EVERY discussion about data protection in Pakistan reaches the same conclusion: we still don’t have a comprehensive data privacy law. Technically, that’s true. The Personal Data Protection Bill has sat in draft form since 2018, and after years of delay it’s easy to assume Pakistan’s approach to data governance is on hold. That assumption can now be challenged. While attention stayed fixed on the stalled privacy bill, another development moved far faster. In late June, the Ministry of Information Technology and Telecommunication (MoITT) released the draft National Data Governance Policy 2026 for public consultation. That consultation closed on July 10. This week, MoITT and the Pakistan Digital Authority (PDA) held a high-level meeting, chaired by Federal Minister Shaza Fatima Khawaja, to finalise the policy ahead of cabinet approval and gazette notification. It isn’t law yet, but we cannot treat it as a mere policy draft either. Many Pakistani tech companies already maintain strong governance practices because foreign clients demand it. The policy isn’t a privacy law, it doesn’t tell private companies how to collect or use their customers’ data. Instead it focuses on something narrower but, in many respects, more consequential: government data. That distinction matters because government data rarely stays inside the government. Across Pakistan, private companies build digital services for public agencies, host government systems, operate call centres, manage cloud infrastructure and process citizen information on the state’s behalf. Many businesses think of themselves as serving a government client; fewer recognise they’re becoming part of its data governance framework. The finalised policy makes that explicit. Its obligations extend beyond ministries and departments to contractors, processors, concessionaires, grantees and other entities processing government data or performing public functions for the federal government. For many technology companies, compliance won’t begin with a regulator knocking, it begins with revised procurement requirements and contractual terms. Pakistan’s privacy debate has largely been framed around one question: when will parliament finally pass a comprehensive data protection law? The finalised policy raises an equally important one that’s already here: how should organisations manage government-held information when governance obligations arrive through contracts rather than legislation? The answer has practical consequences. The policy classifies government data by sensitivity and restricts where certain categories may be stored or processed. It tightens controls on cross-bo­­rder transfers of sensitive information and expects contractors to notify PDA, the body designated to enforce the framework, promptly following qualifying security incidents. Citizens also gain visibility into who accessed their data and why, making audit trails more than good internal practice, none of it dependent on a private-sector privacy law. It flows instead through the relationship between the state and the organisations it works with. One detail from this week’s meeting stands out. PDA Chairman Dr Sohail Munir was clear the policy does not centralise government data or permit unrestricted sharing. Ownership stays with individual entities; a new mechanism, the WASL fra­mework, enables secure exchange between them based on classification and governance standards, not a single pooled database. That’s a more federated, realistic model than many expected, a sign the drafters were listening during consultation. This reflects a broader shift in how governments think about data. For years, information collected by public bodies was treated as just another operational asset. The finalised policy takes a different view, describing government data as a strategic national asset held in trust for the people. This language shouldn’t be dismissed as symbolic. Organisations processing that data on the state’s behalf now assume responsibilities beyond delivering a contracted service; they are no longer simply vendors with access to sensitive information, but participants in a governance system built to protect it across its lifecycle. Cabinet approval and gazette notification will start a phased rollout, with PDA-led capacity-buil­ding and governance arrangements, though detai­led timelines await a forthcoming National Data Strategy. That clock won’t stop at the ministries. Companies working with the government can exp­ect new requirements around data residency, security controls, breach reporting, access management and documentation as the rollout proceeds. Many organisations will find the hard part isn’t technical safeguards, it’s knowing where government data resides, how it moves, and who has access, questions surprisingly hard to answer if never asked before. There’s an opportunity hidden inside these obligations too, and the numbers aren’t small. Pakistan’s IT and IT-enabled services exports crossed $4.6 billion this past fiscal year, and nearly all of that revenue depends on the same kind of client trust the finalised policy now asks companies to demonstrate domestically. Many Pakistani technology companies already maintain strong governance practices because international clients demand it; GDPR-compliant protections for Europe, security assessments for the US. The finalised policy means those investments can now serve domestic requirements too, let­­ting organisations build one programme that satisfies both international and public-sector demands. That’s a more efficient way to think about compliance, and it reflects how regulation is evolving. Governments once relied mainly on legislation to shape corporate behaviour; increasingly, they do it through procurement, infrastructure requirements and technical standards. Companies waiting for a landmark privacy statute may find governance already arrived by other routes. Pakistan’s Personal Data Protection Bill remains important; eventually the country will need a comprehensive legal framework governing personal data across both sectors. But waiting for that moment risks overlooking what has already happened this week. The National Data Governance Policy doesn’t answer every privacy question in Pakistan, it was never meant to. What it signals is that data governance no longer waits for parliament. For much of the technology sector, it’s already arriving through the contracts they sign, the systems they build and the information they’re trusted to handle. That is a change worth paying attention to, regardless of when Pakistan’s long-awaited privacy law finally arrives. The writer is a technology lawyer specialising in data protection. Published in Dawn, August 7th, 2026