Skip to the content
Global Data RulesData governance rules, country by country

Pakistan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Dormant

Pakistan has no general privacy law. Draft bills have been circulating since 2018 and none has been passed, and there is no privacy regulator. For most businesses, nothing stops data leaving the country. But four regulated industries are strict: telecoms, banking, payments and government all have to keep data inside Pakistan unless a regulator says otherwise.

Data governance in Pakistan

The eight things that decide how you handle data about people in Pakistan. Same eight on every country page, so you can compare.

Who has to follow these rules

There is no general privacy law, so there is no general privacy duty that reaches a foreign company. Two other laws do reach across the border. The cybercrime law covers acts done outside Pakistan that harm a person, a computer system or data inside Pakistan. The telecoms regulator can also order any website or app that people in Pakistan can reach to take content down. There is no size or revenue threshold, and no general duty to appoint anyone in Pakistan.

High confidenceNational rules

Where the data is allowed to live

In general, yes, and with no paperwork, because there is no law that controls it. Four industries are the exception and they are strict. Telecoms companies need the telecoms regulator's approval to store any data outside Pakistan. Banks must put cloud data on servers inside Pakistan and cannot put core banking on a cloud at all. Electronic money firms need the central bank's written approval before moving any function abroad. Government bodies must use clouds located in Pakistan.

High confidenceDepends on your industryNo restrictionApproval each time

Sending data out of the country

At national level there is nothing to put in place, because there is no rule. In the regulated industries the model is permission, one case at a time, from the regulator that licenses you. There is no approved-country list, no government-published standard contract, and no certification scheme you can rely on instead. Because there is no list, there is also no list that can be quietly filled in.

High confidenceNo restrictionApproval each timeNothing requiredGovernment sign-off neededExplicit consent

The regulator, and whether it actually acts

Nobody enforces privacy, because Pakistan has no privacy regulator. The 2023 draft bill would create one, but the bill has never been passed. What does exist and does work are the industry regulators: the central bank supervises banks and payment firms, and the telecoms regulator supervises telecoms companies. The new digital authority is staffed and publishing, but it has issued no binding rules yet. Its own website says rules will be posted when they become available.

Medium confidenceDormant

How long you must keep it — and when to delete it

There is a floor but almost no ceiling. Telecoms and internet companies must keep connection records for at least one year, and the telecoms regulator can change that period by notice. Electronic money firms must keep records for at least ten years. The emergency response teams keep incident data for at least three years. Nothing in force tells an ordinary company when it must delete personal data.

High confidenceKeep data for a minimum periodKeep logs

If something goes wrong

There are three separate clocks and they do not line up. If you are in a critical sector such as banking or telecoms, you must tell your sector emergency response team and the national one within one hour. Banks must also tell the central bank within forty-eight hours. Telecoms licensees must tell the telecoms regulator within seventy-two hours. There is no general duty to tell the people whose data was exposed.

High confidenceReport cyber incidentsReport breaches to the regulator

What catches people out

The biggest trap is reading the headline and stopping. Pakistan's real data rules are licence conditions, not privacy law, so the penalty is your licence rather than a fine. Banks cannot put core banking on any cloud at all, local or foreign. Moving bank customer data abroad needs the customer's consent and the central bank's written approval. And the cybercrime law is criminal, so people go to prison, not just companies get fined.

High confidenceCriminal liabilityLoss of your licenceKeep the data in the country

What's changing next

One thing is close. A National Data Governance Policy was published in draft in June 2026, consultation closed on 5 August 2026, and the digital authority says it has moved to final stage. It still needs Cabinet approval and publication in the official gazette. It would force restricted, confidential and personal government data to stay inside Pakistan. A general privacy law is still only a draft and has been for eight years.

High confidenceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Critical Telecom Data and Infrastructure Security Regulations, 2020

Directly binding regulation · Made by the Pakistan Telecommunication Authority under the Pakistan Telecommunication (Re-organization) Act, 1996

In forceNo — it stays put

Every telecoms licensee in Pakistan must keep its data inside the country unless the telecoms regulator approves otherwise, and must report a breach within seventy-two hours. This is the hardest localisation rule in Pakistan and it binds mobile operators, fixed-line operators and internet service providers.

In force since 20 November 2020

Enforced by Pakistan Telecommunication Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence
Banking

Enterprise Technology Governance & Risk Management Framework for Financial Institutions, with the Framework for Risk Management in Outsourcing Arrangements by Financial Institutions

Regulator directive · BPRD Circular No. 05 of 2017 and BPRD Circular No. 06 of 2017

In forceNo — it stays put

Banks, development finance institutions and microfinance banks must keep cloud services on providers and servers located in Pakistan, may not put core banking on a cloud at all, and need the central bank's prior approval before outsourcing anything abroad. Sending customer data offshore also needs the customer's consent.

In force since 30 May 2017But only enforceable from 30 June 2018

Enforced by State Bank of Pakistan

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

High confidence
Payments

Regulations for Electronic Money Institutions

Directly binding regulation · PSD Circular No. 01 of 2019, made under the Payment Systems and Electronic Fund Transfers Act, 2007

In forceYes, with paperwork

Electronic money institutions, the licensed digital wallet and prepaid card firms, may not move any function outside Pakistan without the central bank's prior written approval, and must keep records for at least ten years.

In force since 1 April 2019

Enforced by State Bank of Pakistan

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Prevention of Electronic Crimes Act, 2016, as amended by the Prevention of Electronic Crimes (Amendment) Act, 2025

Act of parliament · Act No. XL of 2016; amending Act No. II of 2025

In forceYes — store it anywhere

Pakistan's cybercrime law is the closest thing to a national data statute. It does not restrict where data is stored, but it forces internet and telecoms providers to keep connection records for at least a year, lets investigators compel decryption, reaches acts done abroad that harm systems in Pakistan, and carries prison sentences rather than administrative fines.

In force since 18 August 2016But only enforceable from 29 January 2025

Enforced by Pakistan Telecommunication Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Personal Data Protection Bill, 2023 (final draft, May 2023)

Draft law · Draft published by the Ministry of Information Technology and Telecommunication

ProposedYes, with paperwork

Pakistan's general privacy law does not exist. This is the latest of three drafts, published in May 2023 and never passed. It would create a national privacy commission, forbid critical personal data leaving Pakistan, and set penalties in United States dollars. Nothing in it binds anyone today and it should not be planned around as if it did.

Enforced by Ministry of Information Technology and Telecommunication

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent

High confidence

Who you would hear from

  • National Commission for Personal Data Protection (NCPDP) of Pakistan

    Would be the general privacy regulator

    Does not exist. It is created only by the May 2023 draft bill, which has never been passed. There is no privacy regulator in Pakistan as at 18 August 2026, and no chairperson, members, budget or address to name.

  • Pakistan Telecommunication Authority

    Telecoms licensing, critical telecom data and infrastructure security, online content blocking, traffic data retention periods

    Fully operational. Publishes determinations, licensing decisions and regulations, ran mobile virtual network operator licensing in June 2026, and issued a 2025 replacement of the critical telecom data regulations.

  • State Bank of Pakistan

    Banks, development finance institutions, microfinance banks, electronic money institutions and payment firms; technology governance, cloud, outsourcing and incident reporting

    Fully operational and issuing circulars through 2026. The localisation rules for banking sit in its frameworks and are supervised through licensing rather than through public fines.

  • Pakistan Digital Authority

    National data strategy and data governance framework across public and private sectors; national data exchange layer; digital standards

    Established by the Digital Nation Pakistan Act 2025 and genuinely staffed and publishing. It ran the consultation on the National Data Governance Policy 2026 and closed it on 5 August 2026. But it has issued no binding rules: its own Acts and Regulations page says rules and regulations will be posted as they become available.

  • Ministry of Information Technology and Telecommunication

    Policy and draft legislation, the Cloud First Policy and its Cloud Office, the draft National Data Governance Policy 2026

  • PKCERT

    National computer emergency response team; incident reporting under the 2023 response team rules

    Operational, publishing security advisories dated 2026 and running incident and vulnerability reporting channels. The sectoral response team for telecoms sits inside the telecoms regulator.

  • Social Media Protection and Regulatory Authority

    Social media platform registration and content removal under the 2025 amendment to the cybercrime law

    Created in law on 29 January 2025. We could not find an official website, published membership or any decision for it as at 18 August 2026, so we do not treat it as operational. Its power to require platforms to enlist is a dormant switch.

  • Securities and Exchange Commission of Pakistan

    Insurance, securities, non-bank finance and companies

    Operational and issuing circulars through 2026, including a cyber security advisory in May 2025. We found no data localisation or cloud instrument from it, checked 18 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The current wording of the Critical Telecom Data and Infrastructure Security Regulations 2025

    The telecoms regulator publishes the 2025 version as a scanned image with no machine-readable text. We verified the localisation and seventy-two hour breach clauses from the 2020 text only. The 2025 version may have changed either. The telecom rule is therefore rated medium confidence.

  • Whether the Removal and Blocking of Unlawful Online Content Rules 2021 are still in force and whether they still require large social media companies to place database servers in Pakistan

    We could not locate an official copy of these rules on any Pakistani government domain during this run, and the 2025 amendment moved social media regulation to a new authority. We do not assert their content.

  • Mapping and geospatial restrictions under the Surveying and Mapping Rules 2015 and the 1981 rules on publication, classification, issue and custody of maps

    Both files on the Survey of Pakistan site are scanned images with no readable text. Restrictions very likely exist, and defence-linked mapping is a known sensitivity, but we will not state terms we could not read.

  • Whether any data localisation or cloud rule exists for insurance companies, securities firms or health providers

    No such instrument was found on the securities regulator's own circulars index for 2024 to 2026, checked 18 August 2026. This is a negative finding from one index page, not proof that no rule exists anywhere.

  • Whether the Social Media Protection and Regulatory Authority has been constituted and given members since January 2025

    We found no official website and no published decision. Proving a body does not exist is harder than proving it does; treat this as unverified rather than as confirmed absence.

  • Whether the State Bank has issued any cloud or technology framework since 2017 that supersedes the 2017 wording

    The 2017 framework is the most recent version we could locate through the bank's own circulars, but the bank's circulars index is search-driven and we could not exhaustively browse 2018 to 2026.

  • Whether the National Data Governance Policy 2026 will bind private companies or only public bodies

    The draft text is framed around government data and public bodies, but its tier one residency rule names personal data generally. The final approved text will settle this and it has not been gazetted.

  • Whether any regulator has actually refused or granted an approval to store telecom data abroad

    No published decisions were found. The approval route exists in the regulation; we have no evidence about how it is exercised in practice.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Pakistan versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.