Act No. 63 of 2026 is Bangladesh's current general personal-data law. The official Bangla Gazette published by the ICT Division is authoritative.
Section 1(3) deems the Act effective from 6 November 2025 except sections 23 and 31 to 35. Those excluded sections commence on a later date appointed by Gazette notification after the stated 18-month period. The checklist does not treat those deferred sections as currently operative.
Grounds and consent: sections 5 to 7 require consent or another permitted ground, purpose limitation and proportionality. Section 9 requires parental or lawful-representative consent for children and persons unable to consent.
Processors and rights: section 8 makes the data fiduciary responsible for contracted processing. Sections 10 and 11 establish request, access and portability mechanisms; the connected rights chapter also addresses correction, restriction and erasure.
Accountability and security: sections 15 to 19 require transparency, confidentiality, risk-based safeguards, retention limits and processing records. Sections 21 and 22 provide for audits and security planning.
Breaches: section 20 requires notification to the Authority where a breach may cause material harm, in the form, manner and time prescribed. No fixed statutory number of hours is imported where the Act leaves detail to subordinate rules.
Transfers: section 29 classifies data and permits conditions, restrictions or localisation requirements for specified categories, including sensitive personal data.
Several operational time limits and procedures are left to rules, standards or Authority directions. Record those dependencies and do not invent a deadline that is not stated in the enacted text.