Reliable Brokers
Online Investing
Alerts & Analysis
Easy Trading

Data Protection Act 2022: More questions than answers

What is the main purpose of the proposed act?

Update : 17 Oct 2022, 01:20 AM

Many countries around the world have taken various initiatives and steps to protect the personal data of citizens. The main purpose of these initiatives is to protect individuals' personal data. 

Article 43(b) of the constitution of Bangladesh recognizes the right to privacy of personal data, but the draft Data Protection Act 2022, omits this provision. On the other hand, if the provisions of the constitution were added, the common people would get a clearer idea about the main purpose of the law.


The preamble to any law explains the purpose of that law and also plays a vital role in explaining the various provisions of the law. In the preamble to the proposed law, it was necessary to specify the purpose of the law more clearly.


The purpose of this law is to provide security for personal data, but the most surprising thing is that there is no definition of personal data in the law. To what extent will the act's purpose be implemented without defining personal data?


According to section 63, for the purpose of fulfilling this act the government can issue instructions to the Director General of the Data Protection office in the interest of the sovereignty and integrity of Bangladesh, national security, friendship with foreign countries, and public order. But once again, there is no definition of the integrity of Bangladesh, national security, friendship with foreign countries, and public order. 

Therefore, anyone who wishes has the opportunity to file a case under section 63 of this law by defining the speech of any person or any activity of any organization as a threat to the sovereignty and integrity of Bangladesh, national security, friendship with foreign countries, and public order.


Section 35 provides for the establishment of the Data Protection Office, and Section 35(2) states that the Data Protection Office shall be under the administration and control of the Digital Security Agency, which is established under the Digital Security Act 2018 (DSA). 

The most surprising thing is that the functions of the Digital Security Agency and the purpose of the Data Protection Office are completely different -- one of the main responsibilities of the Data Protection Office is to preserve and protect the right to privacy of data; on the other hand, one of the key functions of Digital Security Agencies is to remove or block any data that poses a threat to digital security.


The Director General will have a “sole” role in exercising powers under the proposed Data Protection Act 2022.  What are the eligibility criteria for the Director General in the highest position on sensitive issues like data protection?  

According to Section 06 of the DSA, the Director General will be a computer and cyber security expert, but what are the standards to judge this expertise? There is no mention of educational qualification; authorities can appoint anyone according to their choice.  

Computer and cyber knowledge have become ubiquitous; most people nowadays have some idea. With no academic qualification or standard mentioned in the act anyone can get hired.


Moreover, the Digital Security Agency is also required to follow the directions and advice of the Digital Security Council as per Section 13 of the DSA. So, according to the law, does this mean that the Office of Data Protection is under the control of the Digital Security Council? If the Digital Security Council has the regulatory role of the Data Protection Office, will it properly ensure the protection of personal data?


The DSA allows law enforcement agencies to monitor personal information, which may undermine the right to privacy. According to Section 59 of the proposed act, the offense shall be investigated by an officer working under the Director General, having the qualifications prescribed by the rules. 

There is again no clear law or guidance on what technical skills and qualifications an officer should have to investigate a specialized matter such as data protection. Therefore, if an official lacks the technical skills and qualifications, it remains to be seen how the protection of personal information will be ensured. 

According to Section 60, offenses committed under this act will be a trial in the Cyber Tribunal constituted under Section 68 of the Information and Communication Technology Act 2006 (ICT Act). It can be appealed to the Appellate Tribunal constituted under Section 82 of the ICT Act 2006. Cases filed under the DSA are also under the jurisdiction of the same court. The purpose of the proposed Data Protection Act 2022, the ICT Act, and DSA are not the same -- so why is the trial in the same tribunal?


Legislation aimed at ensuring the security of citizens' personal data after a long period of independence is no doubt laudable, but if there is an ulterior motive behind that law, it is a concern for citizens.


Therefore, a fully independent commission can be constituted to ensure the security of personal data.  All commission officers shall have special competence in data protection, and the commission shall arrange for training as necessary. Specialized tribunals can be constituted for crimes under the said act and it is essential to provide a clearer understanding of the purpose of the act in the preamble by adding the relevant provisions of the constitution.

It is the responsibility of the state to ensure the protection of the personal data of citizens -- it is a constitutional right.


Md Harisur Rohoman is a freelance contributor and a student of law.

Top Brokers