Logo

Alpine Law Associates is the leading full-service law firm encompassing a wide range of legal practices located in Kathmandu, Nepal. It consists of a team of the country's best lawyers, each with expertise in their respective fields, tailored to meet clients' specific needs.

Office Address

Anamnagar-29, Kathmandu

Phone Number

+977 9841114443

Email Address

info@lawalpine.com

Privacy Laws in Nepal (2026): Privacy Act 2075 & Data Protection Guide
Table of Contents0sections

Privacy laws in Nepal begin with Article 28 of the Constitution of Nepal 2072 and operate mainly through the Individual Privacy Act 2075. The framework covers personal information, consent, authorised handling, rectification, complaints and criminal penalties. For a privacy-related offence, our criminal-law practice area explains the related legal route.

Key Takeaways

  • Article 28 makes privacy of the person, residence, property, documents and data, correspondence, and character or reputation inviolable, except according to law.
  • The Individual Privacy Act 2075 is Nepal’s principal statute for privacy and personal-data handling.
  • Its framework recognises authority approval, data-subject consent and the right to be informed.
  • Sections 23–28 address authorised handling, purpose, storage, disclosure, cross-border transfer and rectification.
  • A person may seek correction of inaccurate personal information under Section 28, with supporting evidence.
  • The current material states that a complaint should be filed in the District Court within three months of the incident.
  • The stated maximum consequence is up to three years’ imprisonment, a fine up to NPR 30,000 and compensation, subject to the applicable facts and legal process.
Figure 1 — Privacy-breach preparation checklist in Nepal
  • Incident recordWhat happened, when it happened and how the information was used or disclosed
  • Personal-information recordThe information, document or data connected with the complaint
  • Consent or notice material if it appliesWhether consent was requested, given, refused or explained
  • Correction evidence if it appliesWhy the personal information is inaccurate and what correction is sought
  • Authority communications if it appliesRequests, responses or notices exchanged with the institution or data handler

Source: Constitution of Nepal 2072, Article 28; Individual Privacy Act 2075, Sections 23-28

Figure 1 — This illustrative preparation checklist helps organise a privacy complaint; the supplied material does not establish one universal statutory document list, so verify requirements with the receiving authority.

What are the privacy laws in Nepal?

Privacy laws in Nepal combine a constitutional right with the Individual Privacy Act 2075 and sector-specific rules. Article 28 supplies the constitutional foundation. The Act gives that protection a statutory structure by addressing personal information, authorised handling, consent, information duties, rectification and criminal consequences. Sectoral laws may add duties for banking, telecom, health and electronic transactions.

The Constitution of Nepal 2072 does not treat privacy as only a technology issue. Its protection reaches the person, home, property, documents and data, correspondence, and character or reputation. That matters because a privacy dispute may concern a paper record, a phone message, a financial detail, a medical record, a database or a disclosure that harms reputation.

The Individual Privacy Act 2075 is often called the Privacy Act 2075 Nepal or the Individual Privacy Act 2018. It is the central, sector-neutral framework described in the supplied material. The Nepal Law Commission’s official portal is an appropriate place to verify the current statutory text before relying on a section in a live dispute.

Layer of protectionWhat it addressesWhy it matters
Constitution of Nepal 2072Protected areas of individual privacySets the fundamental-right foundation
Individual Privacy Act 2075Personal information, handling, consent and remediesProvides the main statutory framework
Sectoral laws and rulesBanking, telecom, health and electronic transactionsMay add duties or exceptions for a specific industry

This layered structure means that the same event can raise more than one legal question. A disclosure by a bank, for example, may require analysis under the Privacy Act and the applicable banking confidentiality rules. A digital intrusion may also raise an issue under the Electronic Transactions Act 2063. The correct route depends on the facts, the institution involved and the legal basis claimed for the disclosure.

What does Article 28 of the Constitution protect?

Article 28 of the Constitution of Nepal 2072 protects privacy relating to the person, residence, property, documents and data, correspondence, and character or reputation. It states that these interests are inviolable except in accordance with law. The qualification matters: a lawful intrusion may be treated differently from unauthorised access, use or disclosure.

  1. Person or body: This concerns information and interests closely connected with the individual, including bodily and personal matters.
  2. Residence: The protection reaches the home and residential sphere. A dispute may therefore involve conduct connected with premises or a person’s private living space.
  3. Property: Property information can include details connected with assets, ownership and financial affairs.
  4. Documents and data: This covers personal records and information held in written, electronic or database form.
  5. Correspondence: Letters, calls, messages, emails and similar communications may raise correspondence-privacy issues, depending on the facts.
  6. Character or reputation: Disclosure of private information may affect a person’s reputation. A related issue may also fall within Nepal’s defamation framework; see our Nepal defamation law guide.

Article 28 is not a promise that every private interest will remain undisclosed in every situation. The words “except in accordance with law” preserve the importance of lawful authority. A search, disclosure, surveillance measure or regulatory request must therefore be assessed against the legal power relied upon, its purpose and its limits.

That distinction is central to individual privacy Nepal disputes. The question is not simply whether information was seen or shared. You must ask who handled it, what authority existed, whether consent was obtained, why the information was used and whether the conduct stayed within the legal permission claimed.

What does the Privacy Act 2075 require?

The Individual Privacy Act 2075 structures privacy protection around authorised handling, consent and information duties. Public bodies, institutions and other data handlers must address how personal information is collected, stored, processed and published. The Act also recognises correction of inaccurate information and provides a criminal route for an established breach.

The three principles in the supplied material work together, but they are not identical:

  • Authority approval: An institution’s collection, storage, processing or publication of personal information should involve the prescribed competent authority or authorised person.
  • Data-subject consent: The person to whom the information relates has a role in deciding whether the information may be handled. The facts must show what was requested and what was agreed.
  • Right to be informed: The individual should be able to understand what information is held, who holds it, why it is used and how it is handled.

These principles should not be compressed into one broad rule. Consent does not automatically answer every authority question. Internal authorisation does not automatically prove the individual was informed. A legal power may also affect whether consent is required in a particular situation. The receiving body, court or regulator may assess the exact legal basis and the evidence.

What are the duties under Sections 23–28?

Sections 23–28 of the Privacy Act 2075 address core duties connected with personal information. The supplied material identifies authorised handling, purpose, storage and security, disclosure restrictions, cross-border transfer and rectification. The exact application depends on the data, the handler, the stated purpose and any lawful exception.

ProvisionSubjectPractical question
Section 23Authorised handlingWas collection, storage, processing or publication carried out by an authorised person or designated official?
Section 24Purpose of useWas the information used for the purpose for which it was collected, or was another legal basis relied upon?
Section 25Storage and securityWere reasonable measures used against unauthorised access, loss, alteration or disclosure?
Section 26DisclosureWas the information shared with consent, legal compulsion or an applicable statutory exception?
Section 27Cross-border transferWhat safeguards and consent issues arise when information is transferred outside Nepal?
Section 28RectificationCan inaccurate personal information be corrected using supporting evidence?

Businesses should not treat this table as a substitute for reviewing the statutory language. For example, a purpose question may differ from a disclosure question. A security incident may involve unauthorised access even where the original collection was lawful. A cross-border transfer may also involve contractual, regulatory or sector-specific issues not resolved by a general statement.

What rights does individual privacy law provide?

The Privacy Act 2075 gives a data subject practical interests alongside the constitutional right. The supplied material identifies consent, information, correction and protection against unauthorised handling. Under Section 28, a person may request rectification of inaccurate personal information by providing supporting evidence; the response and timing should be verified with the relevant handler or authority.

The right to rectification is narrower than a right to erase every record. It concerns inaccurate personal information and requires evidence supporting the proposed correction. A person should identify the disputed entry, explain why it is wrong and state the accurate information sought.

The right to be informed also requires careful wording. It does not mean every institution must answer every question in the same format. It means the individual’s position should be assessed against the information held, the purpose of handling, the institution’s authority and any legal restriction on disclosure.

Consent should be examined as evidence, not as a label. A general form may not answer what information was collected, why it was collected or whether later publication was covered. On the other hand, a disclosure may rely on legal authority rather than consent. That is why the source, purpose and legal basis must be reviewed together.

How should you respond to a privacy breach in Nepal?

Respond to a suspected privacy breach by preserving the facts, identifying the information and checking the legal basis for handling. The supplied material states that a complaint may be filed in the District Court within three months of the incident. Because this is a strict limitation statement, confirm the date and filing route promptly.

  1. Record the incident: Write down what happened, when you learned of it and who appears to have accessed, used or disclosed the information.
  2. Identify the protected interest: Decide whether the issue concerns the person, residence, property, documents or data, correspondence, or character and reputation.
  3. Preserve available evidence: Keep relevant notices, messages, records, screenshots, correspondence and responses in their original form where possible. Do not alter material while trying to improve it.
  4. Ask what legal basis was used: Consider authority approval, consent, the stated purpose and any claimed statutory exception.
  5. Consider rectification: If the information is inaccurate, prepare the correction request and supporting evidence contemplated by Section 28.
  6. Check limitation immediately: If a complaint is being considered, calculate the three-month period from the incident and verify the District Court filing requirements with the receiving authority.

This is a legal-response sequence, not a promise that every complaint follows identical administrative steps. The receiving court or authority can require a particular format, evidence or procedural act. Verify those requirements before filing. If the facts suggest a criminal offence, the complaint may need a separate assessment under related criminal or cyber laws.

What evidence or documents should you prepare?

No universal document list is established in the supplied material for every privacy complaint. Prepare material that shows the incident, the information involved, the consent or authority relied upon, the harm or inaccuracy and your requested remedy. Verify the receiving authority’s current filing requirements before submitting originals or copies.

A practical preparation file may contain the following categories:

  • A clear chronology of the event and the date it occurred.
  • The personal information, record, message or disclosure connected with the complaint.
  • Any privacy notice, consent language, authorisation, contract or institutional response available to you.
  • Evidence showing why information is inaccurate if rectification is requested.
  • Communications showing that you raised the concern and how the institution responded.
  • Material supporting compensation or other relief, where the facts permit such a claim.

Do not assume that more material is always better. Sensitive data can create a second privacy risk if circulated widely. Share relevant material through a secure and legally appropriate channel. If you are unsure whether a document is privileged, confidential or safe to disclose, obtain legal advice before sending it.

How long do you have to complain about a privacy breach?

The supplied material states that a privacy complaint should be filed in the District Court within three months of the incident. Treat that period as urgent rather than waiting for internal correspondence to continue indefinitely. The exact start date, exceptions and filing requirements should be verified with the court or a lawyer.

A limitation period is different from the time needed to investigate a complaint. Gathering evidence does not automatically extend the period. Nor should a person assume that a later discovery always changes the legal starting date. Those questions depend on the facts and the applicable procedural rule.

If the incident involves several disclosures or continuing conduct, identify each relevant event and obtain advice without delay. Keep a written record of dates. This protects against confusion and helps counsel assess whether a claim remains within time.

What penalties can a privacy breach attract?

The supplied material states that a proven privacy breach may attract up to three years’ imprisonment, a fine up to NPR 30,000 and compensation. These are stated maximum consequences, not an automatic sentence. The actual result depends on the offence proved, the evidence, the applicable provision and the court’s assessment.

Figure 2 — Possible privacy breach consequences in NepalThis graduated graphic shows the possible consequences stated in the supplied material: a privacy breach may involve a fine, imprisonment up to three years and compensation. It is not a sentencing prediction.Figure 2 — Privacy breach consequencesThe Act’s stated maximums are not an automatic outcome.Breach assessedAct and evidenceFineUp to NPR 30,000ImprisonmentUp to 3 yearsTrigger: unlawful conductTrigger: penalty provedTrigger: statutory maximumCompensation may also arise where the legal and factual basis is established.
Figure 2 — The Privacy Act 2075 framework described here includes a fine up to NPR 30,000, imprisonment up to three years and compensation; the court determines the result.

Compensation is not the same as the criminal fine. A fine is a penal consequence. Compensation concerns the loss or injury recognised by the applicable legal process. The amount and availability of compensation cannot be predicted from the maximum fine alone.

How do sectoral laws affect data protection in Nepal?

Data protection Nepal is not limited to one statute. The supplied framework includes the Electronic Transactions Act 2063 for cyber-related privacy and data offences, banking confidentiality duties, telecom rules, health-related protections and the E-Commerce Act 2081. The relevant sector may change the legal basis, regulator, evidence and response route.

A bank or financial institution may hold financial and identity information under duties different from those applying to an ordinary business. Telecom information may involve subscriber records and communications. Health information can raise a heightened confidentiality concern. An online business may need to consider consumer-data obligations under the E-Commerce Act 2081.

The existence of a sectoral rule does not automatically remove the Privacy Act from consideration. It may add a duty, create an exception or provide a separate complaint route. Review the institution’s industry, the data type and the conduct complained of before selecting a remedy.

Pending or proposed technology legislation should not be treated as current law without verification. The data protection bill guide can help you separate discussion of proposed reform from the statute currently relied upon.

What should a Nepal business do about personal data?

A Nepal business should map the personal information it handles, identify the purpose, control access and document consent or lawful authority. Sections 23–28 provide the key statutory questions. The business should also consider sectoral duties, cross-border transfers, correction requests and the possibility that an incident may create criminal and compensation exposure.

Start with a simple information map. List the categories of personal information, the people who can access it, the reason it is collected and the places where it is stored. Then identify who is authorised to handle it. This makes the Section 23 question practical rather than theoretical.

Next, review notices and consent language. A person should be able to understand what is collected and why. If a new use is unrelated to the original purpose, obtain advice before relying on the old collection process. Marketing, publication and sharing with another institution deserve separate attention.

Security controls should match the information and the risk. Limit access, preserve records of important decisions and create a response plan for suspected disclosure. The supplied material does not establish one technical standard for every business. Verify sector-specific requirements with the relevant authority.

For corporate implementation, our team can help assess legal documents, internal policies and responses to a suspected breach. That assistance is legal advice for the particular facts; it is not a government certification or a promise that a complaint or defence will succeed.

What alternatives and edge cases should you consider?

Privacy disputes may involve more than a District Court complaint. A correction request, sectoral complaint, criminal case, compensation claim or constitutional remedy may be relevant depending on the conduct. A lawful disclosure, foreign transfer, public-body request or inaccurate record can each change the analysis, so no single remedy fits every case.

  • Lawful authority: Article 28 permits the possibility of action authorised by law. Ask what law, order or statutory power supports the intrusion.
  • Public bodies: Handling by a government body may involve statutory authority, official duties and restrictions on disclosure. Do not assume that public status makes every use lawful.
  • Cross-border transfer: Transfer outside Nepal raises consent and safeguard questions. The relevant institution and sector may impose additional requirements.
  • Incorrect information: Section 28 may be more directly relevant than a disclosure claim where the central problem is an inaccurate record.
  • Reputation harm: A disclosure may also raise defamation or other civil or criminal issues. The facts must be separated rather than placed under one label.
  • Foreign nationals and NRNs: The same constitutional and statutory framework may be relevant, but jurisdiction, location of the handler and cross-border evidence can affect the practical route.
Figure 3 — Which privacy-law route may apply in Nepal?A decision tree asks whether the conduct concerns protected privacy, whether consent or legal authority exists, and whether the information is inaccurate. The outcomes direct the reader to verify the legal route.Figure 3 — Choose the next privacy-law questionProtected privacy?Person, data or correspondenceNoCheck otherlegal routesYesConsent or legalauthority shown?NoPreserve factsand assess breachYesReview purpose and scopeInformation wrong?ConsiderSection 28
Figure 3 — This decision tree separates protected privacy, lawful authority, inaccurate information and the possible Section 28 rectification route.

What are common privacy-law mistakes?

Common mistakes include missing the three-month complaint period, treating consent as a complete defence, assuming public bodies can disclose freely, and mixing an inaccurate-record claim with a disclosure claim. Another mistake is relying on a blog summary without checking the Act, the relevant section and the current receiving authority.

Do not publish private information merely because it is already circulating. Earlier disclosure does not automatically prove that a later disclosure was lawful. Do not delete records after an incident, either. Preserve relevant material and obtain advice on retention, confidentiality and response.

Businesses should also avoid copying foreign data-protection templates without checking Nepal’s legal terms. A policy may use words such as “controller,” “processor” or “data subject,” but the legal effect depends on the Nepal statute, the institution and the sector involved.

What does privacy-law compliance cost?

The total cost of addressing a privacy issue depends on the facts, the amount of information, the number of people or institutions involved, the forum and whether advice, drafting, negotiation or litigation is required. Government charges and professional fees are separate matters. Verify any current government charge with the receiving authority and contact us for a current professional estimate.

A simple correction request may require a different level of work from a contested criminal complaint, constitutional proceeding or business-wide compliance review. Cross-border evidence, sectoral regulation and urgent limitation issues can also increase the work involved.

Alpine Law Associates advises and represents clients; it is not the court, regulator or government office. Our team can help you assess a suspected breach, prepare a legal response, review business privacy documents or consider litigation. We cannot promise registration, a decision, a processing time or a particular outcome.

In short: Nepal’s privacy framework starts with Article 28 and is developed through the Individual Privacy Act 2075. Identify the protected interest, authority, consent, purpose and evidence. If a complaint is being considered, treat the stated three-month District Court period as urgent and verify the current filing position.

People also search for

If you need advice about privacy laws in Nepal, personal data, a suspected disclosure or a business compliance issue, contact Alpine Law Associates. Our team can also assist through company compliance services in Nepal, subject to reviewing your facts and the current law.

Frequently Asked Questions

Privacy law in Nepal requires careful checking of the legal issue involved. The supplied sources do not establish one complete, single privacy code or settle every data-use question. The answer may depend on the facts, the people involved, and the relevant sector. For case-specific advice, contact Alpine Law Associates.

The materials supplied for this article do not provide the exact constitutional wording or article number needed to answer this safely. A privacy claim may require checking the Constitution together with other applicable Nepal laws. Do not rely on a general online summary where your facts involve surveillance, disclosure, or personal harm.

The supplied materials refer to a Nepal data-protection bill article, but they do not confirm the current enacted status, final wording, or commencement of a Personal Data Protection Act. A bill, proposal, or draft should not be treated as binding law without verification. Check the current position with a Nepali lawyer.

The available grounding does not confirm whether the referenced Data Protection Bill has become an enacted and effective law in Nepal. Its status, final provisions, and commencement date must be verified from an authoritative current source. Businesses should avoid claiming compliance with a bill until that legal status is confirmed.

Whether a company may collect customer data in Nepal depends on the purpose, type of information, collection method, notice or consent, retention, disclosure, and any sector-specific rule. The supplied materials do not settle those requirements. A business should obtain tailored advice before launching a data-collection system or sharing customer information.

Consent may be important, but the supplied materials do not identify a confirmed Nepal rule stating when consent is always required, what form it must take, or what exceptions apply. The answer can change with the information, purpose, relationship, and sector. Obtain legal review before relying on consent alone.

CCTV legality in Nepal depends on where cameras operate, their purpose, who is recorded, notices, access to footage, retention, and disclosure. The supplied sources do not provide a definitive rule covering every situation. Recording in a private or sensitive setting creates greater legal risk and should be reviewed before installation.

Sharing private photographs, messages, or other personal material may create legal consequences, but the supplied materials do not identify the exact offence, civil remedy, or required proof for every situation. Preserve the original files, messages, account details, and dates. If the disclosure caused harm, seek prompt advice through /contact-us.

If personal data is leaked, preserve evidence before deleting accounts or messages. Record what was exposed, when you learned of it, where it appeared, and who may have accessed it. The supplied materials do not establish one universal Nepal reporting route or deadline, so obtain advice based on the incident.

Employee monitoring in Nepal depends on the monitoring method, workplace policy, notice, purpose, information collected, and the employment relationship. The supplied materials do not confirm a single rule authorising or prohibiting every form of monitoring. Employers and employees should obtain advice before using monitoring software, recording communications, or disclosing workplace data.

Medical records and banking information are sensitive in practical terms, but the supplied materials do not provide the specific Nepal provisions governing their collection, access, disclosure, retention, or misuse. The applicable answer may depend on the institution and transaction. Do not publish or transfer such information without checking the relevant legal duties.

You may have a complaint or legal remedy, but the correct authority and procedure depend on what happened, who handled the information, and whether the issue involves civil, criminal, cyber, employment, or sector regulation. The supplied materials do not identify a universal privacy complaint office or deadline. Contact Alpine Law Associates for guidance.

Children’s privacy requires particular care, but the supplied materials do not state the exact Nepal consent, disclosure, publication, or safeguarding requirements that apply to every child-data situation. The facts matter, including the child’s age, the information, and the person using it. Obtain advice before publishing or sharing identifying details.

Foreign nationals and Non-Resident Nepalis may face different practical issues when information is collected in Nepal, transferred abroad, or used by a foreign organisation. The supplied materials do not establish the territorial rules for every case. The answer depends on the parties, data location, purpose, and applicable Nepal procedure.

A Nepali lawyer can first identify the conduct, information, parties, and possible legal routes, then verify the current statutes and procedures that apply. This is especially important because the supplied materials do not settle every privacy question. Alpine Law Associates can assess the situation through /contact-us without assuming a guaranteed outcome.

Disclaimer:
This article is intended solely for informational purposes and should not be interpreted as legal advice, advertisement, solicitation, or personal communication from the firm or its members. Neither the firm nor its members assume any responsibility for actions taken based on the information contained herein.

Chat on WhatsApp