The intersection of artificial intelligence (AI) and data privacy represents the most consequential regulatory frontier of the twenty-first century. In Pakistan, however, this frontier is currently defined by a striking paradox: a rapid, state-sponsored acceleration toward AI adoption juxtaposed against a stagnant, decade-long delay in enacting comprehensive privacy legislation. With the federal cabinet’s approval of the National Artificial Intelligence Policy in July 2025, and the subsequent signing of the Islamabad AI Declaration in February 2026, the state has formally committed to building what it terms “sovereign AI” capabilities. The ambitious targets that follow include training one million AI professionals and establishing geographically distributed Centres of Excellence in AI.
Yet this digital architecture is being constructed on a precarious legal foundation. As machine learning algorithms, large language models and automated decision-making tools are increasingly deployed across the public and private sectors, the absence of an enacted Personal Data Protection Bill (PDPB) — which has languished in various draft iterations since 2018 — leaves Pakistani citizens fundamentally exposed. While alternative, ad-hoc governance frameworks are beginning to emerge, they are highly fragmented. To safeguard constitutional liberties, prevent algorithmic discrimination and build a truly resilient digital economy, Parliament must urgently enact comprehensive, statutory data protection laws tailored specifically to the algorithmic age.
Why a Privacy Statute Cannot Be Improvised
A comprehensive privacy law introduces necessary normative friction into this process. Globally recognised data protection principles — data minimisation, purpose limitation and explicit consent — stand in direct opposition to the unchecked data scraping required to train unregulated AI. AI deployments also raise novel privacy challenges that older legal frameworks cannot address, including the “right to explanation” (the ability of a citizen to demand the rationale behind an AI-driven decision that affects their welfare, employment or liberty) and the “right to be forgotten” (the ability to compel the deletion of personal data from a model’s training set). Without a statutory framework establishing an independent privacy commission, Pakistani citizens have no legal recourse to demand algorithmic transparency or audit the datasets being used to profile them.
Governance by Contract: A Pragmatic but Partial Stopgap
In the absence of parliamentary action, the executive branch has begun engineering alternative routes to data security. A prime example is the draft National Data Governance Policy rolled out by the Ministry of Information Technology and Telecommunication (MoITT) in mid-2026. This policy represents a significant paradigm shift, but its parameters matter: it is not a blanket privacy law, but a targeted framework governing state-owned data.
Through mechanisms like the newly proposed WASL framework, the government aims to regulate how private tech companies, contractors, processors and cloud hosts handle public sector data, imposing strict requirements on data residency, cross-border transfers and security breach notification via procurement requirements and contractual obligations overseen by the Pakistan Digital Authority (PDA). The state is no longer treating data as a mere operational byproduct, but as a strategic national asset held in trust for the public.
This “governance by contract” is ingenious and pragmatic. It forces compliance upon the technology sector not through regulatory fines, but through the leverage of government contracts. From an academic and human rights perspective, however, it remains profoundly insufficient. Contractual obligations between the state and its vendors do not create universal, legally enforceable rights for the average citizen. Crucially, the National Data Governance Policy does not restrict how private corporations exploit consumer data for their own AI deployments. A telecom operator or a fintech startup deploying predictive AI on its own user base remains largely unrestrained by this policy. While the government is securing its own data supply chain, the broader citizenry remains unprotected in the private marketplace.
A Cybercrime Statute Is Doing a Privacy Statute’s Job
The legal uncertainty surrounding AI in Pakistan is compounded by the misapplication of existing statutes. Currently, the Prevention of Electronic Crimes Act (PECA) 2016 acts as the de facto governing law for the digital sphere. PECA, however, is fundamentally a criminal statute designed to police cybercrime and online speech; it was never engineered to regulate complex data ecosystems or algorithmic accountability. Recent amendments to PECA in 2025, which introduced sweeping powers to police “false information,” have exacerbated concerns among rights groups regarding state surveillance and the chilling of free speech.
Applying a cybercrime lens to data privacy is legally myopic. Article 14 of the Constitution of Pakistan explicitly guarantees the inviolability of human dignity and, subject to law, the privacy of the home, and the Supreme Court has historically upheld this right, notably in rulings against unauthorised surveillance and phone-tapping. Yet translating Article 14 into the era of artificial intelligence requires specific legislative mechanics. When an AI system denies a citizen a bank loan due to an opaque algorithmic bias, or when facial recognition software misidentifies an individual resulting in a wrongful arrest, invoking the broad constitutional right to privacy is a slow, costly and often inaccessible remedy for the common citizen. A dedicated privacy statute is required to codify these constitutional guarantees into actionable, everyday regulatory standards.
The Two-Tiered System Pakistan Is Building by Default
The global digital economy is rapidly coalescing around stringent data protection standards, heavily influenced by the European Union’s General Data Protection Regulation (GDPR) and the impending enforcement of the EU AI Act. Pakistani technology firms operating internationally are already forced to maintain GDPR-compliant frameworks to serve European and North American markets. By failing to enact a domestic equivalent, Pakistan is essentially maintaining a two-tiered system of digital dignity: offering robust data protection to foreign clients while denying those same protections to its own citizens. Enacting the PDPB would harmonise domestic compliance with international standards, reducing the friction of cross-border data flows, attracting foreign direct investment and legitimising Pakistan’s aspirations to become a global hub for AI research and development.
The Window Is Closing
The narrative that data governance can afford to wait for the perfect legislative moment is a dangerous fallacy. As the deployment of AI accelerates across Pakistan’s legal, financial and administrative sectors, the window to proactively govern these systems is rapidly closing. The National Data Governance Policy of 2026 proves that the state recognises the value of data, but true digital sovereignty extends beyond protecting a state asset — it is about protecting the fundamental rights of the people who generate that data.
Parliament must immediately revive and pass a modernised Personal Data Protection Bill, ensuring the establishment of an independent, well-resourced privacy commission. Pakistan cannot build a secure, sovereign and equitable AI ecosystem on a foundation of unregulated data exploitation. The intelligence of tomorrow must be governed by the rule of law today.
Esquare Legal advises technology companies, financial institutions and public sector clients on AI governance and data protection compliance across Pakistan and the wider region. Contact us to discuss your compliance position ahead of the PDPB.
Author: Hassan Raza, Associate, Esquare Legal.
