Add-ons · Data
Which documents SI may read, and who may see them.
Super Intelligence (SI) answers each person only from files that person may open. The Data add-on settles that list before anything is indexed, and prepares your organisation for the duties of the Personal Data Protection Act 2026.
Where it starts
A new law, with a date attached
The Personal Data Protection Act 2026 (Act 63, 10 April 2026) asks organisations that hold personal data for clear consent, notice to the people concerned, security measures, breach notice to the regulator and to affected people, and answers to requests for access, correction, erasure and portability. Organisations classed as significant data controllers must appoint a Chief Data Officer. Fines reach BDT 25 lakh, or BDT 50 lakh for significant data controllers.
The officer and fine sections start after an 18-month transition, around October 2027, on a date the gazette sets. The rules under the Act had not been issued as of October 2026, so we read the Act itself with a partner law firm and update the kit as the rules arrive.
For Bahlul SI
What it does for the product
An SI server reads what you load into it and answers each person only from the files that person may open. Somebody has to decide what goes in and who may see it. The Data add-on produces that list: for every document collection, its owner, the access group that may open it, its class under the Act, and the consent or notice that covers any personal data inside.
Each data owner approves their row before anything is indexed. The first phase of most SI servers uses policies, SOPs, circulars and manuals rather than personal data, so the harder questions come later and with a plan.
A person still decides. The data owner approves each collection, your named approver signs the list, and a lawyer gives any legal opinion. We prepare the records and the evidence.
Offers and prices
A package, then a retainer
| Offer | Unit | 2027 price | Duration |
|---|---|---|---|
| Data protection readiness package | Package | BDT 9.5 lakh | Six weeks |
| Data office retainer | Month | BDT 1.2 lakh | Monthly |
Proposed 2027 prices, before VAT. The standard package covers one legal entity, up to 15 systems that hold personal data and 8 to 12 interviews with data owners; larger organisations get a written quote.
Sold on its own
Readiness for the Act, with or without SI
Organisations with no SI plans buy the package as readiness for the Act. In six weeks you get a baseline score against the Act's duties, a list of your systems and a record of processing, a list of the personal data you send abroad, a rated gap register reviewed by a partner law firm, five policy drafts, a personal data breach response plan, a readiness report with a 90-day, 6-month and 12-month roadmap, a two-hour handover and a check 90 days later.
The retainer keeps it current: a part-time data office that updates the record of processing, runs the request log with you, trains one team a month, checks breach readiness, sends a report by the fifth working day and runs a tabletop exercise each quarter. For a Bahlul SI server, it also checks each new document collection before it is indexed.
Who delivers
A data protection officer and a partner law firm
A data protection officer from Bahlul World leads each package, with a named approver on your side. A partner law firm reviews every legal reading, the duty checklist and the policy pack before you see them. We work from descriptions, counts and interviews, not copies of your data; samples are viewed on your premises, and the founders abroad see client data only with your written consent.
We sell readiness and evidence. Lawyers give legal opinions, and certification bodies certify. Nothing we deliver claims to make you compliant; it shows where you stand and what to do next.
FAQ
Questions we are asked
Does the package make us compliant with the Act?
No, and we do not say it does. It gives you a baseline, a gap register reviewed by a partner law firm, the policies, the breach plan and a roadmap. Legal opinions come from lawyers, and compliance is a judgement a regulator or a court makes.
Do you need copies of our personal data?
No. We work from descriptions, counts and interviews with your data owners. Where a sample must be seen, it is seen on your premises. Client data stays in Bangladesh, and the founders abroad see it only with your written consent.
We have no SI plans. Is the package still for us?
Yes. Most of the package is readiness for the Act: the inventory, the record of processing, the policies and the breach plan. The SI documents list is the part added, within the same package, for organisations that plan a server.
Start with the collections your staff search most
Bring the list of document sets you would load first. In six weeks you will know which may be indexed, who may open each, and what the Act asks of you.