P@SHA Policy Briefing Β· V3

National Data Governance Policy 2026

Analysis of Pakistan's first unified data governance framework β€” its pillars, global positioning, and repercussions for the IT & ITeS industry.

πŸ“„ Draft by Ministry of IT & Telecom 🏒 P@SHA Government Affairs Committee β€”

Overview

Last month Pakistan's Ministry of IT and Telecommunication released the draft National Data Governance Policy 2026. It is the country's first unified framework for how public government bodies collect, protect, and share data. It rests on the premise that public data should be treated as a national asset, and introduces the operating arrangements, standards, and supporting instruments for data interoperability amongst the government bodies.

P@SHA's Policy team convened the Government Affairs Committee to review the draft, and conducted a structured survey across member companies to understand industry feedback. This briefing consolidates that member input and analyses the draft against regional and global data governance frameworks.

P@SHA's position: The policy is a building block in Pakistan's digital ecosystem and a crucial step for AI readiness. Member feedback was broadly positive on data governance approach, transparency in AI decision-making, and cybersecurity controls. Concerns were raised around ambiguity in definitions, limited visibility on security controls, and data residency implications for exports.

The Six Pillars

The draft policy organizes itself around six pillars. Together they represent the most structurally ambitious data governance attempt Pakistan has made to date.

1

Custodianship, Not Ownership

A conceptual break: departments hold data in trust for citizens, not as property. Custodianship carries a duty to protect, maintain quality, share lawfully, and disclose proportionately. This removes the institutional incentive to hoard data in silos.

2

AI & Cybersecurity Governance

AI systems in decision-making must be explainable, continuously monitored, and subject to human oversight. A public AI registry of high-risk systems will be maintained by the Pakistan Digital Authority. The draft includes GenAI-specific controls against factual inaccuracy, IP violations, and data leakage.

3

Once Only Principle & WASL

Agencies must rely on designated Primary Data Registers instead of duplicate copies. Data moves between agencies through WASL, a national data exchange platform conceptually closest to Estonia's X-Road β€” a first for South Asia at this scale.

4

Privacy by Design

Citizens can see who accessed their data, when, and why. Rights to correction, portability, and erasure. Meaningful human oversight required for legally significant automated decisions. An extension of GDPR principles.

5

Institutional Approach

A central regulator, the Pakistan Digital Authority (PDA), with binding powers. A National Chief Data Officer plus mandatory CDOs in every federal body. An annual public National Data Maturity Index ranking institutions.

6

Sovereignty & Openness

Sensitive government and personal data generally must be hosted within Pakistan; offshore processing needs prior approval. Non-sensitive data published via a National Open Data Portal. Cross-border transfers permitted only through approved mechanisms.

Global Comparison

US, EU, India, and Singapore represent four distinct governance approaches. The table below places Pakistan's draft alongside them. Corrections noted in the analysis section below.

Dimension Pakistan United States EU India Singapore
⚠️ Corrections applied: India data localization row corrected (RBI payment data mandate, DPDP §16 blacklist approach). EU AI Act status updated (entered into force Aug 2024). US legal form expanded. India DPDP enforceability qualified. See analysis for details.

Repercussions for IT & ITeS

Member consultation surfaced a consistent set of structural and definitional concerns.

πŸ“‹ Public vs. Private Data Ambiguity

The draft doesn't clearly distinguish public from private data. Critical for companies in public-private partnerships (PPHI, PSDF). Private companies providing services to public departments will face technical controls and audits β€” but the frameworks are undefined. Members identified this as the single most consequential gap.

🌍 Data Residency Restrictions

Mandatory in-country residency for all sensitive and semi-sensitive personal data. While limited to public data, this still limits access to global cloud, SaaS, cybersecurity services, AI tools, DR infrastructure, and international support. Members flagged this for continued attention β€” a proportionate, risk-based approach would look very different.

πŸ’Έ Economic Opportunity & Reputation

Two-sided risk: government access provisions + unclear cross-border rules could make international clients cautious, compounding compliance burden with reputational damage. Conversely, overly restrictive rules could foreclose legitimate opportunities β€” e.g., Pakistani health datasets (high diabetes prevalence) have real AI research value.

πŸ’» Freelance & Remote Economy Critical

The draft defines cross-border transfer to include remote access to government data by persons under another jurisdiction. This could sweep in freelancers, distributed teams, and Pakistani employees at global companies. Pakistan is a top-5 freelance market globally β€” this provision, as worded, is existential for the IT export model and deserves its own focused advocacy.

βš™οΈ Compliance Cost

Zero-trust architecture, mandatory CDO appointments, breach notification systems, and audit readiness all carry real price tags. The briefing does not yet quantify cost impact β€” member companies need a rough sense of compliance overhead even where exact numbers aren't available.

🏒 Sector-Specific Exposure

Health (PPHI/PSDF) is mentioned, but fintech, e-governance contractors, BPO/KPO, and cloud service providers all have distinct exposure profiles that warrant individual assessment.

Open Questions & Internal Tensions

A closer critical read surfaces internal tensions worth understanding before drawing conclusions.

βš–οΈ

Data Economy vs. Data Stewardship

The draft uses trustee and custodian language for citizens while simultaneously asserting sovereign control at the border. One clause states the PDA may prescribe licensing models, pricing, and value capture for public sector non-personal data. Licensing and monetizing data is what owners do, not custodians. This is a real conceptual tension.

πŸ—οΈ

Institutional Readiness vs. Implementation

The draft takes a phased approach, but the EU's Digital Omnibus shows even mature regimes can outpace capacity. Pakistan proposes to establish a regulator, an exchange, a registry, and a maturity index simultaneously. Estonia's X-Road took 15+ years to mature.

πŸ”§

Non-Binding vs. Enforcement

The policy references audits as enforcement, but India, Singapore, and the EU all attach financial penalties (India up to ~INR 250 crore). Whether Pakistan's framework will attach comparable financial consequences is an open question. The supporting instruments β€” fine schedules, enforcement regulations β€” are not yet developed.

🌐

Data Residency vs. Remote Access

Cross-border transfer is defined to include remote access to government data by persons in another jurisdiction. This sweeps in freelancers, distributed teams, and global company employees β€” potentially far more arrangements than intended.

Analysis & Assessment

βœ“ What Works

  • Six-pillar architecture is clear and accurate. Plain-language explanations make technical governance accessible to member companies.
  • Open Questions section is the strongest part. Four genuine internal tensions are identified β€” the custodian-vs-monetizer contradiction is particularly sharp and well-observed.
  • Recommendations are specific and actionable β€” adequacy decisions, SCCs, regulatory sandbox, scope-limiting to government-data processors. These are the right asks.
  • Remote-access-as-transfer flag is existential for Pakistan's IT export model. Correctly identified.

βœ— Problems Identified

#IssueSeverityFix
1 India localization: "Not generally required" β€” Incorrect. RBI mandates payment data localization. DPDP Β§16 empowers govt to restrict transfers to notified countries. High Correct to: "RBI payment data localization; DPDP Β§16 blacklist approach"
2 EU AI Act: "delayed" β€” Entered into force Aug 1, 2024 with phased rollout through 2026-27. "Delayed" without context is misleading. Medium Correct to: "Entered into force Aug 2024; phased application through 2027"
3 India DPDP: "binding" β€” Passed, but Rules not notified. Largely inoperable without them. Medium Qualify: "Passed 2023; Rules pending notification"
4 US legal form: "State by state laws" β€” Oversimplified. Ignores HIPAA, GLBA, FERPA. Low Correct to: "No comprehensive federal law; sectoral + state laws"
5 "Ahead of most public sector policies globally" β€” Unsourced comparative claim about GenAI controls. Medium Source or qualify: specify which policies were compared
6 No comment-period timeline or P@SHA submission process mentioned. High Add: comment deadline, submission channel, P@SHA's own submission plan
7 Freelance impact buried in Β§5 instead of frontline in Β§4. High Promote to its own subsection in Industry Impact
8 No compliance cost discussion. Medium Add rough cost-impact discussion for member companies

πŸ“ Structural Observations

  • Inconsistent hedging: Document says "premature to draw firm conclusions" while issuing 9 specific, decisive recommendations. The recommendations ARE conclusions β€” own them.
  • Reputational-risk framing underdeveloped. International clients are already risk-sensitive post-instability. Data governance uncertainty compounds this.
  • Comparison table missing dimensions: No enforcement/penalties row, no citizen-rights row, no cross-border transfer-mechanism row β€” despite these being discussed in text.
  • "First for South Asia at this scale" needs qualification. India has data exchange initiatives (IDEX/DIGO). Should specify "first national-scale government data exchange."

Full Policy Cross-Reference

Line-by-line validation of the P@SHA briefing against the actual 25-page policy document (DNP-D.001 POL, v1.1). Every claim, table entry, and assertion was checked against the source text.

Verdict: The briefing is a solid member-facing communication (~70% coverage, mostly accurate on what it includes), but as a policy analysis document it has real gaps. The biggest miss is the entire Data Economy section (Β§15). The "blanket residency" characterization is the most consequential factual error β€” the policy already has a tiered approach.
20
Claims Verified βœ“
4
Inaccuracies βœ—
9
Sections Omitted ⚠
19
Instruments Listed

βœ… Verified Claims β€” What P@SHA Got Right

+

20 claims from the briefing were checked against the source policy text. All confirmed accurate.

P@SHA ClaimPolicy RefStatusDetail

❌ Inaccuracies β€” What P@SHA Got Wrong

+

4 factual errors or misleading characterizations identified. Each includes a side-by-side comparison.

🌐 Actual Residency Tier System (§8.2)

+

The policy already has a 3-tier risk-based residency system. P@SHA's recommendation to "replace blanket residency with a risk-based rule" mischaracterizes what the policy already does. The real issue: ALL personal data falls into Tier 1, so the tiered system doesn't help the IT/ITeS sector.

TierApplies ToRequirement

πŸ”΄ Major Omissions β€” Entire Sections Missed

+

9 policy sections or topics with significant industry implications are absent from the P@SHA briefing. Severity rated Critical / Major / Minor based on relevance to IT industry members.

πŸ“‹ The 17 Supporting Instruments (Annex II)

+

The policy lists 19 specific instruments with reference codes, purposes, and series designations. P@SHA complains about "limited visibility on security controls" β€” but Annex II explicitly enumerates all of them. The instruments haven't been published yet, but the policy defines exactly what each will contain.

ReferenceInstrumentPurpose

πŸ“ Editorial Claims β€” P@SHA's Opinion, Not From Policy

+

These claims aren't wrong per se, but they're presented as if derived from the policy when they're P@SHA's editorial judgments. Comparative claims without specific sourcing weaken credibility.

🎯 Recommended Fixes (Prioritized)

+

Concrete, prioritized fixes for the P@SHA briefing. Priority 1 = factual corrections, Priority 2 = missing sections, Priority 3 = deepen existing analysis.

πŸ—ΊοΈ Structural Coverage Map

+

The policy has 19 sections. Here's how P@SHA's six pillars map to them β€” and what's missing.

P@SHA PillarPolicy Sections CoveredSections Missed
Pillar 1 (Custodianship)Β§5β€”
Pillar 2 (AI + Cyber)Β§14, Β§6.13-6.14, Β§11.8β€”
Pillar 3 (Once-only/WASL)Β§6.4-6.6, Β§10β€”
Pillar 4 (Privacy)Β§11, Β§12Β§12.4-12.6 (PETs, ZKP, credentials)
Pillar 5 (Institutional)Β§16Β§16.5 (NDGC), Β§16.9 (PDPL coordination)
Pillar 6 (Sovereignty)Β§8, Β§9, Β§13β€”
NOT COVEREDβ€”Β§15 β€” Entire Data Economy section (9 sub-sections)
NOT COVEREDβ€”Β§17-19 β€” Implementation, Compliance, Conformity
NOT COVEREDβ€”Annex II β€” 17 supporting instruments

Recommendations

P@SHA Government Affairs Committee recommendations, grouped by theme. The cross-reference analysis above informs the prioritized fixes below.

Clarify Scope & Residency

  • Define public vs. private data with explicit rules for PPP arrangements
  • Clarify the data classification framework β€” tiers, assignment criteria, decision-makers
  • Replace blanket residency with a risk-based rule recognizing adequacy decisions and SCCs
  • Distinguish cross-border access types β€” time-bound approval path for remote/offshore work
  • Scope rules to government-data processors, not the IT/ITeS export sector as a whole

Protect Economic Interests

  • Assess export competitiveness impact before the policy is finalized, not after
  • Harmonize the PDA's mandate β€” avoid overlap with future data-protection and sectoral regulators

Strengthen AI Oversight & Enforcement

  • Strengthen AI governance standards β€” update guidance frequently, following Singapore's advisory model
  • Define fines and penalties for non-compliance and breach-reporting failures

Sequence the Rollout

  • Publish an implementation roadmap with binding sequencing plus a regulatory sandbox

Update Log

This page is maintained as a living document. Changes are logged here.