TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Pakistan TerraLex Guide to Data Protection Guide

Authors:
Saqib Majeed
Date posted:
23/06/2021
Last update:
21/03/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

At present, Pakistan does not have comprehensive data protection legislation. Over the past years, the Government has issued various drafts of such legislation, the latest being the draft Personal Data Protection Act, 2023 (the “Draft PDP Bill”). For the Draft PDP Bill to become law, it requires approval from both houses of Parliament — the National Assembly and the Senate — as well as the President's assent. To date, no further progress has been made, and the Draft PDP Bill has yet to be introduced in Parliament for enactment.

Certain other laws and regulations issued by various local regulators contain provisions related to the privacy and security of personal information.For instance:

  • The Prevention of Electronic Crimes Act, 2016 (“PECA 2016”), defines various offenses related to certain types of data and communication including unauthorized access to, copying, or transmission of data, unauthorized use of identity information of another person, and unauthorized interception of information. The Removal and Blocking of Unlawful Online Content (Procedure, Oversight, and Safeguard) Rules, 2020, issued under PECA 2016 contain certain instructions for social media companies related to local retention of data, the opening of local offices, and the appointment of local agents.
  • Under the National Database and Registration Authority Ordinance, 2000, unauthorized access to, and/or use of any data collected thereunder, including biometric data of the citizens of Pakistan, is a criminal offense punishable with imprisonment up to 14 years or with a fine commensurate with the nature of offense and harm caused by such offense, or with both.
  • Pakistan’s central bank, the State Bank of Pakistan (SBP), has issued several regulations which contain general obligations related to the protection of data of their consumers by companies operating in the banking and financial sectors in Pakistan.
  • Pakistan’s corporate regulator, the Securities and Exchange Commission of Pakistan (SECP), has also issued regulations that contain general obligations for protection and security of data of their consumers by fintech companies and companies operating in the insurance sector in Pakistan.
  • Pakistan’s telecom regulator, Pakistan Telecommunications Authority (PTA), has also issued regulations that cast general obligations requiring companies operating in the telecom sector in Pakistan to protect and maintain the confidentiality of their consumers' data.

To whom do the laws apply?

If enacted in its current form, the Draft PDP Bill will apply to data controllers and processors registered or present in Pakistan that process, control, or authorize the processing of personal data. It will also extend to foreign data controllers and processors operating in Pakistan, whether digitally or non-digitally, and handling personal data related to any commercial or non-commercial activity, including profiling data subjects in Pakistan. Additionally, it will cover data controllers and processors collecting personal data of data subjects in Pakistan. Accordingly, the Draft PDP Bill will have extraterritorial application in certain cases.

As regards to other laws, PECA 2016 applies to every person within the territory of Pakistan. It also applies to any act committed outside Pakistan if such act affects any person, property, information system, or data located in Pakistan.

The regulations issued by various regulators mentioned above apply to the entities operating in Pakistan which are engaged in activities regulated by the relevant regulator. For example, the regulations issued by PTA generally apply to telecom companies, service providers, and social media companies. Likewise, the regulations issued by SBP typically apply to banks, micro-finance banks, financial institutions, and electronic money institutions, etc. Similarly, the regulations issued by SECP apply to fintech companies and those operating in insurance sectors.

Scope of protection

What type of data is covered by the law?

If enacted in its current form, the Draft PDP Bill will apply to:

  1. Personal data — any information that directly or indirectly relates to a natural person who is identified or identifiable from that information alone or in combination with other data held by a data controller;
  2. Sensitive personal data — including financial information, health data, computerized national identity card or passport details, biometric and genetic data, religious beliefs, criminal records, political affiliations, caste, tribe, or ethnicity; and
  3. Critical personal data — data held by public service providers, data classified as critical by sector regulators and the Commission, or data linked to international obligations.

However, anonymized or pseudonymized data that cannot identify an individual will not be considered personal data.

PECA 2016 applies to both content data (that includes any representation of fact, information, or concept for processing in an information system including source code or a program suitable to cause an information system to perform a function) and traffic data (that includes data relating to a communication indicating its origin, destination, route, time, size, duration, or type of service).

Regarding the regulations issued by the local regulators, these regulations cast a general obligation on the relevant entities to take measures to protect the data of their customers without specifying the nature of such data. Such data may include both personal data and sensitive personal data of customers depending on the nature of services provided by the relevant entity and the extent of data collection.

What are the main exemptions (if any)?

If enacted in its current form, the Draft PDP Bill will not apply to: 1. Anonymized, encrypted, or pseudonymized data which is incapable of identifying an individual as such data will not be treated as personal data; 2. Personal data processed by an individual only for that individual’s personal, family, or household affairs, including recreational purposes; and 3. Personal data processed for prevention or detection of crime or investigations, apprehension, or prosecution of offenders.

In addition, the processing of personal data in the following cases will be exempt from the application of specific provisions of the Draft PDP Bill subject to satisfaction of the relevant conditions:

  1. The assessment or collection of any tax or duty or any other imposition of a similar nature by the relevant governmental authority;
  2. Processing of information about the physical or mental health of a data subject where compliance with the relevant legal requirement would be likely to cause serious harm to the physical or mental health of the data subject or any other individual;
  3. Processing of information for preparing statistics or carrying out research;
  4. Processing of data that is necessary for or in connection with an order or judgment of a court;
  5. Processing of data to discharge regulatory functions; or
  6. Processing of data for journalistic, literary, or artistic purposes.

The Draft PDP Bill authorizes the federal government to grant further exemptions and to revoke an existing exemption granted by it.

What rights do the laws grant to the data owners?

If enacted in its current form, the Draft PDP Bill will grant the following rights to the data subjects:

  1. The right to be informed: An individual will be entitled to be informed by a data controller about the processing of his or her personal data by or on behalf of such data controller;
  2. The right to access to personal data: An individual will have the right to access and obtain from a data controller in an intelligible form a copy of his or her personal data processed by or on behalf of such data controller;
  3. The right to correct personal data: If an individual considers that his or her personal data is inaccurate, incomplete, misleading, or not up to date, he or she may make a written request to the relevant data controller to correct his or her personal data;
  4. The right to withdraw consent: An individual may by notice in writing withdraw his or her consent to the processing of personal data in respect of which he or she is a data subject;
  5. The right to restrict processing: An individual may through a written notice require the relevant data controller to cease the processing of his or her personal data or processing of such data for a specified purpose or in a specified manner where such processing is likely to cause substantial damage or distress to such individual or a relevant person;
  6. The right to erasure: An individual may request his or her personal data processed by a data controller be erased.
  7. The right to data portability: An individual has the right to receive their personal data from a data controller in a machine-readable format and transfer it to another controller or processor without restriction. Where feasible, they may request a direct transfer of their personal data between data controllers; and
  8. The right against automated processing: An individual has the right to avoid decisions based solely on automated processing, including profiling, that result in legal obligations or cause significant harm — unless they provide explicit consent. The individual also has the right to request information about such decisions, and human intervention.

The above rights are not absolute. The exercise of any of these rights will be subject to fulfillment of the applicable requirements laid down under the Draft PDP Bill.

As regards existing laws, PECA 2016 entitles the data owner to lodge a criminal complaint in case of unauthorized access to or use of data. The regulations issued by several local regulators do not expressly provide any right to the data owner. However, it is still possible for the data owner to file a complaint with the relevant regulator in case of failure of the relevant entity to comply with the applicable regulations.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

If enacted in its current form, the Draft PDP Bill will allow the processing of personal data or sensitive personal data on any of the following grounds:

Processing of personal data:

  1. Consent: where the data subject has given consent to the processing of his or her personal;
  2. Performance of a contract: where the processing is necessary for the performance of a contract to which the data subject is a party, or for taking steps at the request of the data subject to enter into a contract;
  3. Compliance of a legal obligation: where the processing is necessary for compliance of a legal obligation by the data controller;
  4. Vital interests: where the processing is necessary to protect the vital interests of the data subject;
  5. Public health, medical emergency, research: for treatment, public health, medical or research purposes or to respond to any medical emergency involving a threat to life or the health of a data subject or any other individual;
  6. Administration of justice: where the processing is necessary for the administration of justice under a court order;
  7. Legitimate interests: where the processing is necessary for legitimate interests pursued by the data controller; and
  8. Public duty: where the processing is necessary for the exercise of any functions conferred on any person by or under any law.

Sensitive personal data:

In case of processing of sensitive personal data, the data controller must establish either that the information contained in the personal data has been made public as a result of steps deliberately taken by the data subject or that the data subject has given explicit consent to the processing of his or her personal data (provided that such consent is not restricted by any other applicable law) and such processing is necessary on any of the following grounds:

  1. Employment: The processing is necessary for exercising or performing any right or obligation which is conferred or imposed by law on the data controller in connection with employment;
  2. Vital Interest: The processing is necessary to protect the vital interests of the data subject or another person, in a case where the consent cannot be given by or on behalf of the data subject, or the data controller cannot reasonably be expected to obtain the consent of the data subject or the processing is necessary to protect the vital interests of another person, in a case where consent by or on behalf of the data subject has been unreasonably withheld;
  3. Medical purpose: the processing is necessary for medical purposes and is undertaken by a healthcare professional or a person who in the circumstances owes a duty of confidentiality which is equivalent to that which would arise if that person were a healthcare professional;
  4. Legal proceedings: the processing is necessary for, or in connection with, any legal proceedings;
  5. Legal advice: the processing is necessary for obtaining legal advice while ensuring its integrity and secrecy;
  6. Legal claim: the processing is necessary for establishing, exercising, or defending legal rights;
  7. Court order: the processing is necessary for the administration of justice under an order passed by a court of competent jurisdiction; or
  8. Discharge of duty: the processing is necessary for the exercise of any functions conferred on any person by or under any written law.

PECA 2016 and the regulations issued by several local regulators are silent on this issue.

What are the main obligations imposed by the law?

If enacted in its current form, the Draft PDP Bill will impose the following main obligations on the data controllers:

  1. Lawfulness: Personal data should be collected with the consent of the data subject, or for another lawful purpose as specified in the Draft PDP Bill;
  2. Transparency: Data controller must inform the data subject about the collection of his or her data, the legal basis of doing that, the use of that data, and its sharing with any third parties;
  3. Purpose limitation: Personal data should only be processed for a lawful purpose directly related to an activity of the data controller. Processing of personal data must be necessary or directly related to that purpose;
  4. Non-disclosure: Personal data must not be disclosed, without consent of the data subjects, for any purpose other than the purpose for which the personal data was disclosed or a purpose directly related to that purpose and any third party other than the parties in respect of which such consent was granted;
  5. Data minimization: Personal data should be adequate but not excessive in relation to the purposes for which it is processed;
  6. Accuracy: Personal data should be accurate, complete, not misleading, and kept up to date having regard to the purpose for which it was collected and processed;
  7. Storage limitation: Personal data should not be kept for longer than is necessary for the purposes for which the personal data is processed; and
  8. Integrity and security: data controllers must comply with all applicable security standards to protect personal data from any loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction. Any breach of personal data should be promptly reported.

As regards the current laws, PECA 2016 defines various offenses related to certain types of data and communication and prohibits a person from unauthorized access to, copying, or transmission of data, and unauthorized use of identity information of another person, and unauthorized interception of information. Similarly, the regulations issued by several local regulators cast a general duly on the relevant entities for the protection and security of data collected by them from their customers.

Do the laws establish a data retention period to be observed?

The Draft PDP Bill does not establish a retention period. However, it requires that the personal data processed for any purpose shall not be kept longer than is necessary for the fulfillment of that purpose.

The current laws and regulations are not explicit on this issue. However, under PECA 2016, an authorized officer may require the person in control of an information system to preserve and maintain the integrity of specified data for up to ninety days. PECA 2016 also requires that a service provider will retain specified traffic data at least for one year or such other period as may be specified by PTA. There may also be data retention requirements for companies operating under banking, insurance, and telecommunication laws.

Must the data processing activities be recorded under the law?

The Draft PDP Bill requires that a data controller shall keep and maintain a record of any application, notice, request, or any other information relating to personal data that has been or is being processed by him. The manner and form in which such record will be maintained will be determined by the National Commission for Personal Data Protection ("NCPDP") to be established by the government after the enactment of the Draft PDP Bill.

The current laws and regulations are not explicit on this issue and do not expressly require data processing activities to be recorded.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

At present, Pakistan does not have a Data Protection National Authority. The Draft PDP Bill calls for the establishment of NCPDP by the government within 6 months of the enactment of the Draft PDP Bill. The main functions of NCPDP, as per the Draft PDP Bill, will be to protect the interest of the data subjects, enforce protection of personal data, prevent any misuse of personal data, promote awareness of data protection, receive and decide complaints, and cooperate with foreign authorities and international organizations in the field of data protection.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

A data controller or processor designated as “significant” by the NCPDP must appoint a Data Protection Officer (“DPO”). The Draft PDP Bill requires the DPO to be well-versed in personal data collection, processing, and associated risks. However, it does not define the DPO’s role. Instead, the NCPDP is tasked with developing a compliance framework that will outline the DPO’s responsibilities. This framework is expected to be issued after the NCPDP is established, following the enactment of the Draft PDP Bill in its current form.

The current laws and regulations are not explicit on this issue and do not expressly require data processing activities to be recorded. However, the rules issued by PTA require every social media company and service provider with more than half a million subscribers from Pakistan to appoint a local representative in Pakistan.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

If enacted in its current form, the Draft PDP Bill will allow the transfer of personal data outside Pakistan, subject to:

  1. The destination country having an adequate data protection legal regime consistent with the Draft PDP Bill; and
  2. The data being processed in line with the Draft PDP Bill and, where applicable, the data subject’s explicit consent.

The NCPDP may permit cross-border transfers to countries without adequate data protection laws in certain cases, including:

  • Transfers under a binding contract,
  • The data subject’s explicit consent (provided it doesn’t conflict with Pakistan’s public interest or national security), or
  • Where international cooperation is required under relevant obligations.

However, any critical personal data will only be processed in a server or data center located in Pakistan.

As regards the current laws, the regulations issued by SBP require that the banking companies and financial institutions must keep their data in Pakistan. Likewise, the rules issued by PTA state that the social media companies having more than half a million subscribers in Pakistan will be required in the future to establish data servers in Pakistan and to keep data of their Pakistani subscribers and related online content on servers in Pakistan. Apart from this, there are no rules to regulate the transfer of data outside Pakistan.

Is it necessary to notify the National Authority prior to the international transfer?

Not applicable as, at present, there is no Data Protection National Authority in Pakistan. The Draft PDP Bill does not require notification of an international transfer of personal data to PDPAP. However, it requires PDPAP to monitor the cross-border transfer of personal data and to develop a framework for regulating the same. It appears likely on account of this requirement that PDPAP may include a condition in the said framework to notify it before any international transfer of personal data.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

If enacted in its current form, the Draft PDP Bill will cast a general obligation on the data controllers and data processors to take practical steps to protect the personal data by having regard:

  1. To the nature of the personal data and the harm that would result from such loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction;
  2. To the place or location where the personal data is stored;
  3. To any security measures incorporated into any equipment in which the personal data is stored;
  4. To the measures taken for ensuring the reliability, integrity, and competence of personnel having access to the personal data; and
  5. To the measures taken for ensuring the secure transfer of personal data.

The Draft PDP Bill obligates NCPDP to prescribe standards to protect personal data from any loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction. It appears likely that NCPDP, after its establishment, will prescribe specific information security standards to be followed by data controllers or processors.

As regards the current laws, the regulations made by SBP, SECP, and PTA impose general requirements on the relevant companies for the security of consumers’ data. They do not impose any specific information security standards.

Do the laws establish any kind of mandatory notification duty?

If the Draft PDP Bill is enacted in its current form, a data controller shall be required to inform a data subject by a written notice about the processing and intended use of his or her personal data. Likewise, in the event of a personal data breach, the data controller shall without undue delay and where reasonably possible, not beyond 72 hours of becoming aware of the personal data breach, notify NCPDP in respect of the personal data breach except where the personal data breach is unlikely to result in a risk to the rights and freedoms of data subjects.

As regards the current laws, the regulations made by SBP, SECP, and PTA require the relevant companies to report any data breach incidents to the relevant regulator.

What are the sanctions for noncompliance with data protection laws?

The Draft PDP Bill defines several offenses all of which, except one, are punishable with fines. The amount of fine may go up to USD 2,000,000 depending on the nature of the offense.

A data controller which continues to process data even after withdrawal of consent by the data subject will be liable to a fine not exceeding USD 50,000. A data controller may be held responsible for any breaches under the Draft PDP Bill committed by its employees or agents and may be punished with a fine of up to 1% of its annual gross revenue in Pakistan or USD 200,000, whichever is higher.

PECA 2016 defines various offenses relating to data. These offenses are punishable with imprisonment, a fine, or both. The term of imprisonment and/or the amount of fine varies depending on the severity of the offense. Likewise, a failure to comply with the regulations issued by a regulator may result in the imposition of a fine and/or the cancellation of the license of the relevant entity to carry out the relevant regulated activity.

Other comments

Other comments

The Draft PDP Bill is the fifth draft of the legislation on the protection of personal data issued by the government (the first draft bill was issued back in 2005). Still, several provisions of the Draft PDP Bill are vague and require clarification. No progress has been made on the Draft PDP Bill during the last more than one year period and it appears unlikely that permanent legislation based on the Draft PDP Bill will be enacted soon.

Nevertheless, the Draft PDP Bill indicates what Pakistan’s personal data protection and privacy law will look like. Therefore, it is recommended that the companies operating in Pakistan should, to the extent possible, formulate their privacy and data processing policies keeping in view the requirements contained in the Draft PDP Bill.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.