
Call records, locations and NID copies are being traded openly in Bangladesh, raising serious questions about the right to privacy and the state's ability to protect it.
A stranger with a phone number and Tk 1,000 can buy a person's call history in Bangladesh. The fact-checking organisationDismislab revealed this in an investigation published early last month. Sellers have advertised openly on Facebook, Telegram and WhatsApp for about three years.
The organisation’s researchers searched Facebook for one common phrase between June 15 and July 15 and found 675 posts. Sellers had posted 605 of them to offer personal data. The researchers also traced 10 active websites that list prices for NID copies, call records and phone locations.
To test the market, researchers bought data from three sellers through bKash. An NID copy cost Tk 500 and arrived in 17 minutes. The location of a phone number reached them in 16 minutes.
A three-month call record cost Tk 1,050 and took about two and a half hours to arrive. The researchers checked everything against the real records and found it accurate. One NID even carried a mother's name that its owner had corrected only two months earlier.
A call record shows whom a person spoke to and when. It can also reveal the mobile tower that handled each call, so months of records can map a person's daily movements. Fraudsters can use an NID record to open fake accounts or commit fraud in the victim's name.
The source of the data remains unclear. One seller claimed that his suppliers tap a government database through an API, but the researchers could not verify this. An anonymous senior official of a mobile operator told the researchers that the company had traced some leaks to a law enforcement agency's system and reported them, yet the sales continued.
The authorities have known about the problem for years. The report said the National Telecommunications Monitoring Centre told the home ministry in April 2024 that sellers were trading NID details and call records in 789 social media groups. The inquiry reportedly found that someone had used police officers' login credentials to pull the data, and a constable admitted that he sold call records for money.
A BTRC official said a home ministry committee is now reviewing the matter and may reach a decision within a month or two. The Election Commission, the NID wing and the National Cyber Security Agency offered no substantive comment.
The issue goes beyond crime. Article 43 of the Constitution protects the privacy of correspondence and other means of communication, subject to reasonable legal restrictions. Bangladesh also acceded to the International Covenant on Civil and Political Rights in 2000, and Article 17 of the Covenant bars arbitrary or unlawful interference with privacy and correspondence.
The UN Human Rights Committee says states must protect this right against private parties as well as public authorities. The Personal Data Protection Act, 2026 aims to give that protection. The law says nobody may disclose personal data for a purpose other than the original one without the person's consent.
Anyone whose rights someone violates can complain to the authority. Organisations that fail to protect data face administrative fines, which can reach Tk 25 lakh in some cases.
Whether the law will work remains unclear. The Tech Global Institute reviewed 68 documented data leaks in Bangladesh and found few cases of effective legal action. A complaint-based system also fits this trade poorly, since victims may never learn that sellers have traded their records.
The harm also falls unevenly. Data that helps a fraudster can put a survivor of domestic violence in danger.
The author is a Fellow, Digitally Rights