P@SHA · Pakistan IT Industry Association Policy Portal
Govt · Ministry of IT & Telecom · 2023

Personal Data Protection Bill 2023 (Draft)

DRAFT Data PrivacyCompliance
§

AI brief

Generated from the document text · 19 Aug 2026

The Personal Data Protection Bill 2023 (Draft) is a comprehensive data privacy legislation being advanced by Pakistan's Ministry of IT & Telecom to establish a legal framework governing the collection, processing, storage, and transfer of personal data. The Bill introduces obligations for data controllers and data processors, defines rights for data principals (individuals whose data is processed), and establishes rules for cross-border data transfers. An enforcement framework is included to ensure compliance, with regulatory oversight mechanisms contemplated under the draft. This Bill represents a significant regulatory development that will impact all organizations handling personal data of Pakistani residents.

Key questions answered

Who does this Bill apply to and what are the obligations for data controllers and processors?

The Bill applies to any organization that collects, processes, or stores personal data of Pakistani residents. Data controllers bear primary responsibility for determining the purposes and means of processing personal data, while processors act on behalf of controllers. Both entities must implement appropriate security measures, maintain data processing records, and ensure compliance with the Bill's requirements.

What are the restrictions on cross-border transfer of personal data under this Bill?

The Bill establishes rules governing the transfer of personal data outside Pakistan. Organizations seeking to transfer data internationally must ensure that the destination country provides an adequate level of data protection or that appropriate safeguards are in place. These provisions aim to protect Pakistani citizens' data even when it crosses borders.

What rights does this Bill grant to data principals (individuals)?

Data principals are granted several rights including the right to be informed about data collection, the right to access their personal data, the right to correction or erasure of inaccurate data, and the right to withdraw consent. Organizations must establish mechanisms to facilitate the exercise of these rights by individuals.

What enforcement mechanisms and penalties does the Bill establish for non-compliance?

The Bill establishes an enforcement framework to monitor compliance and address violations. Organizations found in breach may face penalties and corrective orders. While specific penalty amounts would be detailed in the full text, the enforcement structure suggests both financial consequences and mandatory remediation requirements for non-compliant entities.

How does this Bill affect our existing data processing activities and what compliance steps should we take?

Companies should conduct a comprehensive audit of their current data collection, processing, and storage practices to identify gaps against the Bill's requirements. Organizations must establish or update policies for consent management, data subject rights requests, data breach notification, and cross-border transfer procedures. A designated data protection officer may be required depending on the nature and scale of processing activities.

§

Ask about this document

Questions are queued and answered against the document's extracted text. Answers appear below once processed.

Questions and briefs are generated by an AI model from the official document text — verify against the primary source before relying on them for compliance decisions.