Skip to the content
Global Data RulesData governance rules, country by country

Pakistan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Pakistan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Dormant

Pakistan has no general privacy law. Draft bills have been circulating since 2018 and none has passed. There is no privacy regulator. For most businesses, nothing stops data leaving the country. But four regulated industries are strict. Telecoms, banking, payments and government all have to keep data inside Pakistan, unless a regulator says otherwise.

Data governance in Pakistan

The eight things that decide how you handle data about people in Pakistan. Same eight on every country page, so you can compare.

Who has to follow these rules

There is no general privacy law, so no general privacy duty reaches a foreign company. Two other laws do reach across the border. The cybercrime law covers acts done outside Pakistan that harm a person, a computer system or data inside Pakistan. The telecoms regulator can also order any website or app that people in Pakistan can reach to take content down. There is no size or revenue threshold. There is no general duty to appoint anyone in Pakistan.

Where the data is allowed to live

In general, yes, and with no paperwork, because no law controls it. Four industries are the exception, and they are strict. Telecoms companies need the telecoms regulator's approval to store any data outside Pakistan. Banks must put cloud data on servers inside Pakistan, and cannot put core banking on a cloud at all. Electronic money firms need the central bank's written approval before moving any function abroad. Government bodies must use clouds located in Pakistan.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

At national level there is nothing to put in place, because there is no rule. In the regulated industries you need permission, one case at a time, from the regulator that licenses you. There is no approved-country list. There is no government-published standard contract. There is no certification scheme you can rely on instead. Because there is no list, there is also no list that can be quietly filled in.

Ways to send data out:
Nothing required · Government sign-off needed · Explicit consent

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

Nobody enforces privacy, because Pakistan has no privacy regulator. The 2023 draft bill would create one, but it has never been passed. What does exist and does work are the industry regulators. The central bank supervises banks and payment firms. The telecoms regulator supervises telecoms companies. The new digital authority is staffed and publishing, but it has issued no binding rules yet. Its own website says rules will be posted when they become available.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a minimum but almost no maximum. Telecoms and internet companies must keep connection records for at least one year. The telecoms regulator can change that period by notice. Electronic money firms must keep records for at least ten years. The emergency response teams keep incident data for at least three years. Nothing in force tells an ordinary company when it must delete personal data.

What you have to do here:
Keep data for a minimum period

What to do: Check the minimum keep-period before you delete anything.

If something goes wrong

There are three separate clocks and they do not line up. If you are in a critical industry such as banking or telecoms, you must tell your industry emergency response team and the national one within one hour. Banks must also tell the central bank within forty-eight hours. Telecoms licensees must tell the telecoms regulator within seventy-two hours. There is no general duty to tell the people whose data was exposed.

What you have to do here:
Report cyber incidents · Report breaches to the regulator

What to do: Your breach process has to reach Pakistan's regulator inside the deadline above.

What catches people out

The biggest trap is reading the easy answer and stopping there. Pakistan's real data rules are licence conditions, not privacy law. So the penalty is your licence, rather than a fine. Banks cannot put core banking on any cloud at all, local or foreign. Moving bank customer data abroad needs the customer's consent and the central bank's written approval. And the cybercrime law is criminal law. People go to prison. Companies do not simply get fined.

What it costs if you get it wrong:
Criminal liability · Loss of your licence

What's changing next

One thing is close. A National Data Governance Policy was published in draft in June 2026. Consultation closed on 5 August 2026, and the digital authority says it has moved to final stage. It still needs Cabinet approval and publication in the official gazette. It would force restricted, confidential and personal government data to stay inside Pakistan. A general privacy law is still only a draft, and has been for eight years.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Critical Telecom Data and Infrastructure Security Regulations, 2020 · Made by the Pakistan Telecommunication Authority under the Pakistan Telecommunication (Re-organization) Act, 1996 · Directly binding regulation

In forceNo — it stays put

Every telecoms licensee in Pakistan must keep its data inside the country, unless the telecoms regulator approves otherwise. It must also report a breach within seventy-two hours. This is Pakistan's strictest rule about keeping data in the country. It binds mobile operators, fixed-line operators and internet service providers.

In force since 20 November 2020

Enforced by Pakistan Telecommunication Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Banking

Cloud and outsourcing rules

Official name: Enterprise Technology Governance & Risk Management Framework for Financial Institutions, with the Framework for Risk Management in Outsourcing Arrangements by Financial Institutions · BPRD Circular No. 05 of 2017 and BPRD Circular No. 06 of 2017 · Regulator directive

In forceNo — it stays put

Banks, development finance institutions and microfinance banks must keep cloud services on providers and servers located in Pakistan. They may not put core banking on a cloud at all. They need the central bank's prior approval before outsourcing anything abroad. Sending customer data offshore also needs the customer's consent.

In force since 30 May 2017Enforced from 30 June 2018

Enforced by State Bank of Pakistan

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

Payments

Payment data rules

Official name: Regulations for Electronic Money Institutions · PSD Circular No. 01 of 2019, made under the Payment Systems and Electronic Fund Transfers Act, 2007 · Directly binding regulation

In forceYes, with paperwork

Electronic money institutions are the licensed digital wallet and prepaid card firms. They may not move any function outside Pakistan without the central bank's prior written approval. They must keep records for at least ten years.

In force since 1 April 2019

Enforced by State Bank of Pakistan

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Telecoms rules

Official name: Prevention of Electronic Crimes Act, 2016, as amended by the Prevention of Electronic Crimes (Amendment) Act, 2025 · Act No. XL of 2016; amending Act No. II of 2025 · Act of parliament

In forceYes — store it anywhere

Pakistan's cybercrime law is the closest thing to a national data statute. It does not restrict where data is stored. But it forces internet and telecoms providers to keep connection records for at least a year. It lets investigators force decryption. It reaches acts done abroad that harm systems in Pakistan. And it carries prison sentences, not fines.

In force since 18 August 2016Enforced from 29 January 2025

Enforced by Pakistan Telecommunication Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

General data protection law

Official name: Personal Data Protection Bill, 2023 (final draft, May 2023) · Draft published by the Ministry of Information Technology and Telecommunication · Draft law

ProposedYes, with paperwork

Pakistan's general privacy law does not exist. This is the latest of three drafts, published in May 2023 and never passed. It would create a national privacy commission, forbid critical personal data leaving Pakistan, and set penalties in United States dollars. Nothing in it binds anyone today and it should not be planned around as if it did.

Enforced by Ministry of Information Technology and Telecommunication

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent

Who you would hear from

  • National Commission for Personal Data Protection (NCPDP) of Pakistan

    Would be the general privacy regulator

    It is created only by the May 2023 draft bill, which has never been passed. There is no privacy regulator in Pakistan as at 18 August 2026, and no chairperson, members, budget or address to name.

  • Pakistan Telecommunication Authority

    Telecoms licensing, critical telecom data and infrastructure security, online content blocking, traffic data retention periods

    Fully operational. Publishes determinations, licensing decisions and regulations, ran mobile virtual network operator licensing in June 2026, and issued a 2025 replacement of the critical telecom data regulations.

  • State Bank of Pakistan

    Banks, development finance institutions, microfinance banks, electronic money institutions and payment firms; technology governance, cloud, outsourcing and incident reporting

    Fully operational and issuing circulars through 2026. The rules requiring banking data to stay in Pakistan sit in its own rulebooks. They are supervised through licensing, not through public fines.

  • Pakistan Digital Authority

    National data strategy and data governance framework across public and private sectors; national data exchange layer; digital standards

    Established by the Digital Nation Pakistan Act 2025, and properly staffed and publishing. It ran the consultation on the National Data Governance Policy 2026 and closed it on 5 August 2026. But it has issued no binding rules. Its own Acts and Regulations page says rules and regulations will be posted as they become available.

  • Ministry of Information Technology and Telecommunication

    Policy and draft legislation, the Cloud First Policy and its Cloud Office, the draft National Data Governance Policy 2026

  • PKCERT

    National computer emergency response team; incident reporting under the 2023 response team rules

    Operational, publishing security advisories dated 2026 and running incident and vulnerability reporting channels. The industry response team for telecoms sits inside the telecoms regulator.

  • Social Media Protection and Regulatory Authority

    Social media platform registration and content removal under the 2025 amendment to the cybercrime law

    Created in law on 29 January 2025. We could not find an official website, published membership or any decision for it as at 18 August 2026. So we do not treat it as operational. Its power to require platforms to enlist has never been used.

  • Securities and Exchange Commission of Pakistan

    Insurance, securities, non-bank finance and companies

    Operational and issuing circulars through 2026, including a cyber security advisory in May 2025. We found no rule from it about cloud, or about keeping data in the country, checked 18 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The current wording of the Critical Telecom Data and Infrastructure Security Regulations 2025

    We could not confirm the 2025 version of these regulations. The telecoms regulator publishes it as a scanned image with no readable text. We verified the rule on keeping data in the country, and the seventy-two hour breach clock, from the 2020 text only. The 2025 version may have changed either. So we rate the telecom rule at medium confidence.

  • Whether the Removal and Blocking of Unlawful Online Content Rules 2021 are still in force and whether they still require large social media companies to place database servers in Pakistan

    We could not confirm these rules against a Pakistani government source. The 2025 amendment also moved social media regulation to a new authority. We do not state their content.

  • Mapping and geospatial restrictions under the Surveying and Mapping Rules 2015 and the 1981 rules on publication, classification, issue and custody of maps

    We could not confirm what Pakistan's mapping rules say. Both files on the Survey of Pakistan site are scanned images with no readable text. Restrictions very likely exist, and defence-linked mapping is a known sensitivity. If you work with maps or location data, check before you rely on this.

  • Whether any keeping data in the country or cloud rule exists for insurance companies, securities firms or health providers

    We found no such rule on the securities regulator's own circulars index for 2024 to 2026, checked 18 August 2026. That is one index page, and it does not prove no rule exists. If you work in securities, check before you rely on it.

  • Whether the Social Media Protection and Regulatory Authority has been constituted and given members since January 2025

    We could not confirm that this body is operating. We found no official website and no published decision. Treat this as unverified, not as confirmed absent.

  • Whether the State Bank has issued any cloud or technology framework since 2017 that supersedes the 2017 wording

    The 2017 rulebook is the most recent version we could find through the bank's own circulars. We could not confirm the full list of circulars from 2018 to 2026, so a later version may exist.

  • Whether the National Data Governance Policy 2026 will bind private companies or only public bodies

    The draft text is written around government data and public bodies. But its tier one rule about where data must sit names personal data generally. The final approved text will settle this, and it has not been gazetted.

  • Whether any regulator has actually refused or granted an approval to store telecom data abroad

    We found no published decisions on how this approval is given. The approval route exists in the regulation. We have no evidence about how the regulator uses it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.