These regulations establish a mandatory framework for the National Database and Registration Authority to protect sensitive data through defined information security policies, access controls, and incident management protocols. The document mandates the appointment of Data Protection Officers and Chief Information Security Officers to oversee compliance, regular auditing, and organizational risk management. It further imposes strict security obligations on third-party service providers and requesting entities, requiring legally binding data-sharing agreements and continuous monitoring to ensure the integrity, availability, and confidentiality of all citizen data.
National Database and Registration Authority (Data Security, Protection & Confidentiality) Regulations, 2024
CHAPTER 1
Short title, extent, commencement.— These regulations may be called the National Database and Registration Authority (Data Security, Protection & Confidentiality) Regulations, 2024.
It extends to the whole of Pakistan.
These Regulations shall come into force on the date of their publication in the Official Gazette.
Definitions.—In these regulations, unless there is anything repugnant in the subject or context:
4.1. “Authentication” means the process of confirming an individual’s identity by matching specific credentials provided by the individual (such as a password, PIN, token, or biometric data like fingerprints, facial recognition, or iris scans) against the corresponding credentials stored in NADRA Citizen Database;
4.2. “Authority” means the National Database and Registration Authority established under section 3 of NADRA Ordinance, 2000 (VIII of 2000);
4.3. “Authorized Personnel” means individuals who have been granted access rights to specific data or systems by the Authority;
4.4. “Biometric data” means personal data resulting of specific technical processing relating to the physical, physiological, or behavioral characteristics of an individual, which allows or confirms the unique identification of that individual, including but not limited to fingerprints, facial recognition data, and iris scans;
4.5. “Citizen Database” means the databases established specifically for the collection and processing of multifaceted data regarding citizens, registered persons and things;
4.6. “Chief Information Security Officer” means an officer designated as Chief Security Officer by the Authority under sub-regulation 4 of these regulations;
4.7. “Data” means any information collected, generated, processed, stored, maintained or transmitted by the Authority, including but not limited to personal data, non-personal data, and aggregated data and shall mean all information, facts, statistics, figures, measurements, records, or any other content, whether in electronic, written, or other formats. This includes, but is not limited to, quantitative and qualitative information, metadata, and any other form of digital or analog input that can be used for analysis, decision-making, or communication;
4.8. “Data Breach” means any unauthorized access, disclosure, alteration, destruction, or loss of data;
4.9. “Data Sharing Agreement (DSA)” means a formal agreement between the Authority and a third party that outlines the terms and conditions under which data will be shared;
4.10. “Demographic information” includes information relating to the name, date of birth, address and other relevant information of an individual;
4.11. “Incident Response Team” means a team designated by the Authority to handle data breaches and security incident.
4.12. “Information Security Department” means Information Security Department of the Authority;
4.13. “Information System” means an electronic system for creating, generating, sending, receiving, storing, reproducing, displaying, recording or processing any information;
4.14. “National Data Warehouse (NDW)” means the collection of databases established by the Authority under section 7 of the Ordinance, including the Citizen Database;
4.15. “Network(s)” means a system of interconnected computers, servers, communication devices, and other digital infrastructure that enables the transmission, exchange, and sharing of data, including personal and biometric information, between different nodes or locations within the Authority’s operational framework;
4.16. “Ordinance” means the National Database and Registration Authority Ordinance, 2000 (VIII of 2000);
4.17. “Personnel” means all officers, employees, staff and other individuals employed or engaged by the Authority for discharging any functions under the Ordinance;
4.18. “Requesting entity” means an agency or person that submits the card number, and demographic information or biometric information, of an individual to the National Data Warehouse for authentication or verification;
4.19. “Service provider” includes all entities engaged by the Authority for discharging any function related to its processes;
4.20. “Verification” means the process of checking or cross-referencing an individual’s identity information or credentials against the data held on the Citizen Database to confirm the accuracy and legitimacy of the claimed identity.
CHAPTER-II
Introduction.—
5.1. Purpose
5.1.1. The purpose of these regulations is to establish a comprehensive framework for ensuring the security, protection, and confidentiality of all data, information systems, and processes within NADRA.
5.2. Scope
5.2.1. These regulations apply to all personnel, contractors, third-party vendors, and any other individuals or entities that have access to the organization’s IT systems, data, or facilities.
5.3. Objectives
5.3.1. To protect sensitive and confidential data from unauthorized access and breaches.
5.3.2. To ensure the integrity and availability of information systems and services.
5.4. Legal and Regulatory Compliance
5.4.1. All activities must comply with relevant laws, including ISO/IEC 27001 standards.
CHAPTER-III
GOVERNANCE AND RESPONSIBILITY
6.1. The Authority shall appoint a Data Protection Officer (DPO).
6.2. The Authority shall define roles and responsibilities for all personnel.
CHAPTER IV
CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY
7.1. Confidentiality measures include secure channels, data masking, and access controls.
7.2. Integrity is maintained through regular validation, hashing, and verification.
7.3. Availability is ensured through redundancy and disaster recovery.
CHAPTER-V
Organizational Security Policies
8.1. The Authority shall maintain an information security policy reviewed annually.
Measures for ensuring information security include asset inventory, access control, malware protection, encryption, and disaster recovery.
CHAPTER-VI
Security obligations of the personnel.
Security obligations of requesting entities and service providers include strict adherence to security policies, prompt reporting of incidents, and conducting background checks on staff with data access.
CHAPTER-VII
Network Security: NADRA network shall be segmented and protected by firewalls and IDS/IPS.
Incident Response: A formal incident response plan shall be maintained, and breaches must be reported to the Incident Response Team (IRT) within 24 hours.
Physical Security: Restricted physical access to facilities using biometric controls and surveillance.
CHAPTER-VIII
Compliance and Audit: Regular internal and third-party audits shall be conducted.
Reporting and Remediation: Audit results and compliance reports shall be communicated to senior management.
Training: Ongoing security awareness and role-based training programs are mandatory.
Third-Party Management: Security requirements must be included in all third-party contracts.
Data Sharing Agreements: Data sharing with external entities requires a legally binding Data-Sharing Agreement.
Business Continuity and Disaster Recovery: BCP and DR plans shall be in place and tested through regular drills.
Documentation: Standards for documenting policies and records must be maintained.
Savings: Previous MOUs and agreements remain in force unless inconsistent with the Ordinance.
Power to issue policies: The Authority may issue circulars to clarify regulations.
Delegation: Authorities may be delegated by the Chairman or relevant officers.
Periodic Review: These regulations shall be reviewed annually by the Data Security Committee.
Severability: Invalid provisions do not affect the validity of remaining regulations.