Pakistan IT Industry Raises Concerns Over Draft National Data Policy

Pakistan’s IT industry has raised concerns about the proposed National Data Governance Policy 2026, warning that unclear definitions, new compliance requirements and potential data localization rules could create difficulties for companies exporting IT services.
The Pakistan IT Industry Association (P@SHA) highlighted these concerns in a member briefing issued on August 12. The draft framework was released by the Ministry of IT and Telecommunication in July 2026 and is intended to establish Pakistan’s first unified system for managing government data.
The proposed policy treats public-sector data as a strategic national asset and seeks to establish common standards for how government institutions collect, protect, exchange and use information.
P@SHA noted that the draft is currently focused on public-sector data rather than privately held information. However, the association believes the policy needs to provide a clearer distinction between the two, especially in cases involving public-private partnerships.
Government to Serve as Data Custodian
Under the proposed framework, government departments would be considered custodians of citizens’ information rather than its owners. They would be responsible for managing the data on behalf of citizens.
The policy also introduces a “once-only” principle, aimed at preventing government agencies from repeatedly collecting or maintaining duplicate citizen records.
Instead, departments would rely on designated Primary Data Registers as authoritative sources of information.
Data exchange between government institutions would be facilitated through WASL, a centrally governed platform conceptually based on Estonia’s X-Road data-sharing system.
Pakistan Digital Authority Proposed
The draft policy calls for the establishment of the Pakistan Digital Authority (PDA) as a central regulator responsible for overseeing data governance.
The proposed authority would have powers related to enforcement, auditing and corrective action.
A National Chief Data Officer would also be appointed, while individual federal public-sector organizations would be expected to designate their own Chief Data Officers.
Government institutions would undergo annual assessments through a National Data Maturity Index. The index would examine factors such as data governance, security, quality, openness and citizen empowerment.
New AI and Privacy Requirements
The proposed framework also covers artificial intelligence and privacy.
AI systems used by public institutions for automated decision-making would need to provide explainable outcomes, maintain appropriate records and be registered in a public PDA system. Human oversight would also be required.
Generative AI systems would be subject to safeguards aimed at addressing issues such as inaccurate information, intellectual property violations and potential data leaks.
The policy would also give citizens greater control over their personal information. Proposed rights include viewing data-access records, correcting personal information, exporting data and requesting deletion where permitted under applicable law.
Government institutions would additionally be expected to implement Zero-Trust cybersecurity architecture, which requires continuous verification instead of automatically trusting users or devices once they gain network access.
Data breaches would also have to be reported to the PDA promptly.
Data Localization Creates Concerns
Potential data localization requirements are among the biggest concerns for Pakistan’s IT export sector.
The draft policy would generally require sensitive personal and government information to be stored and processed within Pakistan. Moving such data outside the country would require prior regulatory approval.
P@SHA believes these requirements could affect software exporters, freelancers and distributed technology teams that work with international clients and systems.
The association is particularly concerned that remote access to data from outside Pakistan could potentially be treated as a cross-border transfer, creating additional compliance obligations for IT businesses.
Meanwhile, non-sensitive public-sector information would generally be made available through a National Open Data Portal in machine-readable formats, making it easier for software and automated systems to process.
Industry Wants Clearer Rules
P@SHA has identified the lack of a clear boundary between public and private data as one of the most important gaps in the proposed policy.
The association has also questioned provisions concerning the monetization of public data. According to P@SHA, there could be tension between the government’s responsibility to act as a custodian of public information and mechanisms allowing certain non-personal data to be licensed or priced.
Another issue highlighted by the industry body is the absence of strong financial penalties for violations.
P@SHA warned that audits without meaningful monetary sanctions could result in weaker enforcement compared with data governance frameworks used in jurisdictions such as the European Union, Singapore and India.
Despite these concerns, P@SHA considers the proposed policy an important step toward strengthening Pakistan’s digital infrastructure and preparing the country for wider adoption of artificial intelligence.
The association has urged policymakers to provide clearer definitions, specify compliance responsibilities and establish transparent rules for cross-border data access before the policy is finalized and implemented.
