Terms of Service
—————————————
Privacy Policy
—————————————
Money Laundering Compliance Policy
Privacy Policy
LEGALSEBA LLP
Privacy Policy
Version 2.2 | Effective date: 4 July 2026 | Supersedes all previous versions
This Privacy Policy explains how LegalSeba LLP (“we”, “our”, “us” or the “Firm”) collects, uses, discloses, transfers, retains and protects personal data, including personal data provided to us through our website at www.legalseba.com (our “Site”). We are a law firm constituted in Bangladesh and we are committed to protecting and respecting your privacy in accordance with the laws of the People’s Republic of Bangladesh.
This Privacy Policy has been prepared to comply with, in particular, the Personal Data Protection Act, 2026 (Act No. 63 of 2026) (the “PDPA”) and the National Data Management Act, 2026 (Act No. 80 of 2026) (the “NDM Act”), each of which came into force on 10 April 2026 together with the other legislation listed in the Schedule (Key Legislation) to this Policy. The PDPA proceeds on the principle that your personal data is deemed to be owned by you, and may lawfully be processed only with your consent or on another legal ground recognised by the PDPA.
How this Privacy Policy works
This Privacy Policy is divided into three parts:
- Part A – General Privacy Notice: our general notice describing how we process personal data in the conduct of our business. It applies to everyone about whom we may process personal data, including visitors to our Site, business contacts and suppliers.
- Part B – Client Privacy Notice: our client-specific notice, applying to everyone who is engaging, has engaged or is in the process of engaging us to provide legal services, and to individuals whose personal data we process in connection with client matters.
- Part C – Recruitment Privacy Notice: our recruitment-specific notice, applying to everyone who submits information to us for recruitment purposes.
Parts B and C supplement Part A and apply in addition to it, as appropriate. Where there is any inconsistency, Parts B and C prevail in respect of the persons to whom they apply.
Key terms
In this Privacy Policy: “personal data” means any information relating to an identified or identifiable natural person (a “data subject”, who, under section 2(3) of the PDPA, may be living or deceased); “processing” means any operation performed on personal data, including collection, recording, organisation, storage, use, disclosure, transfer and erasure; “data fiduciary” means the person who determines the purposes and means of processing personal data (equivalent to a “data controller”); “data processor” means a person who processes personal data on behalf of a data fiduciary; and “sensitive personal data” has the meaning given to it in section 2(21) of the PDPA and includes genetic and biometric data; data relating to minority ethnic groups or communities; political, philosophical or religious belief; trade union membership; health data; sexual orientation; personal data relating to the commission of, criminal proceedings for, conviction of, or allegations of, an offence; data revealing a person’s instantaneous location or geo-location; and any other personal data prescribed by rules or regulations.
Part A: General Privacy Notice
1. Who we are and our role as data fiduciary
When we process personal data about you or others in connection with promoting and administering our business, providing legal services or recruiting, we do so as a data fiduciary within the meaning of the PDPA. The data fiduciary is LegalSeba LLP, a limited liability partnership constituted under the laws of Bangladesh, with its registered office at Holding No 1/5, Flat B3, Block E, Lalmatia, Dhaka, Bangladesh. LegalSeba LLP has overall responsibility for personal data collected via the Site and in the course of our business.
Where we engage third parties to process personal data on our behalf (for example, IT hosting providers), those parties act as data processors under written arrangements which impose obligations of security and confidentiality consistent with the PDPA.
2. The legal framework we comply with
Our processing of personal data is governed principally by the PDPA and the NDM Act, supervised by the National Data Management Authority (the “NDMA”) constituted under the NDM Act. As a law firm, we are additionally subject to sector-specific obligations, including the Bangladesh Bar Council Canons of Professional Conduct and Etiquette (client confidentiality), the Money Laundering Prevention Act, 2012 (as amended), the Cyber Security Act, 2026 (Act No. 81 of 2026), which repealed and replaced the Cyber Security Ordinance, 2025, and the other instruments listed in the Schedule. Where another law imposes a stricter obligation of confidentiality or a mandatory disclosure, retention or localisation requirement, we comply with that law in addition to the PDPA.
3. Contact details of our Data Protection Officer
We have appointed a Data Protection Officer (“DPO”, also referred to as our Privacy Manager) who is responsible for overseeing questions in relation to this Privacy Policy, handling data subject requests and acting as our point of contact with the NDMA. If the Firm is designated a significant data fiduciary by regulation, our DPO will discharge the functions of a Chief Data Officer under section 23 of the PDPA when that section is brought into force. You can contact our DPO:
- by post: Data Protection Officer, LegalSeba LLP, Holding No 1/5, Flat B3, Block E, Lalmatia, Dhaka, Bangladesh; or
- by email: [email protected].
4. Keeping your personal data accurate and up to date
It is important that the personal data we hold about you is accurate, complete and current. Please inform us if your personal data changes during your relationship with us. You also have a statutory right to require the rectification, completion or updating of your personal data, as described in section 18 (Your rights) below.
5. Categories of personal data we collect
We may collect and process different kinds of personal data when you interact with us via the Site, social media, email, telephone, post or in person, or when we receive information from third parties. Depending on the circumstances, this may include:
- Identity Data: your name, title, and, where relevant, national identity (NID) number, passport details, date of birth and photograph.
- Contact Data: email address, telephone number, postal address and other contact details.
- Enquiry Data: the content of enquiries about engaging us for legal services or about job opportunities.
- Correspondence Data: correspondence and communications between you and us.
- Technical Data: IP address, device identifiers, operating system, browser type and version, time-zone setting, and information about how you use our Site.
- Marketing and Communications Data: your preferences in receiving communications from us and your communication preferences.
- Tracking Data: information collected through cookies and similar technologies, as described in section 13 (Cookies).
We also collect, use and share Aggregated Data, such as statistical or demographic data. Aggregated Data may be derived from your personal data but is not personal data where it cannot, directly or indirectly, identify you. If Aggregated Data is combined with your personal data so that it can identify you, we treat it as personal data governed by this Privacy Policy.
We do not usually seek to collect sensitive personal data about you, and we ask that you do not volunteer it, other than where it is necessary for the provision of legal services (see Part B) or where you choose to disclose it to us. Unless required to comply with a legal obligation or as part of providing legal services, we do not usually collect personal data relating to criminal convictions or offences.
6. How we obtain personal data
Most personal data is collected directly from you. We may also receive personal data from: publicly available sources (such as public registers, court records and professional directories); your employer or organisation, where you are a contact person; other parties connected with a matter; identity verification, sanctions and anti-money laundering screening providers; and analytics providers in respect of the Site.
7. Purposes and legal grounds for processing
We will only process your personal data where the PDPA permits us to do so. Under section 5 of the PDPA, the primary basis for processing is your consent. Section 5(3) of the PDPA also permits processing without consent on certain closed statutory grounds — which the PDPA itself labels “legitimate interests”, although they operate as an exhaustive list rather than an open balancing test — provided that the processing satisfies the statutory conditions of benefit, indispensability, proportionality and purpose limitation. Those grounds are: performance of a contract to which you are a party; steps taken at your request prior to entering into a contract; the establishment of a legal right or the defence of a legal claim in legal proceedings; the protection of vital interests concerning life or health; the implementation of legal rights concerning employment, labour rights or social security; where you have made the personal data public yourself; and where withholding processing would likely result in harm to another person. In addition, we process personal data where processing is necessary to comply with duties imposed on us by law.
The table below sets out the principal purposes for which we process personal data under this Part A and the corresponding legal grounds. Purposes specific to clients and job applicants are set out in Parts B and C.
|
Purpose / activity |
Categories of personal data |
Legal ground under the PDPA |
|
Responding to enquiries about our services or the Firm, and corresponding with you |
(a) Identity Data (b) Contact Data (c) Enquiry Data (d) Correspondence Data |
Steps taken at your request prior to entering into a contract; consent (where you initiate contact with us) |
|
Administering, operating and improving our Site, and maintaining its security |
(a) Technical Data (b) Tracking Data |
Consent (for non-essential cookies); performance of duties imposed by law (network and information security obligations under the Cyber Security Act, 2026) |
|
Undertaking client due diligence, anti-money laundering, sanctions and conflict checks before accepting instructions |
(a) Identity Data (b) Contact Data (c) related verification documents |
Compliance with duties imposed by law (including the Money Laundering Prevention Act, 2012 (as amended)); steps taken at your request prior to entering into a contract |
|
Sending legal updates, newsletters and invitations to events, and managing your preferences |
(a) Identity Data (b) Contact Data (c) Marketing and Communications Data |
Consent, which you may withdraw at any time (see section 12) |
|
Maintaining business records, managing our relationships with suppliers and service providers, and administering the Firm |
(a) Identity Data (b) Contact Data (c) Correspondence Data |
Performance of a contract; compliance with duties imposed by law (accounting, tax and regulatory record-keeping) |
|
Establishing, exercising or defending legal claims, and protecting our legal rights |
All categories, as relevant |
Establishment of a legal right or the defence of a legal claim in legal proceedings |
|
Complying with orders, directions or lawful requests of courts, regulators or the NDMA |
All categories, as relevant |
Compliance with duties imposed by law |
Purpose limitation. In accordance with the PDPA, we will not, without your consent, use or disclose your personal data for any purpose other than the purpose for which it was collected (or a purpose consistent with that primary purpose), unless another statutory ground applies. Where we intend to process your personal data for an unrelated new purpose, we will notify you and, where required, obtain your consent.
8. Consent and your right to withdraw
Where we rely on your consent, that consent must be, and will be sought on the basis that it is, voluntary, specific, explicit and revocable. Before you give consent, we will inform you of the purpose of the processing, the retention period, any process of transfer of the data, and how you may withdraw your consent. You may withdraw your consent at any time by contacting our DPO or by using any unsubscribe or preference mechanism we provide. Once consent is withdrawn, we will stop the relevant processing without undue delay, save to the extent that another legal ground applies (for example, statutory record-keeping obligations). Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
9. Sensitive personal data
Sensitive personal data under the PDPA extends beyond the familiar categories and includes criminal offence and allegation data and instantaneous geo-location data. We process sensitive personal data only in accordance with section 7 of the PDPA (which applies subject to sections 5 and 6), namely where: we have obtained your specific consent; you have entered into a contract as a party and the processing is required in that context; the processing is required in connection with employment or social security rights or obligations under law; the data is processed by a healthcare provider in the course of providing medical care or urgent treatment; the processing is in fulfilment of a duty imposed by or under law; or you have voluntarily made the data public. In a client engagement context, our approach to sensitive personal data is described further in Part B.
10. Children’s personal data
Our Site and services are not directed at children. We do not knowingly collect personal data of a child except where necessary for the provision of legal services (for example, family, guardianship or succession matters). Where we process a child’s personal data, we do so in accordance with section 9 of the PDPA, including by obtaining prior verifiable consent from the child’s parent or legal guardian and taking reasonable measures to verify the identity and authority of the consenting guardian, unless another statutory ground applies. If you believe a child has provided personal data to us without appropriate consent, please contact our DPO.
11. Sharing your personal data
As a law firm, we are bound by the Bangladesh Bar Council’s professional conduct rules, which require us to keep client affairs confidential unless disclosure is required by law or authorised by the client. Subject to those duties, we may share personal data with:
- our partners, employees and consultants, on a need-to-know basis;
- regulators, supervisory bodies and public authorities where required by law, including the NDMA, Bangladesh Bank, the Bangladesh Financial Intelligence Unit, the Bangladesh Bar Council and the National Board of Revenue;
- courts, tribunals and law enforcement agencies, pursuant to lawful orders or obligations;
- third-party service providers acting as data processors, for IT, document management, business administration, archiving and communications services;
- our professional indemnity insurers, auditors, bankers and professional advisers;
- analytics and (with your consent) advertising service providers in respect of the Site; and
- prospective purchasers or their advisers, in the event of a sale, merger or reorganisation of our business, subject to appropriate confidentiality safeguards.
We require all third parties to whom we disclose personal data to respect its security and confidentiality, to treat it in accordance with the law and not to use it for their own purposes. We do not sell personal data.
12. Marketing and communications preferences
We may use your Identity, Contact, Technical and Tracking Data to form a view on which of our services, publications and events may be of interest to you. We will send you electronic marketing communications only where you have consented to receive them or, in the case of existing clients, where the communication relates to legal developments and services similar to those we provide to you and you have not objected (see Part B, section 9). You can withdraw your consent or opt out at any time, free of charge, by using the unsubscribe link in any of our communications or by emailing [email protected]. We will action opt-out requests promptly. Opting out of marketing does not affect communications that are necessary for the provision of our services.
13. Cookies and similar technologies
Our Site uses cookies and similar technologies. Strictly necessary cookies are used to make the Site work and to maintain its security. Analytics and advertising cookies are deployed only with your consent, which you may give or refuse through the cookie banner or settings on the Site and may withdraw at any time. You can also set your browser to refuse some or all cookies, although this may affect the functionality of parts of the Site. Information collected through cookies is Tracking Data for the purposes of this Privacy Policy.
14. Cross-border transfers of personal data
We store personal data primarily in Bangladesh. In some circumstances — for example, where a matter involves foreign counsel, foreign courts or international transactions, or where our service providers host data abroad — we may transfer personal data outside Bangladesh. Where we do so, we will:
- inform you, before obtaining your consent where consent is the applicable ground, of the process of transfer of your personal data;
- transfer only what is necessary and proportionate for the relevant purpose;
- put in place contractual and technical safeguards with the recipient to ensure a standard of protection consistent with the PDPA, including confidentiality, security and onward-transfer restrictions;
- transfer classified personal data abroad only where section 29(3) of the PDPA permits — that is, with your consent, under a contract for goods or services to which you are a party, or, with your consent, in connection with your business, education, emigration, immigration or similar interests — recognising that the Government may classify personal data as public, internal, confidential or restricted against the criteria in the Schedule to the PDPA;
- transfer personal data only to places or countries in which suitable technology and equipment for the protection of the data, as prescribed by regulation, exist, in accordance with section 29(4) of the PDPA, and comply with the standards of any bilateral, multilateral or cross-border co-operation arrangements entered into by Bangladesh under section 30 of the PDPA;
- notify the NDMA in advance, as required by section 29(6) of the PDPA, of any large-volume cross-border transfer of sensitive personally identifiable data (such as government-issued identity numbers, biometric identifiers, genetic or DNA data, or criminal records);
- comply with any conditions, standards, directions or restrictions imposed under the PDPA, the NDM Act or by the NDMA, including any suspension or discontinuation of the supply of personal data to foreign recipients ordered by the NDMA; and
- comply with sectoral restrictions, including (where applicable to a matter) the restriction in section 12 of the Bank Companies Act, 1991 on the removal of banking records outside Bangladesh without the prior permission of Bangladesh Bank.
Details of the safeguards applied to any cross-border transfer of your personal data are available from our DPO on request and form part of your right of access under section 18.
15. How we protect personal data
In accordance with section 17 of the PDPA, we have implemented appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data and to prevent its accidental or unlawful destruction, damage, misuse, alteration, unauthorised disclosure or access. Our measures are calibrated to the amount and sensitivity of the data, the potential harm to data subjects, the scope of processing, retention periods and available technology, and include:
- encryption of personal data in transit and, where appropriate, at rest, and pseudonymisation where practicable;
- access controls limiting access to personal data to those who need it for their role, supported by confidentiality obligations binding on all partners, employees and consultants;
- measures to ensure the ongoing security, integrity, confidentiality, availability and resilience of our processing systems, and the timely recovery of access to personal data in the event of a physical or technical incident;
- periodic risk assessments and regular testing, evaluation and auditing of the effectiveness of our security measures against current and emerging risks; and
- alignment with applicable government information security guidance and cyber security legislation.
16. Personal data breaches
We maintain procedures to identify, contain, assess and remediate personal data breaches, meaning any unauthorised processing or accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Where a breach occurs and is likely to cause significant harm to affected data subjects, we will notify the NDMA and, where required, the affected data subjects, in the manner and within the timeframes prescribed by section 20 of the PDPA and any regulations, guidelines or directions issued under it, and we will keep records of breaches and our response.
17. How long we keep personal data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, regulatory, professional, accounting, tax or reporting requirements, and thereafter we securely delete, destroy or irreversibly anonymise it. In outline:
- general business contact and enquiry data is retained for no longer than two years from our last substantive interaction with you, unless Part B or Part C applies or you continue to subscribe to our publications;
- client matter files are retained for the longer periods described in Part B, reflecting limitation periods and professional obligations; and
- recruitment data is retained as described in Part C.
Details of applicable retention periods for particular categories of data are set out in our Information Retention Policy, available from our DPO on request. Before obtaining your consent to any processing, we will inform you of the applicable retention period. In accordance with section 19 of the PDPA, we maintain a register recording our processing of personal data, which is kept for at least five years and updated to reflect processing, retention, structuring, storage, alteration, portability and related matters.
18. Your rights as a data subject
Under the PDPA (in particular sections 10 to 14) you have the following rights in relation to your personal data, exercisable by written application to us and subject to the conditions and exceptions in the PDPA and regulations made under it. Under section 10(4) of the PDPA these rights are universal, inherent, inalienable and inviolable, and cannot be excluded or varied by contract or notice:
- Right of access: to obtain confirmation of processing and a copy of your personal data in a concise and understandable format, together with a summary of the data, the actions taken, the purposes and types of processing, the recipients (including a description of all persons, data fiduciaries or processors with whom the data has been shared), retention periods, the source of the data, the protection measures applied to any cross-border transfers, and the reasoning and implications of any automated decisions.
- Right to rectification: to require the rectification of inaccurate or misleading personal data, the completion of incomplete personal data and the updating of out-of-date personal data. If we decline a rectification request, we will give you our reasons in writing; you may then require us to mark the data as disputed and notify the NDMA. Where we make a rectification, completion or update, we will inform you and all concerned recipients within 30 days, as required by section 12(4) of the PDPA.
- Right to erasure: to require the erasure of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal ground applies, or in the other circumstances provided for in section 13 of the PDPA. Section 13(3) permits us to decline erasure in limited cases, including where the data must be retained to comply with a legal obligation, is held for archival purposes, or constitutes confidential or restricted personal data; matter files retained under our legal and professional obligations fall within these grounds.
- Right to withdraw consent: at any time, as described in section 8.
- Right to data portability: where applicable, to have your personal data transferred directly to another data fiduciary, including through Federated Interoperable Ecosystems, in the manner prescribed by regulations.
- Rights in relation to automated decision-making: to be informed of the reasoning and implications of decisions based solely on automated processing that significantly affect you. We do not currently make such decisions about individuals.
- Right to complain and to compensation: to lodge a complaint with the NDMA and, where the NDMA upholds a complaint, to receive any compensation it determines, as described in section 19.
To exercise any of these rights, please contact our DPO. We do not charge a fee for exercising your rights unless permitted by law, and we will respond within the timeframes prescribed by the PDPA and applicable regulations. We may need to verify your identity before acting on a request. Please note that certain data we hold is subject to legal professional privilege and statutory duties of confidentiality owed to clients; these may lawfully limit the information we can disclose in response to a request made by a person other than the client concerned. Where providing requested data may jeopardise national security, law and order or the rights of third parties, we are required to refer the matter to the relevant authorities and act on their decision.
19. Complaints and the National Data Management Authority
The supervisory authority for data protection in Bangladesh is the National Data Management Authority (NDMA), constituted under section 8 of the National Data Management Act, 2026 and exercising the functions conferred on it by sections 25 and 26 of the PDPA. Under sections 31 to 35 of the PDPA, the NDMA handles complaints from data subjects, may impose administrative fines of up to BDT 2.5 million (up to BDT 5 million for significant data fiduciaries) and may award compensation to data subjects in addition to any fine; a person aggrieved by such a fine or compensation order may appeal within 30 days to the Tribunal established under section 68 of the Information and Communication Technology Act, 2006. Please note that, under section 1(3) of the PDPA, sections 23 and 31 to 35 (which govern the Chief Data Officer requirement and the complaints, fines and compensation regime) come into force on a date to be notified by the Government following the 18-month transition period; the remainder of the PDPA is deemed to have effect from 6 November 2025. We would appreciate the opportunity to address your concerns first, so please contact our DPO in the first instance; once the complaints provisions are in force you will also have the right to lodge a complaint with the NDMA at any time, and in the meantime the NDMA exercises its general supervisory powers under the NDM Act.
20. Third-party links
Our Site may include links to third-party websites, plug-ins and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.
21. Changes to this Privacy Policy
We keep this Privacy Policy under regular review and will update it to reflect changes in law, guidance issued by the NDMA and changes to our practices. The latest version, with its effective date, is always available on our Site and on request from our DPO. Where a change materially affects the way we process your personal data, we will take reasonable steps to bring it to your attention and, where required by the PDPA, obtain fresh consent.
Part B: Additional Client Privacy Notice
1. Scope
This Part B applies where you engage, have engaged or are in the process of engaging us to provide legal services, and to individuals (such as directors, officers, employees, beneficial owners, counterparties, witnesses and other persons) whose personal data we process in connection with a client matter. It supplements Part A.
2. Additional categories of personal data we collect
In addition to the categories described in Part A, when you instruct us we may collect:
- Identity and Verification Data: copies of your NID, passport, TIN certificate or other identification documents, and beneficial ownership information, required for client due diligence under the Money Laundering Prevention Act, 2012 (as amended) and related rules and circulars;
- Matter Data: any personal data connected with your instructions and the conduct of your matter, which may include sensitive personal data (a category which, under the PDPA, includes data relating to criminal offences, proceedings, convictions and allegations) where relevant to the matter;
- Financial Data: bank account and payment details, billing information and financial information relevant to the matter; and
- Transactional Data: details of payments to and from you and details of services we have provided to you.
3. Purposes and legal grounds for processing
The table below sets out the principal purposes for which we process personal data in connection with client matters and the corresponding legal grounds under the PDPA.
|
Purpose / activity |
Categories of personal data |
Legal ground under the PDPA |
|
Undertaking client due diligence, anti-money laundering, sanctions and conflict checks and client onboarding |
(a) Identity and Verification Data (b) Matter Data (c) Financial Data |
Compliance with duties imposed by law (Money Laundering Prevention Act, 2012 (as amended)); steps taken at your request prior to entering into a contract |
|
Providing legal advice and representation and progressing your matter as instructed |
(a) Identity Data (b) Contact Data (c) Matter Data |
Performance of a contract to which you are a party; establishment of a legal right or the defence of a legal claim in legal proceedings |
|
Providing legal advice and progressing your matter, where this requires the use of sensitive personal data (e.g. health data in a personal injury or family matter) |
Sensitive personal data, including data revealing race or ethnicity, religious or philosophical belief, political opinion, trade union membership, health, sex life or sexual orientation, and genetic or biometric data |
Your specific consent, given by way of the engagement letter or on a case-by-case basis; processing required in the context of a contract to which you are a party; fulfilment of a duty imposed by or under law (section 7, PDPA) |
|
Providing legal advice and progressing your matter, where this requires data relating to criminal offences, proceedings, convictions or allegations (which is sensitive personal data under section 2(21) of the PDPA) |
Personal data relating to the commission of, criminal proceedings for, conviction of, or allegations of, an offence |
Section 7 conditions: your specific consent, given by way of the engagement letter or on a case-by-case basis; processing required in the context of a contract to which you are a party; fulfilment of a duty imposed by or under law |
|
Liaising with third parties as necessary to progress your matter (e.g. courts, opposing counsel, overseas law firms, notaries, experts, forensic accountants or barristers) |
(a) Identity Data (b) Matter Data (c) Financial Data (d) Transactional Data |
Performance of a contract; establishment of a legal right or the defence of a legal claim in legal proceedings; your consent, where sought in the engagement letter |
|
Managing payments, fees and charges, and maintaining accounting records |
(a) Matter Data (b) Financial Data (c) Transactional Data |
Performance of a contract; compliance with duties imposed by law (accounting and tax legislation) |
|
Collecting and recovering money owed to us |
(a) Matter Data (b) Financial Data (c) Transactional Data |
Performance of a contract; establishment of a legal right or the defence of a legal claim in legal proceedings |
4. Legal professional privilege and confidentiality
Personal data processed in connection with your matter is held subject to our duty of confidentiality under the Bangladesh Bar Council’s professional conduct rules and, where applicable, legal professional privilege, including the protections afforded to professional communications under the Evidence Act, 1872 (as amended). These duties operate alongside, and are not displaced by, this Privacy Policy. They may also limit the extent to which we can respond to requests concerning matter files made by persons other than the client.
5. Anti-money laundering and mandatory disclosures
We are obliged to comply with the Money Laundering Prevention Act, 2012 (as amended) and related rules and directives, including obligations to undertake client due diligence, to maintain records and, where required, to report to and share information with the Bangladesh Financial Intelligence Unit and other competent authorities. Such disclosures are made pursuant to duties imposed by law and may be made without your consent or knowledge where the law so requires.
6. Sharing personal data in connection with your matter
To provide our services we may share Matter Data with courts and tribunals, arbitral institutions, opposing parties and their counsel, regulators, government agencies, foreign counsel, experts, translators, notaries, process servers and other professionals engaged for the purposes of your matter, in each case only to the extent necessary to progress your matter or comply with law. Where a matter requires the transfer of personal data outside Bangladesh, the safeguards described in Part A, section 14 apply.
7. Retaining matter files
We store matter files digitally and, where necessary, in hard copy. Reflecting applicable limitation periods, professional indemnity requirements and record-keeping obligations, we ordinarily retain matter files for fifteen to twenty years from the conclusion of the matter, or for such longer period as may be required by law, as detailed in our Information Retention Policy. Anti-money laundering records are retained for the periods prescribed under the Money Laundering Prevention Act, 2012 (as amended).
8. Destruction and retrieval of files
At the end of the applicable retention period we will securely destroy files, or earlier with your consent. Please notify our DPO if you object to destruction or wish to make alternative arrangements. Original documents belonging to you will be returned to you on request, subject to any lien we may lawfully exercise. We may charge a reasonable administrative fee for retrieving archived files after the completion of a matter.
9. Client communications and mailing list
We produce newsletters, client briefings and events on legal developments. We may send these to clients in reliance on the engagement relationship, and you may opt out at any time, free of charge, by emailing [email protected] or using the unsubscribe link in any communication.
10. Source of personal data and failure to provide it
Most personal data comes directly from you, but we may also obtain personal data from other parties connected with your matter, from public registers and records, and from screening providers. Where we need personal data to comply with our legal duties (for example, to complete anti-money laundering checks) or to perform our engagement, and you do not provide it when requested, we may be unable to accept or continue to act on your instructions. We will notify you if this is the case.
Part C: Recruitment Privacy Notice
1. Scope
This Part C applies to everyone who applies to join us or submits information to us for recruitment purposes, whether as a partner, associate, trainee, intern, consultant or member of business services staff. It supplements Part A.
2. Categories of personal data we collect
- Identity Data: your name, NID or passport copy, date of birth and photograph;
- Contact Data: email address, telephone number and postal address;
- Career Data: your CV, education, qualifications, bar enrolment details, skills, experience, references and interview records; and
- Financial Data: salary history and expectations and, if an offer is made, bank account and tax details.
We ask that you do not include sensitive personal data in your application unless you consider it relevant; any sensitive personal data you volunteer will be processed only in accordance with section 7 of the PDPA, as described in Part A, section 9.
3. Purposes and legal grounds for processing
|
Purpose / activity |
Categories of personal data |
Legal ground under the PDPA |
|
Receiving and reviewing applications and assessing suitability for a role |
(a) Identity Data (b) Contact Data (c) Career Data |
Steps taken at your request prior to entering into a contract; your consent, given by submitting your application |
|
Conducting interviews, assessments and preliminary hiring steps, and communicating with you about your application |
(a) Identity Data (b) Contact Data (c) Career Data |
Steps taken at your request prior to entering into a contract |
|
Verifying qualifications, bar enrolment and references, and conducting background checks |
(a) Identity Data (b) Career Data |
Compliance with duties imposed by law and regulatory requirements; your consent, which we will seek before contacting referees or conducting checks |
|
Preparing an offer, contract of employment or engagement, and onboarding |
(a) Identity Data (b) Contact Data (c) Career Data (d) Financial Data |
Steps taken at your request prior to entering into a contract; performance of a contract; implementation of legal rights concerning employment, labour rights or social security |
4. Sharing recruitment data
We may share your data internally with those involved in the recruitment process and, where necessary, with our insurers, regulators, professional advisers, referees you have nominated, and background screening providers. Background checks will be conducted only as permitted or required by law and, where consent is the applicable ground, with your prior consent.
5. Retaining recruitment data
If your application is successful, personal data gathered during recruitment will be transferred to your personnel file and further privacy information will be provided when you join. If your application is unsuccessful, we will retain your data for no longer than is necessary to demonstrate the fairness of our process and to deal with any queries or claims, and in any event we will delete it within two years of receipt, unless you consent to us retaining your details for longer so that we can contact you about future opportunities. You may withdraw that consent, and request earlier deletion, at any time.
6. Source of personal data and failure to provide it
Most recruitment data comes directly from you, but we may obtain additional information from referees, educational institutions, the Bangladesh Bar Council and other professional bodies, publicly available sources, and screening providers. We cannot properly consider your application without your CV and your participation in the recruitment process; if you do not provide requested information, we may be unable to progress your application.
7. Automated decision-making
We do not use decisions based solely on automated processing, including profiling, in our recruitment. Every application is reviewed by a person. If this changes, we will update this notice and provide the information required by the PDPA, including the reasoning and implications of any such decision.
8. Your rights
You have the rights described in Part A, section 18 in relation to your recruitment data, including access, rectification, erasure and withdrawal of consent, and the right to complain to the NDMA.
Schedule: Key Legislation
This Privacy Policy has been prepared having regard to, and should be read with, the following laws of Bangladesh as amended or replaced from time to time:
|
Term / instrument |
Description |
|
Personal Data Protection Act, 2026 (Act No. 63 of 2026) (PDPA) |
The principal legislation governing the protection and processing of personal data, repealing the Personal Data Protection Ordinance, 2025 and the Personal Data Protection (Amendment) Ordinance, 2026. Most provisions are deemed effective from 6 November 2025; sections 23 and 31–35 commence on a date to be notified. It deems personal data to be owned by the data subject and governs consent, lawful grounds for processing, conditions for sensitive and children’s data, security obligations, breach notification, record-keeping, data subject rights, data classification and cross-border transfers, complaints and administrative penalties. Pending publication of the Authentic English Text under section 45, references in this Policy follow the authentic Bangla text, which prevails in case of conflict. |
|
National Data Management Act, 2026 (Act No. 80 of 2026) (NDM Act) |
In force from 10 April 2026, repealing the National Data Management Ordinance, 2025. Constitutes the National Data Management Authority (NDMA) to regulate, manage and secure national, personal and government data across public and private sectors, including compliance monitoring, guidelines, audits, complaint handling and penalties, and provides the interoperability framework referred to in the PDPA. |
|
Money Laundering Prevention Act, 2012 (as amended) |
Imposes client due diligence, record-keeping and reporting obligations on us, including disclosures to the Bangladesh Financial Intelligence Unit. |
|
Cyber Security Act, 2026 (Act No. 81 of 2026) |
In force from 10 April 2026, repealing the Cyber Security Ordinance, 2025. Governs cyber security, critical information infrastructure, cyber offences and lawful interception powers of the Government; informs our information security measures. |
|
Information and Communication Technology Act, 2006 |
Requires reasonable security practices in relation to electronic data and provides for government powers of interception and decryption in defined circumstances. |
|
Bank Companies Act, 1991 (section 12) |
Restricts the removal of banking documents and records outside Bangladesh without the prior permission of Bangladesh Bank; relevant to certain banking and finance matters. |
|
Evidence Act, 1872 (as amended) |
Provides protections for privileged professional communications between lawyer and client, and governs the admissibility of electronic records. |
|
Right to Information Act, 2009 |
Confers on citizens a right to obtain information from public “authorities” and establishes the Information Commission. As a private law firm we are not an “authority” subject to its disclosure obligations, and the Information Commission is not the data protection regulator; the Act is relevant where matters involve information requests to or from public authorities, and its disclosure provisions override conflicting restrictions in other laws. |
|
Bangladesh Bar Council Canons of Professional Conduct and Etiquette |
Professional conduct rules binding on us, including the duty to keep client affairs confidential. |
If you have any questions about this Privacy Policy or our privacy practices, please contact our Data Protection Officer at [email protected].
© LegalSeba LLP 2026. Version 2.2, effective 4 July 2026.
