
By Falak Naz Batool
In this digital era, most people in Pakistan remain unaware that their names, credentials, phone numbers, and fingerprints are not truly under their control. This is the reality every resident now lives with, whether they realise it or not. The core problem is that Pakistan has no personal data protection law: not a weak one, not a strict one, none at all.
The Prevention of Electronic Crimes Act of 2016 (PECA) has served as the country’s primary legislative framework for nearly a decade now. But that doesn’t mean it substitutes for real data protection, since it was never built to cover the full range of harm that citizens face once their data is exposed. PECA is a cybercrime statute designed to penalise violations after they occur; its safeguards apply only after harm has been done. It does not eliminate the need for a law establishing proactive rules for state institutions, private corporations, and commercial entities on collecting, processing, storing, and transferring citizens’ information.
Legislative proposals materialise only to dissipate. The recurrent failure to advance these drafts to approved legislation has little to do with drafting deficiencies; rather, it reflects the lack of transparency the state is willing to extend to its own citizens.
Two examples fit this pattern of institutional behaviour regarding citizens‘ personal data. The first is the Personal Data Protection Bill 2023 — a revised version of an earlier draft that had never advanced this far. Cabinet approved this version, and it was on track to be enacted until an administrative intervention disrupted the furthest any personal data protection bill has come to passage. It happened when a private member introduced a parallel version in the Senate, prompting the Ministry of IT and Telecommunication, which had drafted the bill, to oppose it. The Ministry cited procedural impediments: that the established protocols hadn’t been followed, and that the parallel version infringed the Rules of Business 1973 by involving improper expenditure from the federal consolidated fund.
The second pattern occurred with the Draft Data Governance Policy 2026, which was opened for public consultation in June 2026 and then routed to the relevant institutions and ministries for approval, though no update has since confirmed that this approval was ever granted. This draft, also prepared by the Ministry of IT and Telecommunication, derives its authority from the Digital Nation Pakistan Act 2025 and, under it, from the Pakistan Digital Authority (PDA). This draft was very citizen-right-centric and showed genuinely progressive ideas, mainly with respect to its clause 5, which ensures the doctrine that government data is not the property of the agency or institution that holds it; rather, the institution is the custodian of the respective data, and its role is to protect it, maintain it and share it lawfully. It reiterates that this data is held in trust for people; it champions the once-only principle, so citizens are not repeatedly asked for the same information at every agency encounter. It likewise sets out practical guardrails on generative AI for public bodies. In short, this policy puts citizens first.
But the public critique raised a few points, including that the policy is overly ambitious and exceeds its implementation and enforcement capacity, and that the Pakistan Digital Authority lacks binding statutory authority to compel compliance from autonomous government bodies, ministries, commercial banks, or other semi-public bodies. Ambition in its clauses was never the problem; promising results well beyond its independent capacity was.
Both examples point to the same institutional reflex. Institutions respond strongly to external scrutiny and will block progress whenever legislation threatens to move a subject beyond their exclusive control. Institutional self-preservation, in other words, takes precedence over public safety. The draft policy itself acknowledges that its provisions are subject to the anticipated Personal Data Protection Law, reducing it to a placeholder with no defined timeline. In a country where state institutions regard citizen data registers as proprietary assets, such a subordinate framework is unlikely to succeed.
This regulatory void has tangible consequences. According to a Joint Investigation Team report furnished to the Interior Ministry, sensitive records belonging to 2.7 million citizens were compromised from NADRA offices in Karachi, Multan, and Peshawar between 2019 and 2023, alongside indications of internal complicity. Several NADRA officials were dismissed, with disciplinary action taken against more than a dozen in total. This incident is not a hypothetical risk that data protection legislation might prevent; it is a completed breach, carried out by personnel within the institution responsible for safeguarding the data, motivated by personal financial gain. When custodians act this way, the absence of a personal data protection framework looks less like a technical oversight and more like a permitted outcome.
Emerging AI technologies have sharpened an existing vulnerability: citizens, youth, and women are increasingly targeted through deepfakes, non-consensual image-based exploitation, manipulated images used for harassment, and blackmail; all with no regulatory body positioned to intervene. Grievance logs from the FIA’s Cybercrime Wing index thousands of such occurrences annually, most involving women, with a conviction rate lingering at 3.16% since 2020. Because of this absence, the mandate of transparency remains unmet, and children and women are especially burdened by the exposure of data they mostly never consented to share. This neglect reflects the gendered, social, and legal costs citizens continue to pay because the legislative safeguards enforcing rights the Constitution already guarantees are absent.
Article 14 of the Constitution already enshrines every individual’s right to privacy and the inviolability of dignity, the core foundation for why personal data protection is needed. The right that the Draft Policy 2026 gestures toward —citizens’ access to information the state holds about them—draws on the same logic as Article 19-A, which guarantees every citizen the right to access information on matters of public importance. When these protections have existed for decades, why is institutional commitment still absent to enable rights the Constitution itself already protects?
Therefore, as long as personal data protection legislation remains unimplemented, PECA will continue to fill the vaccum, acting as a substitute form of penalisation rather than governance. Until then, the state will keep framing personal privacy as a security risk that interferes with its control; entities will continue to commodify citizens’ personal information in the absence of law. So, until custodianship is redefined to protect citizens’ trust over institutional ownership, policy or legislative initiatives will yield no result, and data breaches will remain a practice that goes unpunished.

