We find the reported online sale of ordinary citizens’ personal information deeply concerning. According to information verification organisation DismissLab, sellers are offering NID details, Call Detail Records (CDRs), mobile phone locations, SMS records, TINs, passport copies and mobile financial service account statements through Facebook, websites, Telegram and WhatsApp. Its investigation found 10 active websites selling such details and more than 600 related Facebook advertisements within a month.
Particularly alarming is the ease and speed with which sensitive data changes hands. DismissLab researchers reportedly paid Tk500 and received a PDF copy of an NID card within 17 minutes. It contained the person’s name, photograph, date of birth and even an updated version of the mother’s name. In another case, researchers paid Tk1,050 for three months of CDRs and received them within two and a half hours. Meanwhile, a website reportedly provided a phone number’s last active time, mobile tower-based location, address and a Google Maps link within minutes of payment. At least 112 mobile numbers and 36 active Facebook groups reportedly promoted these services. More importantly, these findings suggest organised networks are involved in the illegal trade in personal information that should remain strictly protected.
The consequences of this exposure can be severe. CDRs can reveal whom a person contacted, when and for how long, while location and IMEI records can expose movement and communication patterns. Criminals can therefore use these details for surveillance, harassment, fraud and blackmail. Citizens, however, have little say in how institutions store, access and protect their personal records. Moreover, the illegal market can erode public trust in NID databases, telecommunications services and digital financial systems. Digitalisation should make life easier, not leave people more vulnerable.
The government must therefore act without delay. Law-enforcement agencies should identify and prosecute the sellers, trace their networks and determine how the data was obtained. The BTRC should order mobile operators to audit access to subscriber, CDR and location records and report unauthorised access to the regulator. The National Identity Registration Wing must audit NID database access and revoke unnecessary privileges. Also, Bangladesh Bank and MFS providers should trace payment channels linked to the illegal trade and share evidence with
investigators.
At the same time, digital platforms should remove identified accounts and groups while preserving relevant evidence. All agencies and companies holding sensitive records must promptly report serious breaches to the appropriate authorities. Officials and institutions responsible through negligence or abuse of access must face appropriate legal and financial
penalties.
We expect the state to make privacy protection a clear institutional responsibility. Independent security audits, strict access controls and effective oversight should be mandatory. Above all, compliance must be monitored and violations punished. Citizens should be able to trust the digital systems they are increasingly required to use. Privacy is a fundamental right, and protecting the information citizens entrust to the state is its solemn duty.