Proposed amendments to the Cyber Protection Act 2026: Propelling to a legislative debacle
The proposed amendments to the Cyber Protection Act 2026 aim to tackle cyberbullying, disinformation, AI-generated abuse and other online harms. Yet the draft raises a crucial question: How far should the state be allowed to regulate speech under the guise of digital security?

Proposed amendments to the Cyber Protection Act 2026; propelling to a legislative debacle
By Barrister Nazifa Sarwar (Associate), Avon Chambers
The proposed amendments to the Cyber Protection Act 2026 aim to tackle illegal online activities such as confronting cyberbullying, disinformation, AI-generated abuse and other emerging online harms.However, in the process, the draft sheds light upon a crucial question in Bangladesh’s cyber-law history: How far should the State be allowed to influence and regulate speech under the guise of digital security?
Introduction
Bangladesh’s cyber-law framework has changed repeatedly in less than a decade. For instance, the Digital Security Act 2018 was replaced by the Cyber Security Act 2023, followed by the Cyber Protection Ordinance 2025 and, ultimately, the Cyber Protection Act 2026. The 2025 reform was rather crucial since its preamble reflected upon the previous regime and the inadequate safeguards it possessed for citizens and how it created opportunities for misuse.
Recently, our Parliament enacted the Cyber Protection Act 2026 (hereinafter referred to as the ‘Act’), on 10 April 2026 and the Act repealed and substantially re-enacted the 2025 Ordinance and is deemed to have taken effect from 21 May 2025. It is now the subject of several proposed reforms, some of which have drawn the attention of practitioners and academics for the reasons discussed below.
What does the Cyber Protection Act seek to do?
The fact that Bangladesh needs effective cyber legislation for protecting individuals, institutions and financial systems from illegal and harmful online activities is not debatable. The primary purpose of the Act is securing cyber protection for the nation collectively and facilitating detection, prevention, suppression and trial of offences occurring in cyberspace.
This Act’s institutional structure includes the National Cyber Protection Agency, arrangements for cyber-response infrastructure, regulation of critical information, digital forensic mechanisms and offenses relating to unlawful access, hacking, cyber fraud, deception even unauthorised electronic transactions. The Act is also notably technologically savvy in the sense that its definitions expressly recognise artificial intelligence, machine learning, blockchain, and other emerging technologies.
What are the proposed amendments trying to address?
The latest draft amendments seek to respond to a rapidly changing digital environment. The underlying concerns expressed by the government are legitimate. For example, artificial intelligence now enables convincing fake photographs, audio and video to be produced almost instantly while cyberbullying can be persistent and anonymous. Additionally, non-consensual intimate material can spread rapidly, while deliberately fabricated information may cause serious harm to individuals, organisations and public order.
The main difficulty lies in determining whether the proposed legal mechanisms are sufficiently precise and proportionate.
Why are the proposed amendments problematic?
Section 8: Emergency intervention and Broad Control Powers
Under the existing section 8(2) of the Act, certain powers to remove, transfer or block information rest principally with law-enforcement agencies where specified threats to national security, public order or communal harmony arise. On the contrary, the proposed amendment materially expands both, the authorities entitled to act and the grounds upon which intervention may occur.
This highlights to distinct expansions; the first is institutional meaning more authorities may exercise coercive content-control powers and the second is substantive meaning the threshold moves in places from actual or proven harm towards a prediction of future harm. It is understandable that preventive powers are sometimes necessary so that a government should not always have to wait for violence or a serious cyber threat to materialise before intervening. However, the broader a preventive power is, the more precisely its threshold must be defined, particularly where the power may be exercised before any harm has occurred.
The draft becomes increasingly concerning when read with the proposed amendment to section 8(4). At present, where information is removed or blocked, permission from the relevant tribunal must be obtained within three days. Without that permission, the restriction must be lifted. The proposed amendment would instead require the aggrieved person to approach the relevant authority or court seeking release of the restriction.
Consequently, this alters the burden of accountability. While the present law requires the relevant authority who is interfering with the information to bear the burden of obtaining swift judicial approval, the proposed amendment would reverse the burden and require the impacted individual to take prompt proceedings, incur the time and expenses of seeking a remedy regarding the release of the restriction. This element may further give rise to an additional practical issue since the requirement of hearing the government or aggrieved party before an application can be disposed off could make obtaining immediate relief less certain in cases where urgent orders may be sought. A stronger approach would preserve emergency blocking powers while retaining mandatory and prompt judicial review.
Section 12: Removal of the National Human Rights Commission
The draft also proposes removing the Chairman of the National Human Rights Commission from the National Cyber Protection Council and intends to replace the Chairman with multiple executive office holders. This would eliminate one of the few existing mechanisms for weighing individual rights against the operation of the law. Rather than removing independent representation, the Council should be strengthened through greater participation by human-rights, cybersecurity, legal and digital-policy experts.
Section 25: Three Distinct Harms
The existing provision under Section 25 of the Act primary deals with sexual harassment, blackmail, revenge pornography, child sexual-abuse material and sextortion. The amendment would further add defamation, degrading conduct and bullying, while increasing the ordinary maximum punishment from two to five years and/or Tk 20 lakh as fine and the enhanced punishment concerning women or children from five to ten years and/or Tk 40 lakh as fine.
The concern here is partly one of legislative structure. Revenge pornography and child sexual-abuse material concern sexual autonomy, exploitation and privacy. Defamation protects reputation. Bullying concerns repeated targeted conduct and psychological harm. These offences may overlap, but they do not necessarily require identical ingredients, defences or sentencing structures.
The proposed definition of defamation also refers to section 499 of the Penal Code 1860 but also expands the concept to various forms of false, misleading, humiliating or harmful digital content. Further, the draft does not precisely clarify how the traditional exceptions and protections contained in section 499 would operate across the newly expanded offence, creating room for uncertainty and inconsistent application.
Section 26A: Misinformation
The proposed section 26A introduces a new offence of disseminating “rumour” or “disinformation” in cyberspace, punishable by up to ten years’ imprisonment or a fine of Tk 40 lakh.
The distinction between the two definitions is important. “Disinformation” requires intentionally created or disseminated false or misleading information designed to deceive or cause harm. “Rumour”, however, extends to unsupported or unverified information capable of causing confusion, panic, excitement or social instability. The underlying overlap between the two creates an obvious difficulty. Information may be true even before it has been formally verified. Breaking news, eyewitness accounts and developing events frequently involve uncertainty.
Criminal law should distinguish deliberate fabrication from reasonable mistake, incomplete reporting and genuinely uncertain information. A more defensible provision would require falsity, knowledge of falsity and an intention to produce clearly defined serious harm.
Section 29: Corporate sanctions
The proposed amendment to section 29 would allow courts, following conviction, to suspend or cancel a company’s registration or licence, or prohibit its activities, imposing a rather draconian punishment. As drafted, the provision does not confine this punishment to entities whose continued operation is itself incompatible with the law, leaving corporate bodies generally exposed to drastic consequences.
Such powers may be justified in extreme cases, but corporate closure affects employees, creditors, shareholders and customers who may have were not involved in the offence. These sanctions should therefore be governed by express proportionality criteria.
Section 41: Cyber Offences and Mobile Courts
The draft also shuffles jurisdiction under section 41. Serious, specified offences, including sections 17, 18, 23, 24, 25(3) and 26A, remain with the Cyber Tribunal, while other offences may be tried by First Class Magistrates and potentially by Mobile Courts where included in the Schedule to the Mobile Court Act 2009.
This raises institutional concerns. Cyber offences often depend on technical evidence involving metadata, account attribution, device ownership, artificial intelligence and digital forensics. Such disputes are generally better suited to judicial proceedings capable of receiving expert evidence and determining contested questions of intention and authorship.
A more defensible way forward
The proposed amendments do not need to be entirely abandoned to solve the concerns discussed above. Majority of their objectives can be achieved and preserved through stricter safeguards and more precise drafting. A revised bill could-
- Retain a narrow emergency content-removal power while restoring mandatory judicial supervision and section 8 should specify seriousness, imminence and causal connection to the protected harm; every emergency blocking decision should require written reasons and prompt judicial confirmation. The present three-day review could be retained, with express provision for urgent interim relief in case of emergencies.
- Limit who may exercise coercive content powers. Rather than allowing an open-ended category of government-authorised agencies, responsibility should rest with specifically designated, technically competent authorities whose decisions are documented, reviewable and subject to statutory and judicial accountability.
- Retain independent representation on the National Cyber Protection Council. The National Human Rights Commission should remain represented, alongside meaningful independent technical, legal and digital-rights expertise.
- Separate section 25 into conceptually coherent and distinct offences without underlying overlaps. Sexual exploitation, revenge pornography, CSAM, sextortion and blackmail should remain strongly criminalised. Cyberbullying can be separately defined around repeated targeted conduct causing or intended to cause serious harm. Defamation should not simply be grafted onto the same offence and penalty structure.
- Rewrite section 26A around deliberate harmful falsehood, not mere uncertainty. Criminal liability should require materially false information, knowledge of falsity, and intention, or at least clearly defined recklessness, as to a specified serious harm. Opinion, satire, parody, reasonable error and good-faith public-interest reporting should be excluded. Ten years' imprisonment should be reconsidered against the seriousness of the conduct actually committed.
- Confine corporate shutdown sanctions to exceptional cases. Cancellation of registration, licensing or operations should require findings as to seriousness, management involvement, recurrence, proportionality and the effect on innocent stakeholders, with lesser sanctions available first.
Conclusion
Bangladesh requires a system where both cyber protection and freedom of expression can coexist efficiently. There remains an urgent need for modernising the law to address AI-generated abuse, harmful online content, online fraud and smear campaigns, however there is an equally strong case for ensuring that the tools designed to address those harms cannot casually be applied to simple mistakes, controversial or different opinions, digital journalism, satire, criticism or one’s exercise of their constitutional rights under Article 39 as a Bangladeshi citizen.
While the present draft identifies a plethora of problems that require legislative remedy, its next revision should be attentive towards a proper structure which will help address the deficiencies. Security may justify power however, in a constitutional system, power requires limits.
This article provides general information and does not constitute legal advice. Legal outcomes depend on the facts and applicable law. Seek advice about your specific circumstances.

