Business Consulting

Data Protection Rules Are Coming to Pakistan — Is Your Business Ready?

Data Protection Rules in Pakistan— Is Your Business Ready? Pakistan does not yet have a comprehensive data protection law. That statement is both true and increasingly misleading as a reason to do nothing. As…

10 mins read
Data Protection Rules in Pakistan

Data Protection Rules in Pakistan— Is Your Business Ready?

Pakistan does not yet have a comprehensive data protection law. That statement is both true and increasingly misleading as a reason to do nothing. As of May 2026, Pakistan has no comprehensive, enacted personal data protection law. But the Personal Data Protection Bill has cleared the Federal Cabinet and is awaiting Parliamentary passage. The Draft Bill provides for fines of up to USD 2 million for unlawful processing of personal data. Sector-specific rules from the State Bank of Pakistan and SECP already impose data handling obligations on regulated businesses. And PECA 2016, as amended in 2025, creates criminal liability for unauthorised disclosure of personal data right now, today, without waiting for new legislation.

The businesses that will be caught off guard when full data protection legislation passes are the ones treating the absence of a comprehensive law as permission to operate without data governance. That window is closing.

What Is Already Law

Before the Personal Data Protection Bill becomes relevant, three existing legal frameworks already impose obligations on Pakistani businesses handling personal data.

PECA 2016 and the 2025 Amendment. Under Section 38 of PECA 2016, any person who has access to personal or sensitive data and transfers that data without the consent of the data subject, except when required by law, faces imprisonment of up to three years, a fine of up to PKR 1 million, or both. Unauthorised access to information systems under Section 3 carries up to three months’ imprisonment and PKR 50,000. Unauthorised copying or transmission of data under Section 4 carries up to six months ‘ imprisonment and PKR 100,000.

The Prevention of Electronic Crimes (Amendment) Act, 2025, passed in January 2025, transferred exclusive cybercrime investigation powers from the FIA to the new National Cyber Crime Investigation Agency. The NCCIA has broader investigative authority and a clearer mandate than its predecessor. Enforcement is becoming more structured, not less.

SBP data governance rules. The State Bank of Pakistan has issued cybersecurity and data governance frameworks that apply to all regulated financial institutions. These cover data classification, access controls, breach notification to the SBP, and vendor management requirements for any third party handling customer financial data. Financial institutions that are not compliant with SBP’s existing framework face regulatory action independent of any new privacy legislation.

SECP requirements. The Securities and Exchange Commission of Pakistan has issued directives covering data protection for licensed entities in capital markets, insurance, and non-banking financial companies. These include requirements around data security, client data handling, and incident reporting.

For any business in financial services, insurance, or capital markets in Pakistan, the compliance obligation is not theoretical and is not waiting for the Personal Data Protection Bill. It is already active.

What the Personal Data Protection Bill Will Require

The Personal Data Protection Bill 2023, also referred to in government communications as the Personal Data Protection Act 2025 in its updated draft form, has been approved by the Federal Cabinet but has not passed both houses of Parliament. As of May 2026, neither version is law.

That said, the bill’s requirements are known, the direction is clear, and businesses that begin aligning now will have a significantly easier compliance path than those that wait for Royal Assent and then scramble.

Lawful basis for processing. Personal data must be processed in a lawful, transparent, and fair manner. Data may only be collected for specified, explicit, and legitimate purposes. This means organisations need to be able to articulate why they are collecting every category of personal data they hold, and to demonstrate that the collection is limited to what is necessary for that stated purpose.

Consent requirements. Under the Draft Bill, sensitive and critical personal data may only be processed on an exceptional basis. Generally, explicit consent of the data subject is required. Implied consent, pre-ticked boxes, and bundled terms-and-conditions consent are all insufficient under this standard. Consent needs to be specific, informed, freely given, and revocable.

A tiered penalty structure. General unlawful processing may attract fines up to USD 125,000, increasing to USD 250,000 for repeat violations. Unlawful handling of sensitive personal data, including financial, health, biometric, or identity data, may result in fines up to USD 500,000. Violations involving critical personal data, including nationally sensitive or regulator-designated data, may attract fines up to USD 1 million.

A 72-hour breach notification window. The pending Personal Data Protection Bill would introduce a 72-hour window for reporting breaches to the proposed National Commission for Personal Data Protection. This mirrors the GDPR’s breach notification requirement and means businesses need both the technical capability to detect a breach promptly and a documented process for reporting it within the window.

Cross-border data transfer restrictions. The bill contains provisions governing cross-border transfer of personal data, requiring that data transferred outside Pakistan goes only to jurisdictions with adequate protection standards or under approved transfer mechanisms. For businesses using cloud services hosted outside Pakistan, including Google Workspace, Microsoft 365, or any SaaS platform with servers abroad, this has direct operational implications.

What “Sensitive Personal Data” Means Under the Bill

The penalty tiers make the definition of sensitive personal data commercially significant. The Personal Data Protection Act 2025 draft introduces an enhanced definition of sensitive data to include caste and ethnicity, as well as provisions on safeguards for children’s data including mandatory age verification and parental consent requirements.

Beyond those additions, sensitive data under the bill covers financial data, health and medical records, biometric data, identity document numbers, and political or religious beliefs. For businesses in financial services, healthcare, e-commerce, and HR, the data they routinely handle falls squarely into the highest penalty tier. Processing that data without the right controls and consent mechanisms is not a technical compliance gap. It is a USD 500,000 exposure per violation.

Data Protection Rules in Pakistan

The Gap Between Current Practice and What the Law Will Require

Most Pakistani businesses that handle personal data are operating without the documentation infrastructure the bill will require. A few specific gaps come up consistently.

No data inventory. Organisations that cannot list what personal data they hold, where it lives, how it flows through their systems, and who has access to it cannot demonstrate a lawful basis for processing. Building that inventory is the first compliance task and the one most organisations have not started.

No documented consent mechanism. Many businesses collect personal data through forms, CRMs, and applications that were built before consent documentation was a consideration. Retrofitting proper consent flows into existing customer journeys takes time and requires involvement from both IT and legal teams.

No breach detection or notification capability. Pakistan currently has no mandatory data breach notification requirement under existing law. Neither PECA 2016 nor the 2025 amendments impose a notification obligation. As a result, most businesses have never built the detection and response capability that a 72-hour notification window demands. Discovering a breach, containing it, assessing scope, and notifying a regulator within 72 hours requires both technical infrastructure and a documented incident response process that most Pakistani businesses do not currently have.

No vendor management framework. Cloud service providers, payment processors, HR software vendors, and any third party that touches personal data on behalf of the business will need to operate under data processing agreements that meet the bill’s standards. Most businesses have no inventory of those relationships and no contracts in place that address data protection obligations.

What to Do Before the Bill Passes

Waiting for the bill to pass before acting is a reasonable short-term posture. Waiting for it to pass before preparing is not.

The most useful thing a Pakistani business can do right now is treat the bill’s requirements as a readiness framework and close the gaps while there is no enforcement pressure. That means:

Conducting a data inventory to understand what personal data the business holds, where it is processed, and who has access. This includes data held in cloud platforms, in CRM systems, in HR software, and in any third-party service.

Reviewing consent mechanisms across every customer touchpoint where personal data is collected. Website forms, mobile apps, e-commerce checkout flows, and account registration processes all need to meet the explicit, specific, and revocable consent standard the bill requires.

Building breach detection and notification capability. An endpoint detection and response platform, network monitoring, and a documented incident response plan are all prerequisites for the 72-hour notification obligation. These also satisfy the security controls that cyber insurance carriers increasingly require.

Mapping third-party data flows. Every vendor that processes personal data on the business’s behalf needs to be identified, inventoried, and eventually covered by a data processing agreement that meets the bill’s standards.

It is prudent for organisations to align their data protection practices with the principles reflected in the Draft Bill, as well as with established international best practices, particularly those embodied in the GDPR, to ensure a higher level of data protection, regulatory readiness, and future compliance once the law is enacted.

How Trubyte Supports Data Protection Compliance in Pakistan

The technical infrastructure that data protection compliance requires- access controls, encryption, breach detection, incident response capability, and data classification tools- is the same infrastructure that good cybersecurity practice demands. They are the same investment, not two separate ones.

Trubyte works with businesses across Pakistan to build IT environments that meet both security and compliance requirements. As an authorised Fortinet partner in Pakistan, we deploy network security infrastructure that includes the traffic visibility, access control, and logging capabilities that data protection frameworks require. As a Google partner, we support businesses in configuring Google Workspace environments with the data loss prevention, access controls, and audit logging that personal data handling obligations demand.

We work with businesses across Pakistan’s major commercial centres to ensure that the technical environment supports compliance rather than creating liability. For businesses in SBP- or SECP-regulated sectors, that means aligning the IT environment with existing regulatory requirements now, and positioning for the Personal Data Protection Bill when it passes.

Contact Trubyte to discuss where your current IT environment stands against the data protection requirements that are already in force, and what preparation for the bill looks like in practice.

Frequently Asked Questions (FAQs) — Data Protection & Compliance in Pakistan

Does Pakistan have a data protection law in 2026?
Not a comprehensive one. As of mid-2026, Pakistan's primary legislation covering personal data is PECA 2016 and its 2025 amendments, which create criminal liability for unauthorised disclosure of personal data. The Personal Data Protection Bill has been approved by the Federal Cabinet but has not passed both houses of Parliament. Sector-specific rules from SBP and SECP impose additional data handling obligations on regulated businesses.
What are the penalties under the Personal Data Protection Bill?
The bill proposes a tiered penalty structure. General unlawful processing attracts fines up to USD 125,000, rising to USD 250,000 for repeat violations. Unlawful handling of sensitive personal data, including financial, health, and biometric data, may result in fines up to USD 500,000. Violations involving critical personal data may attract fines up to USD 1 million or higher at the Commission's discretion.
What counts as sensitive personal data under the bill?
The draft bill defines sensitive data broadly, including financial data, health and medical records, biometric data, identity document numbers, political and religious beliefs, caste and ethnicity, and data relating to children. Businesses handling any of these categories face the highest penalty tier and the strictest consent and security requirements.
Does my business need to comply with data protection rules if the bill has not passed?
Possibly yes, depending on your sector. PECA 2016 creates existing criminal liability for unauthorised personal data disclosure. Financial institutions and capital markets businesses face SBP and SECP data governance requirements that are already active. All businesses should treat the bill's requirements as a readiness framework and begin closing compliance gaps before enforcement begins.
How can Trubyte help with data protection compliance in Pakistan?
Trubyte builds the technical infrastructure that data protection compliance requires, including access controls, network monitoring, breach detection, incident response capability, and secure cloud configuration. As an authorised Fortinet partner and Google partner in Pakistan, Trubyte works with businesses across Karachi, Lahore, and Islamabad to align IT environments with existing regulatory requirements and prepare for the Personal Data Protection Bill. Contact Trubyte to start with an assessment.

Syed Ahsan

Contributor at Trubyte.

Leave A Comment

Your email address will not be published. Required fields are marked *