Pakistani businesses ask two questions about data: is there a law yet, and does any of it apply to us.

The honest answers are that a comprehensive personal data protection statute has been in draft for some years and is not yet in force in the way businesses expect — and that several other things already bind you regardless.

Waiting for the statute is the wrong posture, because the obligations that currently bite come from four other directions.

What already applies

PECA 2016. The Prevention of Electronic Crimes Act criminalises unauthorised access to information systems and data, and unauthorised copying, transmission and interference. It cuts both ways: it is your remedy when someone takes your data — see online fraud and cybercrime complaints — and it is exposure if your people access or copy data they should not.

Sectoral regulation. Banks and financial institutions operate under State Bank requirements covering customer information, outsourcing and technology risk. Telecoms, insurance and health carry their own. If you are regulated, your regulator's rules are the operative data rules for you today. See launching a fintech in Pakistan.

Contract. This is the one most businesses underestimate. Foreign clients, platforms and enterprise customers impose data obligations by agreement — security standards, breach notification within fixed hours, audit rights, deletion on termination, restrictions on sub-processing. Those are enforceable against you whatever Pakistani legislation says, and breaching them is a commercial and legal problem at once.

Foreign law reaching you. If you handle personal data of people in the EU or UK — common for software houses and freelancers serving overseas clients — the GDPR regime can apply extraterritorially, and your client will almost certainly flow those obligations down to you contractually anyway.

The pending statute

Draft personal data protection legislation has been under consideration in Pakistan for several years, in successive versions. The broad shape is familiar: lawful basis for processing, data subject rights, security obligations, breach notification, restrictions on cross-border transfer, and a regulator with enforcement powers.

Two practical implications.

Do not build as though nothing is coming. A business that knows what personal data it holds, why, and where it sits will adapt cheaply. One that does not will face a scramble.

Do not claim compliance with a law not yet in force. Overstating your position to clients creates its own liability.

What to put in place now

This is proportionate for a normal Pakistani business, and most of it is a weekend of work.

Know what you hold. A simple inventory: what personal data, whose, why you have it, where it is stored, who can access it, and how long you keep it. Almost nobody has this, and everything else depends on it.

Reduce it. The cheapest security measure is not holding data you do not need. Copies of CNICs collected "for the file", years of old customer records, ex-staff data — delete what has no purpose.

Control access. Role-based, removed promptly when people leave. Data walking out with departing staff is the most common incident we see — see when a key employee leaves.

Basic security hygiene. Encryption in transit and at rest where practicable, multi-factor authentication, patching, backups that are tested, and logging that would let you establish what happened.

A privacy notice on your website and in your onboarding, saying honestly what you collect and why.

Vendor terms. Where you pass data to a payment processor, cloud host, marketing tool or outsourced support provider, know what they do with it and what your agreement says.

A breach plan. Who is called, in what order, within what time. Contractual notification windows are frequently 24 to 72 hours, which is not long enough to be inventing a process.

If a breach happens

Contain first — revoke access, isolate systems — then preserve evidence rather than wiping and rebuilding, because the logs are what establish scope.

Establish what was actually affected, whose data, and how. Then check your contractual notification obligations and any regulatory ones applicable to your sector; those clocks are short and they start at discovery.

Take advice before notifying customers, and before making any public statement. An inaccurate first statement is very difficult to correct.

Where the breach involves unauthorised access by a person, PECA is available.

For businesses serving overseas clients

You will be asked to sign a data processing agreement, and you will be audited against it. Read it before signing, particularly the security standards, the notification window, sub-processor restrictions and any indemnity.

Do not accept obligations you cannot actually meet — a 24-hour notification commitment is a promise about a process you must genuinely have.

How the firm can help

We advise on the obligations that currently apply to a particular business, draft privacy notices, data processing and vendor agreements, and review the data clauses in client contracts before you sign them.

We also act on incidents: containment advice, notification obligations, PECA complaints where data has been taken, and disputes with clients or vendors arising from a breach.

If you hold customer data and have never looked at this, contact the firm. Starting with an inventory is inexpensive, and it is the step everything else depends on.