CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Why Bangladesh’s new data protection law may fail to protect your data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2180

As cited

Copy frozen at (site build).

regulatory

Why Bangladesh’s new data protection law may fail to protect your data

Bangladesh's major retail chain Shwapno suffered a breach in August 2025 exposing personal data of 4 million customers, including names, phone numbers, and purchase histories. The company did not disclose the incident to affected customers for seven months, raising questions about the effectiveness of Bangladesh's data protection law in enforcing notification and transparency requirements.

Why it matters: Organizations operating in Bangladesh and customers whose personal data is subject to Bangladesh's jurisdiction need to understand the enforcement gaps in the new law, and practitioners must assess whether their data protection policies meet the actual disclosure standards being applied in the market.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary