Pakistan’s IT industry has raised concerns over the draft National Data Governance Policy 2026, warning that unclear compliance requirements and proposed data localization rules could create challenges for IT exporters, freelancers and technology companies serving international clients.
The Pakistan IT Industry Association (P@SHA) highlighted its concerns in a member briefing published on August 12 regarding the draft policy released by the Ministry of IT and Telecommunication in July. The ministry currently lists the Data Governance Policy 2026 as a draft policy.
The proposed framework is designed to establish a unified system for collecting, protecting, sharing and managing government data. It treats public-sector data as a strategic national asset, while government institutions would act as custodians of citizens’ information rather than its owners.
Under the proposed policy, government departments would be responsible for safeguarding citizens’ data and ensuring that it is properly managed.
The framework also introduces a “once-only” principle aimed at preventing different government agencies from repeatedly collecting the same information. Instead, departments would rely on designated Primary Data Registers as authoritative sources of citizen data.
Data sharing between public institutions would take place through WASL, a centrally governed national data exchange platform modeled conceptually on Estonia’s X-Road system.
The draft policy proposes giving the Pakistan Digital Authority (PDA) a central role in regulating data governance. The authority would have powers related to enforcement, audits and corrective measures.
The framework also proposes appointing a National Chief Data Officer along with Chief Data Officers in federal public bodies. Government institutions would be assessed through a National Data Maturity Index covering areas such as governance, security, data quality, openness and citizen empowerment.
The proposed policy also introduces rules for artificial intelligence and citizen privacy.
AI systems used by government bodies for automated decision-making would need to be explainable, properly logged and subject to human oversight. Generative AI systems would also face safeguards relating to inaccurate information, intellectual property violations and potential data leaks.
Citizens would receive rights to access data usage logs, correct inaccurate information, export their data and request deletion where legally permitted.
Government institutions would also be expected to adopt Zero-Trust cybersecurity measures and report data breaches to the PDA without delay.
P@SHA’s major concern relates to proposed data localization requirements. Under the draft framework, sensitive personal and government data would generally need to be hosted and processed within Pakistan, while transferring such information abroad would require prior regulatory approval.
P@SHA warned that these provisions could affect software exporters, freelancers and distributed technology teams if remote international access to data is treated as a cross-border transfer.
The association said the issue is particularly important for companies serving overseas customers and relying on international cloud infrastructure. Pakistan’s IT industry depends heavily on cross-border digital services, making clear rules on international data access important for exporters.
P@SHA has identified the lack of a clear distinction between public-sector and private-sector data as one of the most significant gaps in the draft policy.
The association said greater clarity is needed, particularly for public-private partnerships where companies may handle government-related information.
P@SHA also raised concerns about proposed mechanisms for licensing or pricing non-personal public data. It said such monetization could create tension with the government’s role as custodian of public data.
The association further questioned the absence of strong financial penalties for non-compliance, arguing that audits without meaningful monetary sanctions could weaken enforcement compared with data governance regimes in other jurisdictions.
P@SHA acknowledged that the National Data Governance Policy could become an important foundation for Pakistan’s digital ecosystem and AI readiness.
However, the association has called for clearer definitions, compliance obligations, data localization requirements and rules governing cross-border data access before the framework is implemented.
The Ministry of IT and Telecommunication currently lists the National Data Governance Policy 2026 as a draft, meaning the framework remains subject to further development and stakeholder input.
The final policy could have significant implications for Pakistan’s IT exporters, freelancers, cloud services, artificial intelligence sector and broader digital economy.
