A Conversation About the Data Privacy Act
A reconstructed dialogue with a CIO who is reading the Act for the first time — what they ask, what I answer, and where the reading turns operational.
This conversation is a composite of three I have had with three different CIOs across BFSI, retail, and SaaS in the past six months. The questions recur; the answers do too. I have set them down here in roughly the order they get asked. Where the answer required a digression into a related international privacy regime, I have kept the digression because the international context is exactly what helps the Bangladeshi reader place the Act inside a frame they can use.
“My head is reasonably full. Where do I actually start?”
You start with a data-flow map. Not a spreadsheet of systems — a diagram, end-to-end, for the three highest-volume personal-data categories in your business. Where it enters, where it processes, where it stores, where it backs up, where it leaves, and which third parties touch it on the way through. Without that artefact, every other conversation is theoretical. And by third parties, I mean every SaaS subprocessor, every analytics service, every help-desk vendor, every backup integration. These are exactly the entities the regulator’s first information request will name.
“Does this force me into a sovereign cloud?”
The Act does not force you into one. It does make the compliance story considerably simpler when you use one — locality, residency, and sovereignty alignments fall out of the deployment model rather than being layered on after. Customers who use a hyperscaler can comply. Most find that the vendor renegotiations and the cross-border-transfer audits cost more than the migration would have. The honest answer is that the choice depends on your workload’s data classification and your tolerance for audit overhead — and the migration cost has come down meaningfully in the last two years.
“What changes inside my own engineering?”
Five operational shifts, in roughly the order they hit you:
Diagrams, kept current, including SaaS subprocessors and operational logs
SCC-equivalents, intra-group agreements, in-country residency proofs — picked per flow
Versioned, scoped, withdrawable, auditable per identity — built into the data model
IR runbooks must scope personal-data exposure inside the regulator's notification window
Recruitment + reporting line + budget protected from product pressure
“Where will most of my budget actually go?”
Not where you expect. The instinct is that this is a cloud problem. It is mostly an application problem. The Act forces work into the data model — fields that store personal data need classification metadata, retention policies need code paths that actually delete, consent state needs to be addressable per identity. Each of these is application work, not infrastructure work. The infrastructure work is real but bounded; the application work is open-ended.
Source: Cloud Digit customer engagements, 2026 to date; effort-weighted.
“How does this compare to GDPR or India’s DPDPA?”
The framing is broadly aligned. The vocabulary — controller, processor, sensitive category, lawful basis — is shared with GDPR, PDPA, DPDPA, and PIPL. The cross-border-transfer regime is more specific to Bangladesh than any of those. The enforcement posture currently appears closer to Singapore’s PDPA than to the EU’s GDPR — proportionate, dialogue-led, educative for the first cycle of major findings. That posture will harden over time.
“What actually triggers a regulator-side investigation?”
Three triggers we have observed so far. A material breach with personal data exposure. A complaint from a citizen exercising their access or erasure rights. And a thematic review — where the regulator selects a sector and reviews multiple institutions against a common framework. The last category is the one most institutions are not preparing for, and is where most of the early enforcement action will land.
“What do I do this quarter?”
Inventory. Flow map. Sovereignty audit. DPO scoping. In that order. Each is a discrete deliverable with a named owner and a date. None of them is glamorous; all of them are necessary; and the sequence matters more than the speed.
Read next
- Compliance
Three Letters to Three Regulators
How public cloud actually fits inside the Bangladeshi regulatory frame, written as three pieces of correspondence — to BTRC, to Bangladesh Bank, and to the Data Protection Authority.
- Compliance
A Lexicon of Three Words That Look Alike
Locality, residency, and sovereignty are not synonyms. A short dictionary, with usage notes, for the procurement office that has been writing the wrong clause for years.
- Finance
The Anomaly: A FinOps Detective Story
A real cost spike, the investigation that found it, and the maturity model that emerged from the lesson. Cloud economics taught the way it actually gets learned.