Executive finding
The statutes arrived in one package on 10 April 2026, and the decade decides whether they become institutions or paper
Chapter 54 of 60 in the Bangladesh 2036 research base. Contents of the series.
The statutes arrived in one package on 10 April 2026, and the decade decides whether they become institutions or paper
Chapter 13 named compute and data governance the fourth force of the digital decade and left the successor statute to the Cyber Security Act 2023 unverified against a primary text; this chapter opens that file and finds it settled by legislation. On 10 April 2026 the official record carried a three law package: the Personal Data Protection Act 2026, Act No. 63 of 2026, the National Data Management Act 2026, Act No. 80 of 2026, that number not confirmed, and the Cyber Protection Act 2026, Act No. 81 of 2026, the last re-enacting the Cyber Protection Ordinance 2025 and repealing the Cyber Security Act 2023, with an amendment act deleting one further section [MinLaw 2026]. The thesis is that the binding constraint of the AI and data decade has moved from legislation to institutions: Bangladesh enters it with the statutory architecture it lacked for ten years, an identity centred delivery state it built without one, and an enforcement base that does not yet exist in any published form. The record behind the laws: the state absorbed the 2016 central bank heist with about 66 million USD still unrecovered at the FY24 accounts [BB AR 2024], runs 110 million citizens through a single biometric credential [IIFC 2026] on an estate of 200 racks [BCC 2024], and publishes no national count of cyber incidents anywhere in the record this research base holds. If the new authorities are staffed, funded and made to publish, the package is the trust infrastructure that converts chapter 02's compliance agenda into an exportable asset; if they are not, it is paper, and the incident record stays invisible. Three risks and one buyer decision price the difference.
Where Bangladesh stands: a heist still unrecovered, an estate of 200 racks, three new laws, and an incident record nobody publishes
The anchor incident is a decade old and still open in the central bank's own accounts. On 4 February 2016, 101 million USD was heisted from the reserve account of Bangladesh Bank at the Federal Reserve Bank of New York through cyber hacking; 20 million USD was recovered immediately from Sri Lanka and 14.6 million USD later from the Philippines, leaving approximately 66 million USD outstanding in the notes to the FY24 accounts [BB AR 2024]. The litigation record in the same note runs through the decade: a United States Federal Court case filed on 31 January 2019 against 20 defendants including Rizal Commercial Banking Corporation, the dismissal of the bank's federal RICO claim, a state court case of 27 May 2020 that survived the defendants' motion on 13 January 2023, and an appellate dismissal of 30 May 2023 that let the claim against one defendant continue [BB AR 2024]. The heist matters to the FY27 to FY36 window the chapter 15 scenarios price not as history but as base rate: it is the measured cost of a single critical infrastructure failure, and the only cyber loss in the national record with audited numbers attached.
The incidents that follow have no numbers attached anywhere in the sources this chapter draws on. A 2024 breach of the government myLocker digital vault exposed citizen data including national identity numbers, names and mobile numbers; from mid 2024 the SikkahBot malware impersonated education board mobile applications through SMS phishing, installing Android packages that intercepted two factor authentication codes; and the national Computer Emergency Response Team reported a campaign compromising government email accounts for internal phishing against officials [IIFC 2026]. The scale of none of these events is published: no incident count series exists in the sources available to this chapter; the CIRT's own statistics could not be confirmed, its annual reporting the resolving source. The national crime record cannot see the offence class at all: the police annual and monthly crime statements through 2024 count dacoity, robbery, murder, kidnapping, arms, narcotics and smuggling, and carry no cyber category [Police HQ 2024]. A country whose flagship cyber incidents are known only through a state company magazine, and whose crime statistics do not record the offence, runs on an unmeasured base; chapter 12's statistics agenda applies to security as much as to GDP.
The estate behind the credential is small, measured and state owned. The National Data Center has run as the first certified Tier III standard government facility since 2010 with more than 200 racks and more than 20 petabytes of storage at its primary site, Uptime Institute Tier 3 design certification, ISO 27001 certification and a Jashore disaster recovery site, more than 500 government customers running more than 2,500 services, more than 140,000 requests fulfilled at a measured 99.982 percent uptime, and an eGovCloud elastic compute line marketed for artificial intelligence, image processing and natural language workloads [BCC 2024]. The pipe it sits on is the submarine cable base: achievable international bandwidth capacity of 3,420 Gbps in FY23, up from 3,000 Gbps in FY21, with 3,050 Gbps lit and 2,556 Gbps utilised in FY23 [BSCPLC 2023]. Secure internet servers, the encrypted web's infrastructure count, rose from 228.71 per million people in 2021 to 527.06 per million in 2024 [WB WDI 2026]. The subscriber base these serve is chapter 13's, 186.1 million mobile and 129.4 million internet subscriptions at end FY23 [BTRC 2023].
The credential is the system's largest concentration of risk. Around 110 million citizens are enrolled in the biometric national identity system that birth registration, stipends, land records and tax filing now run through [IIFC 2026], with the Election Commission's identity database the resolving primary source for the exact stock; 61.47 percent of adults hold a SIM registered in their own name [WB Findex 2024, con11], so the identifier anchors both the payment rail chapter 37 documents and the registration regime chapter 13 measures. The state's own service accounting cannot settle on a denominator: the a2i programme claims more than 1,000 e-services in public use [A2I 2025] while the state owned infrastructure facilitator counts more than 2,000 digitised public services [IIFC 2026], neither claim carrying a published service list to check against.
AI adoption is a budget line, a training target and a marketing clause rather than a measured sector. The Global Innovation Index scored the country 21.4 and ranked it 106 of 133 economies in 2024 [WIPO GII 2024]. The national AI policy text, any GPU scale public compute figure and the country's score on the Government AI Readiness Index of Oxford Insights or the Global Cybersecurity Index of the ITU are all absent from the record available to this chapter, and could not be confirmed; the ICT Division, Oxford Insights and the ITU would resolve them. What the state actually prices sits in the development budget: the revised FY26 programme allocates 2,286.25 crore BDT across 18 projects of the ICT Division [Planning Commission ADP 2026], within which the youth AI technology training project carries a committed cost of 46.36 crore BDT and cumulative expenditure of zero, and the Technical and Madrasah Education Division's Smart Bangladesh plan targets training 5,000 teachers in robotics, cyber security and AI for education themes by 2025 [DTE 2024].
The three laws are the new fact. The Personal Data Protection Act treats personal data as property of the individual, builds processing on consent, grants data holders access, portability, rectification, withdrawal and erasure rights, obliges controllers to keep security safeguards, records, audits and a chief data officer, requires breach notification to an authority where significant harm is likely, and exempts national security, crime prevention, tax detection, statistics, research and journalism from the consent requirement [MinLaw 2026]. Its fines run to 25 lakh taka, 0.25 crore BDT, for violations of data holder rights and to 50 lakh taka, 0.50 crore BDT, for violations by designated important data fiduciaries [MinLaw 2026]. The National Data Management Act establishes a national data management policy board chaired through the head of government and a National Data Management Authority with an executive chairman, tiers of national data warehouses, interoperability duties for ministries, and special provisions for exchanging state important and sensitive data [MinLaw 2026]. The Cyber Protection Act creates a National Cyber Security Agency under a director general, a national cyber security council, a computer emergency response team, certified digital forensic laboratories and a critical information infrastructure designation with security monitoring, inspection and audit powers [MinLaw 2026].
Mechanism: identity first delivery concentrated risk in one credential, cyber was priced as projects rather than institutions, and the speech law lineage shaped the trust base
Three mechanisms produced this position, and each names the policy decision the decade inherits.
The first is identity concentration. The state digitised delivery by hanging every service off one biometric credential: stipends, land records, tax filing, the mobile registration regime and the government to person payment rail of chapter 37 all verify against the national identity number that 61.47 percent of adults carry on a SIM in their own name [WB Findex 2024, con11]. Concentration makes the credential valuable and its compromise systemic: the myLocker exposure of identity numbers alongside names and mobile numbers maps the linkage the architecture created [IIFC 2026]. The Personal Data Protection Act's classification schedule designates government single identity numbers, biometric identifiers, genetic data and criminal records as sensitive personal data whose large scale cross border transfer risks sovereignty, national security or financial stability [MinLaw 2026]. The state is regulating, a decade late, the concentration its own delivery design created, and the rules bind every bank, operator and fintech verifying against the same credential.
The second mechanism is the project form of the cyber budget. The national CIRT exists as a development project, the BGD e-Gov CIRT capacity enhancement project: committed cost 206.23 crore BDT, revised FY26 allocation 33.17 crore BDT, cumulative expenditure 137.08 crore BDT; the police counterpart for national and regional digital investigation capacity: committed cost 59.09 crore BDT, FY26 allocation 20.81 crore BDT, cumulative expenditure 15.20 crore BDT [Planning Commission ADP 2026]. Set against the heist: the unrecovered 66 million USD converts at the FY25 nine month average exchange rate of 120.29 taka per US dollar to roughly 794 crore BDT, nearly four times the total committed cost of the national CIRT project and about thirteen times the police digital forensics project [BB AR 2024] [BBS NA 2025, FY25 provisional estimate, compilation note] [Planning Commission ADP 2026]. A project ends when its development budget closes; an institution publishes. The incident record is invisible because cyber is priced as capital works with no operating disclosure requirement, and no annual report of the CIRT, the agency or a cyber tribunal exists in the sources available to this chapter.
The third mechanism is the trust base the speech law lineage left under the data economy. The lineage chapter 13 documents ran from the Digital Security Act 2018 through the Cyber Security Act 2023 to an unresolved successor, and the package settles it: the Cyber Protection Act repeals the 2023 law and voids every pending case and sentence under nine enumerated sections of the 2023 law and eight of the 2018 law, the speech and harassment provisions under which journalists and users were prosecuted [MinLaw 2026]. What survives is a narrower control core: the agency's director general may remove or block information on cyber security grounds, with tribunal ratification required within three days and a government duty to publish the blocked content list; religious or communal hate speech in cyberspace carries up to two years or a 10 lakh taka fine, bailable; critical information infrastructure hacking carries up to seven years, non-bailable, and the offence definition expressly reaches users of AI tools and data newly produced through AI agents [MinLaw 2026]. The measured base this settlement inherits is the expression index at 0.412 in 2022, the last carried year, 0.082 below its 2013 level [VDem 2022], and the export stakes the buyer decision prices. Digital trade is trust trade, and the voided prosecutions plus a published block list are the verifiable facts its pricing runs on.
The decade ahead: an authority to build, an enforcement stack to fund, an AI estate to price, and buyers who decide what the package is worth
Four decision sets carry the agenda to FY36, the horizon the chapter 15 scenarios price, and each names its author.
The authority decision comes first because everything in the data protection act is secondary legislation dependent. The Personal Data Protection Act leaves the form, manner and time of breach notification to regulations and its operation to a body the National Data Management Act defines; the acts empower rules, regulations, an executive chairman, a fund and staff, none verifiable in the record available to this chapter, so the authority's constitution status could not be confirmed; the ICT Division and the Legislative and Parliamentary Affairs Division would resolve it [MinLaw 2026]. The decision is whether the authority is constituted, staffed with the chief data officers the act requires across ministries and companies, and publishing, on the timetable the reform scenario of chapter 15 assumes for institutional buildouts, or whether it follows the pattern of statutory bodies announced by act and constituted never.
The enforcement stack decision is authored by the cyber agency, Bangladesh Bank and the police, with the Finance Division holding the purse. The CIRT, the forensic laboratories, the critical infrastructure audits and the cyber tribunals with statutory disposal deadlines give the state a complete enforcement architecture on paper [MinLaw 2026] [Planning Commission ADP 2026]. The decision that matters is disclosure: an agency that publishes incident counts, response times and audit findings converts the invisible incident record into a measured series, and a central bank that reports payment system disruptions in the financial stability report gives the heist's successors a documented base rate. The alternative is the status quo scaled by estate growth: more services on the credential, no public count, the offence class still missing from the crime statistics [Police HQ 2024].
The AI estate decision is authored by the ICT Division with the Bangladesh Computer Council and the education and youth ministries. The measured estate is one government cloud marketed for AI workloads [BCC 2024], a skills project whose cumulative expenditure is zero [Planning Commission ADP 2026], a 5,000 teacher training target whose deadline has passed without a published completion count [DTE 2024], and no verified national compute figure, a continuation of chapter 13's finding. The decision is whether the state prices AI compute and data access the way it priced fibre, as infrastructure with a published capacity series, or leaves the AI estate as budget lines. The innovation base it would serve ranks 106 of 133 [WIPO GII 2024], the research system is chapter 33's, the startup finance question chapter 55's, and the jobs question is bounded by structure: with 84.9 percent of employment informal [BBS LFS 2022], the directly AI exposed workforce, formal service jobs performed through screens, is a small share of total employment on this chapter's arithmetic, concentrated in the urban formal tier the services export sector employs; the modelled exposure shares of the ILO and the World Economic Forum could not be confirmed here; those bodies would resolve them.
The buyer decision is authored outside the country. Chapter 02 documents the GSP+ application and the 27 conventions on labour, environment and governance that the European Union requires, and the services trade counterpart is data protection enforcement that satisfies the buyers of services, not only the regulators of goods. The European regime's transfer rules, the personal data provisions of the trade agreements the decade negotiates, and the due diligence of enterprise buyers will treat the April 2026 package as worth what its enforcement record shows: fines levied and published, breach notices received, a block list published and bounded. The 740.89 million USD FY25 services export line, the series high [WB WDI 2026], is the stake, and the freelancer tier chapter 20 carries is the first casualty of failure and the first beneficiary of success.
Three risks print in enforcement records and the upside converts the package into the trust trade
Risks. First, the authority never functions: the acts pass, the regulations never come, breach notices have nowhere to go, and the data protection regime is a husk buyers discount on sight; the revealing indicator is the authority's first published annual report and administrative fine, on the timetable the reform scenario assumes. Second, the control core reverts: the blocking power becomes routine crisis management and the bailable hate speech offence reabsorbs the speech docket the transitional provisions voided, with the revealing indicators the government's blocked content list, absent or unpublished, and the V-Dem expression index falling back through the 0.35 reversion line chapter 13 defines [VDem 2022]. Third, a critical infrastructure event lands on the unmeasured base: a payment system disruption or identity database compromise on the scale the heist priced, arriving under non-bailable provisions that invite arbitrary application; the revealing indicators are a disruption entry in the central bank's financial stability reporting and whether the CIRT's disclosure precedes the press [BB AR 2024].
Upside. First, the trust trade conversion: an enforced data protection act plus the compliance agenda of chapter 02 gives services buyers the certifications they price, and the revealing indicator is the ICT service export line sustained above the 1 billion USD threshold chapter 13 sets, from its 740.89 million USD FY25 base [WB WDI 2026]. Second, the consumer protection leg of the payment rail: formal account ownership fell to 43.28 percent of adults in 2024 from 52.81 percent in 2021 [WB Findex 2024, account.t.d], and an enforced fraud and data remedy under the new acts is the trust mechanism chapter 37's rail has lacked, with the revealing indicator account ownership recovering through the 2021 level. Third, AI assisted state delivery: 1,000 plus e-services on a certified Tier III estate [A2I 2025] [BCC 2024] are the installed base where translation, triage and fraud screening pay for themselves first, and the revealing indicator is the Global Innovation Index rank breaking into the top 100, the entry the reform scenario targets, alongside a published national compute figure [WIPO GII 2024].
What to watch: five indicators whose thresholds mark the regime
- Personal data enforcement record. Current value: none, the act is published 10 April 2026 and the authority's constitution is unverified [MinLaw 2026]; the statutory fines run to 0.25 crore BDT and 0.50 crore BDT for important data fiduciaries, about 20,000 and 41,000 US dollars on chapter arithmetic at the end May 2026 rate of 122.75 taka per US dollar [BIS 2026]. Threshold: a constituted authority publishing an annual report with administrative fines inside FY28, the timetable the reform scenario assumes, marks the enforcement regime; a second full fiscal year past the act with no published enforcement confirms the paper regime.
- National cyber incident disclosure. Current status: no published incident series available to this chapter, the flagship incidents known only through a state company publication [IIFC 2026], and no cyber offence category in the police crime statements [Police HQ 2024]. Threshold: a CIRT or agency annual report with incident, response and audit counts converts the record to a measured series; a second myLocker scale breach surfacing only through unofficial channels confirms the counting gap.
- Secure internet servers. Current value 527.06 per million people in 2024 [WB WDI 2026]. Threshold: above 1,000 per million by FY30, the path the reform scenario assumes, signals encryption and trust infrastructure deepening; a reading stuck under 600 per million marks the stall scenario for the digital estate.
- State cyber investment and its disclosure. Current values: BGD e-Gov CIRT revised FY26 allocation 33.17 crore BDT against a committed cost of 206.23 crore BDT with 137.08 crore BDT cumulative expenditure; police digital forensics FY26 allocation 20.81 crore BDT of 59.09 crore BDT committed [Planning Commission ADP 2026]. Threshold: combined annual cyber allocation holding above 100 crore BDT with published output counts institutionalises the stack; ADP cyber lines falling below 25 crore BDT reverts to project tokenism on the 794 crore BDT heist reminder [BB AR 2024] [BBS NA 2025, FY25 provisional estimate, compilation note].
- AI budget execution. Current value: the youth artificial intelligence skills project holds an FY26 allocation of 13.25 crore BDT against 46.36 crore BDT committed cost and cumulative expenditure of zero, and the 5,000 teacher training target of the Smart Bangladesh plan passed its 2025 date unpublished [Planning Commission ADP 2026] [DTE 2024]. Threshold: cumulative expenditure crossing 25 percent of committed cost within the project's first two ADP cycles marks a real programme; a further year at zero confirms the AI agenda is a budget line without a programme, whatever a national AI policy eventually says.
Sources used
[MinLaw 2026] Legislative and Parliamentary Affairs Division, Bangladesh Code online: Personal Data Protection Act 2026, Act No. 63 of 2026, 10 April 2026, breach notification section 20, exemptions section 24, authority functions section 25, sensitive data classification section 29, fines section 32; National Data Management Act 2026, Act No. 80 of 2026, that number not confirmed, policy board and authority with executive chairman; Cyber Protection Act 2026, Act No. 81 of 2026, re-enacting the Cyber Protection Ordinance 2025, agency, council, CIRT, forensic labs, blocking section 8, penalties sections 17 to 26, bailability section 46, repeal section 50; 2026 amendment act repealing section 20. Primary text unreachable at bdlaws.minlaw.gov.bd, connection refused, checked 2026-09-06; PDPA number, date and fine tiers, and the Cyber Protection Act's 10 April passage, corroborate against a secondary legal summary and press report read the same day; section detail unconfirmed. [BB AR 2024] Bangladesh Bank annual report 2023 to 2024, notes to the financial statements: heist amount, recoveries and litigation history, via ocr_text/bb/annual_report. [IIFC 2026] IIFC Insight vol 1 issue 2, 2026, cybersecurity in e-governance essay: digitised service count, biometric national identity enrolment, CIRT reported email compromise campaign, SikkahBot malware from mid 2024, and the 2024 myLocker breach, via ocr_text/iifc. [BCC 2024] Bangladesh Computer Council, National Data Center service portfolio 2024: tier certification, rack and storage capacity, customers, uptime and eGovCloud service lines, via ocr_text/bcc. [BSCPLC 2023] Bangladesh Submarine Cable Company Limited operational panel via the MoF SOE compilation in bdpolicy.db: achievable capacity 3,000 Gbps FY21, 3,370 Gbps FY22, 3,420 Gbps FY23, lit up 3,050 Gbps and utilisation 2,556 Gbps FY23. [WB WDI 2026] World Bank World Development Indicators: secure internet servers per million people IT.NET.SECR.P6, 228.71 in 2021 and 527.06 in 2024, and ICT service exports BX.GSR.CCIS.CD, a fiscal-year basis series, 740.89 million USD FY25, the series high, read 2026-09-06. [BTRC 2023] BTRC subscriber and bandwidth series through FY23 via the MoF SOE compilation, from chapter 13. [A2I 2025] a2i policy briefs, more than 1,000 e-services in public use, from chapter 13. [WIPO GII 2024] Global Innovation Index 2024, Bangladesh score 21.4, rank 106 of 133. [DTE 2024] Directorate of Technical Education, Smart Bangladesh implementation plan 2024: robotics, cyber security and AI for education teacher training, 5,000 teachers by 2025, via ocr_text/dte_bd. [Planning Commission ADP 2026] Revised Annual Development Programme FY2025-26 project tables: ICT Division 2,286.25 crore BDT, 18 projects; e-Gov CIRT cost 206.23 crore, FY26 allocation 33.17 crore, cumulative 137.08 crore; police cyberspace cost 59.09 crore, allocation 20.81 crore, cumulative 15.20 crore; youth AI skills cost 46.36 crore, allocation 13.25 crore, cumulative zero; BCC digital government project FY26 allocation 828.12 crore; lakh taka converted to crore. [WB Findex 2024] Global Findex 2024 wave, Bangladesh, SIM registered in own name con11, account ownership account.t.d. [BBS LFS 2022] BBS Labour Force Survey 2022, informal employment rate 84.9 percent, from chapter 08. [VDem 2022] V-Dem dataset, freedom of expression and alternative sources of information index v2x_freexp_altinf, 0.412 in 2022, from chapter 13. [Police HQ 2024] Bangladesh Police Headquarters annual crime statement 2024, offence categories counted, no cyber offence category, via ocr_text/police_hq. [BIS 2026] Bank for International Settlements, USD/BDT exchange rate, 122.75 end May 2026, from chapter 03. [BBS NA 2025] BBS national accounts FY25 provisional estimate, nine month July to March average exchange rate 120.29 taka per USD, from chapter 53.
Verified with open items: 61 claims checked, 2 corrected. Claims that could not be confirmed against a primary source are stated as unconfirmed in the text rather than dropped.
Previous: 53 Statistics and data credibility
Cite / Reproduce
BDPolicyLab Research. (2026). 54 AI adoption, data protection and cybersecurity. Bangladesh Policy Laboratory. https://bdpolicylab.com/publications/2026-09-06-bangladesh-2036-ch54-ai-data-protection-cybersecurity
Method and source
Source: Primary sources cited at point of use in the publicationAs of 6 Sep 2026