Data Protection bill 2023 concluded by Ministry of IT

data-protection-bill-2023-concluded-by-ministry-of-it

The “Personal Data Protection Bill, 2023” has been finalized by the Ministry of Information Technology and Telecommunication, and it proposes a fine of up to $2 million, or its equivalent in Pakistani rupees, for anyone who processes or causes to be processed, disseminates, or discloses personal data in violation of the proposed legislation’s provisions.

The Personal Data Protection Bill, 2023, according to the bill’s draft is intended to regulate the collection, processing, use, disclosure, and transfer of personal data. It also offers a data protection mechanism that includes offences related to the violation of an individual’s data privacy rights.

When someone gathers, processes, stores, uses, and discloses data, they must respect the rights, liberties, and dignity of the person in all aspects related to and incidental to that activity.

Within six months of the start of this Act, the Federal Government shall, by a Gazetted notification, create a Commission for this Act, which shall be known as the National Commission for Personal Data Protection (NCPDP) of Pakistan.

The federal government may decide to notify in the Official Gazette with at least three months’ prior notice from the effective date that it shall not take effect more than two years after the date of its promulgation.

Due to the responsibilities and obligations outlined in this Personal Data Protection Bill, the modus operandi and supporting information for the usage of personal data by the government, organizations, and individuals for processing purposes, including processing, collection, storage, and disclosure, will be laid down in this Bill.

By providing legal protections for online transactions and the sharing of private and sensitive information or data for personal, international e-commerce, and e-government services, it supports the environment of ethical behaviour in the digital economy.

The Personal Data Protection Bill of 2023 will be implemented in accordance with the current patchwork of international and regional laws on the protection of personal data in order to match common ground and pinpoint places where various approaches tend to diverge.

A wide range of economic, political, and social activities have been digitalized as a result of rapid technological development and increased use of internet services. This has had a profound impact on how people conduct business and interact with one another, with the government, with businesses, and with other stakeholders.

The Bill makes careful to provide further safety for children’s data. To ensure that the opportunities arising from the economy can be effectively utilized, building trust online is a vital task.

Personal data, which is at the heart of the global economy’s transformation to a connected information universe and powers online cross-border commerce, may have implications for people, corporations, and the government.

This Bill assures that any personal data obtained from a person must be obtained lawfully, fairly, and with consent, and that it may only be used or disclosed for those reasons or for any closely connected ones.

Grounds For Processing Personal Data Protection

Among the reasons for processing personal data are;

The processing of any kind of data subject’s personal information is prohibited unless the data controller first obtains that subject’s consent or as otherwise required by this Act’s requirements.

The Commission must establish the best worldwide standards to safeguard personal data against loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction given the importance of the matter to the nation.

In the event of a personal data breach, the data controller is required to notify the Commission and the affected individual within 72 hours of becoming aware of the breach, unless it is highly unlikely that the affected individual’s rights and freedoms will be violated.

When personal information, excluding vital personal information, must be transferred to a system or entity outside Pakistan’s borders that is not directly under the jurisdiction of the government of Pakistan, data protection will be provided by the other nation.

The transfer of data shall be processed in accordance with the provisions of this Act, and, where applicable, the data subject shall provide explicit consent.

It will be ensured that it provides at least an adequate legal framework for the protection of personal data that is consistent with the protection provided under this Act.

Only servers or other digital infrastructure installed on Pakistani soil may process critical personal data.

Any person who violates the terms of this Act by processing, disseminating, or disclosing any personal data may be fined up to 125,000 USD (or the equivalent amount in Pakistani rupees), and in the event that the person continues to process personal data unlawfully, the fine may be increased to 250,000 USD (or the equivalent amount in Pakistani rupees).

If the violation of subsection (1) involves the use of sensitive personal data, the offender could be fined up to $500,000 USD or an equivalent amount in Pakistani rupees.

If the violation of subsection (1) involves the disclosure of sensitive personal information, the offender could be fined up to $1,000,000 USD, the equivalent in Pakistani rupees, or another amount the Commission deems suitable.

A punishment of up to $50,000 USD or its equivalent in Pakistani rupees may be imposed on anybody who disregards the terms of this Act, its Rules, and regulations with regard to adopting suitable security measures to protect data security.

If someone disobeys the Commission’s or a court’s orders when they are needed of them, they could be fined up to $50,000 USD or the equivalent in Pakistani rupees.

When a data controller or processor violates a provision of this Act, the Rules or regulations adopted thereunder, a Federal Government policy, a direction from the Commission, or a condition of registration, the Commission may, by written notice within fifteen days, require the controller or processor to explain why an enforcement order should not be issued.

The notice referred to in subsection (2) must include information about the violation’s nature and the steps the licensee must take to make it right.

Anyone who fails to:

Regardless of what was previously said, the legal entity will be fined a sum not to exceed 1% of its annual gross income in Pakistan, or 200,000 USD, whichever is higher, or a sum comparable in Pakistani rupees, or as the Commission may determine.

To read our blog on “Redrafting of the Personal Data Protection Bill by the IT Ministry,” click here.

Exit mobile version