Skip to content
GlanceDeskJurisdiction

Home › Law library › Pakistan SBP/PTA data rules

PK

Pakistan SBP/PTA data rules

SBP Framework on Outsourcing to Cloud Service Providers (BPRD Circular 01/2023) and PTA Critical Telecom Data and Infrastructure Security Regulations

Sourced. Last verified 9 October 2026

Pakistan Privacy

Status
SBP cloud framework in force (16 Jan 2023; existing arrangements to comply by 31 Dec 2023). PTA CTDISR first issued 2020; revised version consulted to 7 Nov 2025.
Who it applies to
SBP: banks, MFBs, DFIs, EMIs, PSOs/PSPs using cloud services. PTA: all licensed telecom operators and their supply chains.
Size thresholds
SBP framework covers both material and non-material cloud workloads, using a risk-based approach.
Regulator
State Bank of Pakistan (SBP); Pakistan Telecommunication Authority (PTA)
Breach or incident reporting
PTA (revised CTDISR, per a news report): report major cyber breaches to PTA within 24 hours. SBP cyber incident reporting timelines.
Deadline to answer personal data requests
Not applicable (no general data subject rights regime); banking secrecy complaints go to the Banking Mohtasib.
Data protection officer
Being verified
Local representative
Not applicable.
Sending data abroad
PTA: telecom operators must store customer and operational data in Pakistan. SBP onshore/offshore cloud conditions.
Cookies and consent
PTA spam regulations (2009): telemarketers must register, respect the Do Not Call Register, and include an unsubscribe option in marketing SMS.
Maximum penalty
Being verified

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

PTA finalised revised CTDISR (Aug–Nov 2025): local data hosting, supply-chain security, 24-hour breach reporting.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].