Pakistan Data Governance Policy 2026: What You Need to Know

In June 2026, the Ministry of Information Technology and Telecommunication proposed the the draft of Data Governance Policy 2026. It sets out how the federal government should collect, use, share, and protect data going forward. It is a long and fairly technical document, so we read through it and pulled out what actually matters, in plain language.

What is this policy actually about?

Strip away the legal language and the policy is really answering one question: who controls your data when it sits inside a government computer, and what rules should the government follow when it collects, stores, shares, or uses it. This applies to federal ministries, departments, regulators, and any private company or contractor that processes government data on the state’s behalf. It does not cover data held purely by private companies about their own customers. That is a separate matter, meant to be handled by a future Personal Data Protection Law, which this policy refers to but does not create.

The core idea: data is held in trust, not owned

The policy opens with a simple but important idea. Government data is described as a national asset that belongs to the people of Pakistan, not to whichever department happens to be holding it. A government office that has your data is called a custodian, not an owner. That distinction matters because a custodian has a duty to protect the data, keep it accurate, and use it responsibly, rather than treat it as property to do whatever it wants with.

For your personal data specifically, the policy goes further and says it is held under something called a fiduciary duty, meaning the government owes you a duty of care over your own information, similar to how a bank is expected to look after your money rather than just hold it.

banner-1-your-data-rights

The main principles, in short

The document lists many principles, but here are the ones that matter most for everyday understanding:

  • Sovereignty by default. Government data should stay under Pakistan’s legal control. Moving it outside the country is meant to be the exception, not the norm, and requires approval.
  • Open by default, closed by exception. Government data should be shared publicly unless there is a specific legal reason to restrict it, not the other way around.
  • Once-only principle. You should not have to submit the same document or information to the government more than once. Departments are supposed to reuse verified data instead of asking you again.
  • Minimum disclosure. When agencies share data with each other, they should share only what is needed for that specific purpose, not entire files.
  • Privacy by design. Privacy protections are supposed to be built into government systems from the start, not added later as an afterthought.
banner-2-data-sovereignty

Where can your data actually be stored?

This is one of the more concrete parts of the policy. It creates three tiers:

  1. Tier 1, mandatory in-country storage: This covers sensitive data, personal data, and any nationally important data. It must be hosted and processed inside Pakistan. Sending it abroad needs special approval.
  2. Tier 2, approval-based offshore processing: Less sensitive internal data may be processed outside Pakistan, but only with prior approval and safeguards.
  3. Tier 3, no restriction: Open data that is already public can be hosted anywhere.

In short, your CNIC details, your medical records if the government holds them, and similar sensitive data are supposed to stay physically inside Pakistan.

What rights does this give you as a citizen?

This is the section that matters most to the average reader, not just IT professionals. The policy says you should be able to:

  • Know what data a government department holds about you
  • Know who accessed your data, when, and why
  • Ask for wrong information to be corrected
  • Ask for your data to be deleted, with some legal exceptions such as court cases or record-keeping laws
  • Get a copy of your own data in a format you can actually use or move elsewhere
  • Ask for a human being to review any decision made about you by an automated system, if that decision has a real effect on your life

It also says that consent, when needed, must be specific and clearly explained, not a blanket “agree to everything” checkbox buried in fine print.

Sharing data between government departments

Right now, different departments in Pakistan often ask you for the same paperwork because their systems do not talk to each other. This policy tries to fix that by creating a single official channel for departments to exchange data, called WASL, meaning “connection” in Urdu. Departments are told not to build their own side arrangements for sharing data outside this system, unless specifically allowed.

Sensitive exchanges, especially ones involving personal data, are supposed to go through something called a Data Sharing Impact Assessment first, essentially a risk check before data is handed over.

banner-3-ai-government

Rules for artificial intelligence in government

The policy also addresses AI use by government bodies, an area that did not really exist in earlier Pakistani policy documents. Key points include:

  • High-risk AI systems, meaning ones that materially affect people’s lives, face stricter checks before and after deployment
  • Automated decisions with legal or serious consequences must allow for meaningful human review, not just a rubber stamp
  • Government bodies using generative AI for public-facing content are expected to disclose that AI was used and check for factual accuracy

Who enforces all this?

A body called the Pakistan Digital Authority, or PDA, is given the job of overseeing this policy. It can issue binding directions to government departments, run audits, and publish an annual scorecard called the National Data Maturity Index, which is supposed to show how well each department is actually following these rules.

Each government body is also required to appoint its own Chief Data Officer, responsible for implementation and for responding to citizen requests about their data.

Why this matters, and what to watch

For ordinary citizens, the promise here is fewer repeated document submissions, more clarity about who is using your data and why, and a formal right to complain and get corrections made. For businesses and researchers, there is a path toward accessing non-personal government data for innovation, under controlled conditions.

That said, a policy is only as strong as its implementation. A few things worth watching as this rolls out:

  • The Personal Data Protection Law, which this policy repeatedly refers to, still does not exist yet. Many citizen protections described here depend on that law eventually being passed.
  • Provincial governments are only “encouraged” to adopt this policy, not required to, so implementation may look different depending on where you live.
  • The real test will be whether departments actually follow through, since the policy itself admits that non-compliance is common with data rules in general, which is why it builds in audits and public reporting.

We will keep tracking this as it moves toward formal notification, and cover the Personal Data Protection Law separately once there is real movement on it.

Source: Data Governance Policy 2026, Ministry of Information Technology and Telecommunication, Government of Pakistan, June 2026.

Full Sources List:

Get notified when we publish

No spam, unsubscribe anytime.

Read our privacy policy for more info.

Leave a Comment

Your email address will not be published. Required fields are marked *