The Pakistan IT Industry Association (P@SHA) has raised concerns over ambiguities, compliance requirements and possible data residency implications for IT exporters under Pakistan's draft National Data Governance Policy 2026.
In a member briefing published on August 12, P@SHA said the draft policy, released by the Ministry of IT and Telecommunication in July 2026, is Pakistan's first unified framework for the collection, protection and sharing of government data.
The draft policy is based on the principle that public sector data should be treated as a strategic national asset. It also sets standards and operating arrangements to allow government entities to share and use data more effectively.
According to P@SHA, the proposed framework currently applies to public sector data rather than private sector data. However, the association said the distinction between the two needs further clarification, particularly in cases involving public-private partnerships.
Govt to Act as Data Custodian
Under the proposed framework, government departments would act as custodians of citizen data rather than its owners. They would hold the information in trust for citizens.
The policy also introduces a 'once-only' principle, under which government agencies would avoid keeping duplicate citizen records. Instead, they would rely on designated Primary Data Registers.
Data sharing between government agencies would take place through a centrally governed platform called WASL, which is conceptually modeled on Estonia's X-Road system.
ALSO READ Pakistan Farms to Use AI for Crop and Pest Detection
Pakistan Digital Authority to Regulate Data
The draft policy proposes establishing the Pakistan Digital Authority (PDA) as a central data regulator. The authority would have enforcement, audit and corrective powers.
The framework also calls for the appointment of a National Chief Data Officer and dedicated Chief Data Officers in every federal public body.
Public institutions would be assessed annually through a National Data Maturity Index. The index would measure areas such as governance, security, data quality, openness and citizen empowerment.
AI and Privacy Rules Proposed
The proposed framework also includes provisions covering artificial intelligence governance and citizen privacy rights.
AI systems used by public bodies for automated decision-making would have to be explainable, logged in a public PDA registry and subject to human oversight.
Generative AI systems would also face safeguards covering factual inaccuracies, intellectual property violations and data leaks.
Citizens would receive several rights under the proposed policy. These would include the ability to view access logs, correct personal data, export information and request deletion where legally permitted.
Government bodies would also be required to adopt Zero-Trust cybersecurity architecture, a security approach that does not automatically trust users or devices even after they enter a network. They would also have to report data breaches to the PDA without delay.
Data Localization Raises Concerns for IT Exporters
One of the key provisions in the draft policy would generally require sensitive personal and government data to be hosted and processed within Pakistan.
Transfers of such data outside the country would require prior regulatory approval.
At the same time, non-sensitive public data would be published by default through a National Open Data Portal in machine-readable formats, allowing computers and software systems to process the information more easily.
P@SHA said the proposed localization requirements could affect software exporters, freelancers and distributed technology teams if remote international access to data is considered a cross-border data transfer.
P@SHA Seeks Clarity on Public and Private Data
P@SHA identified the lack of a clear distinction between public and private data as the most critical gap in the draft policy.
The association also raised concerns about proposed data monetization mechanisms. It said these could create tension between the government's role as a custodian of public data and provisions that allow the licensing or pricing of non-personal public data.
P@SHA also pointed to the absence of strict financial penalties for non-compliance.
The association warned that audits without meaningful monetary sanctions could weaken enforcement when compared with data governance regimes in jurisdictions including the European Union, Singapore and India.
P@SHA said the draft policy remains an important building block for Pakistan's AI readiness and digital ecosystem. However, it said the framework needs greater clarity on definitions, compliance obligations and cross-border data access before it is implemented.
(0)Comments