TODAY’S PAPER | August 24, 2026 | EPAPER

Pakistan can no longer wait for personal data protection law

Recurring incidents show cost of delay, while digital ambitions demonstrate scale of opportunity


Saifullah Khan August 24, 2026 4 min read
Photo: File

ISLAMABAD:

Pakistan's digital economy is expanding faster than its legal protections for personal data. Recent incidents continue to demonstrate the scale and sophistication of threats facing individuals and organisations alike.

A government inquiry reportedly found that the personal particulars of 2.7 million citizens held by NADRA were compromised between 2019 and 2023. In May 2025, the National Cyber Emergency Response Team warned that credentials linked to more than 180 million internet users had appeared in an unencrypted database. More recently, the National Cyber Crime Investigation Agency (NCCIA) announced arrests linked to the alleged unlawful acquisition and sale of call records, SIM details, family registration information and location data.

In addition, cybersecurity researchers have recently identified Pakistan among the countries affected by sophisticated SIM card-related cyber scams, highlighting the growing risks associated with the misuse of personal data and digital identities. Collectively, these incidents reinforce one unavoidable conclusion: Pakistan can no longer afford to delay the enactment of a comprehensive Personal Data Protection Law (PDPL).

The first and most compelling reason is the protection of citizens' rights. Article 14 of the Constitution protects the dignity of the individual and the privacy of the home. Yet citizens routinely provide identity, financial, health, communications and location data to public authorities and private organisations without the benefit of a comprehensive law governing its collection, use, retention, sharing and protection. A modern PDPL should establish lawful grounds for processing, security obligations, breach notification requirements, accountability for controllers and processors, and meaningful rights and remedies for individuals.

Cybercrime laws and sectoral regulations remain important, but they serve a different purpose. Criminal enforcement generally responds after wrongdoing has occurred. A dedicated data protection law is preventive, it requires organisations to collect only necessary data, process it for legitimate purposes, retain it only as long as necessary, implement appropriate safeguards and demonstrate ongoing compliance.

The second reason is commercial. Pakistan's IT and IT-enabled services sector has become an increasingly important source of foreign exchange. The finance minister recently highlighted that IT exports have grown to approximately $4.5 billion, with a national ambition to increase them to $25 billion within the next five years. Achieving that objective will require more than technical talent and competitive pricing. It will also require international confidence in Pakistan's legal framework for handling personal data.

In today's digital economy, personal data moves only where trust exists, and trust increasingly depends upon the existence of a credible legal framework for its protection. Foreign banks, hospitals, technology companies and other multinational organisations are often required to ensure that personal data is transferred only to jurisdictions providing an adequate level of legal protection, or where equivalent safeguards can be demonstrated. While enacting a PDPL would not by itself make Pakistan an "adequate protection jurisdiction", it is the indispensable first milestone towards that objective. Without a dedicated legal framework, Pakistani software houses, BPO providers, fintech companies, cloud service providers and AI developers may continue to face additional contractual hurdles, or even exclusion, from projects involving transfer of personal data to Pakistan.

The proposed law is equally important for the effective functioning of the newly established Pakistan Digital Authority. As Pakistan expands digital identity, e-governance, digital payments and AI-enabled public services, public confidence will depend upon the knowledge that personal information is collected lawfully, protected against misuse and subject to independent oversight.

The European Union, the United Kingdom, Singapore, Brazil, Saudi Arabia, the United Arab Emirates, China, India (and many more) have already enacted comprehensive personal data protection laws. While their legal models differ as regards respective legal system, they have collectively demonstrated that modern data privacy legislation can strengthen consumer confidence, facilitate responsible innovation and enhance participation in global digital economy.

Pakistan is not starting from scratch. In 2023, the Ministry of Information Technology and Telecommunication (MoITT) published a substantially revised draft of the Personal Data Protection Bill following extensive stakeholder consultations. The 2023 draft provides a sound legislative foundation. It incorporates internationally recognised principles, including lawful processing, accountability, data subject rights, controller and processor obligations, security requirements and safeguards governing international transfers of personal data. The legislative groundwork has therefore largely been completed, what is now required is the political will to enact the law and establish an effective implementation framework.

The PDPL should therefore not be viewed merely as another regulatory statute. It is simultaneously a constitutional safeguard, a foundation for trusted digital government and a strategic economic reform capable of supporting technology exports, facilitating international data transfers and, over time, positioning Pakistan as a jurisdiction capable of meeting internationally recognised standards of adequate protection. Pakistan's recurring data incidents show the cost of delay, while its digital ambitions demonstrate the scale of the opportunity. The question is no longer whether Pakistan needs a modern data protection law, but how much longer it can afford to proceed without one.

The writer is a practicing lawyer. His practice areas include data privacy, trade remedy laws of the WTO, customs and competition law

COMMENTS

Replying to X

Comments are moderated and generally will be posted if they are on-topic and not abusive.

For more information, please see our Comments FAQ