Pakistan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Pakistan has no general privacy law. Draft bills have been circulating since 2018 and none has been passed, and there is no privacy regulator. For most businesses, nothing stops data leaving the country. But four regulated industries are strict: telecoms, banking, payments and government all have to keep data inside Pakistan unless a regulator says otherwise.
Data governance in Pakistan
The eight things that decide how you handle data about people in Pakistan. Same eight on every country page, so you can compare.
Who has to follow these rules
There is no general privacy law, so there is no general privacy duty that reaches a foreign company. Two other laws do reach across the border. The cybercrime law covers acts done outside Pakistan that harm a person, a computer system or data inside Pakistan. The telecoms regulator can also order any website or app that people in Pakistan can reach to take content down. There is no size or revenue threshold, and no general duty to appoint anyone in Pakistan.
The Prevention of Electronic Crimes Act 2016, section 1(3), applies to every citizen of Pakistan wherever they are and to every other person for the time being in Pakistan. Section 1(4) extends it to any act committed outside Pakistan that constitutes an offence under the Act and affects a person, property, information system or data located in Pakistan. Section 37 gives the Pakistan Telecommunication Authority power to remove or block online content on broad public-order and national-security grounds. The 2025 amendment created a Social Media Protection and Regulatory Authority which 'may require any social media platform to enlist with it' — a registration power that exists on paper but which we found no evidence has been switched on. The 2023 draft privacy bill would go much further, reaching controllers and processors with no physical presence in Pakistan, but it is a draft and binds nobody.
Sources
- Official sourceNational Cyber Emergency Response Team of Pakistan (PKCERT)Prevention of Electronic Crimes Act, 2016, section 1 (extent and application)
pkcert.gov.pk
“It shall also apply to any act committed outside Pakistan by any person if the act constitutes an offence under this Act and affects a person, property, information system or data located in Pakistan.”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025 (Act No. II of 2025)
na.gov.pk
“The Authority may require any social media platform to enlist with it in such manner, form and on payment of such fee, as may be prescribed.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationLegislation page listing the Personal Data Protection Bill only as a draft (2018, 2020, 2023)
moitt.gov.pk
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and with no paperwork, because there is no law that controls it. Four industries are the exception and they are strict. Telecoms companies need the telecoms regulator's approval to store any data outside Pakistan. Banks must put cloud data on servers inside Pakistan and cannot put core banking on a cloud at all. Electronic money firms need the central bank's written approval before moving any function abroad. Government bodies must use clouds located in Pakistan.
Sector by sector, checked 18 August 2026. TELECOM — closed by default. The Critical Telecom Data and Infrastructure Security Regulations 2020 say plainly that no data shall be stored beyond the country's geographical boundaries without the approval of the Pakistan Telecommunication Authority. This binds every PTA licensee, which includes mobile operators, fixed-line operators, internet service providers and long-distance operators. A 2025 replacement version of these regulations is published on the regulator's site but is a scanned image with no readable text, so we cannot confirm whether the wording changed. BANKING — closed for cloud, permission-based for everything else. The State Bank of Pakistan's Enterprise Technology Governance and Risk Management Framework requires that cloud service providers be located in Pakistan and that all physical servers and data centres reside and operate from Pakistan. Separately, core banking systems that process or store customer data may not be put on a cloud at all. The outsourcing framework requires prior State Bank approval for any outsourcing arrangement outside Pakistan, bans offshore providers that are not themselves regulated, bans subcontracting of offshore work, and requires both customer consent and prior written State Bank approval before confidential customer information goes to an offshore provider. PAYMENTS AND E-MONEY — permission-based. Electronic money institutions may not outsource any function outside Pakistan without prior written approval from the State Bank. GOVERNMENT — closed. The Cloud First Policy 2022 confines government cloud deployments to Pakistani locations and requires private cloud infrastructure to be located in Pakistan. Restricted, confidential and secret classes of government data may only sit on government or private cloud inside the country. INSURANCE AND SECURITIES — no localisation rule found on the regulator's own site as at 18 August 2026. The Securities and Exchange Commission of Pakistan has issued a cyber security advisory circular but we found no cloud or data residency instrument. HEALTH, EDUCATION, GAMBLING — no rule found, checked 18 August 2026. Gambling is a criminal offence in Pakistan, so there is no licensed gambling sector to regulate. MAPPING AND GEOSPATIAL — restrictions almost certainly exist. The Survey of Pakistan publishes Surveying and Mapping Rules 2015 and 1981 rules on the publication, classification, issue and custody of maps, but both files are scanned images we could not read, so we do not assert their content.
Sources
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 8(13)
pkcert.gov.pk
“No Data shall be stored beyond country's geographical boundaries without the approval of the Authority.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework for Financial Institutions
archive.sbp.org.pk
“For all types of cloud services including Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS), the CSPs shall be located in Pakistan and all physical servers and services (data centers and allied infrastructure) shall reside and operate from Pakistan.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“Any outsourcing arrangement outside Pakistan will require SBP's prior approval subject to approval of the Country Head.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions
archive.sbp.org.pk
“EMI shall not outsource, outside Pakistan, any of its function(s) without prior written approval from SBP.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPakistan Cloud First Policy, 2022 — cloud selection matrix and deployment rules
moitt.gov.pk
“Private Cloud infrastructure must be located in Pakistan either on premise or off premise.”
Link checked 18 August 2026
- Official sourceSecurities and Exchange Commission of PakistanCirculars index — no cloud or data residency circular found for 2024 to 2026
secp.gov.pk
Link checked 18 August 2026
Sending data out of the country
At national level there is nothing to put in place, because there is no rule. In the regulated industries the model is permission, one case at a time, from the regulator that licenses you. There is no approved-country list, no government-published standard contract, and no certification scheme you can rely on instead. Because there is no list, there is also no list that can be quietly filled in.
The national picture is unrestricted, not blocklist or allowlist: there is no instrument that names permitted or forbidden destinations. In telecoms, transfer abroad is a discretionary approval from the Pakistan Telecommunication Authority under the critical telecom data regulations. In banking, it is prior approval from the State Bank, and for confidential customer information it is prior written State Bank approval plus the customer's own consent, with subcontracting by the offshore provider prohibited outright. Banks must also ensure that all information relating to outsourcing outside Pakistan remains available domestically and open to State Bank inspection at any time — a mirror requirement in practice. For electronic money institutions it is prior written State Bank approval for any offshore function. In the public sector, the Cloud Office inside the Ministry of Information Technology and Telecommunication signs off deviations. The 2023 draft privacy bill would introduce an adequacy test plus binding contracts and consent, and would forbid critical personal data leaving at all, but it is a draft.
Sources
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“The FIs shall ensure that all information relating to outsourcing outside Pakistan is available domestically and is also available for review or inspection by SBP at any time.”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 8(13)
pkcert.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, May 2023 draft, clauses 31 and 32 (transfer abroad)
moitt.gov.pk
“Critical Personal Data shall only be processed in a server(s) or digital infrastructure located within the territory of Pakistan.”
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody enforces privacy, because Pakistan has no privacy regulator. The 2023 draft bill would create one, but the bill has never been passed. What does exist and does work are the industry regulators: the central bank supervises banks and payment firms, and the telecoms regulator supervises telecoms companies. The new digital authority is staffed and publishing, but it has issued no binding rules yet. Its own website says rules will be posted when they become available.
There is no data protection authority in Pakistan, constituted or otherwise. The May 2023 draft bill would have created a National Commission for Personal Data Protection within six months of commencement; the bill was never enacted, so the Commission does not exist. The Pakistan Digital Authority, created by the Digital Nation Pakistan Act 2025, is genuinely operational: it has a chairman, it ran the consultation on the National Data Governance Policy 2026 and closed it on 5 August 2026, it runs the national data exchange layer, and it publishes a standards register. But its own Acts and Regulations page carries only the founding Act and the line that rules and regulations will be posted as they become available. It has issued no binding data rules. The 2025 amendment to the cybercrime law created two more bodies. The National Cyber Crime Investigation Agency took over cybercrime investigation from the Federal Investigation Agency. The Social Media Protection and Regulatory Authority was created on paper; we could not find any official website or published decision for it, so we do not treat it as operational. The national computer emergency response team is operational and issues security advisories dated 2026. Overall rating: dormant for data protection. That is a statement about privacy enforcement, not about banking or telecoms supervision, which are active and licence-backed.
Sources
- Official sourcePakistan Digital AuthorityActs and Regulations — only the founding Act published; rules to follow
pda.gov.pk
“Rules & regulations will be posted here as they become available.”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025 — creation of the investigation agency and social media authority
na.gov.pk
Link checked 18 August 2026
- Official sourcePKCERTNational Cyber Emergency Response Team of Pakistan — advisories dated 2026
pkcert.gov.pk
Link checked 18 August 2026
- Official sourcePakistan Digital AuthorityPress releases — consultation on the National Data Governance Policy 2026 concluded 5 August 2026
pda.gov.pk
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor but almost no ceiling. Telecoms and internet companies must keep connection records for at least one year, and the telecoms regulator can change that period by notice. Electronic money firms must keep records for at least ten years. The emergency response teams keep incident data for at least three years. Nothing in force tells an ordinary company when it must delete personal data.
FLOOR. The cybercrime law requires a service provider to retain its specified traffic data for a minimum period of one year, or such other period as the Pakistan Telecommunication Authority may notify, and to hand it over on a court warrant. Failure can attract a fine up to ten million rupees, roughly thirty-six thousand United States dollars. Electronic money institutions must maintain all necessary records for at least ten years or as required by other laws. Computer emergency response teams must securely retain data they receive for at least three years unless a competent authority extends or erases it. The critical telecom data regulations tell licensees to observe their licensed retention periods and to ask the regulator when the period is unclear, which means the real answer for a telecoms licensee sits in its own licence, not in a public rule. CEILING. No general deletion duty is in force. The draft National Data Governance Policy 2026 would introduce one for government data, saying personal data shall not be retained beyond the defined period except where required by law or judicial process, but it is not yet approved. The 2023 draft privacy bill would introduce a general one. CONFLICT. Because there is no general ceiling, there is nothing for the floors to conflict with. If the draft policy or bill is adopted, the pattern in both texts is that a specific legal retention requirement wins over the deletion duty.
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPrevention of Electronic Crimes Act, 2016, section 32 (retention of traffic data)
moitt.gov.pk
“A service provider shall, within its existing or required technical capability, retain its specified traffic data for a minimum period of one year or such period as the Authority may notify from time to time and, subject to production of a warrant issued by the Court, provide that data to the investigation agency.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions — record keeping
archive.sbp.org.pk
“EMIs shall maintain all necessary records for at least 10 years or as required by the relevant laws.”
Link checked 18 August 2026
- Official sourcePKCERT / Ministry of Information Technology and TelecommunicationPakistan Computer Emergency Response Team Rules, 2023 — retention of incident data
pkcert.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationDraft National Data Governance Policy 2026 — retention limit for personal data
moitt.gov.pk
“Personal data shall not be retained beyond the defined period save where expressly required by applicable law or by judicial process.”
Link checked 18 August 2026
If something goes wrong
There are three separate clocks and they do not line up. If you are in a critical sector such as banking or telecoms, you must tell your sector emergency response team and the national one within one hour. Banks must also tell the central bank within forty-eight hours. Telecoms licensees must tell the telecoms regulator within seventy-two hours. There is no general duty to tell the people whose data was exposed.
CLOCK ONE — one hour. The Computer Emergency Response Team Rules 2023 require covered entities to summarily report incidents to their sectoral and to the national response team within one hour of the incident being identified, using best estimates and updating later. The rules cover federal and provincial government bodies and critical sectors including defence, telecom, banking, finance, power and utilities. CLOCK TWO — forty-eight hours. Financial institutions must report to the State Bank's Banking Policy and Regulation Department within forty-eight hours all established information or cyber security breaches involving financial loss, theft of confidential data, or a major disruption leaving customers without banking services for more than two hours. CLOCK THREE — seventy-two hours. Telecoms licensees must inform the Pakistan Telecommunication Authority within seventy-two hours of discovering a data breach or damage to critical telecom infrastructure or critical data. A large bank running its own network can be inside all three at once. There is no duty in force to notify affected individuals; the 2023 draft bill would have added a seventy-two hour duty to notify both the regulator and the person, but it is a draft.
Sources
- Official sourcePKCERT / Ministry of Information Technology and TelecommunicationPakistan Computer Emergency Response Team Rules, 2023 — one hour reporting
pkcert.gov.pk
“summarily report incidents to their respective Sectoral and the National CERT within one hour of being identified”
Link checked 18 August 2026
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework — incident reporting
archive.sbp.org.pk
“The FI(s) shall report to Banking Policy & Regulation Department (BPRD), SBP within forty eight (48) hours after the incident all established information/cyber security breaches and related incidents involving financial loss, stealing of confidential data and major disruption in the banking system”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations, 2020, regulation 18(2)
pkcert.gov.pk
“In case of a data breach or damage to CTI or critical data, the licensee shall duly inform the Authority within 72 hours from the discovery of the incident.”
Link checked 18 August 2026
What catches people out
The biggest trap is reading the headline and stopping. Pakistan's real data rules are licence conditions, not privacy law, so the penalty is your licence rather than a fine. Banks cannot put core banking on any cloud at all, local or foreign. Moving bank customer data abroad needs the customer's consent and the central bank's written approval. And the cybercrime law is criminal, so people go to prison, not just companies get fined.
1. THE RULES LIVE IN LICENCES. Because there is no privacy statute, the binding obligations sit in regulator frameworks and licence conditions. A compliance review that searches for a data protection act finds nothing and concludes Pakistan is open. The telecoms and banking rules are enforced through supervision and licensing, where the sanction is suspension or loss of licence rather than a headline fine. 2. NO CLOUD FOR CORE BANKING, ANYWHERE. The State Bank rule is not only about location. Core banking applications, services and business processes used to process or store customer and borrower data may not be placed under cloud-based outsourcing at all. Cloud is confined to non-core support such as collaboration tools, human resources and procurement. A local cloud region does not fix this. 3. BANK CUSTOMER DATA ABROAD NEEDS TWO KEYS. Sharing confidential customer information with an offshore provider needs both the customer's consent and prior written State Bank approval, and it is needed regardless of what the contract says. The offshore provider must itself be a regulated entity, and it may not subcontract at all. 4. CRIMINAL, NOT ADMINISTRATIVE. The cybercrime law creates prison sentences, including up to three years for using another person's identity information without authorisation. Investigators can compel a person holding decryption information to hand over readable data. This is personal exposure for staff, not a corporate fine. 5. THE ONE-HOUR CLOCK. Most incident playbooks are written around seventy-two hours. In Pakistan a critical-sector entity has one hour to make a first report to its sector and national response teams. Missing it is the most common failure we would expect. 6. THE TELECOM RULES WERE REPLACED IN 2025 AND THE NEW TEXT IS UNREADABLE. The regulator publishes a 2025 version of the critical telecom data regulations as a scanned image with no machine-readable text. The 2020 wording is what we can verify; the current wording may differ.
Sources
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework — cloud restrictions
archive.sbp.org.pk
“Core banking applications/services/operations and business processes used to process and store customer/borrower data/information shall not be placed under cloud-based outsourcing arrangements.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements — offshore customer data
sbp.org.pk
“the FIs shall seek consent of the customer and prior written approval of SBP. Such approval is necessary regardless of the fact that the specified data/information is provided to a third party.”
Link checked 18 August 2026
- Official sourcePKCERTPrevention of Electronic Crimes Act, 2016, sections 16 and 35
pkcert.gov.pk
“require any person who is in possession of decryption information of an information system, device or data under investigation to grant him access to such data, device or information system in unencrypted or decrypted intelligible format”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations 2025 (scanned image, no readable text)
pta.gov.pk
Link checked 18 August 2026
What's changing next
One thing is close. A National Data Governance Policy was published in draft in June 2026, consultation closed on 5 August 2026, and the digital authority says it has moved to final stage. It still needs Cabinet approval and publication in the official gazette. It would force restricted, confidential and personal government data to stay inside Pakistan. A general privacy law is still only a draft and has been for eight years.
COMING. The draft National Data Governance Policy 2026, published by the Ministry of Information Technology and Telecommunication on 26 June 2026, sets a three-tier residency model. Tier one, covering restricted, confidential and personal data, must be hosted, stored and processed within the territory of Pakistan. Tier two, internal data, may be processed offshore only with prior approval from the Pakistan Digital Authority plus contractual safeguards. Tier three, open data, may be hosted anywhere. The document itself records its status as proposed, effective on gazette notification. The Pakistan Digital Authority announced on 5 August 2026 that consultation had concluded and the policy had moved from draft to final stage. Read the scope carefully: the text is framed around government data and public bodies, and it is not yet clear how far it will bind private companies. STILL A DRAFT. The Personal Data Protection Bill has existed in drafts dated 2018, 2020 and 2023 and has not been passed. The 2023 draft would forbid critical personal data leaving Pakistan, require an adequacy-style test for other transfers, create a National Commission for Personal Data Protection within six months, impose a seventy-two hour breach notification duty, and set penalties up to two million United States dollars or one per cent of annual gross revenue, whichever is higher. None of this binds anyone today. DORMANT SWITCHES, which matter more. 1. The telecoms regulator can refuse or withdraw approval for storing data abroad at any time, under a regulation that is already in force. No consultation is needed. 2. The cybercrime law lets the telecoms regulator change the traffic data retention period by notification, from the current one year to any period it chooses. 3. The 2025 amendment lets the new social media authority require any social media platform to enlist with it, on terms to be prescribed. The power exists; the rules have not been made. 4. The telecoms regulator's content blocking power is broad and immediate, and the 2025 amendment adds a twenty-four hour removal deadline for content the authority treats as false information. 5. The Pakistan Digital Authority has statutory power to develop and enforce a national data strategy and a data governance framework across both public and private sectors, and has published no rules yet.
Sources
- Official sourceMinistry of Information Technology and TelecommunicationDraft National Data Governance Policy 2026 — tiered residency model
moitt.gov.pk
“Hosted, stored, and processed within the territory of Pakistan.”
Link checked 18 August 2026
- Official sourcePakistan Digital AuthorityConsultations concluded on the National Data Governance Policy 2026, 5 August 2026
pda.gov.pk
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, May 2023 draft
moitt.gov.pk
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanDigital Nation Pakistan Act, 2025 (Act No. I of 2025) — powers of the Pakistan Digital Authority
na.gov.pk
“develop and enforce a National Data Strategy and comprehensive data governance framework within government entities and across public and private sectors”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Critical Telecom Data and Infrastructure Security Regulations, 2020
Directly binding regulation · Made by the Pakistan Telecommunication Authority under the Pakistan Telecommunication (Re-organization) Act, 1996
Every telecoms licensee in Pakistan must keep its data inside the country unless the telecoms regulator approves otherwise, and must report a breach within seventy-two hours. This is the hardest localisation rule in Pakistan and it binds mobile operators, fixed-line operators and internet service providers.
Enforced by Pakistan Telecommunication Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryNo data may be stored outside Pakistan without the telecoms regulator's approval.
- Put a transfer safeguard in placeApproval of the Authority is the only route out.
- Report breaches to the regulator — within 72 hoursData breach or damage to critical telecom infrastructure or critical data.
- Secure the data
- Keep data for a minimum periodLicensed retention periods apply; the licensee must ask the regulator where the period is unclear.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions and regulations made under the telecoms Act
- Order to stopEnforcement order by the Authority
Sources
- Official sourcePakistan Telecommunication Authority, republished by PKCERTCritical Telecom Data and Infrastructure Security Regulations, 2020
pkcert.gov.pk
“No Data shall be stored beyond country's geographical boundaries without the approval of the Authority.”
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityCritical Telecom Data and Infrastructure Security Regulations 2025 (successor version, scanned image)
pta.gov.pk
Link checked 18 August 2026
Enterprise Technology Governance & Risk Management Framework for Financial Institutions, with the Framework for Risk Management in Outsourcing Arrangements by Financial Institutions
Regulator directive · BPRD Circular No. 05 of 2017 and BPRD Circular No. 06 of 2017
Banks, development finance institutions and microfinance banks must keep cloud services on providers and servers located in Pakistan, may not put core banking on a cloud at all, and need the central bank's prior approval before outsourcing anything abroad. Sending customer data offshore also needs the customer's consent.
Enforced by State Bank of Pakistan
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What it makes you do
- Keep the data in the countryCloud providers must be located in Pakistan and all physical servers and data centres must reside and operate from Pakistan.
- Put a transfer safeguard in placeAny outsourcing arrangement outside Pakistan requires prior State Bank approval; the offshore provider must itself be regulated and may not subcontract.
- Get consentCustomer consent plus prior written State Bank approval before confidential customer information goes offshore.
- Written vendor contractAgreements must give auditors and State Bank inspection teams timely access to information, records, data, applications, databases and networks.
- Report breaches to the regulator — within 48 hoursBreaches involving financial loss, theft of confidential data, or outage of customer services beyond two hours.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory action by the State Bank for breach of a prudential framework
- Loss of your licencePersistent non-compliance by a licensed financial institution
Sources
- Official sourceState Bank of PakistanEnterprise Technology Governance & Risk Management Framework for Financial Institutions
archive.sbp.org.pk
“the CSPs shall be located in Pakistan and all physical servers and services (data centers and allied infrastructure) shall reside and operate from Pakistan”
Link checked 18 August 2026
- Official sourceState Bank of PakistanFramework for Risk Management in Outsourcing Arrangements by Financial Institutions
sbp.org.pk
“No offshore outsourcing arrangement shall be allowed in case the offshore service provider is not a regulated entity.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanBPRD Circular No. 06 of 2017 — compliance required by 30 June 2018
sbp.org.pk
Link checked 18 August 2026
Regulations for Electronic Money Institutions
Directly binding regulation · PSD Circular No. 01 of 2019, made under the Payment Systems and Electronic Fund Transfers Act, 2007
Electronic money institutions, the licensed digital wallet and prepaid card firms, may not move any function outside Pakistan without the central bank's prior written approval, and must keep records for at least ten years.
Enforced by State Bank of Pakistan
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Put a transfer safeguard in placePrior written State Bank approval before any function is outsourced outside Pakistan.
- Keep data for a minimum period — 10 yearsAll necessary records for at least ten years, or longer where another law requires it.
- Register or notifyLicensing by the State Bank is required to operate as an electronic money institution.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of the licensing regulations
- Order to stopSupervisory direction by the State Bank
Sources
- Official sourceState Bank of PakistanRegulations for Electronic Money Institutions
archive.sbp.org.pk
“EMI shall not outsource, outside Pakistan, any of its function(s) without prior written approval from SBP.”
Link checked 18 August 2026
- Official sourceState Bank of PakistanPSD Circular No. 01 of 2019 — issuance of the Regulations for Electronic Money Institutions
sbp.org.pk
Link checked 18 August 2026
Pakistan Cloud First Policy
Government policy document · Approved by the Federal Cabinet, February 2022
Federal ministries, departments and agencies must host restricted, confidential and secret data on government or private clouds located inside Pakistan, and use accredited providers. It binds the public sector only, but it is the rule that decides whether a foreign cloud vendor can win Pakistani government work.
Enforced by Ministry of Information Technology and Telecommunication
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryGovernment cloud deployments are restricted to Pakistani locations and private cloud infrastructure must be located in Pakistan.
- Hold a security certificateCloud providers must be registered or accredited under the ministry's accreditation criteria for cloud service providers.
- Put a transfer safeguard in placeThe ministry's Cloud Office must confirm appropriate security controls before any cross-border flow.
- Secure the data
What it costs if you get it wrong
- Order to stopAdministrative direction; this is a policy binding public bodies, not a statute with fines
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPakistan Cloud First Policy, 2022
moitt.gov.pk
“Private Cloud infrastructure must be located in Pakistan either on premise or off premise.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationPolicies index listing the Cloud First Policy and the Accreditation Criteria for Cloud Service Providers as approved
moitt.gov.pk
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Prevention of Electronic Crimes Act, 2016, as amended by the Prevention of Electronic Crimes (Amendment) Act, 2025
Act of parliament · Act No. XL of 2016; amending Act No. II of 2025
Pakistan's cybercrime law is the closest thing to a national data statute. It does not restrict where data is stored, but it forces internet and telecoms providers to keep connection records for at least a year, lets investigators compel decryption, reaches acts done abroad that harm systems in Pakistan, and carries prison sentences rather than administrative fines.
Enforced by Pakistan Telecommunication Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 1 yearService providers must retain specified traffic data for at least one year, or any period the telecoms regulator notifies.
- Keep data for a minimum period — 1 year
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: PKR 10 million — about $36 thousandService provider failing to retain traffic data, first offence
- Criminal liability: 3 years imprisonment or PKR 5 million — about $18 thousandObtaining, selling, possessing, transmitting or using another person's identity information without authorisation
- Criminal liability: 3 years imprisonment or PKR 2 million — about $7 thousandSpreading false information online, added by the 2025 amendment
- Order to stopBlocking or removal of online content by the telecoms regulator
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPrevention of Electronic Crimes Act, 2016
moitt.gov.pk
“A service provider shall, within its existing or required technical capability, retain its specified traffic data for a minimum period of one year or such period as the Authority may notify from time to time”
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanPrevention of Electronic Crimes (Amendment) Act, 2025
na.gov.pk
Link checked 18 August 2026
- Official sourcePakistan Telecommunication AuthorityLegislation page listing the 2016 Act and the 2025 amendment as in force
pta.gov.pk
Link checked 18 August 2026
Personal Data Protection Bill, 2023 (final draft, May 2023)
Draft law · Draft published by the Ministry of Information Technology and Telecommunication
Pakistan's general privacy law does not exist. This is the latest of three drafts, published in May 2023 and never passed. It would create a national privacy commission, forbid critical personal data leaving Pakistan, and set penalties in United States dollars. Nothing in it binds anyone today and it should not be planned around as if it did.
Enforced by Ministry of Information Technology and Telecommunication
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What it makes you do
- Keep the data in the countryWould require critical personal data to be processed only on servers or infrastructure inside Pakistan.
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Get consent
- Put a transfer safeguard in place
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: $1 million — about $1 millionUnlawful processing involving critical personal data, as drafted
- Percentage of global turnover: $2 million or 1 per cent of annual gross revenue, whichever is higher — about $2 millionGeneral contravention, as drafted
Sources
- Official sourceMinistry of Information Technology and TelecommunicationPersonal Data Protection Bill, final draft, May 2023
moitt.gov.pk
“Critical Personal Data shall only be processed in a server(s) or digital infrastructure located within the territory of Pakistan.”
Link checked 18 August 2026
- Official sourceMinistry of Information Technology and TelecommunicationLegislation index showing the Personal Data Protection Bill under Draft Bills only
moitt.gov.pk
Link checked 18 August 2026
- Official sourceNational Assembly of PakistanActs of Parliament index — no personal data protection Act among the Acts passed in 2025 or 2026
na.gov.pk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The current wording of the Critical Telecom Data and Infrastructure Security Regulations 2025
The telecoms regulator publishes the 2025 version as a scanned image with no machine-readable text. We verified the localisation and seventy-two hour breach clauses from the 2020 text only. The 2025 version may have changed either. The telecom rule is therefore rated medium confidence.
Whether the Removal and Blocking of Unlawful Online Content Rules 2021 are still in force and whether they still require large social media companies to place database servers in Pakistan
We could not locate an official copy of these rules on any Pakistani government domain during this run, and the 2025 amendment moved social media regulation to a new authority. We do not assert their content.
Mapping and geospatial restrictions under the Surveying and Mapping Rules 2015 and the 1981 rules on publication, classification, issue and custody of maps
Both files on the Survey of Pakistan site are scanned images with no readable text. Restrictions very likely exist, and defence-linked mapping is a known sensitivity, but we will not state terms we could not read.
Whether any data localisation or cloud rule exists for insurance companies, securities firms or health providers
No such instrument was found on the securities regulator's own circulars index for 2024 to 2026, checked 18 August 2026. This is a negative finding from one index page, not proof that no rule exists anywhere.
Whether the Social Media Protection and Regulatory Authority has been constituted and given members since January 2025
We found no official website and no published decision. Proving a body does not exist is harder than proving it does; treat this as unverified rather than as confirmed absence.
Whether the State Bank has issued any cloud or technology framework since 2017 that supersedes the 2017 wording
The 2017 framework is the most recent version we could locate through the bank's own circulars, but the bank's circulars index is search-driven and we could not exhaustively browse 2018 to 2026.
Whether the National Data Governance Policy 2026 will bind private companies or only public bodies
The draft text is framed around government data and public bodies, but its tier one residency rule names personal data generally. The final approved text will settle this and it has not been gazetted.
Whether any regulator has actually refused or granted an approval to store telecom data abroad
No published decisions were found. The approval route exists in the regulation; we have no evidence about how it is exercised in practice.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Pakistan versus
Compare