Pakistan's Personal Data Protection Bill (PDPB) has moved through multiple drafts and consultation cycles, following the broader regional and global trend toward GDPR-influenced privacy law. Businesses that wait for final enactment before acting typically find themselves scrambling — the operational changes required (consent management, breach response, vendor contracts) take months to implement properly, not weeks.
What the bill is expected to require
While specific provisions have shifted across drafts, the core structure has stayed consistent and mirrors patterns seen in GDPR, UAE's PDPL, and Saudi's PDPL:
✓
A defined lawful basis for processing — consent as the default basis, with limited exceptions for legitimate business purposes.
✓
A dedicated data protection authority — an independent regulator with investigation and enforcement powers, similar to authorities established elsewhere in the region.
✓
Cross-border data transfer restrictions — limitations on transferring personal data outside Pakistan without adequate safeguards, echoing data localization themes common across regional privacy laws.
✓
Breach notification obligations — mandatory reporting to the regulator and, in higher-risk cases, to affected individuals, within a defined timeframe.
✓
Data subject rights — access, correction, and deletion rights individuals can exercise against organizations holding their data.
✓
Extraterritorial scope — applying to organizations outside Pakistan that process the personal data of individuals within the country.
Where organizations typically have the biggest gaps
In readiness assessments across Pakistani businesses, the same gaps come up repeatedly: no current data inventory (nobody can say definitively what personal data is held, where, or why), consent that's implied rather than documented, vendor and processor contracts silent on data protection obligations, and no defined breach response process with clear notification timelines and ownership.
How to build readiness before enforcement
✓
Build a data inventory — identify what personal data you collect, process, and store, and why, across every system and vendor.
✓
Document lawful basis and retention for each category of personal data, rather than retaining everything indefinitely by default.
✓
Strengthen consent mechanisms — clear, specific, and revocable, not buried in generic terms of service.
✓
Review vendor and processor contracts to ensure data protection obligations flow through to third parties handling your data.
✓
Define a breach response plan with named owners, notification timelines, and a communication process — before an incident forces you to build one under pressure.
How this connects to ISO 27001 and ISO 27701
Organizations already pursuing ISO 27001 have a head start — asset inventories, access control, and incident response processes overlap significantly with privacy readiness. Adding ISO 27701, the privacy information management extension to ISO 27001, builds the consent, data subject rights, and processing-purpose documentation that PDPB readiness specifically requires, without duplicating work already done for information security certification.
Frequently asked questions
Is Pakistan's Personal Data Protection Bill already law?+
The Personal Data Protection Bill has moved through multiple draft versions and consultation rounds without full enactment as of this writing. Organizations should treat it as imminent rather than distant — the direction of travel is consistent across drafts, so early preparation isn't wasted effort even before final enactment.
Does the bill apply to companies outside Pakistan?+
Draft versions of the bill have consistently included extraterritorial scope similar to GDPR — applying to any organization that processes the personal data of individuals in Pakistan, regardless of where the organization itself is based, when that processing relates to offering goods or services to those individuals.
What should businesses do before the bill is finalized?+
Build the operational foundation now: a current data inventory, documented lawful basis for processing, a breach response plan with defined notification timelines, and vendor/processor contracts that address data protection obligations. This foundation also supports ISO 27001 and ISO 27701 certification, so the investment isn't law-specific.