P@SHA has expressed concerns regarding Pakistan’s Data Governance Policy 2026, citing risks to national sovereignty and digital privacy. Pakistan’s proposed National Data Governance Policy 2026 represents an important step toward building a more structured digital state, but concerns raised by the Pakistan Software Houses Association for IT and ITES (P@SHA) suggest that the framework could have significant implications for the country’s technology and IT-export sector. The Association warns that unresolved issues around data classification, localization, and enforcement could create challenges for Pakistan’s technology sector and IT exporters.
P@SHA’ Concerns on Data Governance Policy:
In a member briefing issued on August 12, P@SHA highlighted ambiguities in the draft policy, particularly around compliance requirements, data residency and cross-border access. The policy, released by the Ministry of IT and Telecommunication in July 2026, seeks to establish Pakistan’s first unified framework for the collection, protection, sharing and use of government data. In reply P@SHA outlined its concerns in a policy paper titled “Analysis of Pakistan’s Data Governance Policy, consolidating feedback from member companies and benchmarking the draft against global data governance frameworks.
The analysis examines the policy’s six core pillars:
- Data Custodianship
- AI & Cyber Governance
- WASL Data Exchange System
- Privacy Rights
- Proposed PDA Regulator
- Data Sovereignty
It also highlights key concerns around ambiguity in the scope separating public and private data, mandatory data residency requirements, and unclear rules around cross-border and remote data access.
Pakistan Data Governance Policy 2026:
At the heart of the proposed framework is the principle that public-sector data should be treated as a strategic national asset. Government institutions would act as custodians rather than owners of citizens’ data, holding information in trust and using it for public purposes.
The policy also introduces a “once-only” principle designed to eliminate unnecessary duplication of citizen records. Government agencies would instead rely on designated Primary Data Registers, while inter-agency data exchange would take place through WASL, a centrally governed platform conceptually modeled on Estonia’s X-Road.
Pakistan Digital Authority:
Another major feature is the proposed role of the Pakistan Digital Authority (PDA) as the country’s central data regulator. The authority would have powers relating to enforcement, audits and corrective action. A National Chief Data Officer and Chief Data Officers within federal public bodies would oversee data governance, while government institutions would be assessed annually through a National Data Maturity Index covering governance, security, quality, openness and citizen empowerment.
The draft also reflects Pakistan’s growing focus on AI governance and digital privacy. Automated decision-making systems used by public institutions would be expected to be explainable, logged in a PDA registry and subject to human oversight. Generative AI systems would face safeguards against misinformation, intellectual-property violations and data leakage. Citizens would also gain rights to access data logs, correct information, export personal data and request deletion where legally permitted.
Concerns over Data Privacy & Sovereignty:
However, data localization is emerging as the most significant concern for Pakistan’s IT industry. The draft would generally require sensitive personal and government data to be hosted and processed within Pakistan, with transfers outside the country subject to regulatory approval. P@SHA has warned that such provisions could create uncertainty for software exporters, freelancers and distributed technology teams. If remote access by overseas employees or clients is interpreted as a cross-border data transfer, Pakistani technology companies could face additional compliance burdens and operational restrictions.
The association has also called for clearer definitions distinguishing public-sector and private-sector data, particularly in public-private partnerships. Questions have additionally been raised about proposed mechanisms for monetizing non-personal public data and the absence of strong financial penalties for non-compliance. Pakistan needs data sovereignty, but it must avoid creating a regulatory environment that makes its IT industry less competitive. A carefully designed governance framework can strengthen cybersecurity, citizens’ digital privacy and AI readiness while still enabling international data flows essential to software exports.
The National Data Governance Policy 2026 therefore has the potential to become a foundation for Pakistan’s digital future. But before implementation, policymakers will need to provide greater clarity on definitions, cross-border data access, compliance obligations and enforcement. The objective should not simply be to control data—it should be to govern it intelligently while allowing Pakistan’s digital economy to grow globally.
By
Editorial, Infocus.pk


