Framework guide • Pakistan

Pakistan PDPB: Pakistan Personal Data Protection Bill

The Pakistan Personal Data Protection Bill (PDPB) is draft legislation from the Ministry of IT & Telecom (MoITT) that would regulate how personal data of people in Pakistan is collected and processed. It proposes an independent Personal Data Protection Authority. The bill has not yet been enacted, and several drafts exist. Komply maps the organisation-facing obligations of the 2020 consultation draft as 30 controls, so teams can prepare early.

Last updated · By the Faseel compliance team · Not legal advice

Pakistan PDPB at a glance

Status
Draft legislation, not yet enacted. Later drafts (e.g. 2023) exist, and the final Act will govern
Proposed by
Ministry of IT & Telecommunication (MoITT); proposes a Personal Data Protection Authority
Version mapped in Komply
PDPB 2020 Consultation Draft (v.09.04.2020)
Size
30 organisation-facing obligations across 5 chapters
Similar to
GDPR — lawful processing, data-subject rights, sensitive data, breach duties

Who must comply with Pakistan PDPB

Data controllers

Organisations that decide why and how personal data of people in Pakistan is processed.

Data processors

Vendors and service providers processing personal data on a controller's behalf.

Anyone handling sensitive data

Health, financial, biometric and other sensitive categories would carry stricter rules.

What Pakistan PDPB requires

  • Process personal data lawfully, with notice and consent, and only for specified purposes.
  • Secure personal data and manage processors.
  • Honour data-subject rights: access, correction, withdrawal of consent and others.
  • Apply stricter conditions to sensitive personal data.
  • Prepare for offences and liability provisions once the law is enacted.

Pakistan PDPB domains and control counts

30 controls across 5 areas, as mapped in Komply.

Pakistan PDPB domains with number of controls
DomainControls
Controller & Processor Obligations (s4–15)12
Rights of Data Subjects (s16–27)12
Sensitive Personal Data (s28)1
Exemptions (s29–31)1
Offences & Liability (s41–47)4
Total30

How Pakistan PDPB maps to ISO 27001

27 of the 30 obligations map to ISO/IEC 27001:2022 Annex A privacy and security controls. Organisations already working toward GDPR will find most of the work reusable.

Komply lets you start PDPB readiness now, on top of your ISO 27001 and GDPR work, and update the mapping when the final Act is passed. See how Komply works.

Pakistan PDPB FAQ

Is Pakistan's Personal Data Protection Bill law yet?

No. The PDPB is still draft legislation, and multiple drafts exist (2020 consultation draft, later revisions). The final enacted Act will set the binding obligations. Treat any current mapping as preparation, not legal compliance.

What does the PDPB require?

The drafts set obligations for data controllers and processors: lawful processing, notice and consent, security, and processor management. They also grant data-subject rights, add stricter rules for sensitive personal data, and include offences and liability provisions.

How is the PDPB different from GDPR?

The PDPB draws on GDPR concepts such as lawful processing, data-subject rights and sensitive data, but it is Pakistan-specific and not yet enacted. Work done for GDPR largely carries over.

How can Komply help with PDPB?

Komply maps the 2020 draft's organisation-facing obligations as 30 controls alongside ISO 27001 and GDPR, so you can prepare now and update when the final Act is passed. This is not legal advice.

Do ISO 27001 once. Prove Pakistan PDPB too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.