What Is Pakistan Privacy Protections: Prevention of Electronic Crimes Act 2016 + Constitutional Article 14 (No Enacted Comprehensive Data Protection Law)?
Pakistan has no verified enacted, operative, comprehensive Personal Data Protection Act in the 7 September 2026 review. The official Senate bill tracker records the Personal Data Protection Bill, 2023 as introduced 13 February 2023, referred to committee, and subsequently withdrawn — never passed or assented. The Ministry of IT and Telecommunications' legislation register still labels the 2018, 2020, and May 2023 instruments "Draft," and the Senate's current Acts register contains no Personal Data Protection Act through its 2026 listings. A National Assembly debate dated 14 May 2026 refers to a "Personal Data Protection Act 2026," but the same passage describes it only as a finalized bill with no Act number, assent date, or Gazette notification — not sufficient evidence of enactment. This is a genuinely active legislative area: the legal landscape could change without much warning, so any current description must be re-checked against the Senate Acts register and official Gazette before being treated as settled. In the absence of a comprehensive law, two things are currently in force: Article 14(1) of the Constitution, which protects the privacy of the home subject to law (a narrow constitutional protection, not a comprehensive data-protection regime), and the Prevention of Electronic Crimes Act, 2016 (PECA), which criminalizes unauthorized copying/transmission of data, unauthorized use of identity information, unauthorized interception, privacy/reputation offences, cyberstalking, and unlawful disclosure of personal information — targeted criminal and content-removal remedies, not a general rights framework.
At a glance
- Full name
- Pakistan Privacy Protections: Prevention of Electronic Crimes Act 2016 + Constitutional Article 14 (No Enacted Comprehensive Data Protection Law)
- Short code
- PECA + Art. 14
- Jurisdiction
- Pakistan
- Enacted
- 2016
- Last major update
- PECA amended by Act No. XXXVII of 2023 and Act No. II of 2025; the Personal Data Protection Bill, 2023 was withdrawn from Senate committee and has not been re-enacted in the 7 September 2026 review
- Regulator
- National Cyber Crime Investigation Agency (NCCIA) for PECA offences; no general personal-data regulator exists
- Private right of action
- Limited
Scope, who PECA + Art. 14 covers
Protected data
Data subject rights
No general statutory right of access, correction, erasure, restriction, objection, or portability currently exists
PECA s.16: application route to request removal, destruction, or blocking of unlawfully used identity information
PECA s.20: application route to request removal, destruction, or blocking of false information harming reputation or privacy
PECA s.25: right to unsubscribe from direct/unsolicited marketing communications
Constitutional Article 14(1): privacy of the home, subject to law
Notable features
This is the queue's clearest "not yet enacted" finding: the Personal Data Protection Bill, 2023 was formally withdrawn from Senate committee, and no later draft (2018, 2020, 2021 consultation, or May 2023 revision) has been enacted. Any description of Pakistani "data protection rights" drawn from these drafts — including a commonly cited 14-day erasure deadline and a proposed data-protection Commission — describes proposed law only and must not be presented as currently enforceable.
Enforcement & penalties
Penalties: PECA criminal penalties (not a data-protection-statute schedule): unauthorized copying/transmission of data (s.4) — up to 6 months imprisonment, Rs. 100,000 fine, or both; unauthorized use of identity information (s.16) — up to 3 years, Rs. 5,000,000, or both; unauthorized interception (s.19) — up to 2 years, Rs. 500,000, or both; privacy/reputation offence (s.20) — up to 3 years, Rs. 1,000,000, or both; cyberstalking (s.24) — up to 3 years, Rs. 1,000,000, or both (higher where the victim is a minor); unlawful disclosure of personal information (s.41) — up to 3 years, Rs. 1,000,000, or both; unsolicited/direct-marketing violation (s.25) — first offence up to Rs. 50,000, subsequent Rs. 50,000-1,000,000.
Private right of action: No general civil right of action for data-protection violations exists because no comprehensive statute exists. PECA provides removal/destruction/blocking application routes for specific offences (ss.16, 20) and criminal prosecution through the NCCIA, but not a general compensation or civil-suit right for ordinary data misuse.
Relevance to data brokers
No data-broker or public-record-specific complaint/deletion route has been located in Senate, MoITT, Pakistan Code, NCCIA, or PTA materials. The closest existing provision, PECA s.16 (unauthorized identity-information use), is not a general data-broker deletion right, and its own public-availability carve-out may exclude aggregated public-record data from its reach entirely.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Pakistan have a data protection law like GDPR?+
Not yet. In the 7 September 2026 review, Pakistan has no enacted, comprehensive Personal Data Protection Act. The 2023 bill was withdrawn from Senate committee, and earlier MoITT drafts remain labeled "Draft" in the ministry's own legislation register. This is an active legislative area that could change; check the Senate Acts register and official Gazette for the current status.
What privacy protections currently exist in Pakistan?+
Constitutional Article 14(1) protects the privacy of the home, subject to law, and the Prevention of Electronic Crimes Act, 2016 (PECA) criminalizes unauthorized copying, use, interception, or disclosure of personal and identity information, with application routes to request removal or blocking in specific circumstances. Neither is a general access, correction, erasure, or portability rights framework.
Can I ask a company or data broker to delete my data in Pakistan?+
No general statutory right to do so currently exists. PECA s.16 provides a narrow application route to request removal, destruction, or blocking of unlawfully used identity information, but it does not create a general data-broker deletion right, and information that is openly available to the public is generally deemed authorized under PECA's own definitions.
Official sources & citations
Other international privacy regimes
PECA + Art. 14 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
