Home › Law library › Pakistan SBP/PTA data rules
PK
Pakistan SBP/PTA data rules
SBP Framework on Outsourcing to Cloud Service Providers (BPRD Circular 01/2023) and PTA Critical Telecom Data and Infrastructure Security Regulations
Sourced. Last verified 9 October 2026
Pakistan Privacy
- Status
- SBP cloud framework in force (16 Jan 2023; existing arrangements to comply by 31 Dec 2023). PTA CTDISR first issued 2020; revised version consulted to 7 Nov 2025.
- Who it applies to
- SBP: banks, MFBs, DFIs, EMIs, PSOs/PSPs using cloud services. PTA: all licensed telecom operators and their supply chains.
- Size thresholds
- SBP framework covers both material and non-material cloud workloads, using a risk-based approach.
- Regulator
- State Bank of Pakistan (SBP); Pakistan Telecommunication Authority (PTA)
- Breach or incident reporting
- PTA (revised CTDISR, per a news report): report major cyber breaches to PTA within 24 hours. SBP cyber incident reporting timelines.
- Deadline to answer personal data requests
- Not applicable (no general data subject rights regime); banking secrecy complaints go to the Banking Mohtasib.
- Data protection officer
- Being verified
- Local representative
- Not applicable.
- Sending data abroad
- PTA: telecom operators must store customer and operational data in Pakistan. SBP onshore/offshore cloud conditions.
- Cookies and consent
- PTA spam regulations (2009): telemarketers must register, respect the Do Not Call Register, and include an unsubscribe option in marketing SMS.
- Maximum penalty
- Being verified
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Banks/fintechs: map all cloud workloads and comply with SBP's 2023 cloud outsourcing framework.
- Keep banking customer data confidential under the Banking Companies Ordinance 1962.
- Telecoms: host customer and operational data inside Pakistan.
- Telecoms: report major cyber breaches to PTA within 24 hours.
- Register as a telemarketer, honour the Do Not Call list and add unsubscribe options to SMS.
Recent changes
PTA finalised revised CTDISR (Aug–Nov 2025): local data hosting, supply-chain security, 24-hour breach reporting.
Sources
- Primary source: https://www.sbp.org.pk/bprd/2023/C1.htm
- Second source: https://meatechwatch.com/2025/11/05/pta-finalizes-new-cybersecurity-regulations-mandating-local-data-hosting-for-telecoms/
- Regulator: State Bank of Pakistan (SBP); Pakistan Telecommunication Authority (PTA)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].