Pakistan Personal Data Protection Bill 2023
The Pakistan Personal Data Protection Bill 2023 establishes a framework for personal data protection in Pakistan. It creates the National Commission for Personal Data Protection as the regulatory authority. The Bill covers data processing principles, individual rights, cross-border transfers, and penalties. While still progressing through legislative process, it signals Pakistan's move toward comprehensive data protection aligned with international standards.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Accountability
| Code | Title |
|---|---|
| PDPB-13 | Records of Processing Activities |
Algorithmic Fairness
| Code | Title |
|---|---|
| PDPB-15 | Automated Decision Making |
Chapter I - Preliminary
| Code | Title |
|---|---|
| Cl. 1 | Short Title, Extent, and Commencement |
| Cl. 2 | Definitions |
| Cl. 3 | Scope and Application |
Chapter II - Obligations of Data Controllers
| Code | Title |
|---|---|
| Cl. 4 | Data Processing Principles |
| Cl. 5 | Consent Requirements |
| Cl. 6 | Purpose Limitation |
| Cl. 7 | Data Minimization |
| Cl. 8 | Data Security Measures |
Chapter III - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
| Cl. 10 | Right to Correction |
| Cl. 11 | Right to Erasure |
| Cl. 12 | Right to Data Portability |
| Cl. 9 | Right to Access |
Chapter IV - Cross-Border Data Transfer
| Code | Title |
|---|---|
| Cl. 13 | Transfer Conditions |
| Cl. 14 | Data Localization Requirements |
| Cl. 15 | Adequacy Determination |
Chapter V - National Commission for Personal Data Protection
| Code | Title |
|---|---|
| Cl. 16 | Establishment of the NCPDP |
| Cl. 17 | Functions of the Commission |
| Cl. 18 | Powers of the Commission |
Chapter VI - Offences and Penalties
| Code | Title |
|---|---|
| Cl. 19 | Data Breach Notification |
| Cl. 20 | Offences |
| Cl. 21 | Penalties |
| Cl. 22 | Complaints and Appeals |
Consent Management
| Code | Title |
|---|---|
| PDPB-2 | Consent Requirements and Withdrawal |
Data Lifecycle
| Code | Title |
|---|---|
| PDPB-16 | Retention and Disposal |
Enforcement
| Code | Title |
|---|---|
| PDPB-19 | Penalties and Enforcement |
Governance
| Code | Title |
|---|---|
| PDPB-6 | Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| PDPB-9 | Personal Data Breach Notification |
Individual Rights
| Code | Title |
|---|---|
| PDPB-4 | Rights of Data Subjects |
International Transfers
| Code | Title |
|---|---|
| PDPB-10 | Cross-Border Transfer Restrictions |
Lawful Processing
| Code | Title |
|---|---|
| PDPB-1 | Lawful Basis for Processing Personal Data |
Localisation
| Code | Title |
|---|---|
| PDPB-11 | Localisation of Critical Personal Data |
Marketing
| Code | Title |
|---|---|
| PDPB-18 | Direct Marketing and Profiling |
People
| Code | Title |
|---|---|
| PDPB-20 | Training and Awareness |
Regulatory Engagement
| Code | Title |
|---|---|
| PDPB-17 | Registration with the National Commission |
Risk Management
| Code | Title |
|---|---|
| PDPB-7 | Data Protection Impact Assessment |
Security
| Code | Title |
|---|---|
| PDPB-8 | Security of Processing |
Special Categories
| Code | Title |
|---|---|
| PDPB-5 | Sensitive and Critical Personal Data |
Third Party Management
| Code | Title |
|---|---|
| PDPB-12 | Processor Obligations and Contracts |
Transparency
| Code | Title |
|---|---|
| PDPB-3 | Notice to Data Subjects |
Vulnerable Subjects
| Code | Title |
|---|---|
| PDPB-14 | Children's Personal Data |
Your Compliance Coverage
If you comply with Pakistan Personal Data Protection Bill 2023, you already cover:
Chile Personal Data Protection Law (Law No. 21.719)
24%
12 controls mapped
Compare →Serbia Law on Personal Data Protection (2018)
24%
12 controls mapped
Compare →GDPR
24%
12 controls mapped
Compare →+ 631 more: EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (24%), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (24%)
See all 634 mapped frameworks ↓Maps to 634 other frameworks
Frequently Asked Questions
What is Pakistan Personal Data Protection Bill 2023?
Pakistan Personal Data Protection Bill 2023 is a compliance framework from Pakistan with 26 domains and 50 controls. The Pakistan Personal Data Protection Bill 2023 establishes a framework for personal data protection in Pakistan. It creates the National Commission for Personal Data Protection as the regulatory authority. The Bill covers data processing principles, individual rights, cross-border transfers, and penalties. While still progressing through legislative process, it signals Pakistan's move toward comprehensive data protection aligned with international standards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Pakistan Personal Data Protection Bill 2023 have?
Pakistan Personal Data Protection Bill 2023 has 50 controls organised across 26 domains. The largest domains are Chapter III - Rights of Data Subjects (12 controls), Chapter II - Obligations of Data Controllers (5 controls), Chapter VI - Offences and Penalties (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Pakistan Personal Data Protection Bill 2023 map to?
Pakistan Personal Data Protection Bill 2023 maps to 634 other compliance frameworks. The top mapping partners are Chile Personal Data Protection Law (Law No. 21.719) (24% coverage), Serbia Law on Personal Data Protection (2018) (24% coverage), GDPR (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Pakistan Personal Data Protection Bill 2023 compliance?
Start your Pakistan Personal Data Protection Bill 2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Pakistan Personal Data Protection Bill 2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required