Organizations operating digital products or services should treat privacy as a governance, contract, security and consumer-trust issue, not merely a website-policy exercise.
Legal context
The Constitution of Nepal recognizes privacy as a fundamental right, and the Privacy Act, 2075 addresses personal information and privacy interests. Electronic-transaction, consumer-protection, electronic-commerce and sector-specific rules may also affect particular processing activities.
Map the data lifecycle
Identify what personal information is collected, why it is needed, where it comes from, who can access it, which service providers receive it, where it is stored and when it is deleted. The map should include websites, apps, forms, cookies, analytics, customer support, marketing and employee systems.
Core controls
- Give clear, accurate notices at relevant collection points.
- Limit collection and access to a defined business need.
- Use proportionate security, authentication and backup controls.
- Contract for confidentiality, security and deletion with vendors.
- Create procedures for complaints, access requests and incidents.
- Retain information only as long as law and purpose require.
Incident readiness
Maintain an escalation plan that identifies decision-makers, technical responders, evidence-preservation steps, legal assessment and communication responsibilities. A rehearsed process reduces delay when an account, device or service provider is compromised.
This article provides general information, not legal advice.
Related services and resources
Primary and official sources
- Privacy Act, 2075 — Nepal Law Commission
- Electronic Commerce Act, 2081 — Nepal Law Commission
- Consumer Protection Act, 2075 — Nepal Law Commission
Share this note
