Pakistan Finalises National Data Governance Policy 2026, Nurturing Government Data Control Ahead of Privacy Law.
Pakistan’s government has adopted a new policy to govern how public data is handled by private firms, a step that could reshape data protection ahead of a comprehensive privacy law.
By AVI News News Desk3 min read
🔍 Click to enlarge
Pakistan Finalises National Data Governance Policy 2026, Nurturing Government Data Control Ahead of Privacy Law.
Image via UnsplashPakistan still lacks a broad data privacy law. The Personal Data Protection Bill has existed only in draft since 2018 and has not yet been passed.
The Ministry of Information Technology and Telecommunication (MoITT) issued a draft National Data Governance Policy 2026 in late June. The public consultation closed on July 10.
A high‑level meeting held this week, chaired by Federal Minister Shaza Fatima Khawaja, brought MoITT and the Pakistan Digital Authority (PDA) together to finish the policy before cabinet approval and gazette notification.
The policy is not a privacy law. It does not prescribe how private companies can collect or use data from customers. Instead it focuses on government data, which is rarely kept strictly within ministries.
Pakistan’s tech sector frequently builds digital services for public agencies, hosts government systems, runs call centres, manages cloud infrastructure, and processes citizen information for the state. The policy makes it clear that such contractors, processors, concessionaires, and grantees are part of the government’s data governance framework.
Key provisions classify government data by sensitivity, restrict where certain categories may be stored or processed, tighten cross‑border transfers of sensitive information, and require contractors to notify PDA of qualifying security incidents. They also give citizens visibility into who accessed their data and why, creating audit trails that are enforced through contracts, not a private‑sector privacy law.
PDA Chairman Dr Sohail Munir stated that the policy does not centralise government data or allow unrestricted sharing. Ownership stays with individual entities, and a new WASL framework lets entities exchange information securely based on classification and governance standards, not a single pooled database.
The policy means companies working with the government must now understand where government data resides, how it moves, and who has access. New requirements include data residency, security controls, breach reporting, access management, and documentation. Guidance on these points will come after a National Data Strategy is released.
Pakistan’s IT and IT‑enabled services exports reached $4.6 billion last fiscal year, and almost all of that revenue comes from clients that expect strong governance. The policy allows firms to apply the same safeguards that satisfy GDPR for European clients or security assessments for U.S. clients to domestic government contracts, creating a unified compliance program.
While the Personal Data Protection Bill remains important for a future comprehensive legal framework, the National Data Governance Policy shows that data governance is already arriving through procurement, contractual terms, and technical standards. The policy’s rollout will begin after cabinet approval and gazette notification, bringing immediate practical changes for technology firms serving the government.
For technology companies in Pakistan, the new policy is a concrete development that will shape how they handle government data, even before a nationwide privacy law is enacted.