Insights · Policy
Nepal's Privacy Act and your CRM, chatbot and AI tools
The short version
Yes, Nepal's Individual Privacy Act, 2075 (2018) applies to your business. If you collect a customer's name, phone number, citizenship details or purchase history, you need their consent, you can only use that data for the purpose you collected it for, and you cannot hand it to anyone else without permission. Breaking the listed rules can mean up to three years in prison, a fine of up to NPR 30,000, or both.
That is the short version. The longer one matters more, because most SMEs now push customer data through five or six tools a day, and some of those tools sit in other countries. This guide walks through what the Act actually says, what it leaves out, and what it means for a CRM, a website chatbot, ChatGPT or Claude, call recordings and KYC files. One thing up front: this is general information, not legal advice. For a specific decision, talk to a Nepali lawyer.
What does the Privacy Act 2075 actually say?
The Act, in force since 2018 and backed by the Individual Privacy Regulation, 2077 (2020), defines personal information broadly in Section 2(c). It covers caste, ethnicity, religion and marital status; education; address, phone number and email; passport, citizenship, national ID, driving licence and voter ID details; fingerprints, retina scans and other biometrics; criminal records; and letters that mention personal details. In practice, almost every row in your CRM qualifies.
The rules that bite hardest for a private business are these:
- Consent to collect. Section 12(2) says a person's consent must be obtained when collecting their personal or family data.
- Purpose limitation. Section 12(3) says data collected by a public body or body corporate with consent may be used only for the purpose it was collected for.
- No disclosure without consent. Section 12(4) lists data you cannot give to anyone or publish without consent, including health, income and property, employment, biometrics, signatures and business or transaction details. Section 26(1) repeats the ban for any body corporate.
- Sensitive data. Section 27 treats caste, political affiliation, religion, health, sexual orientation and property details as sensitive, and bars public bodies from processing them outside narrow exceptions.
- Recording conversations. Section 19(3) bars recording talks held over electronic means without the consent of the people involved.
- Security. Section 25 requires public bodies to guard collected data against unauthorised access, change, disclosure or transmission.
Penalties are in Section 29: imprisonment of up to three years, a fine of up to NPR 30,000, or both, for breaches of the listed sections, including 12(4), 19(2)-(3) and 26(1). Section 31 lets a victim ask the District Court for compensation on top of that, and Section 30 gives most complainants three months to file.
What the Act leaves out matters just as much, so here are the gaps. The Act has no dedicated data protection regulator; complaints go to the District Court, and for some offences the Government of Nepal becomes the plaintiff. It has no duty to notify anyone after a data breach. It sets no general retention period for private companies. The explicit security duty in Section 25 is written for public bodies. And it is silent on sending data abroad, a gap Nepali commentators flagged years ago.
None of that is a licence to be careless. A breach you can't explain still turns into a complaint under Sections 12 or 26, and customers remember. Treat the gaps as places where good practice has to do the work the law doesn't.
What has changed since 2018?
Three things are moving. First, the Information Technology and Cyber Security Bill, 2082, tabled in the House of Representatives in 2025, is meant to replace the Electronic Transactions Act, 2063 and adds personal-data duties, including destroying data once its purpose is served. The Kathmandu Post reported free-speech concerns about it in August 2025. Check its status before relying on either text; until a replacement is in force, the 2063 Act remains the baseline for electronic records.
Second, the National AI Policy, 2082, approved in August 2025, calls for laws on the ownership, privacy and security of personal and institutional data used in AI. It is a policy, not a statute, but it signals where rules are heading. Third, regulated sectors already carry extra duties: banks and financial institutions follow Nepal Rastra Bank's IT Guidelines on confidentiality, outsourcing and information security, and the Data Center and Cloud Service directive of 2081 requires providers to be listed with the Department of Information Technology.
How does personal data flow through a typical SME stack?
Here is the path a single enquiry usually takes: a web form, then the CRM, then an email tool, then someone pastes it into an AI assistant, and finally it sits in backups for years. Each hop is a place where consent, minimisation, access control or deletion either happens or doesn't. Tap any node to see which duty applies there.
Where the Privacy Act touches a typical SME data flow
One customer enquiry, five systems, four duties
Tap any component above for its role and the real tech.
Duties from the Privacy Act 2075, Sections 12, 19, 25 and 26, mapped onto an ordinary SME tool chain.
- Customer (External): The data subject. Under Section 12(2) their consent is needed when you collect their data, and under Section 12(3) you may use it only for that stated purpose.
- Web form + chatbot (Client, Consent checkbox, privacy notice): Where consent is captured. Ask only for fields you need (minimisation), say why, and log the consent timestamp with the record.
- CRM (Data, HubSpot, Zoho, custom): The system of record. Role-based access, no shared logins, and a field that records consent and purpose. Section 26(1) bars passing records to anyone without consent.
- Email and SMS tool (Service, Mailchimp, Sparrow SMS): Send only to contacts whose consent covers marketing. Promotional SMS or email also needs prior consent under the Advertisement (Regulation) Act 2076, per DLA Piper.
- Staff laptops (External, Exports, spreadsheets): The quiet leak. CSV exports and downloaded KYC scans spread copies you can no longer delete. Limit export rights.
- Redaction step (API, Mask names, IDs, phone numbers): Strip or mask identifiers before text reaches an AI tool. Most summarising and drafting tasks don't need the customer's name or citizenship number.
- AI assistant (Model / AI, ChatGPT Business, Claude, Gemini for Workspace): Use business tiers: OpenAI, Anthropic and Google say business and API data isn't used for training by default. Consumer accounts follow different rules.
- Backups (Data, Cloud storage, NAS): Encrypt, restrict who can restore, and include backups in your deletion schedule, or deleted customers live on in old snapshots.
- Deletion job (Service, Scheduled purge + log): The Act sets no general retention period, so set your own. Keep what a sector law requires (for example KYC under AML rules), purge the rest, and log it.
Tap a component to see which privacy duty applies at that step.
What does it mean for your CRM and your website chatbot?
For the CRM, the Act's core demands translate into a short list. Record consent and purpose alongside each contact. Collect only what the purpose needs; a delivery business rarely needs a citizenship number. Give each staff member their own login with the least access that works. And don't share the list with a partner, a sister company or a marketing agency unless the customer agreed to it, because Section 26(1) makes that an offence.
A website chatbot is a data-collection form that talks. Show a one-line notice before the first message, say what you keep and for how long, and don't ask for ID numbers in chat. Keep transcripts on a timer, not forever. We covered the wider set of practical AI jobs for small firms in our guide to AI for Nepali SMEs; the same rules apply to every one of them. For a public-sector version with audit logs built in, see the citizen-services assistant blueprint.
Is it safe to paste customer data into ChatGPT, Claude or Gemini?
It depends on which account you use. OpenAI says it does not train on data from ChatGPT Business, Enterprise, Edu or its API by default, and lets eligible customers set retention, including zero data retention on the API. Anthropic says it doesn't use inputs or outputs from its commercial products to train models, unless you send feedback or opt in. Google says Gemini in Workspace doesn't use customer data to train models without the customer's permission, and content isn't reviewed by humans for that purpose.
Consumer accounts are a different story, and their settings change. If staff paste customer records into personal accounts, you have handed data to a third party without consent, which is exactly what Section 26 forbids. The practical fix is dull but effective: a company account on a business tier, a written rule about what may be pasted, and masking names and ID numbers before anything leaves your systems.
Can you send data to servers outside Nepal?
Here is the honest answer: the Privacy Act doesn't say. There is no clause that permits transfers abroad and none that bans them. Most SaaS tools Nepali firms use, from CRMs to email platforms to every major AI model, run outside the country, and the Act doesn't make that illegal on its face. What it does say still applies wherever the server sits: you need consent, you must stick to the purpose, and you can't disclose data to others without permission.
Sector rules can be stricter. Banks and financial institutions answer to Nepal Rastra Bank's IT Guidelines, which cover outsourcing and information security, and government projects fall under the 2081 cloud directive. If you are in either group, get the regulator's position in writing before moving data offshore. If you're not, tell customers in your privacy notice that their data may be processed abroad, and name the vendors.
What about call recordings and KYC documents?
Call recordings fall squarely under Section 19(3): recording a conversation held over electronic means needs the consent of the people talking. The familiar opening line, telling callers the call is recorded and why, is the minimum. Store recordings with the same access control as the CRM, and delete them on a schedule.
KYC files are the most sensitive thing most businesses hold: citizenship scans, photos, sometimes fingerprints, all named in Section 2(c) and 12(4). Anti-money-laundering rules set their own minimum retention for financial institutions, so check that before you delete anything. Beyond that, encrypt the files, keep them out of shared drives, and never paste them into a general chatbot. Our KYC document AI blueprint shows how extraction can run with audit trails and masked outputs.
How does Nepal's law compare with the GDPR and India's DPDP Act?
If you serve European or Indian customers, their laws may reach you too. The comparison below shows why Nepal's Act feels light on paper: no regulator, no breach-notice rule, a small fixed fine. The GDPR and India's DPDP Act 2023 are far heavier.
Nepal's Privacy Act vs GDPR vs India's DPDP Act
Key points for a business handling customer data
| Criterion | Nepal Privacy Act 2075 | EU GDPR (2016/679) | India DPDP Act 2023 |
|---|---|---|---|
| Applies to private companies | ✓ | ✓ | ✓ |
| Consent to collect | RequiredSection 12(2) | One of six legal basesArticle 6 | Consent or legitimate usesSections 6-7 |
| Dedicated regulator | ✕District Court complaints | ✓National supervisory authorities | ✓Data Protection Board of India |
| Breach notification duty | ✕ | 72 hours to authorityArticle 33 | To Board and each personSection 8(6) |
| Cross-border transfer rules | SilentNo clause either way | Adequacy or safeguardsArticles 44-49 | Allowed unless restrictedSection 16 |
| Maximum penalty | 3 years' prison and/or NPR 30,000Section 29(2) | EUR 20m or 4% of global turnoverArticle 83(5) | Up to INR 250 croreSchedule |
| Court-ordered compensation to victims | ✓Section 31 | ✓Article 82 | ✕No compensation route in the Act |
Nepal's Act is broad in scope but light on enforcement machinery. Sources: The Privacy Act, 2075 (Nepal Law Commission English text), Sections 12, 29, 31; Regulation (EU) 2016/679 (EUR-Lex), Articles 6, 33, 44-49, 82, 83; Digital Personal Data Protection Act, 2023 (MeitY), Sections 6-8, 16 and Schedule. General information, not legal advice. As of 1 September 2026.
Hover a row to compare how each law handles the same issue.
What should you do this month?
You don't need a compliance department. You need a short list you actually finish. Filter the table below by tool or by section to find what applies to you.
Privacy Act obligations vs practical actions
| Practical action | |||
|---|---|---|---|
| Get consent when collecting | Privacy Act s.12(2) | Web form, chatbot | Consent checkbox plus one-line notice; store the timestamp with the record |
| Use data only for its purpose | Privacy Act s.12(3) | CRM, email tool | Record purpose per contact; separate marketing consent from service consent |
| No disclosure without consent | Privacy Act s.12(4), s.26(1) | AI assistant, agencies, partners | Business-tier AI accounts only; mask names and IDs; no list sharing |
| Consent to record calls | Privacy Act s.19(3) | Call centre, phone system | Recorded-call notice at the start; restrict playback access |
| Protect sensitive data | Privacy Act s.12(4), s.27 | KYC store, HR files | Encrypt at rest; no shared drives; access log |
| Guard against unauthorised access | Privacy Act s.25 (public bodies); good practice for all | CRM, backups, laptops | Individual logins, 2FA, limit CSV exports |
| Consent for marketing messages | Advertisement (Regulation) Act 2076 | Email and SMS tool | Opt-in list only; easy unsubscribe |
| Sector rules for BFIs | NRB IT Guidelines | Core banking, outsourced cloud | Check outsourcing and offshore hosting with NRB rules first |
A working checklist, not a legal opinion. Sources: The Privacy Act, 2075, Sections 12, 19, 25, 26, 27 (Nepal Law Commission English text); DLA Piper, Data protection laws in Nepal (Mar 2026) for the Advertisement Act consent rule; Nepal Rastra Bank IT Guidelines (2012).
Type a tool name or section number to filter the checklist.
If you only do three things, do these: move every staff AI account to a business tier, add a consent line to your forms and your call greeting, and write down how long you keep each kind of record. That covers most of the real risk for a typical SME.
We build AI and automation for Nepali businesses, and privacy is part of the design from the first sketch: redaction before any model call, audit logs, consent fields and deletion jobs that actually run. If you want a second pair of eyes on how customer data moves through your tools, talk to our team or see what our Neural AI service covers.
Sources
Frequently asked
Does Nepal's Privacy Act apply to private companies?
Yes. Section 12 requires consent whenever anyone collects a person's data, and Section 26 bars a public body or body corporate from using or passing on personal information without the person's consent, apart from narrow legal exceptions. A registered company is a body corporate, so a private SME with a customer list is covered, not just government offices.
What is the penalty for breaking the Privacy Act 2075?
Section 29 sets imprisonment of up to three years, a fine of up to NPR 30,000, or both, for the listed offences. Under Section 31, a victim can also ask the District Court for compensation for loss or harm. Most complaints must be filed within three months of the act, under Section 30. There is no separate turnover-based fine like the GDPR's.
Can a Nepali business store customer data on servers outside Nepal?
The Privacy Act 2075 does not directly address cross-border transfer. It neither allows nor bans it in plain words. Consent, purpose and disclosure rules still apply wherever the server sits. Banks and financial institutions also answer to Nepal Rastra Bank rules, and government work has its own cloud directives, so check your sector before moving data abroad.
Want this run on your numbers?
We'll do the same analysis on one of your workflows in the two-week Automation Sprint.
Related service · Neural AI