Pakistan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Pakistan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Pakistan has no general privacy law. Draft bills have been circulating since 2018 and none has passed. There is no privacy regulator. For most businesses, nothing stops data leaving the country. But four regulated industries are strict. Telecoms, banking, payments and government all have to keep data inside Pakistan, unless a regulator says otherwise.
Data governance in Pakistan
The eight things that decide how you handle data about people in Pakistan. Same eight on every country page, so you can compare.
Who has to follow these rules
There is no general privacy law, so no general privacy duty reaches a foreign company. Two other laws do reach across the border. The cybercrime law covers acts done outside Pakistan that harm a person, a computer system or data inside Pakistan. The telecoms regulator can also order any website or app that people in Pakistan can reach to take content down. There is no size or revenue threshold. There is no general duty to appoint anyone in Pakistan.
The Prevention of Electronic Crimes Act 2016, section 1(3), applies to every citizen of Pakistan wherever they are, and to every other person who is in Pakistan at the time. Section 1(4) extends it to any act committed outside Pakistan that is an offence under the Act and affects a person, property, information system or data located in Pakistan. Section 37 gives the Pakistan Telecommunication Authority power to remove or block online content, on broad public-order and national-security grounds. The 2025 amendment created a Social Media Protection and Regulatory Authority. That body 'may require any social media platform to enlist with it'. The registration power exists on paper. We found no evidence it has been switched on. The 2023 draft privacy bill would go much further. It would reach companies with no physical presence in Pakistan, whether they decide how data is used or only handle it for someone else. But it is a draft and binds nobody.
Sources
- Official sourceNational Cyber Emergency Response Team of Pakistan (PKCERT)Prevention of Electronic Crimes Act, 2016, section 1 (extent and application)
pkcert.gov.pk
“It shall also apply to any act committed outside Pakistan by any person if the act constitutes an offence under this Act and affects a person, property, information system or data located in Pakistan.”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025 (Act No. II of 2025)
na.gov.pk
“The Authority may require any social media platform to enlist with it in such manner, form and on payment of such fee, as may be prescribed.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationLegislation page listing the Personal Data Protection Bill only as a draft (2018, 2020, 2023)
moitt.gov.pk
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and with no paperwork, because no law controls it. Four industries are the exception, and they are strict. Telecoms companies need the telecoms regulator's approval to store any data outside Pakistan. Banks must put cloud data on servers inside Pakistan, and cannot put core banking on a cloud at all. Electronic money firms need the central bank's written approval before moving any function abroad. Government bodies must use clouds located in Pakistan.
Here is what we found industry by industry, checked 18 August 2026. TELECOM. Closed by default. The Critical Telecom Data and Infrastructure Security Regulations 2020 say plainly that no data shall be stored beyond the country's geographical boundaries without the approval of the Pakistan Telecommunication Authority. That binds every licensee of the Authority. It covers mobile operators, fixed-line operators, internet service providers and long-distance operators. A 2025 replacement version is published on the regulator's site. It is a scanned image with no readable text, so we cannot confirm whether the wording changed. BANKING. Closed for cloud, permission-based for everything else. The State Bank of Pakistan's Enterprise Technology Governance and Risk Management Framework requires cloud service providers to be located in Pakistan. All physical servers and data centres must sit and operate in Pakistan. Separately, core banking systems that handle or store customer data may not be put on a cloud at all. The outsourcing rules require prior State Bank approval for any outsourcing outside Pakistan. They ban providers abroad that are not themselves regulated. They ban sub-contracting of work done abroad. And they require both customer consent and prior written State Bank approval before confidential customer information goes to a provider abroad. PAYMENTS AND E-MONEY. Permission-based. Electronic money institutions may not outsource any function outside Pakistan without prior written approval from the State Bank. GOVERNMENT. Closed. The Cloud First Policy 2022 limits government cloud to Pakistani locations. Private cloud infrastructure must be located in Pakistan. Restricted, confidential and secret classes of government data may only sit on a government or private cloud inside the country. INSURANCE AND SECURITIES. We found no rule about keeping data in the country on the regulator's own site as at 18 August 2026. The Securities and Exchange Commission of Pakistan has issued a cyber security advisory circular. We found no rule from it on cloud or on where data must sit. HEALTH, EDUCATION, GAMBLING. We found no rule, checked 18 August 2026. Gambling is a criminal offence in Pakistan, so there is no licensed gambling industry to regulate. MAPPING AND GEOSPATIAL. Restrictions almost certainly exist. The Survey of Pakistan publishes Surveying and Mapping Rules 2015, and 1981 rules on the publication, classification, issue and custody of maps. Both files are scanned images we could not read, so we do not state their content.
Sources
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 8(13)
pkcert.gov.pk
“No Data shall be stored beyond country's geographical boundaries without the approval of the Authority.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework for Financial Institutions
archive.sbp.org.pk
“For all types of cloud services including Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS), the CSPs shall be located in Pakistan and all physical servers and services (data centers and allied infrastructure) shall reside and operate from Pakistan.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“Any outsourcing arrangement outside Pakistan will require SBP's prior approval subject to approval of the Country Head.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions
archive.sbp.org.pk
“EMI shall not outsource, outside Pakistan, any of its function(s) without prior written approval from SBP.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPakistan Cloud First Policy, 2022 — cloud selection matrix and deployment rules
moitt.gov.pk
“Private Cloud infrastructure must be located in Pakistan either on premise or off premise.”
Link checked 18 August 2026
- Official sourceSecurities and Exchange Commission of PakistanCirculars index — no cloud or data residency circular found for 2024 to 2026
secp.gov.pk
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
At national level there is nothing to put in place, because there is no rule. In the regulated industries you need permission, one case at a time, from the regulator that licenses you. There is no approved-country list. There is no government-published standard contract. There is no certification scheme you can rely on instead. Because there is no list, there is also no list that can be quietly filled in.
- Ways to send data out:
- Nothing required · Government sign-off needed · Explicit consent
At national level there is no restriction. No law names permitted or forbidden destinations. In telecoms, sending data abroad needs approval from the Pakistan Telecommunication Authority, which it can grant or refuse. That comes from the critical telecom data regulations. In banking, you need prior approval from the State Bank. For confidential customer information you need prior written State Bank approval plus the customer's own consent. The provider abroad may not sub-contract at all. Banks must also make sure all information about outsourcing outside Pakistan stays available inside Pakistan, and open to State Bank inspection at any time. That works like a keep-a-copy-here rule. For electronic money institutions, any function abroad needs prior written State Bank approval. In the public sector, the Cloud Office inside the Ministry of Information Technology and Telecommunication signs off exceptions. The 2023 draft privacy bill would add a test of whether the destination country is safe enough, plus binding contracts and consent. It would forbid critical personal data leaving at all. But it is a draft.
Sources
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“The FIs shall ensure that all information relating to outsourcing outside Pakistan is available domestically and is also available for review or inspection by SBP at any time.”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 8(13)
pkcert.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, May 2023 draft, clauses 31 and 32 (transfer abroad)
moitt.gov.pk
“Critical Personal Data shall only be processed in a server(s) or digital infrastructure located within the territory of Pakistan.”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
Nobody enforces privacy, because Pakistan has no privacy regulator. The 2023 draft bill would create one, but it has never been passed. What does exist and does work are the industry regulators. The central bank supervises banks and payment firms. The telecoms regulator supervises telecoms companies. The new digital authority is staffed and publishing, but it has issued no binding rules yet. Its own website says rules will be posted when they become available.
There is no data protection authority in Pakistan at all. The May 2023 draft bill would have created a National Commission for Personal Data Protection within six months of the law starting. The bill was never enacted, so the Commission does not exist. The Pakistan Digital Authority, created by the Digital Nation Pakistan Act 2025, really is operational. It has a chairman. It ran the consultation on the National Data Governance Policy 2026 and closed it on 5 August 2026. It runs the national data exchange layer. It publishes a standards register. But its own Acts and Regulations page carries only the founding Act, plus a line saying rules and regulations will be posted as they become available. It has issued no binding data rules. The 2025 amendment to the cybercrime law created two more bodies. The National Cyber Crime Investigation Agency took over cybercrime investigation from the Federal Investigation Agency. The Social Media Protection and Regulatory Authority was created on paper. We could not find any official website or published decision for it, so we do not treat it as operational. The national computer emergency response team is operational and issues security advisories dated 2026. Overall: nothing is happening on data protection. That is about privacy enforcement only. Banking and telecoms supervision are active and backed by licences.
Sources
- Official sourcePakistan Digital AuthorityActs and Regulations — only the founding Act published; rules to follow
pda.gov.pk
“Rules & regulations will be posted here as they become available.”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025 — creation of the investigation agency and social media authority
na.gov.pk
Link checked 18 August 2026
- Official sourcePKCERTNational Cyber Emergency Response Team of Pakistan — advisories dated 2026
pkcert.gov.pk
Link checked 18 August 2026
- Official sourcePakistan Digital AuthorityPress releases — consultation on the National Data Governance Policy 2026 concluded 5 August 2026
pda.gov.pk
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum but almost no maximum. Telecoms and internet companies must keep connection records for at least one year. The telecoms regulator can change that period by notice. Electronic money firms must keep records for at least ten years. The emergency response teams keep incident data for at least three years. Nothing in force tells an ordinary company when it must delete personal data.
- What you have to do here:
- Keep data for a minimum period
MINIMUM. The cybercrime law requires a service provider to keep its specified traffic data for at least one year, or any other period the Pakistan Telecommunication Authority notifies. It must hand the data over on a court warrant. Failure can attract a fine up to ten million rupees, roughly thirty-six thousand United States dollars. Electronic money institutions must keep all necessary records for at least ten years, or as required by other laws. Computer emergency response teams must securely keep data they receive for at least three years, unless a competent authority extends that or erases it. The critical telecom data regulations tell licensees to follow their licensed keeping periods, and to ask the regulator when a period is unclear. So the real answer for a telecoms licensee sits in its own licence, not in a public rule. MAXIMUM. No general deletion duty is in force. The draft National Data Governance Policy 2026 would introduce one for government data. It says personal data shall not be kept beyond the defined period, except where required by law or judicial process. It is not yet approved. The 2023 draft privacy bill would introduce a general one. CONFLICT. There is no general maximum, so there is nothing for the minimums to conflict with. If the draft policy or bill is adopted, both texts follow the same pattern. A specific legal keeping requirement wins over the deletion duty.
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPrevention of Electronic Crimes Act, 2016, section 32 (retention of traffic data)
moitt.gov.pk
“A service provider shall, within its existing or required technical capability, retain its specified traffic data for a minimum period of one year or such period as the Authority may notify from time to time and, subject to production of a warrant issued by the Court, provide that data to the investigation agency.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions — record keeping
archive.sbp.org.pk
“EMIs shall maintain all necessary records for at least 10 years or as required by the relevant laws.”
Link checked 18 August 2026
- Official sourcePKCERT / Ministry of Information Technology and TelecommunicationPakistan Computer Emergency Response Team Rules, 2023 — retention of incident data
pkcert.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationDraft National Data Governance Policy 2026 — retention limit for personal data
moitt.gov.pk
“Personal data shall not be retained beyond the defined period save where expressly required by applicable law or by judicial process.”
Link checked 18 August 2026
What to do: Check the minimum keep-period before you delete anything.
If something goes wrong
There are three separate clocks and they do not line up. If you are in a critical industry such as banking or telecoms, you must tell your industry emergency response team and the national one within one hour. Banks must also tell the central bank within forty-eight hours. Telecoms licensees must tell the telecoms regulator within seventy-two hours. There is no general duty to tell the people whose data was exposed.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator
CLOCK ONE. One hour. The Computer Emergency Response Team Rules 2023 set this. You must make a short report of an incident within one hour of identifying it. It goes to your industry response team and to the national one. Use best estimates and update later. The rules cover federal and provincial government bodies and critical industries, including defence, telecom, banking, finance, power and utilities. CLOCK TWO. Forty-eight hours. Financial institutions must report to the State Bank's Banking Policy and Regulation Department within forty-eight hours. That covers all confirmed information or cyber security breaches involving financial loss, theft of confidential data, or a major disruption leaving customers without banking services for more than two hours. CLOCK THREE. Seventy-two hours. Telecoms licensees must inform the Pakistan Telecommunication Authority within seventy-two hours of discovering a data breach, or damage to critical telecom infrastructure or critical data. A large bank running its own network can be inside all three at once. There is no duty in force to notify the people affected. The 2023 draft bill would have added a seventy-two hour duty to notify both the regulator and the person. It is a draft.
Sources
- Official sourcePKCERT / Ministry of Information Technology and TelecommunicationPakistan Computer Emergency Response Team Rules, 2023 — one hour reporting
pkcert.gov.pk
“summarily report incidents to their respective Sectoral and the National CERT within one hour of being identified”
Link checked 18 August 2026
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework — incident reporting
archive.sbp.org.pk
“The FI(s) shall report to Banking Policy & Regulation Department (BPRD), SBP within forty eight (48) hours after the incident all established information/cyber security breaches and related incidents involving financial loss, stealing of confidential data and major disruption in the banking system”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 18(2)
pkcert.gov.pk
“In case of a data breach or damage to CTI or critical data, the licensee shall duly inform the Authority within 72 hours from the discovery of the incident.”
Link checked 18 August 2026
What to do: Your breach process has to reach Pakistan's regulator inside the deadline above.
What catches people out
The biggest trap is reading the easy answer and stopping there. Pakistan's real data rules are licence conditions, not privacy law. So the penalty is your licence, rather than a fine. Banks cannot put core banking on any cloud at all, local or foreign. Moving bank customer data abroad needs the customer's consent and the central bank's written approval. And the cybercrime law is criminal law. People go to prison. Companies do not simply get fined.
- What it costs if you get it wrong:
- Criminal liability · Loss of your licence
1. THE RULES LIVE IN LICENCES. There is no privacy statute, so the binding duties sit in regulator rulebooks and licence conditions. A compliance review that searches for a data protection act finds nothing and concludes Pakistan is open. The telecoms and banking rules are enforced through supervision and licensing. The penalty is suspension or loss of licence, not a large public fine. 2. NO CLOUD FOR CORE BANKING, ANYWHERE. The State Bank rule is not only about location. Core banking applications, services and business processes used to handle or store customer and borrower data may not go on a cloud at all. Cloud is limited to non-core support, such as collaboration tools, human resources and procurement. A local cloud region does not fix this. 3. BANK CUSTOMER DATA ABROAD NEEDS TWO KEYS. Sharing confidential customer information with a provider abroad needs both the customer's consent and prior written State Bank approval. You need both, whatever the contract says. The provider abroad must itself be regulated, and it may not sub-contract at all. 4. CRIMINAL, NOT ADMINISTRATIVE. The cybercrime law creates prison sentences. Using another person's identity information without authorisation carries up to three years. Investigators can force a person holding decryption information to hand over readable data. That is personal exposure for staff, not a company fine. 5. THE ONE-HOUR CLOCK. Most incident plans are written around seventy-two hours. In Pakistan a critical-industry organisation has one hour to make a first report to its industry and national response teams. Missing it is the failure we would most expect. 6. THE TELECOM RULES WERE REPLACED IN 2025 AND THE NEW TEXT IS UNREADABLE. The regulator publishes a 2025 version of the critical telecom data regulations as a scanned image with no readable text. We can verify the 2020 wording. The current wording may differ.
Sources
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework — cloud restrictions
archive.sbp.org.pk
“Core banking applications/services/operations and business processes used to process and store customer/borrower data/information shall not be placed under cloud-based outsourcing arrangements.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements — offshore customer data
sbp.org.pk
“the FIs shall seek consent of the customer and prior written approval of SBP. Such approval is necessary regardless of the fact that the specified data/information is provided to a third party.”
Link checked 18 August 2026
- Official sourcePKCERTPrevention of Electronic Crimes Act, 2016, sections 16 and 35
pkcert.gov.pk
“require any person who is in possession of decryption information of an information system, device or data under investigation to grant him access to such data, device or information system in unencrypted or decrypted intelligible format”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations 2025 (scanned image, no readable text)
pta.gov.pk
Link checked 18 August 2026
What's changing next
One thing is close. A National Data Governance Policy was published in draft in June 2026. Consultation closed on 5 August 2026, and the digital authority says it has moved to final stage. It still needs Cabinet approval and publication in the official gazette. It would force restricted, confidential and personal government data to stay inside Pakistan. A general privacy law is still only a draft, and has been for eight years.
COMING. The draft National Data Governance Policy 2026 was published by the Ministry of Information Technology and Telecommunication on 26 June 2026. It sets three tiers for where data may sit. Tier one covers restricted, confidential and personal data. It must be hosted, stored and handled within the territory of Pakistan. Tier two is internal data. It may be handled abroad only with prior approval from the Pakistan Digital Authority, plus safeguards in the contract. Tier three is open data. It may be hosted anywhere. The document records its own status as proposed, taking effect on gazette notification. The Pakistan Digital Authority announced on 5 August 2026 that consultation had ended and the policy had moved from draft to final stage. Read the scope carefully. The text is written around government data and public bodies. It is not yet clear how far it will bind private companies. STILL A DRAFT. The Personal Data Protection Bill has existed in drafts dated 2018, 2020 and 2023, and has not been passed. The 2023 draft would forbid critical personal data leaving Pakistan. It would require a test of whether the destination country is safe enough for other transfers. It would create a National Commission for Personal Data Protection within six months. It would impose a seventy-two hour breach notification duty. And it would set penalties up to two million United States dollars, or one per cent of annual gross revenue, whichever is higher. None of this binds anyone today. POWERS ALREADY IN PLACE, WHICH MATTER MORE. 1. The telecoms regulator can refuse or withdraw approval for storing data abroad at any time, under a regulation already in force. No consultation is needed. 2. The cybercrime law lets the telecoms regulator change the traffic data keeping period by notification, from the current one year to any period it chooses. 3. The 2025 amendment lets the new social media authority require any social media platform to enlist with it, on terms to be set. The power exists. The rules have not been made. 4. The telecoms regulator's content blocking power is broad and immediate. The 2025 amendment adds a twenty-four hour removal deadline for content the authority treats as false information. 5. The Pakistan Digital Authority has legal power to develop and enforce a national data strategy and national data governance rules, across both the public and private sectors. It has published no rules yet.
Sources
- Official sourceMinistry of Information Technology and TelecommunicationDraft National Data Governance Policy 2026 — tiered residency model
moitt.gov.pk
“Hosted, stored, and processed within the territory of Pakistan.”
Link checked 18 August 2026
- Official sourcePakistan Digital AuthorityConsultations concluded on the National Data Governance Policy 2026, 5 August 2026
pda.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, May 2023 draft
moitt.gov.pk
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanDigital Nation Pakistan Act, 2025 (Act No. I of 2025) — powers of the Pakistan Digital Authority
na.gov.pk
“develop and enforce a National Data Strategy and comprehensive data governance framework within government entities and across public and private sectors”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Critical Telecom Data and Infrastructure Security Regulations, 2020 · Made by the Pakistan Telecommunication Authority under the Pakistan Telecommunication (Re-organization) Act, 1996 · Directly binding regulation
Every telecoms licensee in Pakistan must keep its data inside the country, unless the telecoms regulator approves otherwise. It must also report a breach within seventy-two hours. This is Pakistan's strictest rule about keeping data in the country. It binds mobile operators, fixed-line operators and internet service providers.
Enforced by Pakistan Telecommunication Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryNo data may be stored outside Pakistan without the telecoms regulator's approval.
- Put a transfer safeguard in placeApproval of the Authority is the only route out.
- Report breaches to the regulator — within 72 hoursData breach or damage to critical telecom infrastructure or critical data.
- Secure the data
- Keep data for a minimum periodLicensed retention periods apply; the licensee must ask the regulator where the period is unclear.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions and regulations made under the telecoms Act
- Order to stopEnforcement order by the Authority
Sources
- Official sourcePakistan Telecommunication Authority, republished by PKCERTCritical Telecom Data and Infrastructure Security Regulations, 2020
pkcert.gov.pk
“No Data shall be stored beyond country's geographical boundaries without the approval of the Authority.”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations 2025 (successor version, scanned image)
pta.gov.pk
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Enterprise Technology Governance & Risk Management Framework for Financial Institutions, with the Framework for Risk Management in Outsourcing Arrangements by Financial Institutions · BPRD Circular No. 05 of 2017 and BPRD Circular No. 06 of 2017 · Regulator directive
Banks, development finance institutions and microfinance banks must keep cloud services on providers and servers located in Pakistan. They may not put core banking on a cloud at all. They need the central bank's prior approval before outsourcing anything abroad. Sending customer data offshore also needs the customer's consent.
Enforced by State Bank of Pakistan
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What you have to do
- Keep the data in the countryCloud providers must be located in Pakistan and all physical servers and data centres must reside and operate from Pakistan.
- Put a transfer safeguard in placeAny outsourcing arrangement outside Pakistan requires prior State Bank approval; the offshore provider must itself be regulated and may not subcontract.
- Get consentCustomer consent plus prior written State Bank approval before confidential customer information goes offshore.
- Written vendor contractAgreements must give auditors and State Bank inspection teams timely access to information, records, data, applications, databases and networks.
- Report breaches to the regulator — within 48 hoursBreaches involving financial loss, theft of confidential data, or outage of customer services beyond two hours.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory action by the State Bank for breach of a prudential framework
- Loss of your licencePersistent non-compliance by a licensed financial institution
Sources
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework for Financial Institutions
archive.sbp.org.pk
“the CSPs shall be located in Pakistan and all physical servers and services (data centers and allied infrastructure) shall reside and operate from Pakistan”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“No offshore outsourcing arrangement shall be allowed in case the offshore service provider is not a regulated entity.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanBPRD Circular No. 06 of 2017 — compliance required by 30 June 2018
sbp.org.pk
Link checked 18 August 2026
Payment data rules
Official name: Regulations for Electronic Money Institutions · PSD Circular No. 01 of 2019, made under the Payment Systems and Electronic Fund Transfers Act, 2007 · Directly binding regulation
Electronic money institutions are the licensed digital wallet and prepaid card firms. They may not move any function outside Pakistan without the central bank's prior written approval. They must keep records for at least ten years.
Enforced by State Bank of Pakistan
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Put a transfer safeguard in placePrior written State Bank approval before any function is outsourced outside Pakistan.
- Keep data for a minimum period — 10 yearsAll necessary records for at least ten years, or longer where another law requires it.
- Register or notifyLicensing by the State Bank is required to operate as an electronic money institution.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of the licensing regulations
- Order to stopSupervisory direction by the State Bank
Sources
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions
archive.sbp.org.pk
“EMI shall not outsource, outside Pakistan, any of its function(s) without prior written approval from SBP.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanPSD Circular No. 01 of 2019 — issuance of the Regulations for Electronic Money Institutions
sbp.org.pk
Link checked 18 August 2026
Government data must stay in the country
Official name: Pakistan Cloud First Policy · Approved by the Federal Cabinet, February 2022 · Government policy document
Federal ministries, departments and agencies must host restricted, confidential and secret data on government or private clouds located inside Pakistan, and use accredited providers. It binds the public sector only, but it is the rule that decides whether a foreign cloud vendor can win Pakistani government work.
Enforced by Ministry of Information Technology and Telecommunication
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryGovernment cloud deployments are restricted to Pakistani locations and private cloud infrastructure must be located in Pakistan.
- Hold a security certificateCloud providers must be registered or accredited under the ministry's accreditation criteria for cloud service providers.
- Put a transfer safeguard in placeThe ministry's Cloud Office must confirm appropriate security controls before any cross-border flow.
- Secure the data
What it costs if you get it wrong
- Order to stopAdministrative direction; this is a policy binding public bodies, not a statute with fines
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPakistan Cloud First Policy, 2022
moitt.gov.pk
“Private Cloud infrastructure must be located in Pakistan either on premise or off premise.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPolicies index listing the Cloud First Policy and the Accreditation Criteria for Cloud Service Providers as approved
moitt.gov.pk
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Telecoms rules
Official name: Prevention of Electronic Crimes Act, 2016, as amended by the Prevention of Electronic Crimes (Amendment) Act, 2025 · Act No. XL of 2016; amending Act No. II of 2025 · Act of parliament
Pakistan's cybercrime law is the closest thing to a national data statute. It does not restrict where data is stored. But it forces internet and telecoms providers to keep connection records for at least a year. It lets investigators force decryption. It reaches acts done abroad that harm systems in Pakistan. And it carries prison sentences, not fines.
Enforced by Pakistan Telecommunication Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 1 yearService providers must retain specified traffic data for at least one year, or any period the telecoms regulator notifies.
- Keep data for a minimum period — 1 year
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: PKR 10 million — about $36 thousandService provider failing to retain traffic data, first offence
- Criminal liability: 3 years imprisonment or PKR 5 million — about $18 thousandObtaining, selling, possessing, transmitting or using another person's identity information without authorisation
- Criminal liability: 3 years imprisonment or PKR 2 million — about $7 thousandSpreading false information online, added by the 2025 amendment
- Order to stopBlocking or removal of online content by the telecoms regulator
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPrevention of Electronic Crimes Act, 2016
moitt.gov.pk
“A service provider shall, within its existing or required technical capability, retain its specified traffic data for a minimum period of one year or such period as the Authority may notify from time to time”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025
na.gov.pk
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityLegislation page listing the 2016 Act and the 2025 amendment as in force
pta.gov.pk
Link checked 18 August 2026
General data protection law
Official name: Personal Data Protection Bill, 2023 (final draft, May 2023) · Draft published by the Ministry of Information Technology and Telecommunication · Draft law
Pakistan's general privacy law does not exist. This is the latest of three drafts, published in May 2023 and never passed. It would create a national privacy commission, forbid critical personal data leaving Pakistan, and set penalties in United States dollars. Nothing in it binds anyone today and it should not be planned around as if it did.
Enforced by Ministry of Information Technology and Telecommunication
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What you have to do
- Keep the data in the countryIt would require critical personal data to be handled only on servers or infrastructure inside Pakistan.
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Get consent
- Put a transfer safeguard in place
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: $1 million — about $1 millionUnlawful processing involving critical personal data, as drafted
- Percentage of global turnover: $2 million or 1 per cent of annual gross revenue, whichever is higher — about $2 millionGeneral contravention, as drafted
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, final draft, May 2023
moitt.gov.pk
“Critical Personal Data shall only be processed in a server(s) or digital infrastructure located within the territory of Pakistan.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationLegislation index showing the Personal Data Protection Bill under Draft Bills only
moitt.gov.pk
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanActs of Parliament index — no personal data protection Act among the Acts passed in 2025 or 2026
na.gov.pk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The current wording of the Critical Telecom Data and Infrastructure Security Regulations 2025
We could not confirm the 2025 version of these regulations. The telecoms regulator publishes it as a scanned image with no readable text. We verified the rule on keeping data in the country, and the seventy-two hour breach clock, from the 2020 text only. The 2025 version may have changed either. So we rate the telecom rule at medium confidence.
Whether the Removal and Blocking of Unlawful Online Content Rules 2021 are still in force and whether they still require large social media companies to place database servers in Pakistan
We could not confirm these rules against a Pakistani government source. The 2025 amendment also moved social media regulation to a new authority. We do not state their content.
Mapping and geospatial restrictions under the Surveying and Mapping Rules 2015 and the 1981 rules on publication, classification, issue and custody of maps
We could not confirm what Pakistan's mapping rules say. Both files on the Survey of Pakistan site are scanned images with no readable text. Restrictions very likely exist, and defence-linked mapping is a known sensitivity. If you work with maps or location data, check before you rely on this.
Whether any keeping data in the country or cloud rule exists for insurance companies, securities firms or health providers
We found no such rule on the securities regulator's own circulars index for 2024 to 2026, checked 18 August 2026. That is one index page, and it does not prove no rule exists. If you work in securities, check before you rely on it.
Whether the Social Media Protection and Regulatory Authority has been constituted and given members since January 2025
We could not confirm that this body is operating. We found no official website and no published decision. Treat this as unverified, not as confirmed absent.
Whether the State Bank has issued any cloud or technology framework since 2017 that supersedes the 2017 wording
The 2017 rulebook is the most recent version we could find through the bank's own circulars. We could not confirm the full list of circulars from 2018 to 2026, so a later version may exist.
Whether the National Data Governance Policy 2026 will bind private companies or only public bodies
The draft text is written around government data and public bodies. But its tier one rule about where data must sit names personal data generally. The final approved text will settle this, and it has not been gazetted.
Whether any regulator has actually refused or granted an approval to store telecom data abroad
We found no published decisions on how this approval is given. The approval route exists in the regulation. We have no evidence about how the regulator uses it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.