Pakistan Has a New Data Policy and Still No Data Protection Law. They Are Not the Same Thing.
The new National Data Governance Policy covers government data. Your personal data still has no law, and the bill sits in Parliament.

The IT ministry has finalised the National Data Governance Policy 2026, and a lot of people are going to read that headline and assume Pakistan now has a data protection law.
It does not. The policy is about how the government manages its own data. Your personal data, held by every bank, telco, shop and app you have ever given a CNIC to, is still governed by no comprehensive law at all.
What the new policy actually does
Finalised by the Ministry of Information Technology and Telecommunication with the Pakistan Digital Authority, after consultation with federal and provincial governments and other stakeholders, it sets a framework for government data: governance, interoperability, legal harmonisation, classification and implementation.
The practical core is exchange. Government data sits in institutional silos that cannot talk to each other, which is why you supply the same CNIC to four departments for one transaction. The policy introduces a WASL system to allow secure exchange between institutions based on classification standards, so sensitivity determines what moves where.
One design choice is worth noting because it is unusual and sensible: data ownership stays with each government entity rather than being centralised into one national pool. Exchange without amalgamation is a meaningfully different architecture from one giant database, and it is the safer of the two.
Federal Minister Shaza Fatima Khawaja put the rationale plainly: the government, as the country's largest custodian of public data, needs a comprehensive framework to manage, protect, share and responsibly use it. That is true, and this is a real piece of work. It is simply not the thing most people searching for data protection in Pakistan are looking for.
The law that does not exist
Here is the position on your personal data, as of today.
| Instrument | What it governs | Status |
|---|---|---|
| National Data Governance Policy 2026 | Government's own data | Finalised |
| Personal Data Protection Bill | Your personal data | Approved by cabinet, not passed by Parliament |
| PECA 2016 | Criminalises specific misuse | In force, amended January 2025 |
| A general law on how companies handle your data | Nothing | Does not exist |
The Personal Data Protection Bill has been through consultation and has been approved by the Federal Cabinet, and it has still not passed both houses of Parliament. It has been in that condition for years. Its draft framework is reported to mirror the European Union's GDPR closely, with penalties for unlawful processing reported up to two million dollars, which would be a serious regime if it were law.
PECA is not a substitute, and the distinction matters. PECA is a criminal statute: it lets the state prosecute certain kinds of misuse after they happen. It does not tell a company what it may collect, how long it may keep it, whether it may sell it, or what you can demand. Those are data rights, and Pakistan has not legislated them.
What the gap means on an ordinary day
Think about who holds your CNIC number. Your bank. Every telco you have taken a SIM from. The property dealer. The car showroom. The hospital. Several apps. A shop that photocopied it for a warranty.
Now ask the questions a data protection law would answer. Which of them may sell that data? How long may they keep it after you stop being a customer? Can you require them to delete it? If a database leaks, who must tell you, and how fast? Which authority do you complain to?
In Pakistan today, the answers are respectively: unclear, indefinitely, no, nobody, and none. There is no data protection authority to receive a complaint, which is a large part of why leaked databases circulate here with so little consequence, and why the SIM lookup sites we wrote about in the CNIC guide can trade in data that would be plainly unlawful in a jurisdiction with a statute.
It is also the backdrop to the scams we document constantly, from fake challan texts to fraudulent scheme selections. Those operations run on personal data that leaked from somewhere, and the somewhere faces no data protection liability for having leaked it.
Why the government's own data still matters to you
Do not read this as the policy being pointless. Government data governance is the foundation everything else in the digital state gets built on.
The single digital ID, the online character certificate and driving permit systems approved this week, and the tax and licensing portals we keep writing about all depend on institutions exchanging data reliably and safely. A classification standard is what stops a convenient integration becoming a careless one.
The uncomfortable observation is about sequence. Pakistan is building the state's capacity to share data faster than it is building the citizen's right to control theirs. Those two things are supposed to arrive together, and one of them has been in Parliament for years.
What to watch
The Personal Data Protection Bill actually passing both houses. That is the single event that would change any of this, and it has been imminent for long enough that scepticism is earned rather than cynical.
Second, whether the governance policy's phased implementation produces anything visible. Policies that arrive with capacity building plans and governance arrangements are easy to announce and hard to deliver, and the measure will be mundane: whether you stop having to submit the same CNIC to four departments.
Questions readers are asking
Does Pakistan have a data protection law?
Not a comprehensive one. The Personal Data Protection Bill has been approved by the Federal Cabinet but has not passed both houses of Parliament, so no general statute governs how organisations handle your personal data.
What is the National Data Governance Policy 2026?
A framework finalised by the IT ministry with the Pakistan Digital Authority for how government institutions manage, classify and exchange their own data. It is about state data, not citizens' personal data.
Does PECA protect my personal data?
Not in the way a privacy law would. PECA 2016 criminalises specific forms of misuse after the fact, but it does not set rules for collection, retention, sharing or deletion, and it gives you no data rights to exercise.
Who do I complain to if my data is misused?
There is no data protection authority in Pakistan. Criminal misuse can be reported to the FIA's cybercrime wing, but there is no regulator for ordinary mishandling by a company.
What is the WASL system?
The mechanism in the new policy for secure exchange of government data between institutions, based on classification standards, with each entity retaining ownership of its own data rather than pooling it centrally.
Would the pending bill be strict?
Its draft framework is reported to follow the EU's GDPR closely, with penalties for unlawful processing reported up to two million dollars. Whether that is what eventually passes is a question for Parliament.
About the author

Author
Ali Akhtar is a young and curious voice here at Pakistan Era. He is currently pursuing his A-Levels and has a growing interest in Pakistan’s changing industrial landscape and educational trends. Ali likes to write in a way that helps him explain and explore the world around him. His writing reflects the perspective of the new generation navigating the evolving trends of Pakistan where technology, youth innovation, and shifting opportunities are reshaping the country’s future.




