Waqar Uddin

Pakistan's Data Governance Policy 2026: A Power the Act Never Granted

July 21, 2026 (3w ago)6 views

MoITT put its draft Data Governance Policy 2026 out for public comment in late June, with the window closing July 10, per Dawn's coverage of the release. The document calls itself, in its own clause 1, "the primary national instrument for data governance" in Pakistan, executed by the Pakistan Digital Authority under the Digital Nation Pakistan Act, 2025. I read the full 25-page draft against that Act, clause against section, rather than against how either has been described in press coverage.

The doctrine holds up well. The enforcement clause does not, and the consultation architecture for the instruments that will carry the actual rules is thinner than the Policy's own language implies.

Disclosure: I work at Jazz as Principal Evangelist Cloud & AI. This article is written as personal industry analysis. Views are my own.

What the doctrine gets right

Clause 5, "The National Data Doctrine," and clause 6, "Foundational principles," are the strongest chapters in the document. Government data is framed as held in trust, not owned: "public bodies are custodians, not proprietors" (5.2), and personal data specifically "is not the subject of any ownership claim by a public body; it is held under fiduciary duty to the data subject" (3.17). Custody stays federated rather than centralized: each public body "owns, controls, and serves its own data," and personal data "shall not be duplicated, replicated, or centrally pooled save where expressly authorised" (6.3). For a single national dataset of record, like a persons or property register, the Policy designates "Primary Data Registers" by Federal Cabinet decision on PDA's recommendation, not by unilateral PDA fiat (6.4A).

The citizen-rights chapter (clause 12) is more specific than most first-draft policies I've read from this region. It commits to granular, unbundled consent (12.2), a right to know who inside government accessed your data and why (12.3), selective disclosure and zero-knowledge verification where the underlying data doesn't need to move at all (12.5), portability to a machine-readable format (12.6), and rectification and erasure subject to named legal exceptions (12.7). These aren't slogans; each maps to a named supporting instrument (the Citizen Identity and Credentials Standard, DNP-D.105) that's supposed to carry the technical detail.

Residency policy is similarly concrete, structured as three tiers rather than a blanket localization mandate:

TierApplies toRequirement
Tier 1, mandatory in-countryRESTRICTED, CONFIDENTIAL, and personal data, including sensitive personal data and authoritative-source data of national importanceHosted, stored, processed within Pakistan. Cross-border processing or remote access needs specific PDA approval and additional safeguards
Tier 2, approval-based offshoreINTERNAL data outside Tier 1, with a credible operational case for offshore processingMay be processed offshore with prior PDA approval, contractual safeguards, and audit rights
Tier 3, no restrictionOPEN dataMay be hosted and mirrored globally, subject to attribution and licence terms

That's a workable, risk-proportionate structure (clause 8.2), and it slots cleanly into the rest of the sovereignty stack I've tracked on this blog: the hosting-layer mandate in PISF and the network-layer mandate in PTA's domestic routing rules.

A power the Act never granted

Clause 16.2 gives PDA a specific enforcement tool: "PDA may issue binding directions to public bodies for the purpose of giving effect to this Policy and its supporting instruments. Directions shall be in writing, with reasons, and shall provide a reasonable opportunity for representation by the public body concerned." Clause 18.5 leans on the same power for compliance: "Where non-compliance is identified, PDA shall require corrective action through binding directions."

Read against the Digital Nation Pakistan Act, 2025 (Act No. I of 2025), that's not the power the Act actually gives the Authority. Section 8(b) says PDA may "issue and enforce regulations, guidelines, and standards necessary to implement the Masterplan," but treats directives as a separate, narrower category: "The Authority may also issue directives with the approval of the Commission, ensuring alignment with the Masterplan." Approval of the National Digital Commission, the Prime Minister-chaired body created by Chapter 2 of the Act, is a condition on the Authority's directive power, not a formality the Policy is free to drop.

The Act's own escalation path for non-compliance confirms the same limit. Section 12(4): if a public entity fails to comply, "the Authority shall issue a formal notice outlining the areas of non-compliance and the required corrective actions... If non-compliance persists, the Authority shall report the matter to the Commission. The Commission may take further remedial actions as it deems necessary." PDA's own unilateral power stops at a formal notice. The actual bite belongs to the Commission.

Clause 16.2 and clause 18.5 describe PDA issuing binding directions on its own authority, gated only by a written-reasons requirement and a chance for the affected public body to respond. Section 8(b) of the enabling Act gates the Authority's directive power on Commission approval, and section 12(4) routes persistent non-compliance to the Commission for remedial action, not to a PDA-issued binding order. Nothing in the Policy's institutional chapter (16) mentions the Commission at all. That's the gap Cabinet should close before this goes to Gazette.

It's also worth flagging what sits behind that gap. Section 29 of the Act is a broad ouster clause: "no decision or action taken under this Act or rules or regulations made thereunder shall be questioned by any agency or challenged in any court or tribunal." Whether a "binding direction" issued under a Policy document, rather than under a rule or regulation properly gazetted under sections 25 and 26, falls inside or outside that bar is genuinely unclear on the text. The Policy doesn't resolve the question either way, which means a public body on the receiving end of an ungated direction may not have an obvious avenue to test whether that direction was properly authorized in the first place.

Scope: public-sector by declaration, wider by clause 15

Clause 1 is explicit about boundaries: the Policy governs "public-sector data," and "does not govern personal data held outside the public sector... save where expressly provided." Clause 7 repeats the same frame, extending only to federal public bodies and to "contractors, processors, concessionaires, grantees, and partners that process Government data or perform public functions" (7.1), bound in by flow-down clauses in their contracts (7.3). That's an appropriately scoped reach into the private sector: it only follows Government data into private hands.

Clause 15, "Data value and the data economy," uses the "save where expressly provided" escape hatch more loosely. Clause 15.3 lets PDA "recognise, register, and supervise data trusts and data intermediaries where such arrangements support the lawful pooling, sharing, or stewardship of data for the public good," with no textual requirement that the pooled data originated as Government data. Clause 15.6 lets "individuals and organisations" contribute personal or non-personal data "for objectives of public interest, through arrangements recognised by PDA," again without tying the contributed data back to the public sector. Both provisions hand PDA an ongoing supervisory relationship with private entities and private data flows that have nothing to do with government custody.

The Act arguably backs this: section 8(h) gives the Authority a mandate to "develop and enforce a National Data Strategy and comprehensive data governance framework within government entities and across public and private sectors." So this isn't ultra vires. It is, though, a gap in the Policy's own drafting discipline. A reader who stops at clause 1's scope statement, which is where a scope clause is supposed to be authoritative, would reasonably conclude the Policy doesn't reach private data trusts or citizen-to-citizen data altruism arrangements. Clause 15 quietly says otherwise, and there's no cross-reference from clause 1 flagging the exception.

Coordination that's precise for a regulator that doesn't exist yet, and thin for the ones that do

Section 8(g) of the Act states an obligation of result: "The Authority shall ensure that there is no overlap with the mandate or jurisdiction of other regulatory bodies and no conflict with relevant laws or existing regulatory frameworks." Clause 16.6 of the Policy translates that into an obligation of process, hedged twice: "PDA shall coordinate with sectoral regulators where domain-specific data regimes apply, and shall conclude memoranda of understanding where required to clarify boundaries, harmonise standards, and avoid duplication." "Where required" is doing a lot of work in a single sentence that's supposed to operationalize a "shall ensure" duty.

Compare that to clause 16.9, on the still-unenacted Personal Data Protection Law's future authority. There, the Policy is precise: a mandatory memorandum of understanding, a commitment to "share supervisory information where lawful," and an explicit reconciliation mechanism, "where the two authorities issue directions or guidance on the same subject, those directions shall be reconciled through consultation and, where necessary, joint instruments." The National Data Governance Council does seat PTA, SBP, SECP, and NADRA's counterparts as members (clause 16.5(c)), but a seat at a forum PDA itself chairs is a weaker guarantee than the specific reconciliation language written for a privacy regulator that doesn't exist yet. Pakistan's PDPL is still listed in the Policy's own abbreviations table as "anticipated" (clause 4), not enacted, so the more carefully drafted coordination clause is the one written for a body with no current jurisdiction to overlap with.

The instruments that carry the actual rules skip the consultation the Policy promises itself

Annex II lists 19 supporting instruments PDA "shall issue, or maintain, to give full operational effect to this Policy" as a minimum: a data security standard covering encryption and key management (DNP-D.103), the cross-border approval mechanics behind the residency tiers (DNP-D.400), the AI and automated-decision-making governance profile (DNP-D.401), and the compliance and certification standard that defines what "enforcement" actually means (DNP-D.107), among fifteen others. Clause 17.1 says PDA "shall issue and maintain" these, plus "such further instruments as PDA considers necessary." No consultation requirement attaches to any of them.

The only consultation guarantee in the entire document sits in clause 18.6, and it applies to "material amendments" of the Policy document itself: "subject to public consultation, save where urgency requires otherwise." Clause 6.17 gestures at "structured stakeholder engagement," but ties it to periodic review, a backward-looking check on instruments already in force, not a gate before a standard like the security instrument or the AI profile first takes effect. Public bodies, and by flow-down their contractors, will be bound by rules that were never circulated for comment before they applied.

This isn't a Policy-specific failure. Section 26 of the Act lets PDA "make regulations, not inconsistent with the provisions of this Act or the rules, for exercising its powers" by simple Gazette notification, no consultation duty attached, while section 11(4) does require consultation, but only for the Masterplan. The Policy inherited the Act's asymmetry rather than correcting it, even though the Policy is the one document specific enough to actually bind day-to-day practice.

The bigger picture

None of this reads as bad-faith drafting. The Act itself was written broadly, giving PDA a sweeping mandate and routing most of the real checks through a Commission that meets twice a year at minimum (section 4(6)) and an Oversight Committee that reviews rather than approves (section 10). A Policy built to operationalize that Act inherited its looseness instead of tightening it. The doctrine chapters read like they were written by someone who studied the EU's Data Governance Act and Estonia's X-Road model and wants Pakistan's citizens to have the same guarantees. The institutional chapters read like they assumed PDA would fill in the missing statutory detail with restraint.

Given that the Digital Nation Pakistan Act gates directives on Commission approval, routes persistent non-compliance through the Commission, and imposes an explicit no-overlap duty on the Authority, closing the gap before Cabinet approval means adding language to clause 16.2 and 18.5 that borrows the Act's own conditions, not asserting an enforcement power the Act never handed over. The Policy's own metadata block marks it "PROPOSED," pending Cabinet approval and Gazette notification (Annex III.1). There's still a clean opportunity to fix this before it becomes binding law rather than after.

Where this fits

Part of an ongoing series on Pakistan's cloud, AI, and digital-infrastructure policy. I flagged this draft in passing in Pakistan's AI Policy: What the Budget Books Actually Show as the quiet vehicle the government appears to be using in place of the still-unpassed NCPDP regulator; this is the full clause-by-clause read against its own enabling Act. See also PISF Closes the Hosting Layer in Pakistan's Sovereignty Stack and Pakistan's Domestic Routing Mandate Closes the Network Layer.