2025-10-13

Added · Updated

NADRA (Digital Identity) Regulations, 2025

These regulations establish a comprehensive framework for the issuance, management, and security of Digital Identities by NADRA for Pakistani citizens. They define strict protocols for user onboarding, consent management, data protection, and Single Sign-On (SSO) mechanisms, mandating that all third-party requesting entities maintain secure infrastructure and adhere to rigorous auditing and breach-reporting obligations. Non-compliance, including unauthorized data processing or failure to secure personal data, subjects entities to enforcement actions under the Prevention of Electronic Crimes Act, 2016.

National Database and Registration Authority logo

Pakistan

National Database and Registration Authority

Click to view thumbnail

NADRA (Digital Identity) Regulations, 2025

CHAPTER-I: PRELIMINARY

  1. Short title, extent, commencement.—These regulations may be called the NADRA (Digital Identity) Regulations, 2025.
  2. It extends to the whole of Pakistan.
  3. These Regulations shall come into force on the date of their publication in the Official Gazette.
  4. Definitions.—(1) In these regulations, unless there is anything repugnant in the subject or context,— (a) "authentication" means the process of confirming an individual’s legal identity by matching specific credentials provided by the individual, such as a password, PIN, token or biometric data like digital signatures, fingerprints, facial recognition, or Iris scan against the corresponding credentials stored in the Identity server; (b) "authentication service" means the service provided by the Authority for authenticating the identity data along with demographic information or biometric information of a Digital ID user through the process of authentication by providing a Yes/ No response or e-KYC data, as applicable; ... [Note: Regulation 4 contains comprehensive definitions for terms including "Authority," "alien requesting entity," "Biometric Data," "Card," "consent," "citizen," "data," "data breach," "Digital Identity," "Digital vault," "e-KYC," "onboarding," "requesting entity," "user," and "verifiable credentials."]

CHAPTER-II: REGULATION OF DIGITAL ID

  1. Regulation and Issuance of Digital IDs.—(1) The Authority shall regulate and maintain the Digital ID system. (2) The Authority may issue a Digital ID to every citizen, having a valid card and verifiable biometrics, upon their request, as per applicable laws.
  2. Terms and Conditions.—(1) A citizen may apply for a Digital ID, which the Authority shall issue based on the eligibility criteria set forth by these regulations and compliance with the provisions of applicable laws.
  3. Manner of User’s Onboarding Process and Eligibility for Issuance of Digital ID.—(1) The Authority shall establish and maintain, or cause to be established and maintained, a registration and multiple database systems. (2) New users shall first onboard the Authority’s dedicated mobile application. (3) Existing registered users must complete outstanding verification steps.
  4. Suspension of Digital ID.—The Authority may suspend a Digital ID in the interest of national security for reasons including investigation of criminal offences, enforcement of legal rights, preventing data breaches, or non-compliance.
  5. Accessibility for Persons with Disabilities.—The Authority shall ensure Digital ID is accessible to persons with disabilities.
  6. Multilingual Accessibility.—The Authority shall ensure the Digital ID provides multilingual support in Urdu, English, and other regional languages.

CHAPTER-III: CONSENT MANAGEMENT & DATA SECURITY

  1. Consent Notice to User.—Requesting entities must inform users of the purpose, duration, data categories, and non-cross-border transfer policies before processing data.
  2. Consent to Process User’s Data.—Data processing requires free, specific, informed, and unambiguous consent; secondary use, sharing, or selling of data is strictly prohibited.
  3. Non-Disclosure of User’s data.—Data disclosure must comply with the Ordinance; sharing is restricted to lawful entities under a Data Sharing Agreement and within Pakistan's jurisdiction.
  4. Data Security.—Requesting entities must host data centres or cloud facilities in Pakistan and store identifiers within designated encrypted vaults.

CHAPTER-IV: SINGLE SIGN-ON MECHANISM

  1. Scope & Eligibility of SSO.—The Authority provides SSO services for authenticated users to access multiple platforms.
  2. Limited Disclosure of Verified Profile Data.—Upon successful authentication, the Authority transmits only limited profile attributes: first name, last name, verified card number, OTP-verified mobile number, and OTP-verified email.

CHAPTER-V: ONLINE AND OFFLINE VERIFICATION SERVICES

  1. Types of Authentication Services.—The Authority offers online authentication via Verifiable Credentials and Yes/No authentication queries.
  2. Notification and Acknowledgement.—Requesting entities must provide notification of authentication success or failure to the user.
  3. Storage & Retention.—The Authority shall retain minimum authentication transaction data as per the Electronic Transaction Ordinance, 2002.

CHAPTER-VI: ON BOARDING, ROLES & RESPONSIBILITIES

  1. Roles and Responsibilities of Requesting Entities.—Entities must use accredited digital certificates, establish secure network connectivity (NDEL), conduct annual audits, and provide full cooperation during fraud investigations.
  2. Responsibilities of Offline Verification Entities.—Entities must not retain biometric data and must inform the Authority of any breach within 72 hours.
  3. Non-Compliance.—Failure to adhere to standards may result in the suspension of operations.

CHAPTER-VII: MANAGEMENT OF DIGITAL VAULT

  1. Management of Digital Vault.—Users maintain exclusive control over their data within the secure, encrypted Digital Vault.

CHAPTER-VIII: SECURITY OBLIGATIONS & CYBER INCIDENT RESPONSE

  1. Cyber Incident Response.—The Authority must implement robust incident reporting and recovery protocols for security breaches.
  2. Cyber security Incident Response.—Requesting entities must notify the Authority of any cyber-security incidents or fraud within one business day.

CHAPTER-IX: MISCELLANEOUS

  1. Confidentiality.—All technical specifications and security protocols are classified and protected.
  2. Periodic Review.—The Authority shall periodically review these regulations to reflect technological advancements.