#
No enacted comprehensive data-protection statute and no independent supervisory authority exist; only unenacted drafts and a sectoral cybercrime law are in play.
Sub-modules (5)
Regulator And AuthorityRed
No independent DPA exists; MoITT is the de facto adjacent competent body pending enactment of a data-protection commission/authority proposed in successive drafts.
Claims (1):
- Pakistan has no independent dedicated data protection authority; the Ministry of Information Technology and Telecommunication (MoITT) holds adjacent competence pending enactment of a comprehensive data-protection law.
Act And InstrumentsRed
Multiple unenacted PDPB drafts (2018/2020/2021/2023) exist alongside the in-force PECA 2016, which is sectoral cybercrime legislation, not a data-protection instrument.
Claims (2):
- MoITT has circulated multiple drafts of a Personal Data Protection Bill (2018, 2020, 2021, and a Final Draft dated May 2023) without enactment into law as of the current verified status.
- The Prevention of Electronic Crimes Act, 2016 (PECA) is an in-force statute addressing unauthorized access to data and cybercrime, but it does not constitute a comprehensive data-protection regime.
Material ScopeRed
Proposed material scope under the 2021 draft extends to processing of personal data throughout Pakistan; not currently operative.
Claims (1):
- The 2021 consultation draft of the Personal Data Protection Bill proposes that the Act extend to the whole of Pakistan, covering processing of personal data by controllers and processors.
Territorial ScopeRed
The May 2023 draft proposes extraterritorial application concepts (e.g., 'significant' controller/processor designation, application of Pakistani law under international law principles), but this remains proposal-stage only.
Claims (1):
- The May 2023 draft bill proposes extraterritorial-style application concepts, including designation of 'significant' data controllers/processors and application of Pakistani law under public or private international law principles, but this remains unenacted proposal text.
Regulator Registration And FilingRed
Draft bills propose establishment of a statutory Commission/Authority with registration-fee provisions; no registration/filing regime is currently operative.
Claims (1):
- Successive drafts (2020 update) propose establishment of a statutory Personal Data Protection Authority/Commission with registration-fee collection powers, but no such body or filing regime is currently operative.
Sources and claims (6)
- ConfirmedGovernment of Pakistan — Pakistan has no independent dedicated data protection authority; the Ministry of Information Technology and Telecommunication (MoITT) holds adjacent competence pending enactment of a comprehensive data-protection law.observed
- ConfirmedMoITT — MoITT has circulated multiple drafts of a Personal Data Protection Bill (2018, 2020, 2021, and a Final Draft dated May 2023) without enactment into law as of the current verified status.observed
- ConfirmedMoITT — The Prevention of Electronic Crimes Act, 2016 (PECA) is an in-force statute addressing unauthorized access to data and cybercrime, but it does not constitute a comprehensive data-protection regime.observed
- ProbableMoITT — The 2021 consultation draft of the Personal Data Protection Bill proposes that the Act extend to the whole of Pakistan, covering processing of personal data by controllers and processors.observed
- UncertainMoITT — The May 2023 draft bill proposes extraterritorial-style application concepts, including designation of 'significant' data controllers/processors and application of Pakistani law under public or private international law principles, but this remains unenacted proposal text.observed
- ProbableMoITT — Successive drafts (2020 update) propose establishment of a statutory Personal Data Protection Authority/Commission with registration-fee collection powers, but no such body or filing regime is currently operative.observed