🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
PK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing11 sources retrieved model claude-sonnet-5 · 2026-08-07

Pakistan

PK schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 28 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 23 August 2026.

Lead Signal

Pakistan's Ministry of Information Technology and Telecommunications, together with the Pakistan Digital Authority, held a high-level meeting to finalise the draft National Data Governance Policy 2026 ahead of cabinet approval and gazette notification, following the close of consultation on 10 July 2026. This is a policy-track instrument distinct from the stalled Personal Data Protection Bill, and its advancement is the most recent development in Pakistan's data-protection enforcement and redress landscape.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No enacted comprehensive data-protection statute and no independent supervisory authority exist; only unenacted drafts and a sectoral cybercrime law are in play.

Traffic-light rationale — RedNo enacted comprehensive data-protection statute and no independent supervisory authority exist; only unenacted drafts and a sectoral cybercrime law are in play.

Sub-modules (5)

Regulator And AuthorityRed

No independent DPA exists; MoITT is the de facto adjacent competent body pending enactment of a data-protection commission/authority proposed in successive drafts.

Claims (1):

  • Pakistan has no independent dedicated data protection authority; the Ministry of Information Technology and Telecommunication (MoITT) holds adjacent competence pending enactment of a comprehensive data-protection law.

Act And InstrumentsRed

Multiple unenacted PDPB drafts (2018/2020/2021/2023) exist alongside the in-force PECA 2016, which is sectoral cybercrime legislation, not a data-protection instrument.

Claims (2):

  • MoITT has circulated multiple drafts of a Personal Data Protection Bill (2018, 2020, 2021, and a Final Draft dated May 2023) without enactment into law as of the current verified status.
  • The Prevention of Electronic Crimes Act, 2016 (PECA) is an in-force statute addressing unauthorized access to data and cybercrime, but it does not constitute a comprehensive data-protection regime.

Material ScopeRed

Proposed material scope under the 2021 draft extends to processing of personal data throughout Pakistan; not currently operative.

Claims (1):

  • The 2021 consultation draft of the Personal Data Protection Bill proposes that the Act extend to the whole of Pakistan, covering processing of personal data by controllers and processors.

Territorial ScopeRed

The May 2023 draft proposes extraterritorial application concepts (e.g., 'significant' controller/processor designation, application of Pakistani law under international law principles), but this remains proposal-stage only.

Claims (1):

  • The May 2023 draft bill proposes extraterritorial-style application concepts, including designation of 'significant' data controllers/processors and application of Pakistani law under public or private international law principles, but this remains unenacted proposal text.

Regulator Registration And FilingRed

Draft bills propose establishment of a statutory Commission/Authority with registration-fee provisions; no registration/filing regime is currently operative.

Claims (1):

  • Successive drafts (2020 update) propose establishment of a statutory Personal Data Protection Authority/Commission with registration-fee collection powers, but no such body or filing regime is currently operative.
Category narrative80 words

Pakistan has no independent dedicated data protection authority. The Ministry of Information Technology and Telecommunication (MoITT) holds adjacent competence and has circulated multiple drafts of a Personal Data Protection Bill (2018, 2020, 2021, and a Final Draft dated May 2023) without any version being enacted into law as of the current verified status (2026-08-07). The Prevention of Electronic Crimes Act, 2016 (PECA) is the only in-force statute touching personal data, but it addresses cybercrime/unauthorized access rather than comprehensive data protection.

Sources and claims (6)
  1. ConfirmedGovernment of Pakistan — Pakistan has no independent dedicated data protection authority; the Ministry of Information Technology and Telecommunication (MoITT) holds adjacent competence pending enactment of a comprehensive data-protection law.observed
  2. ConfirmedMoITT — MoITT has circulated multiple drafts of a Personal Data Protection Bill (2018, 2020, 2021, and a Final Draft dated May 2023) without enactment into law as of the current verified status.observed
  3. ConfirmedMoITT — The Prevention of Electronic Crimes Act, 2016 (PECA) is an in-force statute addressing unauthorized access to data and cybercrime, but it does not constitute a comprehensive data-protection regime.observed
  4. ProbableMoITT — The 2021 consultation draft of the Personal Data Protection Bill proposes that the Act extend to the whole of Pakistan, covering processing of personal data by controllers and processors.observed
  5. UncertainMoITT — The May 2023 draft bill proposes extraterritorial-style application concepts, including designation of 'significant' data controllers/processors and application of Pakistani law under public or private international law principles, but this remains unenacted proposal text.observed
  6. ProbableMoITT — Successive drafts (2020 update) propose establishment of a statutory Personal Data Protection Authority/Commission with registration-fee collection powers, but no such body or filing regime is currently operative.observed

#

All lawful-basis and special-category provisions exist only in unenacted draft form; no in-force consent or sensitive-data regime.

Traffic-light rationale — RedAll lawful-basis and special-category provisions exist only in unenacted draft form; no in-force consent or sensitive-data regime.

Sub-modules (4)

Lawful BasesRed

The May 2023 draft contains a 'Grounds for processing personal data' chapter, proposal-stage only.

Claims (1):

  • The May 2023 draft Personal Data Protection Bill contains a proposed 'Grounds for processing personal data' chapter, not yet enacted.

Special CategoriesRed

The May 2023 draft proposes 'Additional requirements for processing sensitive and critical personal data'; unenacted.

Claims (1):

  • The May 2023 draft bill proposes 'Additional requirements for processing sensitive and critical personal data' as a distinct chapter.

Pseudonymisation And AnonymisationRed

No pseudonymisation or anonymisation safe-harbour provisions were identified in any reviewed MoITT draft bill or secondary DataGuidance material. Absent-field provenance: searched 'Pakistan data protection pseudonymisation anonymisation' across MoITT draft PDFs and DataGuidance Pakistan overview pages with no responsive text located.

Category narrative63 words

No enacted lawful-basis, consent, or special-category regime exists. Draft bills (2021, May 2023) propose consent-centric processing grounds, per-purpose consent requirements, and additional requirements for 'sensitive and critical personal data,' but none are in force. Pseudonymisation/anonymisation safe-harbour definitions were not located in any reviewed draft text or secondary guidance (searched MoITT draft-bill PDFs and DataGuidance Pakistan notes); this sub-module is recorded as a gap.

Sources and claims (3)
  1. UncertainMoITT — The May 2023 draft Personal Data Protection Bill contains a proposed 'Grounds for processing personal data' chapter, not yet enacted.observed
  2. ProbableMoITT — The 2021 consultation draft requires that a separate consent be obtained from the data subject for each processing purpose.observed
  3. ProbableMoITT — The May 2023 draft bill proposes 'Additional requirements for processing sensitive and critical personal data' as a distinct chapter.observed

#

All data subject rights provisions are proposal-stage only; none in force.

Traffic-light rationale — RedAll data subject rights provisions are proposal-stage only; none in force.

Sub-modules (5)

Access RightRed

May 2023 draft includes 'Right to access' and 'Compliance with the data access request' provisions, unenacted.

Claims (1):

  • The May 2023 draft bill includes proposed 'Right to access' and 'Compliance with the data access request' provisions, not yet enacted.

Rectification And ErasureRed

2020 and 2021 drafts propose erasure rights, including a 14-day erasure window and an undue-delay erasure standard; unenacted.

Claims (2):

  • The 2020 updated draft proposes that data controllers erase personal data within a period of 14 days where specified conditions are met.
  • Draft bill text provides that a data subject shall have the right to obtain from the data controller the erasure of personal data concerning him without undue delay.

Restriction And ObjectionRed

Draft text proposes a 'right to prevent processing likely to cause damage or distress,' an objection-style right; unenacted.

Claims (1):

  • Draft bill text includes a proposed 'right to prevent processing likely to cause damage or distress,' functioning as an objection-style right.

Data PortabilityRed

No explicit data-portability right was identified in any reviewed draft bill text (2018/2020/2021/2023). Absent-field provenance: reviewed all four MoITT draft PDFs' indexed section titles with no portability provision located.

Deadlines And Response WindowsRed

The 2021 draft proposes a 30-day response window for data-correction requests; unenacted.

Claims (1):

  • The 2021 draft proposes that a data controller satisfied that a data correction request is warranted must act not later than thirty days from the date of receipt of the request.
Category narrative52 words

No enacted subject-access, correction, erasure, objection, or portability regime exists. Draft bills propose access, correction (30-day response window per the 2021 draft), erasure (14-day window per the 2020 draft), and an objection-style 'right to prevent processing likely to cause damage or distress.' No explicit data-portability right was located in any reviewed draft.

Sources and claims (5)
  1. ProbableMoITT — The May 2023 draft bill includes proposed 'Right to access' and 'Compliance with the data access request' provisions, not yet enacted.observed
  2. ProbableMoITT — The 2020 updated draft proposes that data controllers erase personal data within a period of 14 days where specified conditions are met.observed
  3. ProbableMoITT — Draft bill text provides that a data subject shall have the right to obtain from the data controller the erasure of personal data concerning him without undue delay.observed
  4. ProbableMoITT — The 2021 draft proposes that a data controller satisfied that a data correction request is warranted must act not later than thirty days from the date of receipt of the request.observed
  5. ProbableMoITT — Draft bill text includes a proposed 'right to prevent processing likely to cause damage or distress,' functioning as an objection-style right.observed

#

Core accountability infrastructure (DPIA, DPO, ROPA, breach notification, retention) exists only in unenacted draft form.

Traffic-light rationale — RedCore accountability infrastructure (DPIA, DPO, ROPA, breach notification, retention) exists only in unenacted draft form.

Sub-modules (7)

Accountability And DpiaRed

Draft bills introduce a 'significant' controller/processor designation implying a risk-tiered accountability approach; no formal DPIA trigger provision was located.

Claims (1):

  • Draft bills designate data controllers and/or processors identified as 'significant' for heightened compliance obligations, implying a proposed risk-tiered accountability approach that is not yet in force.

Dpo RequirementsRed

No DPO appointment threshold or independence provision was identified in reviewed draft text. Absent-field provenance: reviewed May 2023, 2021, and 2020 draft bill indexes with no DPO-specific chapter located.

Ropa RequirementsRed

No records-of-processing (ROPA) obligation was identified in reviewed draft materials. Absent-field provenance: same draft-bill review as DPO sub-module.

Joint Controller ArrangementsRed

No joint-controller allocation-of-responsibility provision was identified in reviewed draft materials. Absent-field provenance: same draft-bill review.

Security MeasuresRed

The May 2023 draft contains a 'Security requirements' chapter, proposal-stage only.

Claims (1):

  • The May 2023 draft Personal Data Protection Bill contains a proposed 'Security requirements' chapter governing technical and organisational measures, not yet enacted.

Breach NotificationRed

The May 2023 draft contains a 'Personal data breach notification' chapter, proposal-stage only; no in-force breach-notification duty exists generally (sectoral SBP circulars addressed separately under sectoral_watch).

Claims (1):

  • The May 2023 draft bill contains a proposed 'Personal data breach notification' chapter, not yet enacted or operative.

Retention And DisposalRed

The May 2023 and 2020 drafts contain 'Data retention requirements' chapters, proposal-stage only.

Claims (1):

  • The May 2023 draft bill contains a proposed 'Data retention requirements' chapter, not yet enacted.
Category narrative59 words

No enacted accountability, DPIA, DPO, ROPA, joint-controller, security, breach-notification, or retention regime exists generally. The May 2023 draft proposes chapters on security requirements, personal data breach notification, and data retention requirements, and designates 'significant' controllers/processors for heightened obligations, but none are in force. DPO appointment thresholds, ROPA requirements, and joint-controller arrangement provisions were not located in reviewed draft materials.

Sources and claims (4)
  1. ProbableMoITT — The May 2023 draft Personal Data Protection Bill contains a proposed 'Security requirements' chapter governing technical and organisational measures, not yet enacted.observed
  2. ProbableMoITT — The May 2023 draft bill contains a proposed 'Personal data breach notification' chapter, not yet enacted or operative.observed
  3. ProbableMoITT — The May 2023 draft bill contains a proposed 'Data retention requirements' chapter, not yet enacted.observed
  4. UncertainMoITT — Draft bills designate data controllers and/or processors identified as 'significant' for heightened compliance obligations, implying a proposed risk-tiered accountability approach that is not yet in force.observed

#

All transfer-mechanism and localisation provisions are unenacted proposals; no adequacy relationships exist.

Traffic-light rationale — RedAll transfer-mechanism and localisation provisions are unenacted proposals; no adequacy relationships exist.

Sub-modules (6)

Transfer MechanismsRed

The 2018 draft proposes a general prohibition on transfer of personal data absent specified conditions; the May 2023 draft proposes 'Restrictions on transferring personal data,' 'Condition for Cross border transfer,' and a framework for cross-border transfer conditions. All proposal-stage only.

Claims (2):

  • The 2018 draft Personal Data Protection Bill proposes a general prohibition on the transfer of personal data outside Pakistan absent specified conditions being met.
  • The May 2023 draft bill contains chapters titled 'Restrictions on transferring personal data,' 'Condition for Cross border transfer,' and 'Framework on conditions for cross-border transfer,' none of which are yet in force.

Adequacy ReceivedRed

No adequacy decision recognising Pakistan has been identified; expected given absence of a comprehensive enacted regime. Absent-field provenance: searched for EU/other adequacy decisions referencing Pakistan; none located.

Adequacy GrantedRed

Pakistan has no operative statutory mechanism to grant adequacy findings to other jurisdictions. Absent-field provenance: no enacted transfer-adequacy framework exists to assess.

Sccs And BcrsRed

No standard contractual clauses or binding corporate rules framework is in force. Absent-field provenance: reviewed draft bill transfer chapters; no SCC/BCR template or approval mechanism located as an operative instrument.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement is in force or clearly specified in reviewed drafts. Absent-field provenance: reviewed May 2023 draft's cross-border transfer chapter; no TIA-equivalent obligation text located.

Data LocalisationRed

The 2020 updated draft proposes that the (then-unformed) Authority devise a mechanism requiring a copy of 'critical personal data' to be kept within Pakistan; proposal-stage only.

Claims (1):

  • The 2020 updated draft bill proposes that the (then-unformed) Authority devise a mechanism for keeping a copy of 'critical personal data' within the territory of Pakistan.
Category narrative59 words

No enacted cross-border transfer regime, adequacy mechanism, SCC/BCR framework, or transfer-impact-assessment requirement exists. Draft bills across versions (2018, 2020, 2023) propose transfer prohibitions/restrictions absent specified conditions, and the 2020 draft proposes a data-localisation requirement for 'critical personal data' copies to be retained in Pakistan. No adequacy decisions to or from Pakistan exist because no comprehensive law is in force.

Sources and claims (3)
  1. ProbableMoITT — The 2018 draft Personal Data Protection Bill proposes a general prohibition on the transfer of personal data outside Pakistan absent specified conditions being met.observed
  2. ProbableMoITT — The 2020 updated draft bill proposes that the (then-unformed) Authority devise a mechanism for keeping a copy of 'critical personal data' within the territory of Pakistan.observed
  3. ProbableMoITT — The May 2023 draft bill contains chapters titled 'Restrictions on transferring personal data,' 'Condition for Cross border transfer,' and 'Framework on conditions for cross-border transfer,' none of which are yet in force.observed

#

Some in-force sectoral cyber-security/content-moderation obligations exist even though no general data-protection law exists; financial-sector overlay is the most developed segment.

Supervisory authorityState Bank of Pakistan (SBP)
Traffic-light rationale — AmberSome in-force sectoral cyber-security/content-moderation obligations exist even though no general data-protection law exists; financial-sector overlay is the most developed segment.

Sub-modules (7)

Financial Sector OverlayAmber

SBP's draft digital-banking framework mandates consumer/data-protection measures for licensees; SBP's PSD Circular No. 3 of 2020 imposes in-force cyber-resilience/access-control duties on regulated financial institutions.

Claims (2):

  • SBP's draft regulatory framework for digital banking mandates entities to provide consumer and data-protection measures, including complaint-handling mechanisms, as part of licensing applications.
  • SBP's PSD Circular No. 3 of 2020 requires banks, microfinance banks, and payment service operators to secure remote-access resources and implement need-to-know/least-privilege access-control principles amid COVID-19-related cyber threats.

Health Sector OverlayRed

No health-sector-specific data rules identified. Absent-field provenance: searched for Pakistan health-data/medical-records privacy statute; none located.

Telecoms And EprivacyAmber

PECA 2016 and the Removal and Blocking of Unlawful Online Content Rules give PTA broad content-removal/blocking powers; these are cybercrime/content-moderation powers, not an ePrivacy consent-for-communications-data regime.

Claims (1):

  • PECA 2016 grants the Pakistan Telecommunication Authority wide powers to remove or block access to online content on public-interest grounds including the integrity, security, or defence of Pakistan; these powers were substantially expanded by the Removal and Blocking of Unlawful Online Content Rules.

Employment DataRed

No employment-data-specific rules identified. Absent-field provenance: searched for Pakistan employee personal data / workplace monitoring rules; none located.

Credit And ScoringRed

No credit-scoring-specific data rules identified. Absent-field provenance: searched for Pakistan credit bureau/credit-scoring data rules; none located beyond general financial-sector circulars.

EducationRed

No education-sector-specific data rules identified. Absent-field provenance: searched for Pakistan student-data privacy rules; none located.

InsuranceRed

No insurance-sector-specific data rules identified. Absent-field provenance: searched for Pakistan insurance-sector data protection rules; none located.

Category narrative97 words

In the absence of a general data-protection statute, sectoral overlays provide the only in-force, data-adjacent obligations. The State Bank of Pakistan (SBP) has issued a draft digital-banking regulatory framework requiring consumer/data-protection measures for prospective digital bank licensees, and an in-force cyber-resilience circular (PSD Circular No. 3 of 2020) directing banks, microfinance banks, and payment service operators to secure remote-access resources. Telecoms/online-content regulation runs through PECA 2016 and PTA's Removal and Blocking of Unlawful Online Content Rules, which are content-moderation/cybercrime powers rather than an ePrivacy-style consent regime. No health-sector, employment-data, credit-scoring, education-sector, or insurance-sector data overlays were identified.

Sources and claims (3)
  1. ProbableDataGuidance — SBP's draft regulatory framework for digital banking mandates entities to provide consumer and data-protection measures, including complaint-handling mechanisms, as part of licensing applications.observed
  2. ConfirmedDataGuidance — SBP's PSD Circular No. 3 of 2020 requires banks, microfinance banks, and payment service operators to secure remote-access resources and implement need-to-know/least-privilege access-control principles amid COVID-19-related cyber threats.observed
  3. ConfirmedDataGuidance — PECA 2016 grants the Pakistan Telecommunication Authority wide powers to remove or block access to online content on public-interest grounds including the integrity, security, or defence of Pakistan; these powers were substantially expanded by the Removal and Blocking of Unlawful Online Content Rules.observed

#

No adtech/commercial-privacy-specific rules identified in any tier of sourcing.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy-specific rules identified in any tier of sourcing.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent regime identified. Absent-field provenance as noted at module level.

Dark PatternsRed

No dark-pattern prohibition identified. Absent-field provenance as noted at module level.

Opt Out SignalsRed

No recognised opt-out signal (e.g., GPC/DAA) mechanism identified. Absent-field provenance as noted at module level.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified. Absent-field provenance as noted at module level.

Cross Context AdvertisingRed

No cross-context-advertising/'sale'-or-'share' restriction identified. Absent-field provenance as noted at module level.

Direct MarketingRed

No direct-marketing consent/suppression regime identified. Absent-field provenance as noted at module level.

Category narrative69 words

No cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition (e.g., GPC), clean-room/data-collaboration rule, cross-context-advertising restriction, or direct-marketing consent/suppression regime was identified for Pakistan. Absent-field provenance: searched 'Pakistan cookie consent law,' 'Pakistan dark patterns regulation,' 'Pakistan direct marketing consent law,' and reviewed MoITT/DataGuidance Pakistan materials; no responsive adtech-specific privacy rules located. This module reflects the broader absence of an enacted general data-protection statute from which such commercial-privacy rules would typically derive.

#

Only a broad security-based content-removal power is confirmed in force; no ADM/biometric/genetic-data-specific regime exists.

Traffic-light rationale — RedOnly a broad security-based content-removal power is confirmed in force; no ADM/biometric/genetic-data-specific regime exists.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision identified in force. Absent-field provenance: reviewed draft PDPB chapters and PECA text; no Article-22-style profiling restriction located.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation-right provision identified. Absent-field provenance as above.

Ai Risk AssessmentsRed

A Senate AI-regulation bill has reportedly been circulated/considered, but retrieved source content was insufficient (title-only) to support a substantive claim on its provisions or enactment status; recorded as an unresolved question requiring escalation.

Biometric RegimeRed

No biometric-data-specific regime (facial recognition, fingerprint, gait) identified. Absent-field provenance: searched 'Pakistan biometric data law facial recognition'; no responsive dedicated statute located beyond general SIM-registration/NADRA biometric-collection practice, which was not corroborated with a citable primary source in this run.

Genetic DataRed

No genetic-data-specific regime identified. Absent-field provenance as above.

State Surveillance CarveoutsAmber

PECA's content-removal grounds function as broad state-surveillance/national-security carveouts exercised by the PTA.

Claims (1):

  • PECA grants the Pakistan Telecommunication Authority (PTA) power to remove or block access to online content on grounds including the integrity, security, or defence of Pakistan, constituting a broad state-security carveout exercised outside any data-protection oversight framework.
Category narrative73 words

No enacted profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-regime, or genetic-data statute exists. PECA 2016 provides broad national-security/public-order grounds for the PTA to remove or block online content, functioning as a de facto state-surveillance/content-carveout mechanism rather than a data-protection ADM safeguard. Reports exist of a separately circulated Senate AI-regulation bill, but reviewed source material was insufficient to confirm substantive content or current status, so this is flagged as an unresolved question rather than a sourced claim.

Sources and claims (1)
  1. ConfirmedDataGuidance — PECA grants the Pakistan Telecommunication Authority (PTA) power to remove or block access to online content on grounds including the integrity, security, or defence of Pakistan, constituting a broad state-security carveout exercised outside any data-protection oversight framework.observed

#

Only a proposed, unenacted children's-data chapter exists; no operative minors' protections.

Traffic-light rationale — RedOnly a proposed, unenacted children's-data chapter exists; no operative minors' protections.

Sub-modules (5)

Age VerificationRed

No age-verification mechanism identified in force. Absent-field provenance: reviewed May 2023 draft table of contents; no separate age-verification chapter identified distinct from the general children's-data chapter.

Minor Profiling BansRed

No minor-profiling-ban provision identified. Absent-field provenance as above.

Education SettingsRed

No education-setting-specific children's-data provision identified. Absent-field provenance as above.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data protection provision identified. Absent-field provenance: searched 'Pakistan dependent adults data protection'; none located.

Category narrative58 words

No enacted age-of-consent, parental-consent, minor-profiling-ban, education-setting, or dependent-adult data protection provision exists. The May 2023 draft Personal Data Protection Bill contains a dedicated chapter on 'Processing personal data of children,' but this is unenacted proposal text. No further detail on the chapter's substantive content (e.g., specific age threshold or parental-consent mechanics) could be extracted from available source excerpts.

Sources and claims (1)
  1. ProbableMoITT — The May 2023 draft Personal Data Protection Bill contains a dedicated chapter titled 'Processing personal data of children,' proposal-stage only and not yet enacted.observed

#

No operative DPA-style enforcement, penalty, or redress mechanism exists; only proposed provisions in unenacted drafts.

Traffic-light rationale — RedNo operative DPA-style enforcement, penalty, or redress mechanism exists; only proposed provisions in unenacted drafts.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Draft bills propose a statutory Commission/Authority with investigative and penalty powers, including a corporate-liability provision, but none are operative.

Claims (1):

  • Successive draft bills (2020/2021/2023) propose a statutory Commission/Authority with corporate personality, investigative powers, and a corporate-liability provision imposing liability for non-compliance committed on the instructions of, or for the benefit of, individuals holding leading positions within an entity.

Enforcement Activity IndexRed

No data-protection-specific enforcement actions identified, consistent with the absence of an operative DPA. Absent-field provenance: searched for Pakistan data protection enforcement fines/decisions; none located.

Regulator Funding And CapacityRed

Not applicable/no data located; no independent DPA exists to fund or staff. Absent-field provenance as above.

Collective Redress And Class ActionsRed

No data-protection-specific collective-redress or class-action mechanism identified. Absent-field provenance: searched for Pakistan class action data protection; none located.

Private Right Of ActionRed

No confirmed private right of action for data-protection breaches identified in reviewed draft-bill excerpts. Absent-field provenance: draft bill sections on court remedies were not retrievable in sufficient detail in this run.

Recent Developments 180DRed

No enactment, new draft, or adequacy determination affecting Pakistan was identified within the last 180 days as of 2026-08-07. The most recent confirmed procedural development located is a August 2024 Senate Committee deliberation on the data-protection bill; broader industry tracking (IAPP, Jan 2025 update, refreshed through 2026) continues to list Pakistan among populous countries lacking a comprehensive privacy law.

Claims (1):

  • As of the most recent verifiable industry tracking, Pakistan remains among the most populous countries without a comprehensive national privacy law, with draft legislation still pending enactment.
Category narrative100 words

No enacted enforcement regime, regulator powers/penalties, collective-redress mechanism, or private right of action specific to data protection exists, because no comprehensive statute is in force. Draft bills (2020/2021/2023) propose a statutory Commission/Authority with corporate personality, investigative powers, and corporate-liability/penalty provisions, but these remain unenacted. As of the most recent verifiable reporting, Pakistan remains among the most populous countries without a comprehensive national privacy law, with draft legislation still pending; a Senate Committee was reported deliberating on the data-protection bill as of August 2024, with no confirmed enactment since. PTA under PECA has content-related enforcement powers, but these are not data-protection-specific.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableMoITT — Successive draft bills (2020/2021/2023) propose a statutory Commission/Authority with corporate personality, investigative powers, and a corporate-liability provision imposing liability for non-compliance committed on the instructions of, or for the benefit of, individuals holding leading positions within an entity.observed
  2. ConfirmedIAPP — As of the most recent verifiable industry tracking, Pakistan remains among the most populous countries without a comprehensive national privacy law, with draft legislation still pending enactment.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct50.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Pakistan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s) (28 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, and children_and_vulnerable_groups relied primarily on T1 anchors (MoITT draft Personal Data Protection Bill texts 2018/2020/2021/2023) plus T2 secondary reporting (IAPP, DataGuidance), all describing unenacted proposals. sectoral_watch and algorithmic_biometric_and_surveillance_governance relied on T1 (PECA-adjacent MoITT materials) and T2 (DataGuidance SBP/PECA reporting) for in-force sectoral findings. adtech_and_commercial_privacy had no T1/T2/T3 anchors located and is recorded as a full gap with absent_field_provenance. enforcement_and_redress relied on T1 draft-bill enforcement chapters plus T2/T3 industry tracking for the 180-day recency check. Several sub-modules across multiple modules (DPO, ROPA, joint-controller, portability, adequacy, SCC/BCR, TIA, health/employment/credit/education/insurance overlays, biometric/genetic regimes, dependent adults) returned no responsive T1-T3 material and are recorded as explicit gaps rather than inferred.

Unresolved questions (5):

  • Has the Personal Data Protection Bill (May 2023 draft or a later version) been introduced to, or passed by, the National Assembly or Senate since the reported August 2024 Senate Committee deliberation?
  • Is there a 2025 or 2026 draft superseding the May 2023 text, and if so, what does it change regarding the Commission's powers, children's-data chapter, or cross-border transfer conditions?
  • Does PECA, as currently amended, contain any provisions imposing direct data-protection obligations (e.g., data-handling duties on service providers) beyond cybercrime and content-removal powers?
  • What is the current substantive content and legislative status of the separately reported Senate AI-regulation bill, and does it interact with the pending Personal Data Protection Bill?
  • Are there NADRA-specific biometric-data handling rules that should be treated as a distinct T1 anchor for the biometric_regime sub-module?

Escalate to primary-source review: yes