Navigating the Intersection of Cyber Defense and Free Speech
Navigating the Intersection of Cyber Defense and Free Speech
In Bangladesh, the Digital Security Act (DSA), 2018, was introduced to regulate digital crimes,
online dissemination, and cybersecurity. The lawmakers claimed that it was essential to prevent
criminal acts and abuses in the digital age. But in reality, some fundamental problems and
constitutional concerns have arisen in the enactment and implementation of the law, especially
regarding free expression, freedom of the press, and the right to privacy of citizens.
Firstly, the Digital Security Act provisions are often vague and broadly worded, utilizing terms
such as “misinformation,” “fearful information,” or “complaintful information” that lack specific
definitions. This vagueness can serve as a powerful tool for law enforcement and can increase
self-censorship among citizens. Journalists and critics have noted that the Digital Security Act
has created a “chilling effect,” in which they are afraid to report on government criticism or
corruption.
Secondly, the implementation of the Digital Security Act has been seen as repressive.
International human rights organizations such as Amnesty International and Human Rights
Watch have said that some sections of the law are highly repressive and restrict the right to
freedom of expression.
Thirdly, the Digital Security Act gives excessive powers to law enforcement, especially the
police or investigative agencies; they can conduct warrantless arrests, searches, and
investigations. Such powers increase the risk of abuse if there are no specific limitations on the
formulation and application of laws.
Fourthly, there are constitutional criticisms against the Digital Security Act. The Bangladesh
Constitution, Article 39, states that “freedom of thought, opinion and expression” and “speech
and a free press” are protected to multiple degrees. Some argue that the Digital Security Acts
vague provisions and harsh penalties interfere with these constitutional rights, specifically
endangering freedom of speech and freedom of the press.
In this context, a new law called the Cyber Security Ordinance, 2025 (CSO,2025) was enacted,
which replaced or repealed the Digital Security Act and the later Cyber Security Act, 2023 (CSA
2023). Cyber Security Ordinance 2025 was presented by lawmakers as a revised measure from
the perspective of curbing digital crime and improving cybersecurity. It gained force with its
publication in the Gazette and incorporated several new provisions.
Arrangements to form a National Cyber Security Agency and a National Cyber Security Council,
which will be responsible for detecting, preventing, and suppressing cybercrime. Some old
repressive clauses have been removed or amended, in particular, the Cyber Security Ordinance,
2025, repealed the clause that dealt with propaganda against the war, the national flag, the Father
of the Nation, the national anthem, etc. New crime categories have been added, such as online
sexual harassment, blackmailing, and AI-based cybercrime (such as Deep-Seek, Google Gemini,
etc.)
There is administrative power to remove and block content, but with court oversight, a “Content
Removal Authority” has been formed, and they are required to seek court approval within 72
hours of making a removal decision. If the court does not approve the removal decision, the
content will be reinstated on the screen. In some cases, sentences have been softened:
particularly, speech or publication offences are now bailable, and the maximum sentence has
been reduced. The courts have been given the power to dismiss cases without a discipline or
charge sheet: Magistrates have the power to dismiss suspicious or baseless cases within 24 hours.
Besides, an amendment to (Section 2), two linguistic and definitional corrections were made to
clarify the meanings of key terms. The word “bujhaibe” (meaning ‘shall mean’) was added after
the phrase “access to tool” to ensure precision in interpretation. Minor grammatical corrections
were made to improve sentence structure and legal clarity. Experts noted that these corrections
enhance the technical accuracy and readability of the law. Under Section 50(1) now correctly
refers to “Act No. 39 of 2023” instead of the previous incorrect citation “Act No. 38 of 2023.”
A new sub-section (4A) has been inserted, which states that all pending cases, investigations, or
proceedings under Sections 21, 24, 25, 26, 27, 28, 29, and 31 of the Digital Security Act, 2018
(Act No. 46 of 2018) shall be cancelled. Any sentences or fines already imposed under these
sections shall also be deemed null and void, and no further action may be taken in this regard.
Although some repressive provisions have been removed in the Cyber Security Ordinance, 2025,
the law still gives administrative agencies the power to remove content and monitor. Although
court approval has been introduced as mandatory, it can create opportunities for abuse if the
process is not transparent and effective. The public and civil society organizations are demanding
stronger mechanisms to monitor and challenge the decisions of law enforcement agencies.
Previously, the Digital Security Act had much more extensive powers of arrest and search for the
police or investigative agencies. The draft Cyber Security Ordinance, 2025, included a clause
that allowed searches of digital devices without a court warrant. However, the ICT Department
said that this clause has been removed in the subsequent draft, and such searches can now only
be carried out in limited circumstances in cases related to critical infrastructure. While this is a
positive change, citizens are concerned about whether there are sufficient guarantees to ensure
“privacy”, especially when law enforcement agencies have expanded their surveillance powers.
The addition of new criminal categories such as online sexual harassment, blackmailing, and AI-
based crimes to the Cyber Security Ordinance, 2025, has brought the law up to date. This was a
necessary step. However, it becomes difficult for lawmakers to make decisions when adding new
categories: if a category is inadequately defined, it can create multiple possibilities for abuse. In
particular, if the “AI-based crime” category is kept too broad or vague, ordinary citizens may
unknowingly fall into the trap of the law.
Although the Cyber Security Ordinance, 2025 has moved away from some repressive provisions
and introduced a judicial review mechanism, it may still be challenging to ensure that decisions
by law enforcement agencies, for example, content removal, arrests, are subject to judicial
review and that citizens have effective legal remedies. If safeguards or appeal mechanisms are
weak, the law may deviate from its purpose, and civil rights may be undermined.
The Constitution of Bangladesh, especially Article 39, protects the freedom of expression and
freedom of speech of citizens. However, it allows for “reasonable restrictions” such as those for
public order, indecency, or defamation. The problem arises when lawmakers or enforcers
interpret those restrictions excessively or vaguely, and give the central government too much
power to impose excessive restrictions on freedom of expression.
The Digital Security Act uses clauses such as “fearful information,” “objectionable propaganda,”
etc., which often go beyond the bounds of reasonable restrictions and undermine freedom of
expression. From this perspective, some clauses of the DSA open the way for constitutional
rights, especially freedom of speech and high moral freedom to be violated.
Cyber Security Ordinance, 2025 seeks to redress this balance in some ways, with the new legal
framework containing some measures to limit the power of courts, constructive process, and
“privacy”. Internet access is recognized as a “civil right”.
Another perspective is governance and accountability. Constitutionally, governance requires
“checks and balances”; there needs to be as much control as possible over the power of law
enforcement agencies, so that they cannot make arbitrary decisions. CSO2025 establishes
cybersecurity councils and agencies, but how their transparency, autonomy, and public oversight
structures work will be the real test in the future.
In light of the use and abuse of the Digital Security Act and the potential limitations of Cyber
Security Ordinance, 2025, it is clear that the formulation and implementation of digital security
laws require a delicate balance, security and crime prevention effectiveness, and the protection of
civil rights and freedoms, both of which must be respected. Merely enacting laws is not enough.
Enforcement mechanisms, safeguards, participatory lawmaking, and judicial oversight are
equally important.
Author
Md. Rafiul Haque Chowdhury
Law Department Student of University of Asia Pacific
Dhaka, Bangladesh

Comments
Post a Comment