Compare with different regulatory event:

Description

Announced Pakistan Personal Data Protection Bill containing data protection measures

The draft Personal Data Protection Bill is approved by the Pakistan Federal Cabinet to be debated by the legislature. The National Commission for Personal Data Protection (NCPDP) is established as the main enforcer of data protection prescriptions. According to the Bill, users must be notified and give their consent when their personal data is collected, used for a purpose different from the collection purpose or disclosed to a third party. Data controllers shall take steps to protect personal data and ensure that they are accurate, complete, and updated, and the retention of data shall be proportional to the purposes of the collection. Moreover, data controllers shall notify the NCPDP in case of a relevant data breach within 72 hours. Users have the right to: be informed about the processing of their personal data; access or have a copy of their personal data processed by a data controller (under the payment of a fee), request correction or erasure of such data, withdraw the consent to personal data processing. Finally, data controllers must keep a record of any notice, request or breach concerning personal data.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-03-15
under deliberation

The draft Personal Data Protection Bill is approved by the Pakistan Federal Cabinet to be debated b…

2023-05-19
under deliberation

On 19 May 2023, the Pakistan Ministry of Information Technology and Telecommunication (MITT) releas…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Any
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): transfer: cross-border
Regulatory tool
Creation of enforcement authority
User notification requirement
User consent: Opt-in requirement
Sanctions
Civil penalty
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
Creation of enforcement authority
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User notification requirement
User consent: Opt-in requirement
Sanctions
Civil penalty
Regulated subjects
1
personal data (all forms): data collection
Regulatory tool
Creation of enforcement authority
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
Sanctions
Civil penalty
Regulated subjects
1
corporate data (all forms): storage (any form)
Regulatory tool
Creation of enforcement authority
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
Preventive security requirement
Responsive security requirement
Data storage/retention obligation
Sanctions
Civil penalty
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): transfer: cross-border

personal data (all forms): data processing

personal data (all forms): data collection

corporate data (all forms): storage (any form)