The invisible crisis: Why Bangladesh must wake up to its data vulnerability

Kalim Ahmed

Bangladesh has been building a data state for nearly two decades — from the first National ID drive in 2008 to today's biometric-laden smart cards that unlock nearly every corner of civic life. But the promise that came with handing over one's face, fingerprints, and personal history was that the state would guard them in return. That promise has been broken so often, across so many governments, that the breaches themselves have become the story.

The first time was in 2008. Following two years of political upheaval, a caretaker state embarked on a mission to accurately count its citizens, paving the way for an election. Every citizen would be photographed and have their details recorded in a single register. This marked the birth of the National Identity card and a tacit agreement: citizens would provide their names, faces, and fingerprints.
However, its administrative reach kept extending. Over the ensuing decade, the NID, initially established to verify identity, evolved into a crucial tool unlocking nearly every aspect of life: bank accounts, SIM cards, land records, pensions, welfare, and passports. With time, this foundation of data access extended outwards, granting ministries, banks, fintechs, port authorities, and other third parties access to the register. Today's smart NID reportedly stores impressions of all ten fingers, iris scans, and 32 categories of personal data, and by late 2024, the Election Commission had prepared approximately 81 million of these cards for an electorate of 122 million.
 

This concentration of data brought millions into the formal economy through conveniences such as mobile money and net banking. However, these conveniences also bolstered the state's surveillance capacity — the very machinery responsible for tracking dissidents and operating during enforced disappearances. Consider the National Telecommunication Monitoring Centre, an agency tasked with intercepting calls and communications, which reportedly allowed nearly 500 officials from 42 public bodies to query citizens' data. In 2023, a foreign security researcher found a database linked to this agency lying exposed: names, addresses, NID numbers, passport information, banking details, phone records, vehicle registrations, and even biometric data belonging to millions of citizens. The same year, a government registry exposed the records of some 50 million citizens, and authorities later admitted that they could not determine how far the breach went.

Then came the second beginning. The July 2024 Monsoon Revolution swept away an order many believed immovable, and Bangladesh found itself once more before a blank canvas — this time, the sweeping strokes carried the promise that the machinery of the state, including its handling of citizens' data, would be rebuilt on better-intentioned terms.

A recently published comprehensive report by Tech Global Institute (TGI) documents at least 68 data breach incidents affecting Bangladeshi institutions between January 2023 and May 2026 — 36 government bodies and 32 private organisations — with the incidents spanning the political divide.

The 2024 rupture changed the faces in power; however, it did not interrupt the pattern of breaches. A recently published comprehensive report by Tech Global Institute (TGI) documents at least 68 data breach incidents affecting Bangladeshi institutions between January 2023 and May 2026 — 36 government bodies and 32 private ones — and the incidents run straight across the political divide. In 2025, more than a million records allegedly from the Bangladesh Road Transport Authority were listed on a criminal forum. And this January, CID investigators uncovered a syndicate inside the Election Commission itself: an office assistant and an outsourced data-entry operator who had sold the NID records of 365,000 citizens in a single month. Days later, a flaw in the Commission's own accreditation portal exposed the personal files of roughly 14,000 journalists applying to cover the national elections. And through April and May, databases of the Ministry of Expatriates' Welfare and the manpower bureau — containing passport records, tax identifiers, and banking details of over a million migrant workers, the very people whose remittances help sustain the economy — were advertised on dark-web forums.

Though the state has fallen victim to data breaches on numerous occasions, the lesson need not be that these leaky vaults are limited to the public sector. In March, Shwapno, one of the country's largest supermarket chains, made headlines after hackers — reportedly inside its systems since December — demanded a $1.5 million ransom, putting the records of over 40 lakh customers at risk. Importantly, this too wasn't discovered by the private company but surfaced only when customers' names, phone numbers, and purchase histories began circulating on social media. 

Yet the most damning number in this record is not 68. It is two. In only two of these incidents did the affected institution — private or public — discover the problem itself. Discovery and acknowledgement by the institution itself are the aberration, while every other breach was discovered by outsiders — i.e., foreign researchers, dark-web monitors, and journalists. And the standard institutional response to each discovery has been silence or denial, followed by nothing, meaning no forensic post-mortem report, no notification to citizens, and no account of what was lost.

The new administration's formal answer arrived in 2026, in the form of ambitious lawmaking: for the first time, a Personal Data Protection Act and a National Data Management Act entered the policy lexicon. But upon interrogation of the fine print, it becomes abundantly clear that the ambitious makeover suffers from the same parochial tendencies. The new law mandates breach notification, but only to the regulator and not to the citizen whose data may be for sale. Notification is triggered only when damage is "significant", a threshold yet to be defined, within a timeframe left to future regulations. Key provisions are subject to delayed commencement, meaning breaches during the transition may incur no penalties and cannot be punished retrospectively. Victims lack an independent right to sue in ordinary courts. Meanwhile, violations by public officials are treated as internal departmental misconduct rather than public wrongs, despite government bodies accounting for the majority of documented breaches.

And the accompanying statute answers a decade of leaks by further centralising data via mandatory database integration, a national data exchange, and compulsory storage in national data centres — all in all, a larger system, with more entry points, guarded by the same watchmen. Moreover, the enforcement record inspires little confidence: in eight years of cybercrime legislation, and with over 7,000 cases filed under the now-repealed Digital Security Act alone, not a single publicly reported prosecution has followed a major data breach. Where a breach results from hacking, unauthorised access, data theft, or other forms of cyber intrusion, the Cyber Protection Act may also be engaged. Yet the problem is twofold: weaknesses in the law itself are compounded by an inconsistent record of enforcement.

A new beginning doesn't need dramatic legislation to inspire confidence. It could be surprisingly simple. For instance, mandatory and time-bound breach notifications should extend to affected citizens, not just regulators — and, importantly, with no carve-outs for public bodies. Forensic post-mortems after each breach should be the standard, and accountability should climb upwards — past the office assistant caught selling records, to the officials who built a system in which a single low-level credential could open the files of a nation.

A state that adopts technologies faster than it writes the procedures to govern them will keep producing breaches that no statute, however well drafted, can prevent.

Laws, moreover, are only half the repair. Bangladesh's digital governance problem has been operational as much as legal. New systems and platforms are routinely rolled out without the standard operating procedures (SOPs) that should accompany them, such as access controls, audit trails, and incident-response protocols — or with rules that arrive late and are applied unevenly. For instance, on 9 April this year, a few social media posts on Facebook and X alleged a data breach involving Bangladesh's Fuel Pass system, a newly launched pilot system aimed at streamlining fuel distribution. Similarly, the journalists' portal that was launched earlier this year by the Election Commission also carried a basic flaw that exposed the data of thousands of reporters. The main takeaway here is this: a state that adopts technologies faster than it writes the procedures to govern them will keep producing breaches that no statute, however well drafted, can prevent.

Every breach should have a real forensic reckoning, with accountability reaching the officials who built fragile systems, not just the low-level staff who exploited them. Until laws and practices both catch up with the scale of what is being collected, the question is not whether another breach will occur, but who will be the one to discover it — a foreign researcher, a journalist, a dark-web forum, or, for once, the institution itself.


Kalim Ahmed is Research Manager at Tech Global Institute.


Send your articles for Slow Reads to slowreads@thedailystar.net. Check out our submission guidelines for details.