Pakistan’s privacy debate
EVERY discussion about data protection in Pakistan reaches the same conclusion: we still don’t have a comprehensive data privacy law.
Technically, that’s true. The Personal Data Protection Bill has sat in draft form since 2018, and after years of delay it’s easy to assume Pakistan’s approach to data governance is on hold.
That assumption can now be challenged.
While attention stayed fixed on the stalled privacy bill, another development moved far faster. In late June, the Ministry of Information Technology and Telecommunication (MoITT) released the draft National Data Governance Policy 2026 for public consultation. That consultation closed on July 10. This week, MoITT and the Pakistan Digital Authority (PDA) held a high-level meeting, chaired by Federal Minister Shaza Fatima Khawaja, to finalise the policy ahead of cabinet approval and gazette notification.
It isn’t law yet, but we cannot treat it as a mere policy draft either.
Many Pakistani tech companies already maintain strong governance practices because foreign clients demand it.
The policy isn’t a privacy law, it doesn’t tell private companies how to collect or use their customers’ data. Instead it focuses on something narrower but, in many respects, more consequential: government data. That distinction matters because government data rarely stays inside the government.
Across Pakistan, private companies build digital services for public agencies, host government systems, operate call centres, manage cloud infrastructure and process citizen information on the state’s behalf. Many businesses think of themselves as serving a government client; fewer recognise they’re becoming part of its........
