Consumer Protection Law in Nepal 2026: Rights & Remedies
"The Consumer Protection Act 2075 (2018) replaced the 1998 Act. It codifies nine consumer rights, sets penalti...
Read more →Alpine Law Associates is the leading full-service law firm encompassing a wide range of legal practices located in Kathmandu, Nepal. It consists of a team of the country's best lawyers, each with expertise in their respective fields, tailored to meet clients' specific needs.
Anamnagar-29, Kathmandu
Businesses in Nepal currently face privacy duties under the Privacy Act 2075 and Constitution Article 28, while the IT and Cybersecurity Bill 2082 remains pending. Consent, lawful handling and criminal penalties already matter; proposed Clause 61 would require data destruction within 35 days after purpose fulfilment if enacted.
For a business-focused review of data protection Nepal rules, see Alpine's business law practice. E-commerce operators can also compare the privacy issues with our e-commerce registration guide. This article reflects the legal material available for 2026, within the 2083 BS calendar period.
Data protection in Nepal covers personal information collected, recorded, stored, processed, used, analysed or disclosed by an organisation. The framework combines Constitution Article 28, the Privacy Act 2075, the Individual Privacy Regulation 2077, the Penal Code 2074 and the Electronic Transactions Act 2063.
Article 28 protects privacy of the body, residence, property, documents, data, correspondence and character. The Privacy Act text published by the Nepal Law Commission is the principal statutory reference. The Act's framework is supported by the Individual Privacy Regulation 2077.
Digital conduct can also fall under Penal Code 2074 Sections 293-298. The Electronic Transactions Act 2063 text is relevant to digital privacy offences, including Section 47 on publication of illegal electronic material.
The Privacy Act 2075 applies to government, private and not-for-profit entities operating in Nepal. It addresses personal information of people residing in or located in Nepal, including names, addresses, telephone details, biometric data, health information, financial information, citizenship and identification details.
This scope reaches more than banks or technology companies. Employers, hospitals, schools, insurers, telecom operators, online businesses and service providers may handle information covered by the framework. The supplied material does not settle every question about a foreign business with no Nepal operation, so that position should be verified with the office or through legal advice.
Section 12 and adjacent provisions of the Privacy Act 2075 require informed, freely given consent for collection, recording, processing or disclosure of personal information. The Individual Privacy Regulation 2077 elaborates the form and timing of consent, while the consent should identify its purpose, scope, recipients and retention period.
For a website, application or KYC process, a business should review whether its notice and consent flow explain what information is collected and why. Implied consent or pre-ticked boxes may be insufficient for sensitive categories such as health, biometric or financial data. The current material also states that withdrawal of consent must be honoured.
Business impact arises from the way an organisation collects, uses, shares and stores personal information. Consent failures can create criminal exposure, while unauthorised disclosure can also raise reputational and litigation risk. Sector rules may add another layer for banking, fintech, insurance, telecom, health and education services.
A business should therefore review privacy notices, onboarding screens, KYC handling, vendor disclosures and internal access. NRB IT Guidelines may matter to BFIs, while NTA IT Policy 2080 may matter to telecom businesses. Tax records may involve the Inland Revenue Department, and health or education operators may need to check sector-specific guidance.
Businesses seeking practical compliance support can review Alpine's company compliance service. The service does not replace the authority of a regulator, court or government office, and no outcome or processing time is promised.
The IT and Cybersecurity Bill 2082 remains a pending proposal in the material supplied for this guide. It would replace the Electronic Transactions Act 2063 and address electronic records, digital signatures, cybercrime and data handling. Its proposed Clause 61 would require information about data use and destruction within 35 days after the purpose is fulfilled.
The supplied material records the Bill as registered in the House of Representatives on 10 June 2025 and tabled by the Communications Minister on 14 August 2025. The Ministry of Communication and Information Technology is identified as the lead ministry; its official website is the relevant government source for that ministry. The material describes the Bill as being in an amendment or public-comment phase.
| Issue | Current framework | Bill 2082 position |
|---|---|---|
| Data use | Consent framework applies | Individuals would receive data-use information |
| Digital statute | ETA 2063, including Section 47 | Would replace ETA 2063 |
| Destruction | No current general term identified | Clause 61 proposes 35 days after purpose fulfilment |
| Regulator | No dedicated data regulator | Not established in the supplied material |
| Breach notice | No statutory obligation identified | No rule identified in the supplied material |
A business review can map information, test consent, check disclosures and prepare for possible Bill 2082 changes. It is a compliance review rather than a government registration process. The supplied material does not identify one universal filing route, portal, approval or processing period for every business.
Nepal's supplied framework does not set one universal business document checklist or require every organisation to file the same privacy documents. A business should instead review the records that explain its data practices, consent, disclosures, retention and incident response, then verify any sector-specific requirement with the relevant authority.
A useful internal review set can include a privacy notice, consent wording, consent records, a personal-information map, disclosure records, vendor terms and an incident log. These are review materials, not a statement that every item must be submitted to a government office. Our team can help with drafting legal documents based on the business's facts.
Current Nepal law does not provide a single business-wide implementation timeline in the supplied material. The only specific destruction period is the proposed 35-day term in Clause 61 of the pending Bill. The material also gives no fixed data-protection registration or compliance charge, so businesses should verify current requirements and professional fees before acting.
Your total cost can depend on the number of systems, the sensitivity of the information, vendor arrangements, sector rules, incident history and the amount of legal drafting or review needed. A government charge, if an authority imposes one for a separate filing, is different from professional fees. Do not treat the proposed 35-day period as a current retention deadline.
Unlawful collection, disclosure or processing may attract up to 3 years' imprisonment and an NPR 30,000 fine under the Privacy Act 2075. Penal Code provisions and Electronic Transactions Act Section 47 may create additional exposure, depending on the conduct, the information involved and the charge selected.
| Provision | Conduct described in the supplied material | Maximum stated penalty |
|---|---|---|
| Privacy Act 2075 | Unlawful collection, disclosure or processing | 3 years and NPR 30,000 |
| Penal Code Section 293 | Unauthorised eavesdropping or recording | 2 years and NPR 20,000 |
| Penal Code Section 294 | Disclosure of professional confidential information | 1 year and NPR 10,000 |
| Penal Code Section 295 | Unauthorised photography | 1 year and NPR 10,000 |
| Penal Code Section 295 | Publication of disfigured or modified photographs | 2 years and NPR 20,000 |
| ETA Section 47 | Publication of illegal electronic material | 5 years and NPR 100,000 |
The Penal Code's privacy provisions run in parallel with the Privacy Act. The current material states that one unlawful disclosure may attract both routes, with the heavier penalty governing. Because the correct charge depends on facts, a business should not assume that every incident produces every listed penalty.
Nepal currently has no dedicated data-protection regulator and no statutory breach-notification obligation identified here. Criminal enforcement may proceed through the District Court, while Article 28 may support writ jurisdiction in the High Court or Supreme Court. NRB, NTA and IRD may matter for their respective sectoral information.
Businesses create avoidable risk when they treat cybersecurity as the whole privacy issue. The current framework also concerns consent, purpose, disclosure, professional confidentiality, photography, electronic publication and sector controls. A privacy policy alone cannot correct collection or sharing practices that do not match what the business tells people.
Consider an illustrative Nepal fintech that collects names, phone numbers, identity details, biometric information and financial information through an application. It shares some information with a service provider for KYC support. The business must examine consent, purpose, recipients, retention and sector rules rather than relying only on a general website notice.
If the service provider later discloses information outside the stated scope, the facts may raise Privacy Act, Penal Code and sectoral questions. The business should preserve records, identify the information affected and obtain legal advice. It should not assume that a statutory breach notice, a dedicated regulator or a fixed government response period exists, because the supplied material does not establish one.
A small online seller, a nonprofit, a telecom operator and a bank may all handle personal information, but their operational risks and sector rules differ. The Privacy Act's stated scope includes government, private and not-for-profit entities operating in Nepal; it does not create one identical compliance model for every organisation.
Cross-border handling is an unresolved edge case in the supplied material because no cross-border transfer rules are identified. A foreign company, NRN-linked business or Nepal service provider using overseas systems should verify the applicable position instead of assuming that foreign privacy law replaces Nepal requirements. E-commerce businesses should also consider the separate issues discussed in our guide to the E-commerce Act in Nepal.
In short: Nepal businesses should treat personal information as a legal compliance issue, not only a technology issue. Start with Article 28, the Privacy Act 2075, consent records and disclosure controls. Review criminal exposure and sector rules. Track the pending Bill 2082, but do not treat its proposed 35-day destruction term as current law.
Readers researching data protection Nepal often compare privacy duties with e-commerce, consumer, banking and document-related rules. These related Alpine guides provide context, but each topic has its own legal basis and should not be treated as a substitute for reviewing the facts of your business.
This article is general legal information, not advice on a particular data incident or business model. Contact Alpine Law Associates for a fact-specific review; our team can help you assess privacy practices and connect the work with company compliance support in Nepal.
Disclaimer:
This article is intended solely for informational purposes and should not be interpreted as legal advice, advertisement, solicitation, or personal communication from the firm or its members. Neither the firm nor its members assume any responsibility for actions taken based on the information contained herein.
-medium.webp)