Loading...
Data localization by sector, government cloud policy & CSP requirements
| Provider/Facility | Location | Type | Tier | Key Details | Reference |
|---|---|---|---|---|---|
| PM Cloud Startups | National (Ignite) | Government Cloud | N/A | Cloud startup program launched 2026 | |
| NADRA Data Centers | Islamabad + Regional | Government | Tier-III+ | Serves 220M+ citizens biometric data | |
| Supernet Data Center | Karachi | Commercial | Tier-III | Major carrier-neutral facility | |
| Cyber Internet Services | Karachi | Commercial | Tier-II+ | Largest ISP data center | |
| PTA Critical Telecom Data | Nationwide | Regulatory | N/A | Critical Telecom Data Regulations (Nov 2020) | |
| SBP Banking Infrastructure | Karachi/Islamabad | Financial | Tier-III+ | SBP Cyber Shield launched Mar 2026 | |
| Government Cloud (Federal) | Islamabad | Government | Tier-II+ | Digital Nation Pakistan initiative | |
| NLC Data Center | Islamabad | Government | N/A | National Logistics Corporation |
| Regulation/Standard | Authority | Data Type | Requirement | Status | Reference |
|---|---|---|---|---|---|
| PECA 2016 | MoITT | Electronic evidence | Data preservation orders | Active | |
| Critical Telecom Data Regulations | PTA | Telecom subscriber data | Must be stored in Pakistan | Active (Nov 2020) | |
| Cyber Security Strategy 2023-2028 | PTA/MoITT | Critical infrastructure | Security framework compliance | Active | |
| SBP Cyber Shield | SBP | Banking/financial data | Banking data protection | Active (Mar 2026) | |
| 5G Security Guidelines | PTA | Telecom network data | Security compliance | Active (Feb 2026) | |
| Aiming for: DPA Pakistan | MoITT | Personal data | Data localization (pending) | Draft stage - Digital Nation Bill | |
| NADRA Act/Regulations | NADRA | Biometric/citizen data | Must remain in Pakistan | Active | |
| National Cyber Security Framework | NCERT | All critical data | Framework compliance | Published |
| Requirement | Details | Authority |
|---|---|---|
| PTA Registration | Required if providing ISP/hosting services to end-users | PTA |
| SECP Registration | Company incorporation required for data center business | SECP — Companies Act 2017 |
| No Standalone License | No explicit "data center license" exists currently — company registration suffices | ✓ |
| Building Codes | Fire safety, electrical, structural compliance per local building authority | Local authorities |
| Environmental | UPS, generators, cooling systems required for Tier II+ classification | Best practice |
| Physical Security | Access control, CCTV, security personnel, 24/7 monitoring | Best practice |
| PSEB Registration | Recommended for 0.25% WHT on export remittances | PSEB |
Per BPRD C1/2025 (Consolidated Customer Onboarding Framework) and PSD C4/2025 (Tech Risk Framework), SBP has specific requirements for cloud outsourcing by regulated entities:
| Requirement | Details | Impact on IT Companies |
|---|---|---|
| Data Localization | All banking/financial data MUST remain in Pakistan | IT companies serving banks must host locally — no AWS/GCP for bank data |
| Cloud Outsourcing Approval | 7-day advance written notice to SBP for material outsourcing; SBP approval for offshore | Must notify SBP before moving bank services to cloud |
| Third-Party Risk Assessment | Banks must conduct risk assessments of IT vendors annually | IT vendors need SOC 2 / ISO 27001 certifications |
| Disaster Recovery | Defined RTO/RPO; annual BCP testing required | IT vendors must demonstrate DR capabilities |
| Encryption | AES-256 minimum for data at rest and in transit | Must implement encryption for all bank client data |
| Audit Rights | SBP and bank auditors have right to inspect cloud infrastructure | Must provide audit access and compliance reports |
| Cloud Provider | Region | Pakistan Data Center? | SBP Compliant? | Notes |
|---|---|---|---|---|
| AWS | Multiple | No (Bahrain/Mumbai closest) | No — for bank data | OK for non-banking IT exports |
| Google Cloud | Multiple | No (Mumbai closest) | No — for bank data | OK for non-banking IT exports |
| Azure | Multiple | No (UAE closest) | No — for bank data | OK for non-banking IT exports |
| Storich (Local) | Pakistan | Yes — Islamabad | Potentially yes | Pakistan-based data center |
| RapidCompute (Local) | Pakistan | Yes — Karachi | Potentially yes | Local IaaS provider |
| NTC Data Center | Pakistan | Yes — Islamabad | Yes — government cloud | For government projects |
| On-Premises | Own facility | Yes | Yes — if compliant | Full control, full responsibility |
| Sector | Requirement | Authority | Source |
|---|---|---|---|
| Banking/Financial | Mandatory — all financial data in Pakistan | SBP | BPRD Cloud Guidelines |
| Telecom | Mandatory — CDRs, subscriber data in Pakistan | PTA | PTA Registration Rules 2000 |
| Government | Mandatory — all government data in Pakistan | MoITT/NITB | G-Cloud Policy |
| Healthcare | Recommended — patient records in Pakistan | Provincial Depts | Draft Digital Health Policy |
| E-commerce | Partial — payment data in Pakistan | SBP/FBR | E-Payment Guidelines |
| General IT/SaaS | No strict requirement (may change with PDPB) | — | — |
| After PDPB Enactment | Data Transfer Impact Assessments (DTIAs) required for cross-border | PDPB (draft) | Pending |
| Reference | Description | Source |
|---|---|---|
| BPRD C1/2025 | Consolidated Customer Onboarding — includes cloud outsourcing provisions | SBP |
| PSD C4/2025 | Tech Risk Framework — 7-day outsourcing notice, data localization | SBP |
| BPRD Cloud Guidelines | Cloud computing framework for banks (BPRD Circular 03/2020) | SBP |
| CRMD CL01/2026 | Cyber Shield — cyber resilience for all SBP-regulated entities | SBP |
| NTC Standards | Government IT security and cloud standards | NTC |
| NTISB Guidelines | Telco/ISP cybersecurity mandatory standards | NTISB |
| PTA Regulations | ISP licensing, type approval for data center connectivity | PTA |
| PDPB (Draft) | Personal Data Protection Bill — data localization, DTIAs when enacted | MoITT |
The Pakistan Cloud First Policy 2022 (approved February 25, 2022) mandates a cloud-first approach for government IT and establishes the regulatory framework for cloud adoption in Pakistan:
| Provision | Details | IT Company Impact |
|---|---|---|
| Cloud-First Mandate | All federal government entities must prioritize cloud-based solutions for new IT projects | Massive cloud procurement opportunities for IT companies serving government |
| Data Classification | Government data classified into categories determining cloud deployment eligibility | Compliance with data classification requirements when hosting government data |
| G-Cloud Marketplace | Government cloud marketplace for standardized procurement of cloud services | IT companies can list cloud services on G-Cloud for streamlined government procurement |
| Cloud Service Provider Framework | Licensing and compliance requirements for cloud service providers serving government | CSP registration, security certifications, and data sovereignty requirements |
| Data Sovereignty | Critical/sensitive government data must remain within Pakistan's borders | On-premise and Pakistan-based data center requirements for government cloud |
| Migration Strategy | Phased migration of existing government systems to cloud | Legacy modernization and cloud migration projects for government |
Source: Pakistan Cloud First Policy 2022 (PDF) (Federal)