EnglishUR
Pakistan flag

Pakistan

Pakistan Data Privacy Laws: PECA and Personal Data Protection Bill Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202620 min read
Pakistan Data Privacy Laws: PECA and Personal Data Protection Bill Guide (2026)

Frequently Asked Questions

Does Pakistan have a comprehensive data privacy law as of 2026?

No. As of May 2026, Pakistan does not have a comprehensive, enacted data protection law. The Prevention of Electronic Crimes Act (PECA) 2016, substantially amended in January 2025, addresses some data misuse through criminal penalties, but was not designed as a privacy framework. The Personal Data Protection Bill 2023 and a newer 2025 draft version prepared by the Ministry of Information Technology and Telecommunications remain unenacted. Neither version has passed both houses of Parliament.

What did the 2025 PECA amendments change?

The Prevention of Electronic Crimes (Amendment) Act, 2025, signed January 30, 2025, made three major changes. First, it created the National Cyber Crime Investigation Agency (NCCIA) and transferred exclusive cybercrime investigation powers from the FIA's Cyber Crime Wing to the NCCIA. Second, it created the Social Media Protection and Regulatory Authority (SMPRA) with powers to require removal of unlawful content from social media platforms. Third, it added Section 26A, which criminalizes intentional dissemination of false or fake information, carrying penalties of up to three years imprisonment and fines up to PKR 2 million.

What penalties does PECA 2016 impose for unauthorized data disclosure?

Under Section 38 of PECA 2016, any person who has access to personal or sensitive data and transfers it without the consent of the data subject (except when required by law) faces imprisonment of up to three years, a fine of up to PKR 1 million (approximately USD 3,500), or both. Unauthorized access to information systems under Section 3 carries up to three months and PKR 50,000. Unauthorized copying or transmission of data under Section 4 carries up to six months and PKR 100,000.

Are businesses required to notify individuals after a data breach in Pakistan?

No. Pakistan currently has no mandatory data breach notification requirement. Neither PECA 2016 nor the 2025 amendments impose a notification obligation. The pending Personal Data Protection Bill 2023 would introduce a 72-hour window for reporting breaches to the proposed National Commission for Personal Data Protection, but this provision has not yet become law. As confirmed by the 2024 NADRA breach investigation, organizations can experience large-scale data theft without any statutory obligation to inform affected citizens.

Does Pakistan require data localization?

Partially. The Pakistan Telecommunication Authority's Critical Telecom Data and Infrastructure Security Regulations 2025 require telecom companies to store all critical telecom data within Pakistan's geographical borders. No critical telecom data may be transferred abroad without explicit PTA approval. The pending Personal Data Protection Bill would also require sensitive personal data to be stored on domestic servers, but this requirement has not yet become law. No general data localization obligation currently applies to all industries.

How does Pakistan's Constitution protect privacy?

Article 14(1) of the Constitution of Pakistan states that the dignity of man and the privacy of home shall be inviolable. In Mohtarma Benazir Bhutto v. President of Pakistan, the Supreme Court held that this protection extends beyond the physical home and prohibits government surveillance of phone calls. Courts have also held that retrieving data from mobile devices without consent or court approval violates Article 14. However, the protection is subject to law, meaning Parliament can authorize privacy intrusions through legislation, and it primarily binds the state rather than private companies.

What happened in the NADRA data breach?

A joint investigation team formed by the FIA confirmed in November 2024 that data for 2.7 million Pakistani citizens had been stolen from NADRA over approximately four years (2019-2023), with theft originating at offices in Karachi, Multan, and Peshawar. The investigation found insider involvement. The stolen data included names, addresses, and personal identifying information. It was sold on international dark web markets. NADRA dismissed a Grade 19 officer and five other employees. Pakistan had no mandatory breach notification law requiring affected citizens to be informed.

What should businesses do now while waiting for Pakistan's data protection law?

Businesses should take several practical steps now. Comply with PECA Sections 3, 4, 5, and 38 (unauthorized access, copying, interference, and data disclosure). Comply with sector-specific rules: PTA regulations for telecom companies, SBP frameworks for banks, and SECP Companies Regulations 2024 for corporate entities. Document what personal data is collected and where it is stored. Assess whether sensitive data would need to be localized if the proposed law passes. Review third-party processor contracts. Identify a Data Protection Officer candidate. This preparation reduces compliance risk when comprehensive legislation eventually passes.

Updates

Major refresh. Added PECA 2025 Amendment Act (SMPRA, NCCIA, Section 26A); updated PDP Bill status to reflect MoITT opposition to Private Member's Bill and work on updated 2025 draft; added dedicated section on recent data breaches (NADRA 2.7M, 180M credential breach, September 2025 personal data sale); updated enforcement landscape to replace FIA Cyber Crime Wing with NCCIA; added SECP Companies Regulations 2024; added recent developments log; expanded Quick Answer section; word count expanded from 2,850 to approximately 5,800 words. Title and meta unchanged (converting well).

Sources and References

  1. Prevention of Electronic Crimes Act 2016 - National Assembly of Pakistan(na.gov.pk).gov
  2. 2025 Amendments to PECA - RSIL Pakistan(rsilpak.org)
  3. NCHR Report on PECA and the 2025 Amendments Act(nchr.gov.pk).gov
  4. Personal Data Protection Bill 2023 - MoITT(moitt.gov.pk).gov
  5. Senate of Pakistan - Personal Data Protection Bill Summary(senate.gov.pk).gov
  6. Senate body discusses Data Protection Bill - January 2025(nation.com.pk)
  7. Constitution of Pakistan - Article 14(pakistankanoon.com)
  8. PTA Critical Telecom Data and Infrastructure Security Regulations 2025(pta.gov.pk).gov
  9. SECP Companies Regulations 2024(secp.gov.pk).gov
  10. State Bank of Pakistan - Banking Regulations(sbp.org.pk).gov
  11. NADRA 2.7 Million Data Breach - Investigation Confirms Theft(biometricupdate.com)
  12. PKCERT Warns of 180 Million Credential Breach(paubox.com)
  13. Why Pakistan Is Stalling On Data Protection(mondaq.com)
  14. ICLG Data Protection Laws and Regulations Pakistan 2025-2026(iclg.com)
  15. State of Privacy Pakistan - Privacy International(privacyinternational.org)
Share: