Loading...

Data Protection & Privacy

PECA 2016, PDPB, data localization, cross-border transfers & sectoral data rules

PDPB 2023 PECA 2016 GDPR Alignment
Share:
Share:
Share:

Key Data & Rates

Data Protection Laws: Pakistan vs International Standards
How Pakistan data protection compares to GDPR and other international frameworks Verified May 3, 2026
AspectPakistan (Current)Digital Nation Bill 2025GDPR (EU)PDPA (Singapore) Reference
Comprehensive DPANo (partial PECA 2016)Yes (proposed)Yes (2018)Yes (2012) PECA 2016 – Pakistan Data Protec...
Data Subject RightsLimitedProposed: access, correction, deletionFull rightsFull rights PDPB Draft – MoIT&T
Consent RequirementsNot codifiedProposed explicit consentExplicit consent requiredConsent or legitimate interest PECA 2016 – Data Subject Rights
Data LocalizationPartial (telecom/banking)Proposed for sensitive dataNot requiredNot required PDPB – Proposed Rights
Breach NotificationNot requiredProposed 72-hour notification72 hours mandatoryAs soon as practicable PECA 2016 – Consent Requirements
DPO RequirementNot requiredProposed for large processorsMandatory for certain orgsMandatory for certain orgs PDPB – Consent Framework
Cross-Border TransferNot regulatedProposed restrictionsAdequacy or safeguardsComparable protection PTA Data Localization Regulations
Maximum PenaltyPECA penaltiesTBD in Bill€20M or 4% global turnoverS$1M or 10% turnover PDPB – Data Localization Provisions
Enforcement AuthorityMultiple (FIA, PTA, SBP)Proposed: Pakistan Digital AuthorityData Protection AuthorityPDPC PECA 2016 – Breach Notification PDPB – 72-Hour Breach Notification PECA 2016 – DPO Requirements PDPB – DPO Provisions PECA – Cross-Border Transfer PDPB – Cross-Border Transfer Rules PECA 2016 – Penalties PDPB – Proposed Penalties FIA – PECA Enforcement PTA – Data Protection Oversight
Share:
Share:
Share:
Current Data Protection Frameworks in Pakistan
Existing laws and regulations with data protection implications Verified May 3, 2026
Law/RegulationAuthorityScopeData Protection ProvisionsStatus Reference
PECA 2016MoITTElectronic crimesUnauthorised access penaltiesActive PECA 2016 – Electronic Crimes Act
Telecom Act 1996PTATelecom sectorCritical Telecom Data Regulations (2020)Active PTA Telecom Act 1996 & Data Guid...
SBP Cyber ShieldSBPBanking/financialCustomer data protection for banksActive (Mar 2026) SBP Cyber Shield & Banking Data ...
NADRA ActNADRACitizen biometric dataStrict data protection for biometricsActive NADRA Act – Biometric Data Prote...
Companies Act 2017SECPCorporate dataDirector/shareholder data confidentialityActive SECP Companies Act 2017 – Corpor...
Consumer Protection ActsProvincialConsumer dataBasic consumer data rightsActive (provincial) Provincial Consumer Protection Acts
Right to Information LawsFederal/ProvincialGovernment dataCitizen access to govt dataActive Right to Information Laws
Digital Nation Pakistan Bill 2025MoITT/Pakistan Digital AuthorityComprehensiveFull data protection frameworkPassed both Houses Digital Nation Pakistan Bill 2025
Share:
Share:
Share:

Data Protection Compliance Roadmap

Step 1
Assess PDPB 2023 Applicability
Share:

Determine if your company processes personal data of Pakistani residents

Step 2
Implement PECA 2016 Compliance
Share:

Section 3: unauthorized access to data systems is criminal offense

Step 3
Appoint Data Protection Officer
Share:

Required if processing significant volumes of personal data

Step 4
Conduct Data Mapping
Share:

Inventory all personal data you collect, process, and store

Step 5
Implement Data Minimization
Share:

Only collect data necessary for stated purposes

Step 6
Establish Breach Notification
Share:

72-hour notification to regulator for data breaches

Step 7
For Exporters: GDPR Alignment
Share:

If processing EU data, comply with GDPR Article 28 DPA

Step 8
Annual Privacy Impact Assessment
Share:

Review data practices yearly and update policies

Details & Regulations

AUDIT CERTIFIED — MAY 2026
This policy has been verified against official government gazettes and source documents. View Audit Log
100% Verified
Pakistan currently lacks a comprehensive Personal Data Protection Act. The PECA 2016 provides partial coverage while the PDPB (draft) is pending in Parliament. This page covers all existing and proposed data protection frameworks.

PECA 2016 — Prevention of Electronic Crimes ActSOURCE VERIFIED

Status
In force (Act No. XL of 2016), amended via PECA Amendment Act 2025 (passed by Senate January 2025)
Key Provisions for IT Companies
SectionOffensePenalty
§3Unauthorized access to information systemsUp to 3 months imprisonment or PKR 50,000 fine or both
§4Unauthorized copying of dataUp to 6 months imprisonment
§5Interference with information systemUp to 2 years + PKR 500,000 fine
§7Unauthorized access to critical infrastructureUp to 5 years imprisonment
§8Electronic fraudUp to 7 years imprisonment + fine
§9Unauthorized issuance of SIM cardsUp to 3 years + fine
§10SpammingUp to 1 month + PKR 50,000 fine
§10ACyber terrorismUp to 14 years imprisonment + fine
§21Online defamation (2025 amendment)Strengthened → fine and/or imprisonment
§42-43International cooperationMutual legal assistance framework
Penalties as per PECA 2016 with 2025 amendments
2025 Amendment Highlights
  • Online defamation provisions strengthened (§21)
  • Increased penalties for fake news on electronic media
  • PEMRA-licensed TV channels NO LONGER exempt from PECA
  • Social media regulation provisions enhanced

Sources: NA Document | Dawn Coverage

Personal Data Protection Bill (PDPB)SOURCE VERIFIED

Status
Draft stage — Multiple versions circulated (2021, 2023, 2024). No standalone act enacted as of Tax Year 2025.
Key Provisions from Latest Known Draft
ProvisionDetails
Data Subject RightsAccess, correction, deletion, portability
Data Controller ObligationsLawful basis, consent, purpose limitation
Consent RequirementsExplicit consent for processing personal data
Cross-Border TransfersRequires government approval or adequacy finding
Data LocalizationMandatory for sensitive personal data
Data Protection AuthorityNew regulatory body to be established
Maximum PenaltiesUp to PKR 500 million for violations (per PDPB Draft §36)
Breach NotificationRequired within 72 hours of discovery
When enacted, PDPB will require: Data Protection Officer appointment, Privacy Impact Assessments, Data Processing Agreements, consent management systems, and data subject rights mechanisms.

Action: Begin GDPR-aligned preparation proactively. Monitor Parliamentary proceedings.

Data Localization Requirements by SectorSOURCE VERIFIED

SectorRequirementAuthorityScope
Banking/FinancialMandatory → all financial data in PakistanSBPBPRD Circular 03/2020
TelecomMandatory — CDRs, subscriber data in PakistanPTAPTA Registration Rules 2000
GovernmentMandatory → all government data in PakistanMoITT/NITBData classification policy
HealthcareRecommended — patient records in PakistanProvincial DeptsDraft Digital Health Policy
E-commercePartial — payment data in PakistanSBP/FBRE-Payment Guidelines
EducationNo strict requirement
General PrivateNo strict requirement (may change with PDPB)
As of Tax Year 2025 — subject to change with PDPB enactment

sbp-data">SBP Data Protection Guidelines for FintechSOURCE VERIFIED

Key Circulars
CircularSubjectApplicability
BPRD Circular 14/2021Framework for Digital LendingBanks/DFIs/Fintech
BPRD Circular 03/2020Cloud Computing GuidelinesBanks/DFIs
BPRD Circular 07/2018Information SecurityBanks/DFIs
E-Payment CircularsElectronic Payment SchemesPSOs/PSPs
Requirements for Fintech Service Providers
  • Data classification policies
  • AES-256 encryption minimum
  • Access control & authentication
  • Incident reporting to SBP
  • Annual security audits
  • BCP/DR plans required
  • Data backup requirements
  • Penetration testing

Cross-Border Data Transfer RulesSOURCE VERIFIED

Current Framework
No comprehensive cross-border data transfer law exists. Sectoral restrictions apply:
ScenarioStatusBasis
Pakistani banking/fintech data on intl serversPROHIBITEDSBP Cloud Guidelines
Government client data abroadPROHIBITEDMoITT/NITB Policy
Telecom subscriber data abroadPROHIBITEDPTA Regulations
General international client dataALLOWEDNo restriction
After PDPB enactmentDTIAs requiredDraft PDPB provisions
PECA 2016 does not explicitly regulate cross-border transfers

Practical Steps for IT CompaniesSOURCE VERIFIED

  1. Immediate: Ensure no Pakistani banking/government client data is hosted outside Pakistan
  2. Short-term: Implement data classification framework (public, internal, confidential, restricted)
  3. Short-term: Create data processing agreements for all clients handling personal data
  4. Medium-term: Conduct data mapping exercise — know what data you hold, where, and why
  5. Medium-term: Implement privacy policies and publish on company website
  6. Long-term: Prepare for PDPB — align with GDPR principles now
🔒 Data Protection Status

Pakistan currently lacks a comprehensive Data Protection Authority, though the Digital Nation Pakistan Bill 2025 (passed both Houses) is expected to establish one. The Pakistan Digital Authority has been created under this framework with PDA Chairperson (verify current appointment) as Chair.

Existing protections: PECA 2016 covers unauthorized data access, PTA regulates telecom data localization, and SBP Cyber Shield protects banking data. However, comprehensive data subject rights (access, correction, deletion) are not yet codified.

PSEB offers a GDPR Compliance Certification program for IT companies handling EU data.

SBP Data Security Requirements for Financial SectorSOURCE VERIFIED

While a general data protection law is pending, the financial sector has mandatory SBP data security requirements:

RequirementSourceApplies To
Technology risk governance at board level; Head of IT + Head of InfoSec mandatoryPSD C4/2025 — Tech Risk FrameworkEMIs, PSOs, PSPs
Cyber resilience program aligned with Cyber Shield strategy (2025-2030)CRMD CL01/2026 — Cyber ShieldAll SBP-regulated entities
NADRA biometric verification at digital onboarding; device fingerprinting; 2-hour cool-off on device switchPSD C4/2025 — Sec.7EMIs, PSOs, PSPs
Cloud outsourcing per SBP framework; 7-day advance notice for material outsourcing; SBP approval for offshorePSD C4/2025 — Sec.8EMIs, PSOs, PSPs
Security of internet banking — encryption, two-factor auth, session managementPSD C3/2015 — Internet Banking SecurityAll banks
Mobile app security — secure coding, VAPT, certificate pinning, runtime integrityPSD CL6/2022 — Mobile App SecurityBanks, EMIs
Payment card security — PCI DSS compliance, EMV, tokenizationPSD C5/2016 — Payment Card SecurityAll card-issuing banks
30-minute fraud dispute SLA; PI liable for delayed alerts and unavailable complaint channelsPSD C4/2025 — Sec.7CEMIs, PSOs, PSPs
Key: SBP regulations impose stronger and more specific data security obligations on the financial sector than the pending PDPB would impose generally. IT companies providing services to banks/EMIs must comply with these sectoral requirements.
Personal Data Protection Bill 2023 — Key Provisions NEW

The Final Draft Personal Data Protection Bill (May 2023) is Pakistan's most comprehensive data protection legislation. Key provisions:

ProvisionDetailsIT Company Compliance
Personal Data Protection CommissionIndependent regulatory body to oversee data protection enforcementRegistration and reporting obligations to the Commission
Data Controller/Processor DistinctionClear legal distinction between data controllers and data processorsIT companies must identify their role — most SaaS providers are data processors
Consent RequirementsExplicit, informed consent required for data collection and processingImplement consent management systems and privacy notices
Data Subject RightsRight to access, rectification, erasure, data portability, and objectionAPI endpoints and processes for data subject request handling
Cross-Border TransfersRestrictions on transfer of personal data outside Pakistan without adequate protectionReview cloud hosting and data processing locations for compliance
Data Breach NotificationMandatory notification to Commission and affected data subjects within 72 hoursImplement breach detection and notification protocols
Data Protection Impact AssessmentRequired for high-risk processing activitiesConduct DPIAs for AI/ML systems, profiling, large-scale processing
PENALTIESSignificant fines for non-compliance (up to 2% of annual turnover)Compliance programs and DPO appointment essential
Status: The PDPB 2023 is pending in Parliament. IT companies should begin compliance preparation now — the 2021 draft was the previous version. The 2023 version has significant enhancements including the 72-hour breach notification and 2% turnover penalty provisions.

Sources: PDPB 2023 (PDF) | PDPB 2021 Draft (PDF) (Federal)

Data Protection Compliance Checklist
Checkboxes are saved in your browser
Source Citations (11)
PECA 2016 Full Text
https://na.gov.pk/uploads/documents/1470910659_707.pdf
pk_only law
PECA 2025 Amendments — Dawn
https://www.dawn.com/news/1888224
verified news
SBP Cloud Computing Guidelines (BPRD 03/2020)
https://www.sbp.org.pk/bprd/2020/CL3.htm
verified circular
SBP Information Security Guidelines (BPRD 07/2018)
https://www.sbp.org.pk/bprd/2018/C7.htm
verified circular
PSD C3/2015 — Regulations for Security of Internet Banking
https://www.sbp.org.pk/psd/2015/C3.htm
verified 2015 circular
PSD C9/2018 — Security of Digital Payments
https://www.sbp.org.pk/psd/2018/C9.htm
verified circular
Share: