In keeping with the rapid evolution of the data privacy and security laws around the world, Bangladesh is taking steps to regularize its data privacy and protection laws.
With the proclaimed purpose of safeguarding the personal data of Bangladeshi citizens, the government has drafted the country’s first-ever data privacy and protection legislation known as the Data Protection Act (DPA).
The promulgation date of the proposed legislation, which is still in its formative stage, has been left uncertain.
BowerGroupAsia, a strategic advisory firm that specializes in the Asia-Pacific, speculates that the proposed legislation will come into force before the December 2023 general election.
Broadly, the draft legislation:
(a) Defines the types of data it localizes
(b) Provides the rights and obligations of data subjects, data controllers and data processors
(c) Creates a framework of the processing of the relevant data which includes collection, storage, use, transfer, disclosure and destruction of data
(d) Introduces a system of check and balance
(e) Provides remedies for unlawful processing of data. It has been pointed out by a wide range of commentators that the provisions contained in the draft DPA are marred with ambiguity, inconsistency, complexity, and loopholes.
Some of the concepts and the relevant processes as contained in the draft legislation which affect the data subjects, the data controllers and the data processors have not been adequately defined.
As a result, it may be difficult for citizens as well as the companies collecting data to understand the extent of their rights and obligations.
DSA
Currently, the main piece of legislation governing online activities in Bangladesh is the controversial Digital Security Act, 2018 (DSA), which has often been criticized for its role in the suppression of citizens’ constitutional rights including freedom of expression, right to privacy and right to liberty.
Once the DPA becomes effective, it could compound the problems faced by the citizens under DSA.
The proposed law shifts the power and control over citizens’ data from the companies that are collecting data to the government by requiring the data of Bangladeshi citizens to stay in the country.
Analysts suggest that this would make citizens’ data more accessible to the government, thereby widening the scope of invasive state-surveillance and misuse of citizens’ data; resulting in further breaches of citizens’ rights.
DPA would enable the government to easily interfere with the rights of citizens due to the power that has been vested in the government, as well as the Director General and the Data Protection Office, which are public bodies.
The Director General and the Data Protection Office and their affiliates have also been given immunity in the draft law of being exempted from prosecution for violations caused if they are “done in good faith”.
Acting alongside the DSA, the DPA can impose limitations on the circulation and free flow of information and opinions on the Internet.
Further criticism
The draft legislation has also been criticized for being too widely applicable.
It is intended to stretch beyond Bangladesh’s domestic space and affect companies, both local and foreign, as well as personnel controlling/collecting/processing data relating to people residing in Bangladesh.
Since the DPA is silent on minimum size of companies or minimum volume of data, small and medium-sized enterprises may be significantly affected if they are to be compliant.
They would have to change large parts of their business infrastructure in order to ensure that data of Bangladeshi citizens remain inside the country which may not be logistically or financially viable.
DPA will also affect foreign businesses operating in Bangladesh.
The proposed law does not bar the transfer of data outside Bangladesh as long as ‘one serving copy of data’ is kept in Bangladesh.
However, the law does not clarify the manner in which this may be done.
This means that foreign companies would need to be prepared to overcome local hurdles to data transfer, as may be prescribed, before they can transfer the data to their headquarters.
It is unrealistic to expect every company to set up a local infrastructure in order to store and transfer data.
It can prove to be quite onerous as this approach would drastically increase the cost and time of doing business in Bangladesh.
On top of that, the entities collecting data will be expected to maintain separate and personalized privacy safeguards for foreigners residing in Bangladesh when handling their respective data.
This would require persons/organizations to have a very high degree of awareness of the fast-expanding privacy laws around the world and accordingly provide customized infrastructure when they operate in Bangladesh.
As a result, companies would need to be adequately prepared to deal with unexpected and problematic situations that may arise.
For example, they may be required to store data of a particular type for a foreign data subject which is legal in their jurisdiction but illegal in Bangladesh.
All these factors have the chance of making doing business in Bangladesh very complex, expensive, time-consuming and make it difficult for foreign companies to compete with local firms.
Furthermore, DPA requires companies to take reasonable steps to ensure that the data they collect is accurate, complete and not misleading.
It is practically impossible for a company to verify the correctness of every piece of information they store online.
Not only do companies need to comply with the obligations placed on them, but they also need to ensure that any company processing the data on their behalf adopts applicable technical and organizational security standards.
DPA creates barriers to burgeoning and thriving businesses in Bangladesh which in turn may cause decline in foreign direct investment and decrease in overall economic investment in Bangladesh.
At a time when the country is set to graduate to a developing country and consequently may experience a decrease in foreign donations, Bangladesh will be in a vulnerable position if it experiences a reduction in foreign direct investment.
Data moves through borders more frequently and in greater volumes than persons or goods across the globe.
It is important for us to have in place proper legal safeguards to secure our private data which travels through the public digital space and is collected for profit-making purposes by big global tech corporations.
Hence, having in place a legal framework like DPA that protects our private data is reassuring.
While the purpose of the proposed data protection legislation in theory is deserving of praise, its ability to be efficacious in practice raises eyebrows.
Before finalizing the draft, it is essential for the policy-makers to consult stakeholders in order to come up with a robust set of laws that strikes a balance between the need to protect citizens’ personal data from undue interference, the rights of companies to operate seamlessly in Bangladesh and the interests of the public and state security being adequately protected.
Saqeb Mahbub is barrister-at-law and partner at Mahbub & Company. He can be reached at Saqeb.mahbub@mahbub-law.com, and Mohua Morshed is barrister-at-law and associate at Mahbub & Company. She can be reached at mohua.morshed@mahbub-law.com