking, data protection instruments when adopted). Implementing rules and related administrative instruments (for example the Digital Security Rules, 2020) further specify procedures under the Act. Agencies responsible for cyber incident response and critical infrastructure protection also issue complementary guidelines and standards to align enforcement and technical responses.

International Alignment

The DSA’s text reflects national priorities in responding to harms arising from digital technologies, but its approach to content regulation, investigatory powers and criminal penalties differs from some international practices and raises questions of alignment with international human rights norms on freedom of expression and privacy. Bangladesh’s official approach emphasises state security and social order while providing administrative mechanisms for blocking, removal and prosecution. Internationally, comparable statutes vary in their balance between security and civil liberties; official government texts and implementing instruments remain the primary sources for interpreting national obligations and practice. For authoritative government materials consult the Government Gazette and official ministry/agency publications cited below.

Implementation Timeline

EventDateOfficial Source
Parliamentary law number published (Digital Security Act, 2018)2018-10-08Extraordinary Gazette (October 2018)
Official English text published by ICT Division (authorised copy)2020-10-06 (published on DoICT site)DoICT — The Authentic English Text
Digital Security Rules (implementing rules)2020-03-08DoICT — Digital Security Rules, 2020

Compliance Checklist

RequirementAction
Understand offences and penaltiesReview the official Act text and ensure legal counsel evaluates exposure for organisation and staff
Data preservation & cooperation ordersImplement retention & incident-response procedures to comply with lawful orders
CII designation impactIdentify whether systems are designated as CII and implement required protections
Content moderation & removalEstablish takedown & redress workflows to respond to lawful removal/blocking directions
Lawful interception & search complianceAdopt policies to handle lawful requests for data and devices

Sources and References

SourceType
Extraordinary Gazette (October 2018) — Digital Security Act, 2018Primary Source
DoICT — The Authentic English Text of the DIGITAL SECURITY ACT, 2018 and related rulesPrimary Source
BGD e-GOV CIRT — Acts (includes Digital Security Act links)Primary Source
Digital Security Act, 2018 (PDF) — portal.gov.bdPrimary Source
Plain English

The Digital Security Act, 2018 (DSA) is a Bangladesh law that establishes a comprehensive legal framework to combat cybercrime and online offences, applying to individuals and entities involved in digital activities within or affecting Bangladesh.

This legislation broadly impacts anyone using digital devices or networks, including individuals, online service providers, and those managing critical information infrastructure. It aims to protect national digital security and address harms arising in the digital environment.

The Act sets out several key prohibitions and obligations: - It criminalises a range of cyber-enabled conduct, such as unauthorised access, hacking, data theft, and sabotage of information systems. - It also prohibits publishing or circulating false, provocative, or defamatory content online, and content that could hurt religious sentiments. - Service providers and intermediaries are obligated to cooperate with authorities, which includes preserving data and complying with lawful orders for content removal or blocking. - Damaging or interfering with designated Critical Information Infrastructure (CII) also carries severe penalties.

The Digital Security Act officially took effect on October 8, 2018. Violations of the Act can lead to significant criminal penalties, including terms of imprisonment and substantial monetary fines, with certain offences designated as non-bailable. Authorities are granted extensive powers for investigation, search and seizure of digital devices, and the ability to order content removal or blocking.

A crucial practical pitfall for product managers and in-house teams is the Act's broad scope, which extends beyond technical cybersecurity to regulate online speech and content. This means platforms and users face potential liability for content deemed false, defamatory, or religiously offensive, requiring robust content moderation policies and readiness to comply with government directives. The Act's dual focus on system security and content regulation demands careful attention to avoid unexpected legal exposure.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 7 marked complete

Plain-English obligations under Bangladesh - Digital Security Act (2018). Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Service providers and intermediaries.

    intermediary and service-provider duties: cooperation, data preservation, and potential penalties for non-compliance;
  2. #2Critical

    Applies to: Entities operating information systems.

    The Act provides for the identification and protection of Critical Information Infrastructure (CII)
  3. #3Critical

    Applies to: Entities operating designated Critical Information Infrastructure.

    protection of critical information infrastructure: designation, access control and penalty for damage or interference;
  4. #4Critical

    Applies to: Service providers and intermediaries.

    intermediary entities that fail to comply with lawful directions (for example, content removal or data preservation orders).
  5. #5Critical

    Applies to: Service providers and entities holding digital data or devices.

    enforcement tools: investigatory powers, preservation orders, search and seizure of digital devices, interception subject to lawful authorisation;
  6. #6CriticalBefore publishing content

    Applies to: Any individual or entity publishing content online.

    content offences: publishing or circulating false, provocative or defamatory content online, hurting religious sentiments...
  7. #7Critical

    Applies to: Entities operating information systems.

    criminalisation of cyber-enabled conduct: unauthorised access, hacking, data theft and sabotage of information systems;

© Regulations.AI — created on 13-Jun-2026