Frameworks / Pakistan Personal Data Protection Bill 2023 / PAKPDPB-8 Pakistan Personal Data Protection Bill 2023
Enforcement and Lifecycle
Pakistan Personal Data Protection Bill 2023 PAKPDPB-8: Enforcement, Penalties, Complaints, Retention, Training Per Pakistan PDPB 2023 Clauses 20-22 + lifecycle: enforcement + penalties + lifecycle management. Requirements include (a) understand offences + penalties per the Bill including significant penalties for breach of obligations + (b) implement Complaints and Appeals mechanism enabling data subjects to lodge complaints with NCPDP + (c) implement Retention and Disposal including retention schedules + secure deletion + anonymisation where retention is no longer justified + (d) maintain Direct Marketing safeguards including consent + opt-out + suppression lists + (e) deliver training and awareness across the organisation including role-based content + onboarding + refresher + (f) maintain governance + lifecycle management + with continuous improvement.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 298 controls across 142 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-7 Cross-Border Data Transfers and International Cooperation AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-2 Article 2 - Basic Concepts BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-2 Section 2 - Interpretation BB-DPA-21 Sections 61-69 - Data Privacy Officer 27557-1 Scope 27557-3 Terms and definitions 27557-4.3 Individual impact consideration 27557-6.2 Scope, context, and criteria for privacy IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data AL-DPA-1 Scope and Definitions AL-DPA-12 International Data Transfers AL-DPA-3 Lawful Basis for Processing APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act) UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27400-3 Terms and definitions 27400-5.4 Data and privacy risks 27400-7.3 Data minimization and purpose limitation 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure 29147-3 Terms and definitions 29147-5.8 Confidentiality of Reports 29147-9.2 Contact mechanisms and scope ITAR-CompliancProgram-ICP-EmpoweredOfficial-Recordkeeping-5Years-Training-IT-Cloud-SupplyChain-Coord-EAR-OFAC-Wassenaar ITAR Compliance Program + Internal Compliance Program (ICP) + Empowered Official + 5-Year Recordkeeping + Training + IT/Cloud (GovCloud + Azure Gov + GCC High) + Supply Chain + Coord EAR + OFAC + Wassenaar + MTCR ITAR-Scope-AECA-22USC2778-22CFR120-130-DDTC-USML-21Categories-DefenseArticle-Service-TechnicalData ITAR Scope + Arms Export Control Act (22 USC 2778) + 22 CFR Parts 120-130 + Directorate of Defense Trade Controls (DDTC) + United States Munitions List (USML) 21 Categories + Defense Article/Service/Technical Data Definitions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs 58.1 Scope 58.3 Definitions R.16-VATR.Scope Scope and applicability of Travel Rule to VASPs (R.16 + Interpretive Note to R.15/R.16) R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct Sapin2-Pillar7-Disciplinary-Regime Pillar 7 - Disciplinary Regime for Anti-Corruption Violations GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements 27011-1 Scope 27011-3 Terms and definitions 27014-1 Scope 27014-3 Terms and definitions 30111-3 Terms and definitions 30111-5.1 Organizational policy MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026 MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data C1 Organizational Boundary C3 Scope 1 and 2 Coverage USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation CFR211-A-3 Section 211.3 - Definitions 4.4.1 Resources, Roles, Responsibility, and Authority AWWA-1.1 Security Policy and Governance CPG-6.B Supply Chain Incident Reporting COBIT-BAI02 Managed requirements definition CA-10 Selects and Develops Control Activities LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) CA-9 Internal System Connections CA-9 Internal System Connections GLBA-Sec6801-PolicyDuty-SafeguardingStandard GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard GLI33-EventWagering-System-Architecture GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management HKMA-SPM-CG-IC-AC-Governance-Control-Audit HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G) IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality 62351-2 Glossary of terms IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA 27007-5.2 Audit Programme Objectives 27050-1.4 Terms and definitions 29115-3 Terms and definitions ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members BIPA-SEC5-1 Biometric Identifier Definition INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12 MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OSSFSC-1 Branch Protection, Code Review, and Repository Governance 2.2.2 2.2.2 Vendor default accounts managed RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1) PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 TEFCAREC-1 Common Agreement Conformance and Onboarding CRM-2 Sanctions Compliance ACE-EX-3 Export License Verification 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 298 it maps to, and the evidence behind each claim, over MCP and REST.