PK Data Governance Policy Draft 2026 Part I: Where Can Your Data Actually Be Stored?

Last week we broke down the overall Pakistan Data Governance Policy Draft 2026 in this article. It covered a lot of ground, so this time we are zooming into just one part of it, the part that honestly affects your daily life the most even if you never read a policy document in your life.

The question is simple: when the government collects your data, where does it actually sit? On a server in Karachi? On a server in another country? Does it matter?

Turns out, under this policy, it matters a lot.

The three tiers, explained like you are hearing it for the first time

The policy sorts data into three buckets. Think of it like three different levels of a locker system.

data-storage-tiers-banner-1-mandatory-in-country

Tier 1: The data that cannot leave Pakistan

This is your sensitive stuff. Your CNIC details sitting with NADRA. Your medical history if you have ever been treated at a government hospital and it got digitized. Your tax records with FBR. Anything the government classifies as “nationally important” data too, which is a broader category covering things like infrastructure and security-related information.

For all of this, the rule is straightforward. It has to be hosted and processed inside Pakistan. Full stop. If any department wants to send this kind of data abroad, even to a cloud server in another country for something as routine as backup or processing, they need special approval first. It is not a quiet, behind-the-scenes decision anymore.

Why this matters to you: right now, you have no real way of knowing whether a scan of your ID card sitting in some government system is being processed on a server in Islamabad or one in Frankfurt. This policy says, for the sensitive stuff, it stays here.

data-storage-tiers-banner-2-approval-based-offshore

Tier 2: The data that can travel, but only with permission

This is the middle tier. Think of internal government data that is not directly about you as an individual, or that is less sensitive, maybe department-level records, some administrative data, that kind of thing.

This data can be processed outside Pakistan, but not without a good reason. The department needs prior approval, and there need to be safeguards in place. So this is not a total ban on using foreign cloud services (which, realistically, a lot of government systems already rely on), it is more like a “ask first, and prove you have protected it” rule.

data-storage-tiers-banner-3-no-restriction

Tier 3: The data that is already public

This is open data. Things like published budget documents, census summaries, public datasets that anyone can already look up. Since it is already public, there is no restriction on where it is hosted. This is actually the data the policy wants to see published more, and there is a plan for a National Open Data Portal where this kind of information gets put out in formats that computers can read easily, not just PDFs buried on some department website.

Put simply

If there is just one thing you take from this article, remember this: your CNIC details, your medical records if the government has them, and other sensitive data like this are supposed to stay physically inside Pakistan. Everything else has some room to move, but even that comes with rules attached, not a free pass.

Why this is not just a technical detail

It is easy to read “data localization” and think this is an IT department problem, not yours. But consider a few everyday situations.

For example, you apply for a government service online, maybe a NADRA-linked verification, a passport renewal, a benefit program that checks your CNIC. Under the old, informal setup, you genuinely could not know where that request was being processed. Was it a local server? Was it routed through a third-party vendor using overseas infrastructure? Nobody had to tell you either way.

This policy at least draws a line and says: for your most sensitive information, no, it cannot just quietly sit on a server somewhere else in the world without anyone signing off on it.

That said, it is worth being honest about the limits here too. As of this draft, the framework is aimed primarily at public sector and government-held data, not every private company or app you use day to day. So if you are handing your data to a private fintech app or an e-commerce site, this particular policy is not the thing regulating where that specific data sits, that is more the territory of Pakistan’s separate data protection law efforts. Worth keeping the two apart in your head.

The pushback from the tech industry

This part is worth mentioning because it is not all smooth sailing. Pakistan’s IT industry body, P@SHA, has raised concerns about how this localization rule could affect IT exporters, freelancers, and companies serving clients abroad, especially around one grey area: if a foreign client remotely accesses data that a Pakistani team is working on, does that count as a “cross-border transfer” under this policy? That is still being debated, and the ministry has not finalized the answer. If you work in IT, freelancing, or software exports, this is a thread worth following, because how it gets resolved could directly affect how you work with international clients.

At the end of the day, this is still a draft, and some details may shift before it’s final. But the direction is clear. Your most sensitive data is meant to stay inside Pakistan, and that alone is a bigger deal than it might sound at first.

Full Sources List:

Get notified when we publish

No spam, unsubscribe anytime.

Read our privacy policy for more info.

Leave a Comment

Your email address will not be published. Required fields are marked *