Bangladesh - Digital Security Act (2018)
Digital Security Act, 2018
Bangladesh
RAI-BD-NA-DIGSE20-2018The Digital Security Act, 2018 (DSA) is a Bangladesh national statute enacted in 2018 to address cybercrime, digital harms, protection of critical information infrastructure and online offences. The Act defines offences related to hacking, digital espionage, false information, defamation, hurting religious sentiments and gives authorities powers for investigation, blocking, removal and prosecution.
Summary
Read full text ↗Plain English
Overview
The Digital Security Act, 2018 (DSA) is a national statute enacted by the Parliament of Bangladesh and published in the Government Gazette in October 2018. The DSA creates a legal framework to address crimes and harms that arise in digital environments — including unauthorised access, hacking, digital espionage, false information, content that affronts religious sentiments and acts that threaten the security of critical information infrastructure. The Act provides powers to designated investigative authorities, sets out penalties for specified offences and contemplates institutional arrangements for digital security governance. The authoritative text of the Act and its official publication are available via government sources such as the Government Press (Gazette) and official ICT Division / agency pages; see the Gazette record for October 2018 and the official English text. For the official gazette entry see Extraordinary Gazette (October 2018) — Digital Security Act, 2018, and for an authorised English text see the ICT Division’s published copy at The Authentic English Text of the DIGITAL SECURITY ACT, 2018 — DoICT.
Definitions
The Act defines core terms used throughout its provisions. Typical statutory definitions include "digital device", "computer", "computer network", "computer system", "information system", "critical information infrastructure (CII)", "service provider/intermediary", "publish", "broadcast", "offence", and "digital security agency/council". The DSA distinguishes between offences that target systems (for example unauthorised access/hacking or damaging CII) and offences that arise from content (for example publishing false information, defamation, or speech that may hurt religious sentiments). The statutory definitions form the basis for jurisdiction, scope of investigatory powers and intermediary obligations.
Governance and Institutional Framework
The DSA contemplates institutional mechanisms for national digital security and enforcement. It provides for the identification and protection of Critical Information Infrastructure (CII) and allocates responsibilities to government ministries, designated law-enforcement units and digital security agencies for oversight, investigation and maintenance of national digital security. The Act enables the government to issue rules and form agencies or councils to coordinate responses; subsequent implementing rules and agency-level guidance have been published by the ICT Division and national cybersecurity bodies. Official implementing instruments and agency guidance (for example the Digital Security Rules, 2020, and agency guidelines) can be found on the ICT Division and National Cyber Security Agency portals; see DoICT — law list and the National Cyber Security Agency’s law page at National Cyber Security Agency (NCSA) for official instrument links. The DSA grants specific operational powers to investigative units, and empowers authorities to require cooperation from service providers, order content removal or blocking and to designate certain systems as essential for national security.
Key Focus Areas
The DSA’s operative focus areas include (i) criminalisation of cyber-enabled conduct: unauthorised access, hacking, data theft and sabotage of information systems; (ii) content offences: publishing or circulating false, provocative or defamatory content online, hurting religious sentiments, contempt of the Liberation War and related offences; (iii) protection of critical information infrastructure: designation, access control and penalty for damage or interference; (iv) enforcement tools: investigatory powers, preservation orders, search and seizure of digital devices, interception subject to lawful authorisation; (v) intermediary and service-provider duties: cooperation, data preservation, and potential penalties for non-compliance; and (vi) remedies and adjudication: criminal penalties and processes for appeals. The Act therefore spans both cybersecurity (technical system protection) and regulation of online speech and content — a hybrid coverage that has produced debate regarding rights balance, procedural safeguards and proportionality.
Implementation Framework
Implementation of the DSA relies on regulations, agency guidelines and operational protocols. The Act authorises the government to issue rules; the Digital Security Rules and related administrative instruments establish procedures for investigation, designation of CII, appointing authorised officers and setting standards for data preservation and cooperation by service providers. Law enforcement units and digital security agencies (and where designated, a national Digital Security Agency or Council) are responsible for operationalising the Act’s investigatory and enforcement powers. Implementation also depends on coordination across ministries (Home Affairs, ICT/Science & Technology, Law) and public bodies responsible for communications infrastructure. Official implementing rules and agency guidance are available from the ICT Division and relevant agencies; see the Digital Security Rules, 2020 linked from the DoICT law list and agency pages such as BGD e-GOV CIRT — Acts for official instruments and downloads.
Monitoring and Evaluation
The Act provides for oversight and reporting by designated agencies and courts. Monitoring primarily occurs through law enforcement casework and administrative oversight of designated CII, while agency guidelines set monitoring protocols for audits, inspections and incident response. Evaluations of implementation — including frequency of content removal orders, prosecutions and designation of CII — are conducted through inter-agency channels and periodic reviews. Official agencies (e.g., ICT Division, National Cyber Security Agency and other authorised bodies) publish notices, rules and guidance to reflect evolving operational practice and to ensure compliance; those publications are available on respective agency sites.
Penalties, Liability, and Appeals
The DSA prescribes a range of criminal penalties and fines for listed offences, including imprisonment terms and monetary fines. Certain offences are designated non-bailable to reflect perceived gravity. The Act also sets out liability pathways for individuals and, in some cases, intermediary entities that fail to comply with lawful directions (for example, content removal or data preservation orders). Criminal prosecutions are subject to the general rules of criminal procedure and statutory appeal routes to higher courts; affected parties may seek remedies through judicial review and ordinary appellate procedures. Official text and the Gazette provide the precise wording for penalties and procedural provisions; consult the Government Gazette entry and the authorised English text for the statutory schedule of penalties.
Relationship to Other Instruments
The DSA operates alongside earlier and subsequent laws governing information and communications technology, criminal procedure and national security. It extends or supersedes provisions previously found in the Information and Communication Technology (ICT) Act in relation to digital offences, and interacts with sectoral laws (for example telecommunications, banking, data protection instruments when adopted). Implementing rules and related administrative instruments (for example the Digital Security Rules, 2020) further specify procedures under the Act. Agencies responsible for cyber incident response and critical infrastructure protection also issue complementary guidelines and standards to align enforcement and technical responses.
International Alignment
The DSA’s text reflects national priorities in responding to harms arising from digital technologies, but its approach to content regulation, investigatory powers and criminal penalties differs from some international practices and raises questions of alignment with international human rights norms on freedom of expression and privacy. Bangladesh’s official approach emphasises state security and social order while providing administrative mechanisms for blocking, removal and prosecution. Internationally, comparable statutes vary in their balance between security and civil liberties; official government texts and implementing instruments remain the primary sources for interpreting national obligations and practice. For authoritative government materials consult the Government Gazette and official ministry/agency publications cited below.
Implementation Timeline
| Event | Date | Official Source |
|---|---|---|
| Parliamentary law number published (Digital Security Act, 2018) | 2018-10-08 | Extraordinary Gazette (October 2018) |
| Official English text published by ICT Division (authorised copy) | 2020-10-06 (published on DoICT site) | DoICT — The Authentic English Text |
| Digital Security Rules (implementing rules) | 2020-03-08 | DoICT — Digital Security Rules, 2020 |
Compliance Checklist
| Requirement | Action |
|---|---|
| Understand offences and penalties | Review the official Act text and ensure legal counsel evaluates exposure for organisation and staff |
| Data preservation & cooperation orders | Implement retention & incident-response procedures to comply with lawful orders |
| CII designation impact | Identify whether systems are designated as CII and implement required protections |
| Content moderation & removal | Establish takedown & redress workflows to respond to lawful removal/blocking directions |
| Lawful interception & search compliance | Adopt policies to handle lawful requests for data and devices |
Sources and References
| Source | Type |
|---|---|
| Extraordinary Gazette (October 2018) — Digital Security Act, 2018 | Primary Source |
| DoICT — The Authentic English Text of the DIGITAL SECURITY ACT, 2018 and related rules | Primary Source |
| BGD e-GOV CIRT — Acts (includes Digital Security Act links) | Primary Source |
| Digital Security Act, 2018 (PDF) — portal.gov.bd | Primary Source |
The Digital Security Act, 2018 (DSA) is a Bangladesh law that establishes a comprehensive legal framework to combat cybercrime and online offences, applying to individuals and entities involved in digital activities within or affecting Bangladesh.
This legislation broadly impacts anyone using digital devices or networks, including individuals, online service providers, and those managing critical information infrastructure. It aims to protect national digital security and address harms arising in the digital environment.
The Act sets out several key prohibitions and obligations: - It criminalises a range of cyber-enabled conduct, such as unauthorised access, hacking, data theft, and sabotage of information systems. - It also prohibits publishing or circulating false, provocative, or defamatory content online, and content that could hurt religious sentiments. - Service providers and intermediaries are obligated to cooperate with authorities, which includes preserving data and complying with lawful orders for content removal or blocking. - Damaging or interfering with designated Critical Information Infrastructure (CII) also carries severe penalties.
The Digital Security Act officially took effect on October 8, 2018. Violations of the Act can lead to significant criminal penalties, including terms of imprisonment and substantial monetary fines, with certain offences designated as non-bailable. Authorities are granted extensive powers for investigation, search and seizure of digital devices, and the ability to order content removal or blocking.
A crucial practical pitfall for product managers and in-house teams is the Act's broad scope, which extends beyond technical cybersecurity to regulate online speech and content. This means platforms and users face potential liability for content deemed false, defamatory, or religiously offensive, requiring robust content moderation policies and readiness to comply with government directives. The Act's dual focus on system security and content regulation demands careful attention to avoid unexpected legal exposure.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 7 marked completePlain-English obligations under Bangladesh - Digital Security Act (2018). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Service providers and intermediaries.
“intermediary and service-provider duties: cooperation, data preservation, and potential penalties for non-compliance;”
- #2Critical
Applies to: Entities operating information systems.
“The Act provides for the identification and protection of Critical Information Infrastructure (CII)”
- #3Critical
Applies to: Entities operating designated Critical Information Infrastructure.
“protection of critical information infrastructure: designation, access control and penalty for damage or interference;”
- #4Critical
Applies to: Service providers and intermediaries.
“intermediary entities that fail to comply with lawful directions (for example, content removal or data preservation orders).”
- #5Critical
Applies to: Service providers and entities holding digital data or devices.
“enforcement tools: investigatory powers, preservation orders, search and seizure of digital devices, interception subject to lawful authorisation;”
- #6Critical⏰ Before publishing content
Applies to: Any individual or entity publishing content online.
“content offences: publishing or circulating false, provocative or defamatory content online, hurting religious sentiments...”
- #7Critical
Applies to: Entities operating information systems.
“criminalisation of cyber-enabled conduct: unauthorised access, hacking, data theft and sabotage of information systems;”
Related Regulations
Cyber Security Act, 2023 (সাইবার নিরাপত্তা আইন, ২০২৩)
Bangladesh93% similar
Draft Personal Data Protection Act / Draft Data Protection Act 2023
Bangladesh87% similar
Bangladesh Telecommunication Regulatory Commission Regulation for Digital, Social Media and OTT Platforms (draft)
Bangladesh86% similar
Computer Crimes Law (Law on Computer Crimes)
Iran85% similar
Prevention of Electronic Crimes (Amendment) Act, 2025
Pakistan85% similar
© Regulations.AI — created on 13-Jun-2026