Data protection

Published March 28, 2024

WHAT do we want? Data protection laws. When do we want them? Immediately. Without delay, if we are to prevent another disaster. A JIT formed last year to probe a Nadra data breach, affecting approximately 2.7m citizens between 2019 and 2023, has shared its findings with the interior ministry. The findings reveal that data was compromised in Nadra’s Karachi, Multan, and Peshawar offices. The incident — not the first of its kind — has exposed the vulnerability of our personal data and the crucial need for stringent laws that mandate safeguarding against such breaches. The JIT’s recommendations, including technological upgrades and disciplinary actions against responsible officials, are necessary steps towards addressing the immediate aftermath of this breach. However, piecemeal responses alone are inadequate to prevent future incidents. The root of the problem lies not only in technological shortcomings but also in the absence of comprehensive legislation to hold accountable those entrusted with safeguarding citizens’ data.

While upgrading the technology employed by Nadra, the government must consider the use of stronger encryption and limiting unnecessary access to data. Moreover, restricting database access solely to the office premises can mitigate risks associated with remote breaches. However, these technical solutions must be complemented by legislation that treats the citizens’ private data as sacred and entails severe consequences for negligence. That Pakistanis’ data had surfaced in countries like Argentina and Romania is particularly alarming. Considering the state of identity theft globally, it is imperative that data protection laws are implemented forthwith and encompass both public and private entities, recognising that public bodies often hold the most extensive troves of personal data. Moreover, given the extensive centralisation of data within Nadra, many services such as telephony, transportation, courier, banking and hospitality rely on its database for biometric verification. This centralised approach, seemingly aimed at surveillance, introduces significant vulnerabilities with multiple parties accessing and utilising this database. This data leak must serve as a wake-up call for policymakers to enact and enforce the relevant laws. Bills have been drafted, but there have been no earnest efforts to advance them. A digitised world leaves no room for such massive security gaps. Pakistan must prioritise the protection of its citizens’ privacy and ensure that their data remains secure. Failure to do so would not only undermine individual rights but also hinder socioeconomic progress and security.

Published in Dawn, March 28th, 2024

Opinion

Respite needed

Respite needed

All one can fear is a familiar accounting exercise that aims to extract a few more rupees from a narrow, weary economic base.

Editorial

Soft on traders
08 Jun, 2026

Soft on traders

THE Fixed Tax Asaan Scheme for traders with an annual turnover of up to Rs200m has been designed as a ‘pragmatic...
Ceasefire in name
Updated 08 Jun, 2026

Ceasefire in name

Both sides accuse the other of violating the truce that was supposed to halt the conflict in April, yet neither appears willing to abandon negotiations altogether.
Damaged childhoods
08 Jun, 2026

Damaged childhoods

CHILD abuse is so prevalent that the UN ranked Pakistan as the least safe country for children. Even so, more than...
JAAC ban
Updated 07 Jun, 2026

JAAC ban

Though the JAAC’s demands are open to scrutiny, banning any political organisation — as long as it remains committed to peaceful activism — is undemocratic.
GB election
Updated 07 Jun, 2026

GB election

It is important that whichever party ultimately forms the government puts the needs of the people of GB above everything else.
ODI win
07 Jun, 2026

ODI win

AT last, the Pakistan cricket team had something to celebrate: a One-day International series victory against...