Logo

Alpine Law Associates is the leading full-service law firm encompassing a wide range of legal practices located in Kathmandu, Nepal. It consists of a team of the country's best lawyers, each with expertise in their respective fields, tailored to meet clients' specific needs.

Office Address

Anamnagar-29, Kathmandu

Phone Number

+977 9841114443

Email Address

info@lawalpine.com

Data Protection Law in Nepal 2026 — Business Impact
Table of Contents0sections

Businesses in Nepal currently face privacy duties under the Privacy Act 2075 and Constitution Article 28, while the IT and Cybersecurity Bill 2082 remains pending. Consent, lawful handling and criminal penalties already matter; proposed Clause 61 would require data destruction within 35 days after purpose fulfilment if enacted.

For a business-focused review of data protection Nepal rules, see Alpine's business law practice. E-commerce operators can also compare the privacy issues with our e-commerce registration guide. This article reflects the legal material available for 2026, within the 2083 BS calendar period.

Key Takeaways

  • Constitution Article 28 protects privacy of the body, residence, property, documents, data, correspondence and character.
  • The principal statute is the Privacy Act 2075, read with the Individual Privacy Regulation 2077.
  • Consent applies to collection, recording, processing and disclosure of personal information under the current framework.
  • The Privacy Act covers government, private and not-for-profit entities operating in Nepal.
  • Unlawful handling can create criminal exposure, including up to 3 years' imprisonment and NPR 30,000 under the Privacy Act.
  • Nepal currently has no dedicated data-protection regulator or statutory breach-notification obligation identified in the supplied material.
  • The pending IT and Cybersecurity Bill 2082 would replace the Electronic Transactions Act 2063 and proposes a 35-day destruction rule.
Figure 1 — Key data protection figures in NepalFour panels show Constitution Article 28, Privacy Act penalties, Penal Code Section 293 penalties and the proposed 35-day data destruction term.Figure 1 — Key figures for Nepal businessesCurrent privacy law and the pending Bill 2082Article 28Constitutionalprivacy anchorConstitution of NepalNPR 30,000Privacy Actmaximum finePrivacy Act 2075NPR 20,000Section 293fine ceilingPenal Code 2074Section 29335 daysproposed datadestruction termBill 2082 Clause 61Source: Constitution Article 28; Privacy Act 2075; Penal Code 2074 Section 293; IT and Cybersecurity Bill 2082 Clause 61.
These four figures summarise the constitutional anchor, statutory penalties and proposed retention change shaping data protection Nepal compliance.

What is data protection in Nepal, and which laws govern it?

Data protection in Nepal covers personal information collected, recorded, stored, processed, used, analysed or disclosed by an organisation. The framework combines Constitution Article 28, the Privacy Act 2075, the Individual Privacy Regulation 2077, the Penal Code 2074 and the Electronic Transactions Act 2063.

Article 28 protects privacy of the body, residence, property, documents, data, correspondence and character. The Privacy Act text published by the Nepal Law Commission is the principal statutory reference. The Act's framework is supported by the Individual Privacy Regulation 2077.

Digital conduct can also fall under Penal Code 2074 Sections 293-298. The Electronic Transactions Act 2063 text is relevant to digital privacy offences, including Section 47 on publication of illegal electronic material.

Who does Nepal's privacy law apply to?

The Privacy Act 2075 applies to government, private and not-for-profit entities operating in Nepal. It addresses personal information of people residing in or located in Nepal, including names, addresses, telephone details, biometric data, health information, financial information, citizenship and identification details.

This scope reaches more than banks or technology companies. Employers, hospitals, schools, insurers, telecom operators, online businesses and service providers may handle information covered by the framework. The supplied material does not settle every question about a foreign business with no Nepal operation, so that position should be verified with the office or through legal advice.

Section 12 and adjacent provisions of the Privacy Act 2075 require informed, freely given consent for collection, recording, processing or disclosure of personal information. The Individual Privacy Regulation 2077 elaborates the form and timing of consent, while the consent should identify its purpose, scope, recipients and retention period.

For a website, application or KYC process, a business should review whether its notice and consent flow explain what information is collected and why. Implied consent or pre-ticked boxes may be insufficient for sensitive categories such as health, biometric or financial data. The current material also states that withdrawal of consent must be honoured.

  • Identify the purpose before collecting the information.
  • Explain the scope and intended recipients.
  • State the retention period used for the consent.
  • Keep a record showing what the person agreed to.

Why does data protection matter to a Nepal business?

Business impact arises from the way an organisation collects, uses, shares and stores personal information. Consent failures can create criminal exposure, while unauthorised disclosure can also raise reputational and litigation risk. Sector rules may add another layer for banking, fintech, insurance, telecom, health and education services.

A business should therefore review privacy notices, onboarding screens, KYC handling, vendor disclosures and internal access. NRB IT Guidelines may matter to BFIs, while NTA IT Policy 2080 may matter to telecom businesses. Tax records may involve the Inland Revenue Department, and health or education operators may need to check sector-specific guidance.

Businesses seeking practical compliance support can review Alpine's company compliance service. The service does not replace the authority of a regulator, court or government office, and no outcome or processing time is promised.

How would the IT and Cybersecurity Bill 2082 affect businesses?

The IT and Cybersecurity Bill 2082 remains a pending proposal in the material supplied for this guide. It would replace the Electronic Transactions Act 2063 and address electronic records, digital signatures, cybercrime and data handling. Its proposed Clause 61 would require information about data use and destruction within 35 days after the purpose is fulfilled.

The supplied material records the Bill as registered in the House of Representatives on 10 June 2025 and tabled by the Communications Minister on 14 August 2025. The Ministry of Communication and Information Technology is identified as the lead ministry; its official website is the relevant government source for that ministry. The material describes the Bill as being in an amendment or public-comment phase.

IssueCurrent frameworkBill 2082 position
Data useConsent framework appliesIndividuals would receive data-use information
Digital statuteETA 2063, including Section 47Would replace ETA 2063
DestructionNo current general term identifiedClause 61 proposes 35 days after purpose fulfilment
RegulatorNo dedicated data regulatorNot established in the supplied material
Breach noticeNo statutory obligation identifiedNo rule identified in the supplied material
Figure 2 — Current law compared with the pending Bill 2082A comparison grid shows current consent, digital law, destruction, regulator and breach-notification positions beside the proposed Bill 2082 position.Figure 2 — Two routes for business complianceCurrent framework compared with the pending Bill 2082Current frameworkPending Bill 2082CriteriaData useConsentInform about useDigital statuteETA Section 47Would replace ETADestructionNo current term35 days proposedRegulatorNone dedicatedNot establishedBreach noticeNo statutory ruleNot stated hereSource: Privacy Act 2075; Electronic Transactions Act 2063; IT and Cybersecurity Bill 2082 Clause 61.
This comparison shows what a Nepal business must review under current privacy law and what remains only a proposed Bill 2082 obligation.

How can a Nepal business review its data protection position?

A business review can map information, test consent, check disclosures and prepare for possible Bill 2082 changes. It is a compliance review rather than a government registration process. The supplied material does not identify one universal filing route, portal, approval or processing period for every business.

  1. Map the information. List the personal information the business collects, records, stores, analyses or shares, including names, contact details, identity information, biometrics, health and financial data.
  2. Set the purpose first. Before collection, identify why the information is needed and explain the purpose, scope, recipients and retention period.
  3. Record consent where required. If the activity involves collection, recording, processing or disclosure, use a consent method that captures the individual's informed agreement.
  4. Control disclosure. Review employees, vendors, KYC partners and sector relationships before sharing information. The decisive condition is whether the disclosure is covered by consent or another applicable legal route.
  5. Prepare for incidents. Record what happened and seek legal advice promptly. Nepal currently has no statutory breach-notification obligation identified in the supplied material, but privacy, criminal, litigation and reputational issues can still arise.
  6. Track the Bill. Do not treat Clause 61 as current law. A business may, however, test whether it could destroy information within 35 days after purpose fulfilment if the proposal becomes law.
Figure 3 — Who does what in a Nepal privacy reviewThree horizontal lanes show business, individual and court or sector body actions across before use, during use and if challenged, with arrows showing hand-offs.Figure 3 — Who does what in a privacy reviewIllustrative business flow, not a statutory filing processBefore useDuring useIf challengedBusinessIndividualCourt / sectorMap dataState purposeControl sharingRead noticeGive consentWithdraw /raise concernDistrict CourtWrit routeSector reviewSource: Privacy Act 2075; Constitution Article 28.
This lane diagram shows how a Nepal business, the individual and a court or sector body may interact during a privacy review.

What documents and records should a business review?

Nepal's supplied framework does not set one universal business document checklist or require every organisation to file the same privacy documents. A business should instead review the records that explain its data practices, consent, disclosures, retention and incident response, then verify any sector-specific requirement with the relevant authority.

A useful internal review set can include a privacy notice, consent wording, consent records, a personal-information map, disclosure records, vendor terms and an incident log. These are review materials, not a statement that every item must be submitted to a government office. Our team can help with drafting legal documents based on the business's facts.

  • Website, application or onboarding privacy notice.
  • Consent wording showing purpose, scope, recipients and retention period.
  • Records for KYC, employee, customer or patient information.
  • Disclosure and access controls for staff and service providers.
  • Incident records for leaks, scraping or insider exfiltration.

What timeline and cost factors apply to data protection compliance?

Current Nepal law does not provide a single business-wide implementation timeline in the supplied material. The only specific destruction period is the proposed 35-day term in Clause 61 of the pending Bill. The material also gives no fixed data-protection registration or compliance charge, so businesses should verify current requirements and professional fees before acting.

Your total cost can depend on the number of systems, the sensitivity of the information, vendor arrangements, sector rules, incident history and the amount of legal drafting or review needed. A government charge, if an authority imposes one for a separate filing, is different from professional fees. Do not treat the proposed 35-day period as a current retention deadline.

What penalties and enforcement routes can apply?

Unlawful collection, disclosure or processing may attract up to 3 years' imprisonment and an NPR 30,000 fine under the Privacy Act 2075. Penal Code provisions and Electronic Transactions Act Section 47 may create additional exposure, depending on the conduct, the information involved and the charge selected.

ProvisionConduct described in the supplied materialMaximum stated penalty
Privacy Act 2075Unlawful collection, disclosure or processing3 years and NPR 30,000
Penal Code Section 293Unauthorised eavesdropping or recording2 years and NPR 20,000
Penal Code Section 294Disclosure of professional confidential information1 year and NPR 10,000
Penal Code Section 295Unauthorised photography1 year and NPR 10,000
Penal Code Section 295Publication of disfigured or modified photographs2 years and NPR 20,000
ETA Section 47Publication of illegal electronic material5 years and NPR 100,000

The Penal Code's privacy provisions run in parallel with the Privacy Act. The current material states that one unlawful disclosure may attract both routes, with the heavier penalty governing. Because the correct charge depends on facts, a business should not assume that every incident produces every listed penalty.

Nepal currently has no dedicated data-protection regulator and no statutory breach-notification obligation identified here. Criminal enforcement may proceed through the District Court, while Article 28 may support writ jurisdiction in the High Court or Supreme Court. NRB, NTA and IRD may matter for their respective sectoral information.

What common mistakes should Nepal businesses avoid?

Businesses create avoidable risk when they treat cybersecurity as the whole privacy issue. The current framework also concerns consent, purpose, disclosure, professional confidentiality, photography, electronic publication and sector controls. A privacy policy alone cannot correct collection or sharing practices that do not match what the business tells people.

  • Collecting more information than the stated purpose requires.
  • Using vague consent that omits recipients or retention.
  • Assuming a pre-ticked box always proves informed consent.
  • Sharing KYC or customer information without checking the consent scope.
  • Calling Clause 61 a current 35-day legal duty before the Bill is enacted.
  • Assuming that the absence of a breach-notification rule removes all legal risk.
  • Ignoring NRB, NTA, IRD, health or education requirements where the sector applies.

What happens in a realistic Nepal business scenario?

Consider an illustrative Nepal fintech that collects names, phone numbers, identity details, biometric information and financial information through an application. It shares some information with a service provider for KYC support. The business must examine consent, purpose, recipients, retention and sector rules rather than relying only on a general website notice.

If the service provider later discloses information outside the stated scope, the facts may raise Privacy Act, Penal Code and sectoral questions. The business should preserve records, identify the information affected and obtain legal advice. It should not assume that a statutory breach notice, a dedicated regulator or a fixed government response period exists, because the supplied material does not establish one.

What alternatives and edge cases should a business consider?

A small online seller, a nonprofit, a telecom operator and a bank may all handle personal information, but their operational risks and sector rules differ. The Privacy Act's stated scope includes government, private and not-for-profit entities operating in Nepal; it does not create one identical compliance model for every organisation.

Cross-border handling is an unresolved edge case in the supplied material because no cross-border transfer rules are identified. A foreign company, NRN-linked business or Nepal service provider using overseas systems should verify the applicable position instead of assuming that foreign privacy law replaces Nepal requirements. E-commerce businesses should also consider the separate issues discussed in our guide to the E-commerce Act in Nepal.

In short: Nepal businesses should treat personal information as a legal compliance issue, not only a technology issue. Start with Article 28, the Privacy Act 2075, consent records and disclosure controls. Review criminal exposure and sector rules. Track the pending Bill 2082, but do not treat its proposed 35-day destruction term as current law.

People also search for

Readers researching data protection Nepal often compare privacy duties with e-commerce, consumer, banking and document-related rules. These related Alpine guides provide context, but each topic has its own legal basis and should not be treated as a substitute for reviewing the facts of your business.

This article is general legal information, not advice on a particular data incident or business model. Contact Alpine Law Associates for a fact-specific review; our team can help you assess privacy practices and connect the work with company compliance support in Nepal.

Frequently Asked Questions

Nepal’s Data Protection Bill cannot be described accurately from the supplied legal materials because they do not include the Bill’s text, status, sections, or commencement notice. A business should first confirm whether it remains proposed or has become enforceable law. For a current Nepal-specific review, contact Alpine through lawalpine.com/contact-us.

The supplied sources do not establish whether Nepal’s Data Protection Bill has been enacted, brought into force, or replaced by another instrument. Those are different legal questions, and a business should not rely on a draft, announcement, or commentary alone. Verify the current official text and commencement position, or ask Alpine to check it.

No reliable commencement date is provided in the supplied materials. The effective date would depend on enactment and any commencement step stated by applicable Nepalese law. Businesses should avoid planning compliance around an unverified calendar date. Ask Alpine for a current status check before setting internal deadlines, changing contracts, or redesigning data systems.

The supplied grounding does not identify the Bill’s scope, territorial reach, sector exemptions, or thresholds. It therefore cannot safely confirm whether a company, bank, platform, employer, charity, or public body would be covered. A Nepal business should obtain the final text and any rules before deciding that the proposal does or does not apply.

No source supplied here confirms an exemption for small businesses, a turnover threshold, or a simplified compliance route. Small companies should therefore avoid assuming they are outside the Bill merely because they have few employees or customers. Whether size changes the duties depends on the enacted Nepali text and implementing rules; seek a review.

The supplied materials do not define the Bill’s categories of personal data, sensitive data, anonymised information, or business records. A company should not label a dataset exempt or regulated based only on its name. Classifying customer, employee, supplier, and online-account information requires checking the final Nepal text and the facts of processing.

No supplied source states whether the proposed framework requires consent, permits other legal grounds, or sets special rules for children, employees, marketing, or sensitive information. Businesses should not assume that a privacy notice alone is enough, or that consent is always required. The answer depends on the final Nepali legislation and applicable rules.

The supplied materials do not establish whether Nepal’s Bill restricts overseas transfers, requires safeguards, or distinguishes cloud hosting from other disclosures. A company using foreign software or storage should not assume that cross-border access is either permitted or prohibited. Check the enacted provisions, rules, and any sector-specific requirements before moving data abroad.

No supplied source confirms whether Nepal’s Bill would require a data-protection officer, privacy officer, local representative, or another responsible person. Businesses should avoid presenting an internal appointment as a statutory requirement until the final law is checked. The need, qualifications, independence, and reporting duties would depend on the enacted framework and the organisation’s activities.

The materials provided do not state the Bill’s penalties, compensation rules, enforcement authority, or treatment of directors and employees. It would be unsafe to quote a fine, imprisonment term, or fixed liability. Businesses should review the final Nepali provisions before assessing exposure, updating risk registers, or making public compliance claims.

Until the Bill’s current legal status and text are verified, businesses can map what information they collect, why they use it, who can access it, and where it is stored without claiming that a particular Bill duty already applies. Legal obligations still depend on the final Nepali framework and each business’s facts; obtain advice.

The supplied sources do not settle whether the Bill would cover a foreign company with customers, staff, vendors, servers, or services connected with Nepal. Coverage could depend on territorial rules, sector, and the type of processing, but those rules are not provided here. Foreign businesses should obtain a Nepal-specific scope review before relying on exclusions.

Nothing in the supplied materials confirms whether employee information receives separate treatment under Nepal’s Data Protection Bill or another applicable instrument. Employers should not assume workplace data is outside the issue, nor that ordinary HR practice answers the question. Review the final Nepali text alongside employment arrangements and the employer’s actual data handling.

The supplied grounding does not state whether a data incident must be reported, to whom, within what period, or in what form. A business should not publish a fixed reporting deadline without verified Nepali authority. If an incident has occurred, seek prompt Nepal-specific advice through Alpine’s contact page before deciding what notice is required.

Alpine Law Associates can review the Bill’s current status and explain possible business implications, but the supplied materials do not support a guaranteed answer about coverage, deadlines, documents, or penalties. Businesses can request a Nepal-specific assessment through lawalpine.com/contact-us. Provide the relevant operations and data flows so the advice addresses the actual risk.

Disclaimer:
This article is intended solely for informational purposes and should not be interpreted as legal advice, advertisement, solicitation, or personal communication from the firm or its members. Neither the firm nor its members assume any responsibility for actions taken based on the information contained herein.

Chat on WhatsApp