Loading...
PECA 2016 compliance: data retention, cybercrime offenses, investigation procedures & penalties
Compliance workflow for Pakistan Electronic Crimes Act 2016
Everything Pakistani IT companies need to know about the Prevention of Electronic Crimes Act.
Last updated: April 2026 | P@SHA Cloud & Digital Committee
The Prevention of Electronic Crimes Act, 2016 (PECA) is Pakistan's primary cybercrime legislation. It defines offenses related to electronic systems, data, and online content, and establishes investigation and prosecution mechanisms.
| Enacted | August 2016 |
|---|---|
| Administered by | FIA (Federal Investigation Agency) Cyber Crime Wing |
| Amendments | 2025 (major), 2022 (minor) |
| Latest Amendment | PECA Amendment Act 2025 |
| Related Laws | ITO 2001, Sales Tax Act 1990, AML Act 2010 |
| Section | Offense | Max Penalty |
|---|---|---|
| §3 | Unauthorized access to information system | 3 months or PKR 50,000 fine or both (PECA §3)ne |
| §3 | Unauthorized access to information system | 3 months or PKR 50,000 fine or both |
| §4 | Unauthorized copying of data | 2 years + PKR 500K fine |
| §5 | Interference with information system | 2 years + PKR 500K fine |
| §6 | Glitch terrorism (critical infrastructure damage) | 14 years + unlimited fine |
| §7 | Electronic fraud | 7 years + PKR 5M fine |
| §8 | Unauthorized use of identity information | 3 years + PKR 500K fine |
| §9 | Offenses against modesty (online harassment) | 1 year + PKR 100K fine |
| §10 | Cyber stalking | 1 year + PKR 100K fine |
| §11 | Offenses against dignity of natural person | 1 year + PKR 100K fine |
| §14 | Spamming | 1 month + PKR 50K fine |
| §16 | Electronic forgery | 3 years + PKR 500K fine |
| §17 | Tampering with communication | 3 years + PKR 500K fine |
| §20 | Offenses relating to online content (removal orders) | PKR 500K per day |
| §21 | Unauthorized encryption | 6 months + PKR 100K fine |
| §29 | Retaining stolen data | 1 year + PKR 100K fine |
| §30 | Making, obtaining or supplying device for offense | 6 months + PKR 100K fine |
PECA §20 allows authorities to issue removal or blocking orders for online content. Platforms and service providers must comply within specified timeframes.
Online Complaint: crime.fia.gov.pk
Helpline: 1991
Email: complaint@fia.gov.pk
Headquarters: FIA Headquarters, Islamabad
Regional Offices: Karachi, Lahore, Quetta, Peshawar
PECA was significantly amended in 2025. Key changes:
| Change | Previous | New (2025) |
|---|---|---|
| Online content removal timeline | No specific timeline | 24 hours from notice |
| Data breach notification | Not required | Mandatory notification to FIA within 72 hours |
| Enhanced penalties for critical infrastructure | §3: 3 months or PKR 50,000 | §21: 5 years / PKR 5M fine (harm to reputation) (§21 PECA 2016) + increased fine |
| Corporate liability | Primarily individual | Corporate officers can be held liable |
| Social media regulation | Limited | New provisions for social media companies |
| Terrorism financing | §6 only | New provisions aligned with FATF |
Pakistan's PDPB has been in draft since 2023-2024. When enacted, it will significantly impact IT companies:
The Prevention of Electronic Crimes (Amendment) Act 2025 (Act II of 2025, effective Jan 29, 2025) introduces sweeping changes:
A Social Media Protection and Regulatory Authority (SMPRA) is established with powers to:
| Provision | Detail | Penalties / Jurisdiction |
|---|---|---|
| New offence: Aspersion (Section 2(iiia)) | Spreading false and harmful information damaging reputation | Federal/ICT — all of Pakistan |
| Social Media Platform definition (Section 2(xxvib)) | Any service with registered user accounts for user-generated content sharing; excludes PTA licensees | All platforms accessible from Pakistan |
| Social Media Protection Tribunal (Chapter 1C) | New Tribunal to hear appeals against SMPRA decisions | Federal/ICT |
| Fake Information Complaint (Section 2C) | Any person may apply to SMPRA for removal/blocking of fake information | 48-hour decision timeline |
| Platform Obligations | Registration, content moderation, local presence, data storage requirements | Non-compliance → blocking |
| SMPRA Composition | Chairperson (ex-officio PTA Chairman), tech/law/social media members | Government-appointed |
The Criminal Laws (Amendment) Act 2023 (Act XXXVII of 2023) significantly strengthened PECA:
| Offence | Penalty (Federal/ICT) | Section |
|---|---|---|
| Online grooming / solicitation of minors | 5-10 years imprisonment + PKR 500,000-10,000,000 fine | New Section 22A |
| Commercial sexual exploitation of children | 14-20 years imprisonment + PKR 1,000,000+ fine | New Section 22B |
| Using information system to kidnap/traffic minors | 14-20 years imprisonment + PKR 1,000,000+ fine | New Section 22C |
| Cyberbullying (revised) | 1-5 years imprisonment + PKR 100,000-500,000 fine | New Section 24A |
| Child sexual abuse content — enhanced penalties | 14-20 years imprisonment | Section 22 (amended) |
PECA 2016 (Act XL of 2016) remains the primary cybercrime law. Key offences still in force:
The PECA Amendment Act 2025 introduces significant changes to the Prevention of Electronic Crimes Act 2016:
| Area | PECA 2016 | PECA Amendment 2025 |
|---|---|---|
| Fake News / Misinformation | Not specifically addressed | New provisions for penalties on spreading fake news and disinformation online |
| Social Media Regulation | Limited platform accountability | Enhanced obligations for social media platforms — content moderation, transparency reporting |
| Platform Accountability | Intermediary liability limited | Increased platform responsibility for user-generated content |
| Enhanced Penalties | Existing penalty structure | Increased penalties for cybercrime offences |
Sources: PECA 2016 Full Text (PDF) | PECA Amendment 2025 (PDF) | PECA Content Rules 2021 (PDF) (Federal)