The Pakistan data governance policy, released in late June 2026 by the Ministry of Information Technology and Telecommunication, is the most sweeping digital reform the country has proposed in its history. Known officially as the National Data Governance Policy 2026, the draft lays down a single set of rules for how every federal ministry, regulator, public-sector company and their contractors must collect, store, share and delete government data. It is still a draft, and it needs Cabinet approval plus a Gazette notification before it becomes binding law, but the direction it sets is already shaping conversations across Pakistan’s tech sector.
What the Pakistan Data Governance Policy Actually Says
The Ministry prepared the policy under the Digital Nation Pakistan initiative. For the first time it creates a comprehensive governance regime for public-sector data, requiring all federal ministries, departments, regulators, public-sector companies and their contractors to follow uniform standards on collection, storage, sharing and disposal of government data.
One of the biggest shifts is that government departments will no longer be treated as owners of the data they hold. Instead, ministries and public institutions will act only as custodians of that data, managing it on behalf of the people of Pakistan.
The Pakistan Digital Authority (PDA) will serve as the national authority responsible for issuing, overseeing and implementing the policy and its supporting instruments under the Digital Nation Pakistan Act, 2025.
Citizen Digital Rights Under the New Framework
The policy puts citizens front and centre in a way that Pakistani digital law has never done before.
The framework recognises extensive digital rights, including the right to know which government officials have accessed personal data, the right to correct inaccurate records, data portability, erasure where legally permissible, and meaningful human review of automated government decisions.
Privacy protections have been significantly strengthened, with mandatory Privacy Impact Assessments for high-risk processing, stricter safeguards for sensitive personal data and children’s information, and mandatory breach notification requirements for public institutions.
This matters because, until now, there has been no law in force that requires a government body to tell you when your data was accessed or by whom. Pakistan’s data protection enforcement has been fragmented across multiple agencies, and no single agency has held a primary mandate for privacy protection as distinct from cybercrime investigation. The new policy begins to close that gap, at least for the public sector.
AI Oversight Rules for Government Agencies
Artificial intelligence gets its own chapter in the framework, and the rules are specific.
Government agencies deploying AI systems that make legally significant decisions will be required to ensure explainability, continuous monitoring, meaningful human oversight and public transparency. Public bodies will also have to publish details of automated decision-making systems in a public registry maintained by the PDA.
Departments will have to assess risks before deploying AI applications and maintain records explaining how the systems function. The policy also gives citizens the right to meaningful human review where they are affected by significant automated decisions.
The policy also introduces controls over the government’s use of generative AI, including safeguards against factual inaccuracies, intellectual property violations and data leakage.
Pakistan’s National AI Policy 2025 promotes AI adoption but offers limited guidance on safeguards for citizen-affecting decisions, so the data governance policy’s AI chapter fills a real gap, though critics note the rules still need clearer detail on surveillance technologies such as Safe City cameras.
Cross-Border Data Transfer Rules
The policy states that government data will remain under the lawful authority and effective control of Pakistan, while cross-border transfers will be permitted only under specific governance mechanisms, justified circumstances and adequate safeguards.
On cross-border data transfers, the policy proposes that sensitive government and personal data generally remain hosted and processed within Pakistan, while allowing offshore processing only in specified circumstances subject to approval and safeguards.
This is significant for cloud providers and SaaS companies that currently host Pakistani government data abroad. Any vendor working with federal agencies will need to review their hosting arrangements carefully once the policy becomes law.
What It Means for Startups and the Tech Sector
The Pakistan data governance policy is aimed at public-sector bodies, but its effects will ripple outward to the private sector, especially companies that build products for or integrate with government systems.
The policy lays the foundation for a national data economy by permitting structured public-private partnerships, data trusts, controlled access for researchers and innovators, and regulated licensing of government datasets. However, it makes clear that commercialisation cannot override citizens’ privacy rights or compromise Pakistan’s sovereign control over critical government databases.
Pakistan’s National AI Policy, approved by the federal cabinet in July 2025, together with the Islamabad AI Declaration of February 2026, has already reset the compliance landscape for technology startups operating in Pakistan. For the first time, founders and CTOs face a formal government framework that addresses risk classification, sovereign-cloud preferences, AI governance structures and sectoral oversight through a new AI Directorate under the Ministry of IT. Startups building or deploying AI systems now need to map data flows, screen products for risk-level classification, and prepare for potential AI impact assessments.
The Pakistan IT export tax, locked at 0.25% until 2029, already gives tech exporters a financial incentive to grow. The data governance framework now adds a compliance layer that could actually help those exporters win contracts from international clients who demand evidence of proper data handling standards.
Federal institutions may be required to appoint Chief Data Officers and follow a unified governance framework. The Pakistan Digital Authority is expected to monitor compliance, conduct audits and publish annual performance assessments.
Compliance will be tracked through annual audits and a National Data Maturity Index, which will rank institutions on governance, security, openness and citizen empowerment. This index is one detail most coverage has overlooked, it turns accountability into something measurable and public, which adds real pressure on agencies to take compliance seriously rather than treat it as a checkbox exercise.
Is This Already a Law?
The proposed National Data Governance Policy 2026 will come into effect after receiving federal Cabinet approval and its publication in the official Gazette. Until that happens, it remains a draft open to stakeholder input. The public consultation window closed on 10 July 2026, so a finalised version is expected soon.
It is also worth noting that the broader Ministry of IT and Telecommunication‘s Personal Data Protection Bill, which would cover the private sector, has been in draft since 2023 and is still pending Parliament’s final approval. The data governance policy makes clear that the PDA’s role will focus on public-sector data as a national asset, while the authority responsible for Pakistan’s future personal data protection law will continue to safeguard personal data rights separately. In other words, Pakistanis will eventually be protected by two complementary frameworks: one for the government sector, one for the private sector.
Frequently Asked Questions
What is the National Data Governance Policy 2026?
It is Pakistan’s first unified framework for managing public-sector data. The draft policy would establish the country’s first unified framework governing how federal agencies collect, store, share and use government data, while introducing new rules for artificial intelligence, cross-border data transfers and citizens’ digital rights.
Is the Pakistan data governance policy already in force?
No. It is still a draft. The proposed National Data Governance Policy 2026 will come into effect after receiving federal Cabinet approval and its publication in the official Gazette. The public feedback window closed on 10 July 2026.
What rights does the policy give to Pakistani citizens?
The policy introduces a major privacy safeguard by granting citizens the right to know who within the government accessed their personal data, when it was accessed, and for what purpose. Citizens will also have the right to correct inaccurate records and request human review of automated government decisions that affect them.
How does this affect AI used by government agencies?
Government agencies using AI or automated decision-making systems in high-impact or rights-related matters will be required to ensure that these systems are explainable, auditable and subject to appropriate governance controls. High-risk AI systems will also need to be registered with the PDA before they can be deployed.
