Ask most people in Pakistan what protects their personal data and the answer is a vague reference to "the privacy law". A comprehensive personal data protection statute of the kind the EU, the UK and India now have has been in draft for years and has not been enacted. That does not mean there is nothing — it means the protection is scattered, and you have to know where to look.
The constitutional floor
Article 14 of the Constitution guarantees that the dignity of man and, subject to law, the privacy of the home shall be inviolable. The superior courts have read privacy expansively, and Article 14 is the anchor for a constitutional petition where a public body has misused personal information.
It binds the state. It does not, by itself, give you a claim against a private company that leaked your data — which is where most breaches actually happen.
PECA: the criminal provisions that do the work
The Prevention of Electronic Crimes Act, 2016 is, in practice, Pakistan's data protection law, because it criminalises the conduct that most breaches involve:
- Section 3 — unauthorised access to an information system or data.
- Section 4 — unauthorised copying or transmission of data.
- Section 5 — interference with data.
- Section 16 — unauthorised use of identity information, which reaches obtaining, selling or using someone's identity data. This is the provision behind most complaints about leaked CNIC and contact databases.
- Section 13 — electronic forgery, and section 20 where false information damages reputation.
The remedy is a complaint to the FIA Cybercrime Wing. Note what this framework is and is not: it punishes misuse after the fact. It imposes no duty on a company to collect only what it needs, to secure it properly, to tell you when it is breached, or to delete it when you ask.
Sector rules that do impose duties
Where a comprehensive statute is missing, sectoral regulation fills part of the gap — and this is where a real obligation on a business is most likely to be found:
- Banking. The State Bank's regulations impose confidentiality, cybersecurity and customer data obligations on banks and payment institutions, and there is a defined complaint route through the bank and then the Banking Mohtasib.
- Telecoms. The PTA regulates operators' handling of subscriber data, SIM issuance and unsolicited communications, and takes consumer complaints.
- NADRA. The statute governing NADRA restricts disclosure of the records it holds, and unauthorised access to those records is an offence.
- Health, education and employment records are governed largely by institutional rules and contract rather than by a general statute.
The contract and tort route
Where a company promised to protect your data — in its terms, its privacy policy or your agreement with it — that promise is a contractual obligation and a breach of it sounds in damages. A privacy policy is not decoration; it is a representation you relied on.
A civil suit for damages, and where publication is involved a claim in defamation, remain available. These are underused, largely because proving quantifiable loss from a data breach is genuinely hard.
If your data has been misused
- Establish what was exposed and by whom. Keep the messages, the calls, the screenshots, the spam that followed.
- Write to the organisation that held it. Ask what was disclosed, to whom, when, and what they have done. Their answer — or their silence — is your evidence.
- Complain to the sector regulator where there is one: SBP or the Banking Mohtasib for a bank, PTA for a telecom operator.
- File with the FIA Cybercrime Wing where the conduct is criminal — hacking, selling data, identity misuse.
- Consider a civil claim where the loss is real and provable.
- Where a public body is responsible, a constitutional petition under Article 199, resting on Article 14, is available.
What to expect next, and what to do meanwhile
Draft personal data protection legislation, providing for consent, purpose limitation, breach notification and a regulator, has been circulated in successive versions. Businesses handling personal data would be sensible to build to that standard now rather than retrofit later — collect only what is needed, secure it, delete it when the purpose ends, and say honestly in your privacy policy what you actually do.
For individuals: assume your CNIC number and phone number are already circulating, be sparing with copies of identity documents, and treat any unsolicited call that already knows your details as a warning rather than a reassurance.
This article describes the legal position on data protection in Pakistan as a framework and is not advice on any particular breach. This area is expected to change when comprehensive legislation is enacted. Confirm the current position and consult an advocate before acting on a breach.
