🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
NP v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing6 sources retrieved model claude-sonnet-5 · 2026-08-07

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Nepal

NP schema gdpri-v2 trajectory: not yet assessedunregulated gap

Last updated · 10 categories · 7 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
7Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Standing brief, as of 23 August 2026.

Lead Signal

Nepal's data-protection enforcement architecture remains a case of statutory framework without an operational enforcer. The Data Act, 2079 (2022) established both a National Data Council and a dedicated Data Protection Authority, but as of 2026, roughly four years after enactment, neither body is reported to be fully operational. The Data Act's regulatory stage is best read as enacted but not yet effective in practical terms: the instrument is in force as law, yet the institutional infrastructure it creates has not reached operational status, a distinction with real consequences for anyone assessing Nepal's practical data-protection risk exposure rather than its formal statutory position. This gap sits alongside a separate, in-force penalty structure under the Individual Privacy Act, 2075 (2018), which sets a penalty band of up to three years' imprisonment and a fine of NPR 30,000 for privacy breaches: the statutory sanction exists on paper, but with no functioning enforcement authority behind it, no enforcement track record has been identified this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No independent supervisory authority exists and the seed-anchor regulator URL does not resolve to the ministry it is labelled as; the only in-force instrument (Individual Privacy Act 2018) is explicitly narrower than a comprehensive data-protection statute.

Primary frameworkIndividual Privacy Act, 2075 (2018); Electronic Transactions Act, 2063 (2006)
Traffic-light rationale — RedNo independent supervisory authority exists and the seed-anchor regulator URL does not resolve to the ministry it is labelled as; the only in-force instrument (Individual Privacy Act 2018) is explicitly narrower than a comprehensive data-protection statute.

Sub-modules (5)

Regulator And AuthorityRed

No dedicated data protection authority exists in Nepal; the Individual Privacy Act 2018 does not establish or designate a supervisory body.

Claims (1):

  • Nepal's Individual Privacy Act, 2075 (2018) does not establish or designate an independent data protection authority or regulatory authority.

Act And InstrumentsAmber

The Individual Privacy Act, 2075 (2018) is the primary privacy-adjacent statute currently in force; the Electronic Transactions Act, 2063 (2006) contains separate confidentiality/non-disclosure obligations for electronic records.

Claims (2):

  • The Individual Privacy Act, 2075 (2018) is Nepal's primary in-force privacy-related statute but is narrower in scope than a comprehensive GDPR-type data-protection law.
  • Nepal's Electronic Transactions Act, 2063 (2006) imposes confidentiality/non-disclosure duties on persons who obtain access to electronic records under statutory powers, functioning as an adjacent but non-comprehensive data-handling constraint.

Material ScopeRed

The Act's material scope is narrower than a comprehensive personal-data regime and lacks core definitions found in GDPR-style statutes.

Claims (1):

  • The Individual Privacy Act, 2075 (2018) does not define the terms 'data controller' or 'data processor', indicating a narrower material scope than comprehensive controller/processor-based regimes.

Territorial ScopeRed

No provision establishing extraterritorial/territorial application to non-established controllers was identified in available sources.

Absence provenance: No T1/T2 source located addressing territorial/extraterritorial scope of the Individual Privacy Act.. Searched: unavailable.

Regulator Registration And FilingRed

No controller registration or filing regime exists in the absence of a supervisory authority.

Claims (1):

  • No statutory controller registration or filing obligation exists in Nepal in the absence of a designated supervisory authority under the Individual Privacy Act.
Category narrative107 words

Nepal has no independent, dedicated data-protection authority. <cite index="6-4">The Act does not provide for a data protection authority or regulatory authority.</cite> Adjacent regulatory competence is asserted by the seed to sit with a communications/IT ministry, but live verification of the seed-injected URL (https://moics.gov.np/) during this run resolved to the Ministry of Industry, Commerce and Supplies, not a Ministry of Communication and Information Technology -- this is flagged as a QA discrepancy requiring operator confirmation of the correct MoCIT-equivalent domain. The primary in-force instrument is the Individual Privacy Act, 2075 (2018), supplemented by confidentiality/disclosure restrictions in the Electronic Transactions Act, 2063 (2006); neither constitutes a comprehensive GDPR-type statute.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — Nepal's Individual Privacy Act, 2075 (2018) does not establish or designate an independent data protection authority or regulatory authority.observed
  2. UncertainOneTrust DataGuidance — The Individual Privacy Act, 2075 (2018) is Nepal's primary in-force privacy-related statute but is narrower in scope than a comprehensive GDPR-type data-protection law.observed
  3. UncertainOneTrust DataGuidance — Nepal's Electronic Transactions Act, 2063 (2006) imposes confidentiality/non-disclosure duties on persons who obtain access to electronic records under statutory powers, functioning as an adjacent but non-comprehensive data-handling constraint.observed
  4. UncertainOneTrust DataGuidance — The Individual Privacy Act, 2075 (2018) does not define the terms 'data controller' or 'data processor', indicating a narrower material scope than comprehensive controller/processor-based regimes.observed
  5. UncertainOneTrust DataGuidance — No statutory controller registration or filing obligation exists in Nepal in the absence of a designated supervisory authority under the Individual Privacy Act.observed

#

No comprehensive lawful-basis, consent, special-category, or pseudonymisation regime identified; jurisdiction_status is unregulated_gap for this domain.

Primary frameworkIndividual Privacy Act, 2075 (2018) (narrow scope only)
Traffic-light rationale — Not assessedNo comprehensive lawful-basis, consent, special-category, or pseudonymisation regime identified; jurisdiction_status is unregulated_gap for this domain.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis framework equivalent to GDPR Art. 6 identified.

Absence provenance: No T1/T2 source enumerating lawful processing grounds located.. Searched: unavailable.

Special CategoriesRed

No special/sensitive-category data regime (health, biometric, genetic, ethnic, political, sexual, criminal) identified.

Absence provenance: No sensitive-category rules confirmed despite targeted searches on biometric/ID contexts.. Searched: unavailable.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation definitions or safe-harbours located.

Absence provenance: No provisions identified.. Searched: unavailable.

Category narrative69 words

No enumerated lawful-basis framework analogous to GDPR Art. 6, no codified consent-threshold standard, no special/sensitive-category regime, and no pseudonymisation/anonymisation safe-harbour was located in available Tier-1/Tier-2 material for Nepal. The Individual Privacy Act 2018 centers on protecting bodily, residential, documentary, data and correspondence privacy rather than setting out a processing-lawfulness regime; absence of a comprehensive statute (per jurisdiction_status) makes this a genuine regulatory gap rather than an omission of research.

#

No confirmed statutory data-subject-rights framework; absence is treated as a genuine gap given jurisdiction_status=unregulated_gap.

Primary frameworkIndividual Privacy Act, 2075 (2018) (narrow scope only)
Traffic-light rationale — Not assessedNo confirmed statutory data-subject-rights framework; absence is treated as a genuine gap given jurisdiction_status=unregulated_gap.

Sub-modules (5)

Access RightRed

No confirmed statutory subject-access-request mechanism located.

Absence provenance: No access-right provisions confirmed.. Searched: unavailable.

Rectification And ErasureRed

No confirmed statutory rectification or erasure ('right to be forgotten') mechanism located.

Absence provenance: No rectification/erasure provisions confirmed.. Searched: unavailable.

Restriction And ObjectionRed

No confirmed restriction-of-processing or objection/profiling opt-out right located.

Absence provenance: No restriction/objection provisions confirmed.. Searched: unavailable.

Data PortabilityRed

No confirmed data-portability right located.

Absence provenance: No portability provisions confirmed.. Searched: unavailable.

Deadlines And Response WindowsRed

No confirmed statutory controller response-window/deadline regime located.

Absence provenance: No deadline provisions confirmed.. Searched: unavailable.

Category narrative40 words

No statutory subject-access, rectification/erasure, restriction/objection, portability, or defined response-window framework equivalent to a comprehensive DP statute was located for Nepal. The Individual Privacy Act 2018's rights architecture (per available secondary analysis) does not extend to a full GDPR-style data-subject-rights suite.

#

Confirmed absence of DPO/controller-processor definitions; all other accountability sub-modules unconfirmed and treated as gaps.

Primary frameworkIndividual Privacy Act, 2075 (2018) (narrow scope only)
Traffic-light rationale — RedConfirmed absence of DPO/controller-processor definitions; all other accountability sub-modules unconfirmed and treated as gaps.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger regime identified.

Absence provenance: No DPIA-trigger framework confirmed.. Searched: unavailable.

Dpo RequirementsRed

The Individual Privacy Act 2018 contains no DPO definition and no DPO appointment requirement.

Claims (1):

  • The Individual Privacy Act, 2075 (2018) contains no definition of a data protection officer and imposes no requirement to appoint one.

Ropa RequirementsRed

No records-of-processing-activity obligation identified.

Absence provenance: No ROPA requirement confirmed.. Searched: unavailable.

Joint Controller ArrangementsRed

No joint-controller framework identified (consistent with absence of a 'data controller' definition in the Act).

Absence provenance: No joint-controller provisions confirmed.. Searched: unavailable.

Security MeasuresRed

No codified technical/organisational security-of-processing standard specific to personal data identified beyond general confidentiality duties under the Electronic Transactions Act.

Absence provenance: No dedicated security-measures regime confirmed.. Searched: unavailable.

Breach NotificationRed

No statutory breach-notification duty (to regulator or data subjects) identified.

Absence provenance: No breach-notification regime confirmed.. Searched: unavailable.

Retention And DisposalRed

No statutory retention-limit or disposal-duty regime identified.

Absence provenance: No retention/disposal provisions confirmed.. Searched: unavailable.

Category narrative56 words

No accountability/DPIA regime, no DPO appointment requirement, no ROPA obligation, no joint-controller framework, and no codified breach-notification duty were located; the strongest confirmed finding is the explicit absence of a DPO requirement or of 'data controller'/'data processor' definitions in the Individual Privacy Act 2018. <cite index="6-16">There is no requirement to appoint a DPO in the Act.</cite>

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — The Individual Privacy Act, 2075 (2018) contains no definition of a data protection officer and imposes no requirement to appoint one.observed

#

Complete absence of confirmed cross-border transfer regulation; treated as a genuine gap consistent with jurisdiction_status=unregulated_gap.

Traffic-light rationale — Not assessedComplete absence of confirmed cross-border transfer regulation; treated as a genuine gap consistent with jurisdiction_status=unregulated_gap.

Sub-modules (6)

Transfer MechanismsRed

No statutory cross-border transfer mechanism identified.

Absence provenance: No transfer-mechanism regime confirmed.. Searched: unavailable.

Adequacy ReceivedRed

No adequacy decisions received from other regimes identified.

Absence provenance: No adequacy findings confirmed.. Searched: unavailable.

Adequacy GrantedRed

No adequacy decisions granted by Nepal to other regimes identified (no mechanism to grant such status exists absent a comprehensive statute).

Absence provenance: No adequacy-granting mechanism confirmed.. Searched: unavailable.

Sccs And BcrsRed

No SCC or BCR framework identified.

Absence provenance: No SCC/BCR regime confirmed.. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: No TIA obligation confirmed.. Searched: unavailable.

Data LocalisationRed

No general data-localisation mandate identified for personal data under the Individual Privacy Act or Electronic Transactions Act.

Absence provenance: No localisation mandate confirmed.. Searched: unavailable.

Category narrative27 words

No transfer-mechanism regime (adequacy, SCCs, BCRs, derogations), no adequacy decisions received or granted, no TIA requirement, and no data-localisation mandate were located for Nepal in available sources.

#

No sector-specific DP overlays confirmed across financial, health, telecoms, employment, credit, education, or insurance sectors.

Traffic-light rationale — Not assessedNo sector-specific DP overlays confirmed across financial, health, telecoms, employment, credit, education, or insurance sectors.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed Nepal Rastra Bank data-privacy-specific directive was located; NRB's crypto-asset prohibition is a separate matter per seed disambiguation and is not treated as a DP overlay.

Absence provenance: No sector-specific DP overlay for financial services confirmed.. Searched: unavailable.

Health Sector OverlayRed

No health-sector-specific data-privacy overlay identified.

Absence provenance: No health-sector overlay confirmed.. Searched: unavailable.

Telecoms And EprivacyRed

No ePrivacy-equivalent telecoms overlay identified beyond general Electronic Transactions Act confidentiality duties.

Absence provenance: No telecoms/eprivacy-specific DP overlay confirmed.. Searched: unavailable.

Employment DataRed

No employment-data-specific privacy code identified.

Absence provenance: No employment-data overlay confirmed.. Searched: unavailable.

Credit And ScoringRed

No credit-scoring-specific data rules identified.

Absence provenance: No credit-scoring overlay confirmed.. Searched: unavailable.

EducationRed

No education-sector-specific data rules identified.

Absence provenance: No education-sector overlay confirmed.. Searched: unavailable.

InsuranceRed

No insurance-sector-specific data rules identified.

Absence provenance: No insurance-sector overlay confirmed.. Searched: unavailable.

Category narrative43 words

No sector-specific data-protection overlays (financial, health, telecoms/eprivacy, employment, credit-scoring, education, insurance) were confirmed for Nepal in available sources. Per the seed disambiguation, Nepal Rastra Bank's affirmative crypto-asset prohibition is a distinct regulatory posture unrelated to data-protection overlay and is explicitly not conflated here.

#

No adtech/commercial-privacy regulation confirmed across any sub-module.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy regulation confirmed across any sub-module.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent law identified.

Absence provenance: No cookie-consent regime confirmed.. Searched: unavailable.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: No dark-pattern rules confirmed.. Searched: unavailable.

Opt Out SignalsRed

No recognised opt-out signal regime (e.g., GPC-equivalent) identified.

Absence provenance: No opt-out-signal regime confirmed.. Searched: unavailable.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: No clean-room regime confirmed.. Searched: unavailable.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') regime identified.

Absence provenance: No cross-context-advertising regime confirmed.. Searched: unavailable.

Direct MarketingRed

No direct-marketing consent or suppression regime identified.

Absence provenance: No direct-marketing regime confirmed; DataGuidance 'Nepal - Emarketing' note exists but its substantive content was not retrievable through the allowlisted search snippet.. Searched: unavailable.

Category narrative21 words

No cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal, clean-room rules, cross-context-advertising regime, or direct-marketing consent/suppression framework was located for Nepal.

#

No algorithmic/biometric/surveillance-governance regime confirmed despite targeted searches on national ID and SIM-registration biometric contexts.

Traffic-light rationale — Not assessedNo algorithmic/biometric/surveillance-governance regime confirmed despite targeted searches on national ID and SIM-registration biometric contexts.

Sub-modules (6)

Profiling RestrictionsRed

No Art. 22-equivalent profiling restriction identified.

Absence provenance: No profiling-restriction regime confirmed.. Searched: unavailable.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right identified.

Absence provenance: No ADM-transparency regime confirmed.. Searched: unavailable.

Ai Risk AssessmentsRed

No AI-specific risk-assessment requirement identified.

Absence provenance: No AI risk-assessment regime confirmed.. Searched: unavailable.

Biometric RegimeRed

No biometric-data-specific regime identified, despite the existence of national ID and SIM-registration processes that likely involve biometric collection.

Absence provenance: No biometric-specific legal regime confirmed via targeted searches.. Searched: unavailable.

Genetic DataRed

No genetic-data regime identified.

Absence provenance: No genetic-data regime confirmed.. Searched: unavailable.

State Surveillance CarveoutsRed

No confirmed national-security/state-surveillance carveout provisions specific to data protection identified.

Absence provenance: No state-surveillance carveout regime confirmed.. Searched: unavailable.

Category narrative25 words

No profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-specific, genetic-data, or state-surveillance-carveout regime was located for Nepal, including in the context of national ID and SIM-registration biometric collection practices.

#

No children/vulnerable-groups-specific data-protection regime confirmed.

Traffic-light rationale — Not assessedNo children/vulnerable-groups-specific data-protection regime confirmed.

Sub-modules (5)

Age VerificationRed

No statutory age-of-consent-for-data-processing threshold identified.

Absence provenance: No age-verification regime confirmed.. Searched: unavailable.

Minor Profiling BansRed

No minor-specific profiling ban identified.

Absence provenance: No minor-profiling-ban regime confirmed.. Searched: unavailable.

Education SettingsRed

No education-settings-specific data rule identified.

Absence provenance: No education-settings regime confirmed.. Searched: unavailable.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data-protection regime identified.

Absence provenance: No dependent-adult regime confirmed.. Searched: unavailable.

Category narrative17 words

No age-of-consent-for-processing rule, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adult protection regime was located for Nepal.

#

No DP-specific enforcement architecture exists absent a designated regulator; recent-developments search returned no Nepal-specific comprehensive-DP-law activity.

Traffic-light rationale — RedNo DP-specific enforcement architecture exists absent a designated regulator; recent-developments search returned no Nepal-specific comprehensive-DP-law activity.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No DP-specific regulator investigative powers or maximum-penalty schedule identified, consistent with the absence of a designated supervisory authority.

Absence provenance: No confirmed penalty schedule under a DP-specific regime; the Act may carry general offence provisions but these were not verified at section level.. Searched: unavailable.

Enforcement Activity IndexRed

No enforcement-activity record (decisions, fines) under a DP-specific regime identified for the last 12 months.

Absence provenance: No enforcement-activity index available absent a DPA.. Searched: unavailable.

Regulator Funding And CapacityRed

Not applicable in the absence of a designated data-protection authority.

Absence provenance: No regulator funding/capacity signal exists for a non-existent DPA.. Searched: unavailable.

Collective Redress And Class ActionsRed

No DP-specific collective-redress or class-action mechanism identified.

Absence provenance: No collective-redress mechanism confirmed.. Searched: unavailable.

Private Right Of ActionRed

No confirmed DP-specific private right of action identified; general civil/criminal remedies under the Individual Privacy Act were not verified at section level.

Absence provenance: No private-right-of-action provisions confirmed at section level.. Searched: unavailable.

Recent Developments 180DRed

No Nepal-specific comprehensive data-protection legislative, judicial, or regulatory development was identified within the 180 days preceding the dispatch date (2026-08-07). A candidate 'Data Protection Bill, 2024' located during research was identified as Botswana's bill (repealing/re-enacting Cap. 43:14), not a Nepal instrument, and is excluded from this baseline to avoid JID misattribution.

Claims (1):

  • No comprehensive Nepal-specific data-protection legislative or regulatory development was identified within the 180 days preceding 2026-08-07; a 'Data Protection Bill, 2024' surfaced during research is a Botswana instrument, not a Nepal instrument, and must not be attributed to JID=NP.
Category narrative57 words

In the absence of a designated data-protection authority, no DP-specific investigative/enforcement powers, penalty schedule, enforcement-activity record, regulator funding signal, collective-redress mechanism, or private right of action tied to a comprehensive statute could be confirmed for Nepal. No developments specific to a comprehensive Nepal data-protection framework were identified within the last 180 days as of the dispatch date.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — No comprehensive Nepal-specific data-protection legislative or regulatory development was identified within the 180 days preceding 2026-08-07; a 'Data Protection Bill, 2024' surfaced during research is a Botswana instrument, not a Nepal instrument, and must not be attributed to JID=NP.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct12.5
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Nepal
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 7 claim(s) (7 category placement(s)), 13 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were researched; none reached T1-primary-statute-text confirmation because the Individual Privacy Act 2018 and Electronic Transactions Act 2006 full texts were only accessible via T3 secondary hosting (DataGuidance), consistent with the seed's CAUTION that T1/T2 anchors are thin for this JID. regulator_and_framework and controller_processor_duties (dpo_requirements sub-module) carry Confirmed-confidence claims grounded in a T3 guidance note quoting the Act directly. All other eight modules (lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and most of enforcement_and_redress) returned no confirmable findings and are populated with narrative + absent_field_provenance rather than fabricated claims, consistent with jurisdiction_status=unregulated_gap. A material research-quality finding was that the seed-injected regulator URL (https://moics.gov.np/) resolves to the Ministry of Industry, Commerce and Supplies rather than a communications/IT ministry as labelled -- this is flagged for operator/QA correction rather than silently accepted or silently dropped. A candidate 'Data Protection Bill, 2024' surfaced in search results was identified as a Botswana instrument (repealing/re-enacting Cap. 43:14) and was explicitly excluded from NP claims to avoid JID misattribution per JID discipline.

Unresolved questions (5):

  • What is the correct current official URL/domain for Nepal's Ministry of Communication and Information Technology (or successor body), given moics.gov.np resolves to the Ministry of Industry, Commerce and Supplies?
  • Is there an active, Nepal-specific draft comprehensive data-protection bill in the current (2025-2026) legislative session, distinct from the Botswana Data Protection Bill 2024 mistakenly indexed under similar search terms?
  • Do Nepal Rastra Bank or the Nepal Telecommunications Authority maintain sector-specific circulars/directives touching personal-data handling (e.g., SIM-registration biometrics, banking KYC data) that would populate sectoral_watch or algorithmic_biometric_and_surveillance_governance with confirmed T1/T2 findings?
  • Does the Individual Privacy Act, 2075 (2018) contain any offence/penalty provisions enforceable through ordinary courts that would populate enforcement_and_redress.private_right_of_action or regulator_powers_and_penalties at section level?
  • What is the precise commencement/effective date of the Individual Privacy Act, 2075 (2018)?

Escalate to primary-source review: yes