On discovering a data breach, which regulators or other government agencies should be notified?
In case of a data breach, the affected person should immediately report the incident to the National Response Centre for Cyber Crimes (NR3C) of the Federal Investigation Agency (FIA) (set to be replaced soon by the National Cyber Crime Investigation Agency) under the Prevention of Electronic Crimes Act, 2016 (“PECA 2016”). The report may be submitted in person at a regional office of FIA's Cyber Crime Wing, by post, via email ([email protected]), or through their website – https://complaint.fia.gov.pk/
Where the data breach incident involves a banking company, an electronic money institution, or a payment system operator, the matter should also be reported to the central bank, the State Bank of Pakistan (SBP). Similarly, in case of a data breach involving an insurance company or a non-banking finance company, the incident should be reported to the Securities and Exchange Commission of Pakistan (SECP). In the case of telecom companies, the incident should be reported to Pakistan Telecommunication Authority (PTA).