Friday, September 11, 2026

Related Posts

I.T. Ministry Makes Public Draft Data Governance Policy

The Ministry of Information Technology and Telecommunication on Monday made public its draft Data Governance Policy 2026, emphasizing government-held data is a strategic national asset held in trust for the people and governed to ensure sovereignty, public value, citizen empowerment and lawful use.

The draft policy, available on the ministry’s website for public comments until July 10, notes it covers data governance but not personal data held outside the public sector, primary legislation, judicial proceedings, or matters falling within specific national security, defense, parliamentary or judicial domains. It would apply to all federal ministries, divisions, departments, attached departments, subordinate offices, statutory corporations, regulators, authorities, commissions, autonomous bodies and public-sector companies under federal jurisdiction. Further, it covers entities receiving public funds to manage government data, as well as contractors, processors, concessionaires, grantees and partners performing public functions or processing government data on behalf of the federal government.

In a press conference announcing the draft document, I.T. and Telecommunication Minister Shaza Fatima said data protection and usage regulations had become essential with the rapid growth of digitization. She said the draft policy would remain open for public feedback until July 10, adding it would be formally notified after incorporating relevant suggestions.

Under the policy, government data is not the property of the agency that holds it and public bodies are custodians rather than proprietors. It grants citizens the right to know the identity of government institutions that access their data, as well as when it was accessed, and for what purpose.

“This right shall not be denied except on narrow grounds expressly provided by law, with reasons recorded,” it states.

The proposed policy also requires public bodies processing personal data to adopt Privacy-Enhancing Technologies in accordance with the Data Security Standards Instrument and the Privacy by Design and Impact Assessment Instrument. It also states that citizens can opt to transmit their data directly between public bodies where technically feasible and legally permissible.

The policy calls for the Pakistan Digital Authority to serve as its primary issuer, overseer and implementer, as well as supporting instruments, under the Digital Nation Pakistan Act, 2025.

According to the proposed policy, government data would remain under the lawful authority and effective control of Pakistan, but cross-border transfers would be permitted under specific governance mechanisms, justified circumstances and adequate safeguards.

The draft encourages provincial governments to adopt the policy or develop equivalent frameworks. It further calls for public-sector data to be open by default and made available through the National Open Data Portal in machine-readable formats with appropriate metadata, except where classification or statutory restrictions apply.

The draft says the policy would be updated if any comprehensive Personal Data Protection law is enacted. It also stresses on enhanced safeguards, including stricter access controls, mandatory encryption, shorter retention periods, explicit lawful basis and enhanced audit requirements, for sensitive personal data.

The proposed policy requires public bodies to notify the Pakistan Digital Authority in the event of any personal data breach, while any breach posing a high risk to the rights and freedoms of individuals must be communicated to affected citizens.