Succession Law in Nepal 2026: Inheritance, Wills & Partition
A 2026 (2083 BS) practitioner's guide to succession and inheritance in Nepal under the National Civil Code 207...
Read more →Alpine Law Associates is the leading full-service law firm encompassing a wide range of legal practices located in Kathmandu, Nepal. It consists of a team of the country's best lawyers, each with expertise in their respective fields, tailored to meet clients' specific needs.
Anamnagar-29, Kathmandu
Privacy laws in Nepal begin with Article 28 of the Constitution of Nepal 2072 and operate mainly through the Individual Privacy Act 2075. The framework covers personal information, consent, authorised handling, rectification, complaints and criminal penalties. For a privacy-related offence, our criminal-law practice area explains the related legal route.
Source: Constitution of Nepal 2072, Article 28; Individual Privacy Act 2075, Sections 23-28
Figure 1 — This illustrative preparation checklist helps organise a privacy complaint; the supplied material does not establish one universal statutory document list, so verify requirements with the receiving authority.
Privacy laws in Nepal combine a constitutional right with the Individual Privacy Act 2075 and sector-specific rules. Article 28 supplies the constitutional foundation. The Act gives that protection a statutory structure by addressing personal information, authorised handling, consent, information duties, rectification and criminal consequences. Sectoral laws may add duties for banking, telecom, health and electronic transactions.
The Constitution of Nepal 2072 does not treat privacy as only a technology issue. Its protection reaches the person, home, property, documents and data, correspondence, and character or reputation. That matters because a privacy dispute may concern a paper record, a phone message, a financial detail, a medical record, a database or a disclosure that harms reputation.
The Individual Privacy Act 2075 is often called the Privacy Act 2075 Nepal or the Individual Privacy Act 2018. It is the central, sector-neutral framework described in the supplied material. The Nepal Law Commission’s official portal is an appropriate place to verify the current statutory text before relying on a section in a live dispute.
| Layer of protection | What it addresses | Why it matters |
|---|---|---|
| Constitution of Nepal 2072 | Protected areas of individual privacy | Sets the fundamental-right foundation |
| Individual Privacy Act 2075 | Personal information, handling, consent and remedies | Provides the main statutory framework |
| Sectoral laws and rules | Banking, telecom, health and electronic transactions | May add duties or exceptions for a specific industry |
This layered structure means that the same event can raise more than one legal question. A disclosure by a bank, for example, may require analysis under the Privacy Act and the applicable banking confidentiality rules. A digital intrusion may also raise an issue under the Electronic Transactions Act 2063. The correct route depends on the facts, the institution involved and the legal basis claimed for the disclosure.
Article 28 of the Constitution of Nepal 2072 protects privacy relating to the person, residence, property, documents and data, correspondence, and character or reputation. It states that these interests are inviolable except in accordance with law. The qualification matters: a lawful intrusion may be treated differently from unauthorised access, use or disclosure.
Article 28 is not a promise that every private interest will remain undisclosed in every situation. The words “except in accordance with law” preserve the importance of lawful authority. A search, disclosure, surveillance measure or regulatory request must therefore be assessed against the legal power relied upon, its purpose and its limits.
That distinction is central to individual privacy Nepal disputes. The question is not simply whether information was seen or shared. You must ask who handled it, what authority existed, whether consent was obtained, why the information was used and whether the conduct stayed within the legal permission claimed.
The Individual Privacy Act 2075 structures privacy protection around authorised handling, consent and information duties. Public bodies, institutions and other data handlers must address how personal information is collected, stored, processed and published. The Act also recognises correction of inaccurate information and provides a criminal route for an established breach.
The three principles in the supplied material work together, but they are not identical:
These principles should not be compressed into one broad rule. Consent does not automatically answer every authority question. Internal authorisation does not automatically prove the individual was informed. A legal power may also affect whether consent is required in a particular situation. The receiving body, court or regulator may assess the exact legal basis and the evidence.
Sections 23–28 of the Privacy Act 2075 address core duties connected with personal information. The supplied material identifies authorised handling, purpose, storage and security, disclosure restrictions, cross-border transfer and rectification. The exact application depends on the data, the handler, the stated purpose and any lawful exception.
| Provision | Subject | Practical question |
|---|---|---|
| Section 23 | Authorised handling | Was collection, storage, processing or publication carried out by an authorised person or designated official? |
| Section 24 | Purpose of use | Was the information used for the purpose for which it was collected, or was another legal basis relied upon? |
| Section 25 | Storage and security | Were reasonable measures used against unauthorised access, loss, alteration or disclosure? |
| Section 26 | Disclosure | Was the information shared with consent, legal compulsion or an applicable statutory exception? |
| Section 27 | Cross-border transfer | What safeguards and consent issues arise when information is transferred outside Nepal? |
| Section 28 | Rectification | Can inaccurate personal information be corrected using supporting evidence? |
Businesses should not treat this table as a substitute for reviewing the statutory language. For example, a purpose question may differ from a disclosure question. A security incident may involve unauthorised access even where the original collection was lawful. A cross-border transfer may also involve contractual, regulatory or sector-specific issues not resolved by a general statement.
The Privacy Act 2075 gives a data subject practical interests alongside the constitutional right. The supplied material identifies consent, information, correction and protection against unauthorised handling. Under Section 28, a person may request rectification of inaccurate personal information by providing supporting evidence; the response and timing should be verified with the relevant handler or authority.
The right to rectification is narrower than a right to erase every record. It concerns inaccurate personal information and requires evidence supporting the proposed correction. A person should identify the disputed entry, explain why it is wrong and state the accurate information sought.
The right to be informed also requires careful wording. It does not mean every institution must answer every question in the same format. It means the individual’s position should be assessed against the information held, the purpose of handling, the institution’s authority and any legal restriction on disclosure.
Consent should be examined as evidence, not as a label. A general form may not answer what information was collected, why it was collected or whether later publication was covered. On the other hand, a disclosure may rely on legal authority rather than consent. That is why the source, purpose and legal basis must be reviewed together.
Respond to a suspected privacy breach by preserving the facts, identifying the information and checking the legal basis for handling. The supplied material states that a complaint may be filed in the District Court within three months of the incident. Because this is a strict limitation statement, confirm the date and filing route promptly.
This is a legal-response sequence, not a promise that every complaint follows identical administrative steps. The receiving court or authority can require a particular format, evidence or procedural act. Verify those requirements before filing. If the facts suggest a criminal offence, the complaint may need a separate assessment under related criminal or cyber laws.
No universal document list is established in the supplied material for every privacy complaint. Prepare material that shows the incident, the information involved, the consent or authority relied upon, the harm or inaccuracy and your requested remedy. Verify the receiving authority’s current filing requirements before submitting originals or copies.
A practical preparation file may contain the following categories:
Do not assume that more material is always better. Sensitive data can create a second privacy risk if circulated widely. Share relevant material through a secure and legally appropriate channel. If you are unsure whether a document is privileged, confidential or safe to disclose, obtain legal advice before sending it.
The supplied material states that a privacy complaint should be filed in the District Court within three months of the incident. Treat that period as urgent rather than waiting for internal correspondence to continue indefinitely. The exact start date, exceptions and filing requirements should be verified with the court or a lawyer.
A limitation period is different from the time needed to investigate a complaint. Gathering evidence does not automatically extend the period. Nor should a person assume that a later discovery always changes the legal starting date. Those questions depend on the facts and the applicable procedural rule.
If the incident involves several disclosures or continuing conduct, identify each relevant event and obtain advice without delay. Keep a written record of dates. This protects against confusion and helps counsel assess whether a claim remains within time.
The supplied material states that a proven privacy breach may attract up to three years’ imprisonment, a fine up to NPR 30,000 and compensation. These are stated maximum consequences, not an automatic sentence. The actual result depends on the offence proved, the evidence, the applicable provision and the court’s assessment.
Compensation is not the same as the criminal fine. A fine is a penal consequence. Compensation concerns the loss or injury recognised by the applicable legal process. The amount and availability of compensation cannot be predicted from the maximum fine alone.
Data protection Nepal is not limited to one statute. The supplied framework includes the Electronic Transactions Act 2063 for cyber-related privacy and data offences, banking confidentiality duties, telecom rules, health-related protections and the E-Commerce Act 2081. The relevant sector may change the legal basis, regulator, evidence and response route.
A bank or financial institution may hold financial and identity information under duties different from those applying to an ordinary business. Telecom information may involve subscriber records and communications. Health information can raise a heightened confidentiality concern. An online business may need to consider consumer-data obligations under the E-Commerce Act 2081.
The existence of a sectoral rule does not automatically remove the Privacy Act from consideration. It may add a duty, create an exception or provide a separate complaint route. Review the institution’s industry, the data type and the conduct complained of before selecting a remedy.
Pending or proposed technology legislation should not be treated as current law without verification. The data protection bill guide can help you separate discussion of proposed reform from the statute currently relied upon.
A Nepal business should map the personal information it handles, identify the purpose, control access and document consent or lawful authority. Sections 23–28 provide the key statutory questions. The business should also consider sectoral duties, cross-border transfers, correction requests and the possibility that an incident may create criminal and compensation exposure.
Start with a simple information map. List the categories of personal information, the people who can access it, the reason it is collected and the places where it is stored. Then identify who is authorised to handle it. This makes the Section 23 question practical rather than theoretical.
Next, review notices and consent language. A person should be able to understand what is collected and why. If a new use is unrelated to the original purpose, obtain advice before relying on the old collection process. Marketing, publication and sharing with another institution deserve separate attention.
Security controls should match the information and the risk. Limit access, preserve records of important decisions and create a response plan for suspected disclosure. The supplied material does not establish one technical standard for every business. Verify sector-specific requirements with the relevant authority.
For corporate implementation, our team can help assess legal documents, internal policies and responses to a suspected breach. That assistance is legal advice for the particular facts; it is not a government certification or a promise that a complaint or defence will succeed.
Privacy disputes may involve more than a District Court complaint. A correction request, sectoral complaint, criminal case, compensation claim or constitutional remedy may be relevant depending on the conduct. A lawful disclosure, foreign transfer, public-body request or inaccurate record can each change the analysis, so no single remedy fits every case.
Common mistakes include missing the three-month complaint period, treating consent as a complete defence, assuming public bodies can disclose freely, and mixing an inaccurate-record claim with a disclosure claim. Another mistake is relying on a blog summary without checking the Act, the relevant section and the current receiving authority.
Do not publish private information merely because it is already circulating. Earlier disclosure does not automatically prove that a later disclosure was lawful. Do not delete records after an incident, either. Preserve relevant material and obtain advice on retention, confidentiality and response.
Businesses should also avoid copying foreign data-protection templates without checking Nepal’s legal terms. A policy may use words such as “controller,” “processor” or “data subject,” but the legal effect depends on the Nepal statute, the institution and the sector involved.
The total cost of addressing a privacy issue depends on the facts, the amount of information, the number of people or institutions involved, the forum and whether advice, drafting, negotiation or litigation is required. Government charges and professional fees are separate matters. Verify any current government charge with the receiving authority and contact us for a current professional estimate.
A simple correction request may require a different level of work from a contested criminal complaint, constitutional proceeding or business-wide compliance review. Cross-border evidence, sectoral regulation and urgent limitation issues can also increase the work involved.
Alpine Law Associates advises and represents clients; it is not the court, regulator or government office. Our team can help you assess a suspected breach, prepare a legal response, review business privacy documents or consider litigation. We cannot promise registration, a decision, a processing time or a particular outcome.
In short: Nepal’s privacy framework starts with Article 28 and is developed through the Individual Privacy Act 2075. Identify the protected interest, authority, consent, purpose and evidence. If a complaint is being considered, treat the stated three-month District Court period as urgent and verify the current filing position.
If you need advice about privacy laws in Nepal, personal data, a suspected disclosure or a business compliance issue, contact Alpine Law Associates. Our team can also assist through company compliance services in Nepal, subject to reviewing your facts and the current law.
Disclaimer:
This article is intended solely for informational purposes and should not be interpreted as legal advice, advertisement, solicitation, or personal communication from the firm or its members. Neither the firm nor its members assume any responsibility for actions taken based on the information contained herein.
-medium.webp)