Quamrun Nahar Mahmud
Advocate, Supreme Court of Bangladesh
Impacts on Human Rights and Press Freedom
The Act’s scope for misuse alarms rights advocates. Key free-expression offenses (e.g. insulting religious sentiments, defamation) remain criminalized. As a result, the new law still “silences critical voices,” according to press freedom groups. Already, rights organizations have observed a divide between the law’s text and practice: thousands were arrested under predecessors for social media posts, and similar outcomes are feared here. The Act partially addresses one problem – it drops 9 of the DSA’s most egregious sections (e.g. criminalizing criticism of state leaders) and grants amnesty to all past cases – but it leaves intact other vague speech crimes. The result is a mixed picture: improved protections against unauthorized exposure (which can benefit women and minors) but continued legal uncertainty for journalists and activists.
Civil Liberties and Privacy
Civil-liberties groups stress that warrantless surveillance and takedowns weaken due process. The homegrown emphasis on “security” over “liberty” means Bangladeshi citizens could face camera surveillance, deep packet inspection, or forced data-sharing by tech companies. Section 8, for example, allows the new Cyber Agency to compel BTRC to block any material deemed a threat to “national unity” or “security,” with minimal oversight. Comparisons have been drawn to other Asian laws (e.g. Pakistan’s amendments to PECA, which allow arbitrary defamation arrests without bail). The Act does not include explicit data protection or privacy safeguards (those are in separate draft ordinances mentioned in [28] but not in CSA 2026), nor does it require transparency reporting by platforms.
Business and Economic Impact
For business and telecom sectors, new obligations arise ISPs and social media firms must cooperate with takedown orders and surveillance requests. Failure to comply is punishable. Some sections explicitly target economic cybercrimes (online fraud, hacking of financial systems). In theory, this could improve investor confidence by combating fraud. However, uncertainty over content restrictions could chill e-commerce or digital media innovation. For example, a startup publishing user content might face criminal liability if any post “annoys” someone. International businesses may face friction: Bangladesh’s mandatory infrastructure controls (like “kill-switch” orders) can deter tech investment, as seen in other markets.
Foreign Relations and International Law
The Act affirms Bangladesh’s obligations under international treaties. It explicitly provides for mutual legal assistance and extradition for cybercrimes (Sec. 48). Cross-border offences against Bangladesh citizens are covered (Sec. 4(2)), so a foreign perpetrator could be tried here. However, the law has raised international concerns. UN human‑rights experts and press‐freedom NGOs had urged repeal of vague speech laws; with CSA 2026, most of those laws are merely re‑enacted. The UN Human Rights Committee’s guidance against criminalizing “hurt sentiments” and defamation is apparently not heeded – Section 26 likely violates Bangladesh’s ICCPR obligations. On the positive side, recognizing Internet access as a right echoes’ global human-rights discourse (see UNESCO and EU declarations) and could align Bangladesh with “digital rights” norms.
Comparisons with Other Jurisdictions
Like India’s IT rules or Pakistan’s PECA, CSA 2026 merges cybercrime with content regulation. However, it is stricter in its treatment of online speech than EU or US law. For instance, unlike the EU’s Digital Services Act (2023), this emphasizes platform accountability and user safeguards, CSA 2026 focuses on criminal penalties for users and gives direct control to the state.
Similarly, the UK’s Online Safety Act (2023) also addresses harmful content, but it relies on Ofcom oversight and mostly civil enforcement on companies, whereas Bangladesh relies on criminal enforcement against individuals. Pakistan’s Prevention of Electronic Crimes Act 2016 provides a closer analogue – it too criminalizes “cyber terrorism,” defamation and hate, with tech-law enforcement agencies wielding strong powers. (Notably, Pakistan’s recent PECA amendments raised defamation penalties up to 5 years imprisonment, echoing Bangladesh’s tougher stance on content offences). Overall, compared to major democracies, CSA 2026 is more repressive: it lacks the procedural safeguards or platform obligations emphasized in EU/UK law, and retains criminal penalties for speech acts that others have dropped.
Ambiguities and Loopholes
Several terms in CSA 2026 are alarmingly vague. What exactly constitutes “insult,” “annoyance,” or “revenge” is undefined. Even “harmful content” for blocking orders (Sec.8) is not clearly delineated. Moreover, enforcement procedures lack safeguards: suspects may be held without warrant or bail, and “urgent” content removals can skip prior judicial review.
These ambiguities risk both over-enforcement and corruption. Observers note a loophole in the fast‑track rule: 90-day deadlines could lead police to round up suspects on flimsy charges to meet targets. Another concern is lack of non‐criminal remedies: the Act has no provisions for independent review of takedown orders or for victims to appeal. In summary, ambiguities in definitions and heavy discretionary powers may allow the law to be used not only against genuine cybercrime, but also for censorship and political purposes.
Recommended Amendments
Urgent attention required to this Act is the absence of a comprehensive public interest defence. Modern cyber security legislation must recognize that not all disclosures of sensitive information are malicious. Journalists, whistleblowers, researchers and civil society actors often play a critical role in exposing corruption, abuse of power, corporate misconduct and systemic security failures. Without explicit statutory protection, legitimate investigative activity may become vulnerable to prosecution, creating a chilling effect on reporting and public accountability. Introducing a carefully crafted public interest defence would allow courts to distinguish between conduct that genuinely threatens cyber security and conduct that serves democratic oversight.
The Act would also benefit from a more precise and narrowly tailored drafting approach. Several key concepts remain broad enough to permit varying interpretations by investigators and prosecutors. In criminal law, ambiguity frequently becomes a source of uncertainty and selective enforcement. Refining the definitions of cyber threats, national security concerns, critical information infrastructure and harmful digital activities would strengthen legal certainty while ensuring that enforcement efforts remain focused on genuinely dangerous conduct. Vague phrases like “annoy” or “hurt sentiments” should be deleted or replaced with precise criteria (e.g. direct threats, incitement, image-based sexual abuse). Transparency requirements should be added: for example, all takedown orders should require immediate judicial sign-off (as many press freedom advocates demand).
A further safeguard would be the introduction of stronger judicial oversight over investigative powers. The authority to search devices, access digital communications, compel disclosure of information or seize electronic data should generally require prior judicial authorization. Such oversight is a fundamental component of democratic governance and serves as an important check against arbitrary or politically motivated investigations. Robust judicial review would not impede legitimate cyber security operations; rather, it would enhance public confidence in the integrity of the enforcement process.
The legislation should also provide explicit protection for journalistic materials and confidential sources. Around the world, democratic systems increasingly recognize that investigative journalism depends upon the ability of sources to communicate information without fear of exposure. Permitting unrestricted access to journalists’ communications, unpublished materials or confidential sources risks undermining media freedom and weakening the public’s ability to scrutinize those in power. Special safeguards should therefore apply whenever enforcement measures intersect with legitimate journalistic activity.
Equally important is the need to protect cyber security researchers engaged in good-faith security testing and vulnerability disclosure. Ethical hackers and independent researchers frequently identify weaknesses in digital systems before they can be exploited by malicious actors. If legal uncertainty exposes such individuals to criminal liability, organizations may become less likely to receive early warnings about vulnerabilities, ultimately making the country’s digital ecosystem less secure. International best practice increasingly favors safe-harbor provisions that encourage responsible disclosure while preserving penalties for malicious intrusion.
Transparency should also become a central pillar of the regulatory framework. Government agencies exercising powers under the Act should be required to publish regular reports detailing the number of investigations initiated, search warrants executed, data requests issued and prosecutions pursued. Such reporting would allow lawmakers, civil society and the public to evaluate whether enforcement powers are being used proportionately and effectively. Transparency is particularly important in cyber security legislation because many enforcement activities occur outside public view.
The establishment of an independent Cyber Rights Ombudsman could provide an additional layer of accountability. Individuals who believe they have been subjected to unlawful surveillance, improper investigations or abuse of authority often face significant practical barriers when seeking remedies through ordinary courts. An independent oversight mechanism with investigative authority would offer a more accessible avenue for addressing grievances and strengthening institutional accountability.
The Act should further embrace internationally recognized data protection principles. Cyber security and privacy are frequently presented as competing interests, yet successful regulatory frameworks increasingly recognize that they are mutually reinforcing objectives. Incorporating principles such as data minimization, purpose limitation, proportionality and accountability would help ensure that security measures do not unnecessarily intrude upon fundamental rights.
Another important reform would be the introduction of mandatory periodic legislative review. Cyber security threats evolve rapidly, and powers considered necessary today may become obsolete, excessive or susceptible to misuse in the future. Requiring Parliament to revisit major provisions at fixed intervals would ensure that extraordinary powers remain justified and proportionate in light of changing technological realities.
The Act should also adopt a more balanced approach to matters involving religious sentiment. While protecting religious harmony is a legitimate objective, international standards generally require restrictions on speech to be limited to incitement of violence, discrimination, or hostility rather than mere offence or criticism. The law should clearly distinguish between hate speech and the lawful exercise of freedom of expression, ensuring that academic discussion, journalism, artistic expression, and public debate on religious matters are not criminalized. Such an approach would be better safeguard both social cohesion and fundamental freedoms in a democratic society. This is particularly significant for a country like Bangladesh, where religious sentiments are high and often attracts violence.
Finally, the long-term credibility of the Act depends on institutional independence. Cyber security agencies tasked with implementing the law should be insulated from political influence through transparent appointment procedures, fixed terms of office and clear accountability mechanisms. Public trust in cyber security regulation is strengthened when enforcement institutions are perceived as professional, impartial and focused on genuine security threats rather than political considerations.
Taken together, these reforms would not weaken Bangladesh’s cyber security framework. On the contrary, they would strengthen its legitimacy by balancing security imperatives with constitutional freedoms, due process guarantees, media independence and democratic accountability. A cyber security regime that enjoys public trust is ultimately more resilient and more effective than one that relies primarily on expansive enforcement powers.
