Cybersecurity laws Nepal April 16, 2026 - BY Admin

Cybersecurity laws Nepal

Are you seeking clarity on cybersecurity laws Nepal framework for your business or personal protection? The Electronic Transactions Act 2063 and Individual Privacy Act 2075 form the foundation, while the draft IT and Cyber Security Bill 2024 promises major reforms. This comprehensive guide explains exactly how cybersecurity laws Nepal work, what protections exist, and how to comply with evolving digital regulations.

Cybersecurity laws Nepal are governed by multiple statutes including the Electronic Transactions Act 2063 (2008), the Individual Privacy Act 2075 (2018), and the National Cyber Security Policy 2023. These laws criminalize unauthorized access, data theft, cyber fraud, and privacy violations while establishing frameworks for digital signatures, electronic records, and data protection. Understanding these provisions is essential for businesses, individuals, and government entities operating in Nepal's rapidly expanding digital economy.

What Are Cybersecurity Laws Nepal?

Cybersecurity laws Nepal refer to the legal framework governing digital activities, electronic transactions, data protection, and cybercrime prevention in Nepal. The primary legislation is the Electronic Transactions Act, 2063 (2008), supplemented by the Individual Privacy Act 2075 (2018), National Penal Code 2074, and sector-specific regulations from Nepal Rastra Bank and other authorities.

Historical Development

Year (AD)MilestoneSignificance
2008Electronic Transactions Act, 2063 enactedFoundation of Nepal's cyber law
2015Constitution of Nepal guarantees privacy as fundamental right (Article 28)Constitutional basis for data protection
2018Individual Privacy Act, 2075 enactedFirst comprehensive privacy legislation
2020National Cyber Security Policy approved by CabinetStrategic cybersecurity framework
2023National Cyber Security Policy 2023 (revised)Updated strategic roadmap
2024Draft Information Technology and Cyber Security BillProposed comprehensive update

Legal Framework for Cybersecurity Laws Nepal

The cybersecurity laws Nepal ecosystem operates under multiple statutes:

Legal InstrumentKey ProvisionsRegulatory Authority
Electronic Transactions Act, 2063 (2008)Cybercrime definitions, digital signatures, electronic records, penaltiesNepal Police Cyber Bureau, Judiciary
Individual Privacy Act, 2075 (2018)Personal data protection, consent requirements, privacy rightsDistrict Courts
Individual Privacy Regulation, 2077 (2020)Detailed implementation of Privacy ActRelevant ministries
National Penal Code, 2074 (2017)Fraud, cheating, identity theft, general criminal provisionsNepal Police, Judiciary
National Cyber Security Policy, 2023Strategic framework, institutional roles, national prioritiesMinistry of Communications and IT
NRB Unified DirectivesBanking cybersecurity, digital payment security, reportingNepal Rastra Bank
Social Network Directives, 2023Social media regulation, content moderation, privacyMinistry of Communications
Draft IT and Cyber Security Bill, 2024Proposed comprehensive update, National Cyber Security CenterPending enactment

Electronic Transactions Act 2063: Core Cybersecurity Provisions

The Electronic Transactions Act is the cornerstone of cybersecurity laws Nepal, establishing both enabling provisions for digital commerce and criminal penalties for cyber offenses.

Cybercrime Offenses and Penalties

OffenseSectionMaximum PenaltyDescription
Pirating/Destroying Computer Source Code463 years + NPR 200,000 fineUnauthorized alteration of protected source code
Unauthorized Access473 years + NPR 200,000 fineAccessing computer systems without authorization
Damage to Computer Information System483 years + NPR 200,000 fineDestroying, damaging, deleting, or altering computer data
Publication of Illegal Materials495 years + NPR 100,000 finePublishing prohibited content online
Confidentiality Breach502 years + NPR 10,000 fineDivulging confidential information without authority
Computer Fraud542 years + NPR 100,000 fineFraudulent use of digital signatures, payment cards
False Statements for Licenses512 years + NPR 100,000 fineLying to obtain digital signature certificates
Unauthorized Certification522 years + NPR 100,000 fineOperating as certifying authority without license

Corporate Liability Under ETA

Cybersecurity laws Nepal hold corporate bodies accountable for cyber offenses:

ScenarioLiability
Offense by corporate bodyChief executive or responsible officer deemed liable
Consent, knowledge, or negligence of director/managerBoth corporate body and individual officer liable
Offense committed outside Nepal affecting Nepali systemsLegal action may still be taken in Nepal

Individual Privacy Act 2075: Data Protection Framework

The Individual Privacy Act 2075 (2018) establishes comprehensive cybersecurity laws Nepal provisions for personal data protection.

Definition of Personal Information

CategorySpecific Data Types
Identity InformationCaste, ethnicity, birth, origin, religion, color, marital status
Contact InformationAddress, telephone, email
Identification NumbersPassport, citizenship, national ID, driving license, voter ID
Biometric InformationThumb impressions, fingerprints, retina, blood group, other biometric data
Professional InformationEducation, qualifications, professional opinions
Criminal BackgroundCriminal history, sentences served

Sensitive Personal Information

Section 27(2) defines sensitive personal information as data revealing:

  • Caste, ethnicity, origin
  • Political affiliation
  • Religious faith/belief
  • Physical/mental health
  • Sexual orientation or sexual life events
  • Property details

Individual Rights Under Privacy Act

RightDescriptionLimitation
Right to Data PrivacyConfidentiality of personal informationSubject to legal exceptions
Right to ConsentInformed consent required for collectionPublic interest exceptions
Right to InformationKnow purpose, nature, scope of collectionLimited to public entities for rectification
Right to RectificationCorrect wrong informationOnly for public entity data
Right to SecurityProtection against unauthorized accessImplementation by data collector

Privacy Act Penalties

ViolationPenalty
Unauthorized collection/use of personal informationUp to 3 years imprisonment + NPR 30,000 fine
Breach of confidentialityUp to 2 years imprisonment + NPR 10,000 fine (ETA)

National Cyber Security Policy 2023

The National Cyber Security Policy 2023 provides the strategic framework for cybersecurity laws Nepal implementation.

Key Policy Objectives

ObjectiveImplementation Strategy
Protect Critical Information InfrastructureIdentification, risk assessment, security standards
Enhance Cyber Threat DetectionNational Cyber Security Center, CERT-NP capabilities
Develop Cybersecurity WorkforceEducation, training, certification programs
Promote International CooperationBilateral agreements, information sharing
Strengthen Legal FrameworkIT and Cyber Security Bill, updated regulations

Institutional Framework

InstitutionRoleStatus
National Cyber Security Center (proposed)Central coordination, threat monitoring, incident responsePending Bill enactment
Computer Emergency Response Team Nepal (CERT-NP)Technical incident handling, advisoriesOperational
Cyber Bureau of Nepal PoliceCybercrime investigation, enforcementOperational
Nepal Telecommunications AuthorityTelecom sector cybersecurityActive

Sector-Specific Cybersecurity Regulations

Banking and Financial Sector

Nepal Rastra Bank has issued comprehensive cybersecurity laws Nepal directives for financial institutions:

RequirementDirectiveCompliance
Information Security PolicyNRB Directive on IT GovernanceMandatory for all BFIs
Cybersecurity FrameworkNRB Cybersecurity GuidelinesRisk-based implementation
Incident ReportingImmediate reporting of cyber incidentsWithin specified timeframes
Penetration TestingRegular security assessmentsAnnual or bi-annual
Data LocalizationSensitive data within NepalFor critical categories

E-Commerce and Digital Services

The E-Commerce Act 2025 and Social Network Directives 2023 establish cybersecurity laws Nepal obligations for digital businesses:

ObligationRequirementPenalty for Non-Compliance
Data PrivacyMaintain confidentiality of personal informationFine + imprisonment under ETA
User RightsProvide access to amend/deactivate personal dataAdministrative penalties
Content ModerationRemove prohibited content, prevent privacy breachesFine up to NPR 50,000 + 6 months imprisonment
Local RegistrationRegister or appoint local representativeOperational restrictions

Draft Information Technology and Cyber Security Bill 2024

The proposed Bill represents the most significant update to cybersecurity laws Nepal in nearly two decades.

Proposed Key Provisions

AreaCurrent LawProposed Change
National Cyber Security CenterNo dedicated authorityEstablishment of centralized agency
AI RegulationNo specific provisionsFramework for artificial intelligence governance
Data Breach NotificationNo mandatory reportingMandatory breach disclosure requirements
Cross-Border Data TransferUnclear/limitedRegulated framework
Data Subject RightsLimited (access, rectification)Expanded rights (erasure, portability, objection)
Critical InfrastructureGeneral provisionsSpecific protection standards

Current Gaps Addressed by Draft Bill

GapImpactProposed Solution
No data protection authorityEnforcement through courts onlyDedicated regulatory body
No mandatory breach notificationDelayed response to data breachesLegal obligation to report
Limited AI governanceUnclear liability for AI harmsSpecific AI provisions
Weak cross-border rulesData exfiltration risksRegulated transfers
Outdated ETA 2008Doesn't address modern threatsComprehensive update

Cybercrime Reporting and Enforcement

Reporting Mechanisms

ChannelContactJurisdiction
Cyber Bureau of Nepal Police[email protected]All cybercrimes
Online Complaint PortalNepal Police websiteGeneral cyber incidents
CERT-NP[email protected]Technical incidents, vulnerabilities
District CourtDirect filingPrivacy Act violations

Investigation Process

  1. Complaint Filing: Victim submits detailed complaint with evidence
  2. Initial Assessment: Cyber Bureau evaluates complaint validity
  3. FIR Registration: First Information Report filed for cognizable offenses
  4. Digital Forensics: Technical analysis of devices, networks, data
  5. Investigation: Evidence collection, suspect identification
  6. Charge Sheet: Prosecution recommendation to District Attorney
  7. Trial: Court proceedings with digital evidence presentation

Compliance Requirements for Businesses

Data Protection Compliance Checklist

RequirementImplementationLegal Basis
Consent ManagementObtain explicit consent before data collectionPrivacy Act 2075
Purpose LimitationUse data only for stated purposesPrivacy Act 2075
Security MeasuresImplement reasonable technical and organizational safeguardsPrivacy Act 2075
Access ControlsRestrict data access to authorized personnelETA 2063
Incident ResponsePlan for breach detection, response, notificationBest practice
Staff TrainingEducate employees on cybersecurity and privacyBest practice
Regular AuditsAssess compliance and security postureNRB directives (for BFIs)

Frequently Asked Questions About Cybersecurity Laws Nepal

What is the main cybersecurity law in Nepal?

The Electronic Transactions Act, 2063 (2008) is the primary cybersecurity laws Nepal legislation, governing cybercrimes, digital signatures, and electronic records. The Individual Privacy Act 2075 (2018) supplements this with data protection provisions.

What are the penalties for cybercrime in Nepal?

Penalties vary by offense: unauthorized access carries up to 3 years imprisonment + NPR 200,000 fine; publication of illegal materials carries up to 5 years + NPR 100,000 fine; privacy breaches carry up to 3 years + NPR 30,000 fine.

Who handles cybercrime complaints in Nepal?

The Cyber Bureau of Nepal Police is the designated authority for cybercrime complaints, reachable at [email protected]. CERT-NP handles technical security incidents.

Is personal data protected under Nepal law?

Yes. The Individual Privacy Act 2075 (2018) and Article 28 of the Constitution protect personal data, requiring consent for collection and mandating security safeguards. However, enforcement mechanisms remain limited compared to international standards like GDPR.

Does Nepal have a data protection authority?

No. Unlike many countries, cybersecurity laws Nepal do not currently establish a dedicated data protection authority. The draft IT and Cyber Security Bill 2024 proposes creating such an authority.

What is the statute of limitations for cybercrime prosecutions?

Cyber offenses under the Electronic Transactions Act must generally be prosecuted within the limitation periods specified in the National Penal Code, typically ranging from 1-3 years depending on offense severity.

Are companies liable for cyber offenses committed by employees?

Yes. The ETA holds corporate bodies liable, with chief executives or responsible officers deemed personally liable unless they prove lack of knowledge or negligence.

What should I do if my company experiences a data breach?

Immediately: (1) contain the breach, (2) assess scope and impact, (3) document evidence, (4) notify affected individuals if feasible, (5) report to Cyber Bureau if criminal activity suspected, (6) implement corrective measures. While mandatory breach notification is not yet law, transparency is recommended.

How does Nepal's cybersecurity framework compare internationally?

Nepal ranked 94th out of 182 nations in the Global Cybersecurity Index 2020. The framework is considered developing, with significant gaps in data protection authority, breach notification, and AI governance that the draft 2024 Bill aims to address.

What are the key changes expected from the IT and Cyber Security Bill 2024?

The draft Bill proposes: establishment of National Cyber Security Center, mandatory data breach notification, AI governance framework, expanded data subject rights, regulated cross-border data transfers, and strengthened critical infrastructure protection.

How Attorney Nepal Supports Cybersecurity Law Compliance

Navigating cybersecurity laws Nepal requires specialized legal expertise. Attorney Nepal PVT LTD provides comprehensive support:

  • Compliance Assessment: Evaluating current practices against ETA, Privacy Act, and sectoral requirements
  • Policy Development: Drafting privacy policies, security procedures, and incident response plans
  • Cybercrime Defense: Representing clients accused of cyber offenses, challenging evidence, negotiating resolutions
  • Victim Representation: Assisting victims of cybercrime with complaint filing, evidence preservation, and recovery
  • Data Breach Response: Advising on legal obligations, notification requirements, and regulatory communications
  • Contract Review: Ensuring vendor agreements and user terms comply with cybersecurity and privacy laws
  • Training Programs: Educating staff on legal obligations and best practices

Contact Attorney Nepal PVT LTD for expert guidance on cybersecurity laws Nepal compliance.

Disclaimer: This guide provides general information about cybersecurity laws Nepal requirements. Specific situations require professional legal assessment. Contact qualified legal practitioners for case-specific guidance.

About the Author: This comprehensive guide was prepared by technology law specialists at Attorney Nepal PVT LTD, Kathmandu, Nepal. The information reflects current legal frameworks as of April 2026.

Related Searches: cyber law Nepal, cybercrime punishment Nepal, data protection Nepal, Electronic Transactions Act Nepal, Individual Privacy Act Nepal, cyber security policy Nepal, cyber bureau Nepal, digital signature Nepal, hacking law Nepal, data breach Nepal, AI regulation Nepal, information technology bill Nepal