2025-10-13

Added · Updated

NADRA (National Data Exchange Layer) Regulations, 2025

These regulations establish a secure, interoperable framework for data exchange between NADRA and authorized public or private entities under the National Data Exchange Layer (NDEL). Entities must undergo a rigorous onboarding process, ensure technical compliance with security protocols, and obtain explicit citizen consent for all data sharing activities. The Authority retains oversight and enforcement powers, including the right to suspend connectivity for non-compliance, security breaches, or failure to maintain mandatory data protection standards.

National Database and Registration Authority logo

Pakistan

National Database and Registration Authority

Click to view thumbnail

NADRA (National Data Exchange Layer) Regulations, 2025

CHAPTER-I: PRELIMINARY

  1. Short title, extent, commencement.—These Regulations may be called the National Database and Registration Authority (National Data Exchange Layer) Regulations, 2025.

  2. It extends to the whole of Pakistan.

  3. These regulations shall come into force on the date of their publication in the Official Gazette.

  4. Definitions.—(1) In these regulations, unless there is anything repugnant in the subject or context,— (a) "authentication" means the process of confirming an individual’s claimed identity typically during login or access control by matching specific credentials provided by the individual, such as a user name, password, or biometric data like fingerprints, or facial recognition, against the corresponding individual’s public-private key stored in the individual’s mobile device; (b) "Authority" means the National Database and Registration Authority established under section 3 of the NADRA Ordinance, 2000 (VII of 2000), which will establish, regulate and maintain the National Data Exchange Layer; (c) "on boarded entity" means any federal or provincial public or private entity, acting either as a service provider or service consumer, that upon being duly authorized by Authority, shall access the NDEL, to enable seamless, secure, standardized, and interoperable data exchange and information sharing between the Authority and on boarded entities for verification services, or between two or more on boarded entities just for data exchange purposes; (d) "Application Programming Interface or API" means a set of rules or protocols that enable software applications to communicate with each other to exchange data, features and functionality; (e) "biometric data" means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of an individual, which allows or confirms the unique legal identification of that individual, including but not limited to fingerprints, facial recognition data and iris scans; (f) "CERT Rules" means Computer Emergency Response Team Rules, 2023; (g) "consent" means any freely given, specific, informed and unambiguous indication of an individual’s intent in the form of a statement or by a clear affirmative action that signifies agreement to the processing of personal data for a specific purpose. Acceptance of a general, vague or broad term of use that contains descriptions of personal data processing along with other, unrelated data does not constitute consent; (h) "citizen" means a citizen of Pakistan who has attained the age of eighteen years and includes both a resident and a non-resident citizen, except a Pakistan Origin Card and Alien Registration Card holders; (i) "citizens database" means the database established specifically for the collection and processing of multifaceted data regarding citizens, registered persons and things; (j) "Chief Information Security Officer or CISO" means an officer responsible for developing, implementing and maintaining information security protocols across the Authority to ensure the integrity, confidentiality, and availability of information systems; (k) "cyber security incident response" means as defined under rule 2(xi) of the CERT Rules, 2023; (l) "data" means any information collected, generated, processed, stored, maintained or transmitted by the Authority, including but not limited to personal data, non-personal data, and aggregated data and shall mean all information, facts, statistics, figures, measurements, records, or any other content, whether in electronic, written, or other formats. This includes, but is not limited to, quantitative and qualitative information, metadata and any other form of digital or analogue input that can be used for analysis, decision-making, or communication; (m) "data breach" means a confirmed or suspected incident involving unauthorized access to, disclosure of, alteration of, or loss of personal or non-personal data exchanged or stored via NDEL; (n) "Data Breach Response Plan" means a documented framework that sets out the procedures, responsibilities, and communication protocols to be followed in the event of a confirmed or suspected data breach incident involving unauthorised access to, disclosure of, alteration of, or loss of personal or non-personal data exchanged or stored via NDEL, consistent with recognised standards such as National Institute of Standards and Technology special publication 800-61r3; (o) "Digital Identity or Digital ID" means legal, secure, verifiable credentials issued by the Authority to an eligible individual who possesses a foundational identity, and able to verify their identity through biometric verification, enabling access to digital services, transactions, and interactions, which shall be developed, issued and managed by the National Database and Registration Authority under the Ordinance; (p) "Digital ID Rules" means the National Database and Registration Authority (Digital Identity) Rules, 2025; (q) "Data Proof Transaction Layer" means a technical mechanism that provides verifiable evidence of all data transactions, including but not limited to access requests, exchanges, consents and other relevant activities through immutable logs, without compromising the confidentiality of underlying data; (r) "Data Sharing Agreement" means a formal agreement between the Authority and on boarded entities or third parties that outlines the terms and conditions under which data will be shared; (s) "Data Sharing Regulations" means the National Database and Registration Authority (Data Sharing) Regulations, 2024; (t) "digital vault" means a secure, encrypted, and controlled access digital repository, residing on a mobile application for encrypted storage, management, and sharing of verifiable credentials, and electronic records associated with Digital ID, which will solely be under the legal possession and control of the citizen; (u) "digital Id user" means a citizen who possesses and uses a Digital ID within the digital ecosystem for identity verification and access to online services; (v) "Government" means the Federal Government, Provincial Government, and Local Government; (w) "incident" means as defined under rule 2(xviii) of the CERT Rules, 2023; (x) "Information security policy" means the policy specified by the Authority; (y) "Key Pair" means the Private Key and its associated Public Key; (z) "National Data Exchange Layer or NDEL" means a secure and interoperable digital framework established and managed by the Authority that facilitates the standardised sharing and integration of data amongst government entities and public sector organisation, while ensuring that data ownership remains with the originating entity, and data is not stored or retained by intermediary systems beyond its processing purpose It also provides secure interfaces for private enterprises to access public services and data as required and ensure data. integrity, privacy, and accessibility without requiring private enterprises to share their proprietary data; (aa) "National Certification Authority" means a national-level public organisation that is responsible for the creation, issuance, revocation, and management of Certificates; (bb) "National Data Warehouse" means the collection of databases established by the Authority under section 7 of the Ordinance; (cc) "onboarding" means an on boarded entity applying to the Authority for onboarding under clause 3 of these regulations; (dd) "Ordinance" means the National Database and Registration Authority Ordinance, 2000 (VII of 2000); (ee) "personal data" means any information relating to an identified or identifiable natural person, an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (ff) "Public Key Infrastructure or PKI" means an infrastructure able to support the management of public keys, able to support authentication, encryption, integrity or non-repudiation services as defined under ITU-T X.509 (10/2019); (gg) "Public key Certificate or PKI Certificate" means the public key of an entity, together with some other information, rendered unforgeable by a digital signature with the private key of the certification authority that issued it, as defined under ITU-T X.509 (10/2019); (hh) "Sectoral CERT" means those CERTS that fall under Government CERT, CII CERT and Defence CERT, as per rule 8 of the Computer Emergency Response Team Rules, 2023; (ii) "Single-Sign-On" means a property of access control of multiple related, but independent software systems. With this property, a user logs in once and gains access to all the systems without being prompted to log in again at each of them, as defined by the National Institute of Standards and Technology's Special Publication 800-63-3; (jj) "verification" means the process of checking or cross-referencing an individual’s identity information or credentials against the data held on the Citizen Database to confirm the accuracy and legitimacy of the claimed identity; (kk) "verifiable credentials" means a tamper-evident credential whose authorship can be cryptographically verified. (2) The words and expressions used but not defined herein shall have the same meaning as are, assigned to them in the Ordinance, rules and regulations, as the case may be.

CHAPTER-II: REGULATORY OVERSIGHT OF NDEL

  1. Regulation of NDEL.—(1) The Authority shall be responsible for the regulation, operation, and maintenance of NDEL to ensure secure, efficient, and compliant data interoperability across on boarded entities. (2) The Authority shall ensure that the NDEL facilitates seamless, secure, standardised, and interoperable data exchange between citizens and the Authority, the Authority and on boarded entities, and between two or more on boarded entities. (3) The Authority shall, from time to time, issue necessary technical specifications, guidelines, standards, protocols, directives, etc, to govern access, integration and use of NDEL by on boarded entities, in compliance with the applicable laws.

  2. Terms and Conditions.—(1) An entity may only access and utilise NDEL upon being boarded by the Authority and establishing a secure connection with NDEL infrastructure, as per the procedure outlined in Regulation 3 of these regulations and/or any other standards specified by the Authority. (2) For an on boarded entity to avail, provide service and/or exchange data by establishing a secure connection with NDEL, the on boarded entity shall fulfill procedural and technical requirements, specifications, security protocols, execution of relevant agreements or any other relevant requirement as specified under these regulations and/or set forth by the Authority from time to time. (3) Only entities that have completed the onboarding process and received confirmation from the Authority shall avail, provide, and/or exchange data through NDEL, as the case may be.

  3. Entities Onboarding Process on NDEL.—(1) Entities seeking to onboard the NDEL shall submit an official request through a designated onboarding portal. Upon receipt, the Authority shall provide the relevant procedures and manner for onboarding and compliance requirements for the entities, depending upon the role of the entity, based on which it requires onboarding on NDEL, from time to time. The onboarding process ensures that each entity is on boarded, authenticated, and adheres to the standards, security protocol and regulations, as specified by the Authority. The entity shall establish secure connectivity and fulfill the necessary configuration requirements as per the Authority’s guidelines. The onboarding of the entity shall be subject to verification by the Authority, and all interactions shall comply with the security, authentication, and data protection standards specified by the Authority or as per applicable laws. The entity shall obtain a PKI Certificate from the National Certificate Authority to meet the PKI requirement to provide or avail services through NDEL, as a mandatory part of the NDEL onboarding process. (2) After the entity has completed the NDEL onboarding process as defined in sub-regulation (1), the on boarded entity shall request access, which, upon approval, will be provided access to the API manager. The Authority shall assess and approve or reject the request based on its internal procedures. Upon approval, the entity shall receive secure login credentials to access NDEL. API access shall be granted through secure and verified channels, and all usage, including authentication, shall be securely recorded in the Data Proof Transaction Layer for audit and verification purposes: Provided that the entity shall not be on boarded to the NDEL unless it specifies the services it intends to provide and those it intends to consume through the exchange layer. (3) Once the NDEL’s registration process outlined in sub-regulations (1), and (2) is completed, any on boarded entity requiring access to the citizen’s data held by the Authority in National Data Warehouse, or any other citizen’s database through the interoperability mechanism of NDEL, shall ensure full compliance with applicable technical standards and procedures specified by the Authority. The citizen shall be informed about the on boarded entity requesting access to their data, and the specific data fields being requested. No data of a citizen will be shared in the course of service provision or consumption unless the individual provides explicit consent. (4) To ensure a valid and binding explicit consent of the citizen for data sharing under the NDEL framework, the Authority shall enable and recognise mobile-based consent, conducted via a citizen’s registered mobile device. Such consent shall be obtained using a secure interface linked to the citizen’s Digital ID. All mobile-based consent actions must be cryptographically recorded, time-stamped, and made auditable for verification and compliance purposes. (5) All consent transaction logs shall be recorded and maintained by the Authority and the on boarded entity for a period to be specified by the Authority for regulatory, audit, and non-repudiation purposes.

  4. Suspension or Revocation of NDEL connectivity.—(1) The Authority either on its motion or upon the request of the Government or any of the on boarded entities operating under the law, in the interest of national security, reserves the right to immediately suspend or revoke an on boarded entity’s access to the NDEL if, at any time during the period of access: (a) for the purpose of the prevention, detection, investigation, or prosecution of any criminal offence; (b) for the enforcement of any legal right or claim; (c) for the enforcement of any decree of court, tribunal, or decision by a judicial or quasi-judicial forum; (d) to prevent data breaches or unlawful and fraudulent activities carried out by the user; (e) if the on boarded entity fails to continue to meet the eligibility criteria specified under regulation (2); (f) on boarded entity breaches any provision of the Ordinance, the applicable rules or regulations, the onboarding agreement, terms and conditions, or technical or operational standards; (g) on boarded entity fails to comply with any direction, or legal instrument issued by the Authority under regulation 20; or (h) on boarded entity engages in any conduct that, in the opinion of the Authority, poses a cyber security risk or may compromise the confidentiality, integrity, or availability of the NDEL or its interconnected information systems: Provided that no order of suspension or revocation shall be passed without first providing the on boarded entity a reasonable opportunity to be heard.

  5. Integration of NDEL with Digital ID.—(1) All on boarded entities interfacing with NDEL for seamless and secure exchange of data shall have access to API Gateway hosted by the Authority possessing citizens’ data, including integration with Digital ID, which is required by an on boarded entity to access citizens data for authentication and verification purposes, under the applicable Digital ID Regulations. (2) The citizen’s data shall only be accessed by the on boarded entities for authentication and verification purposes as per the consent of the Digital ID user and on the fulfilment of other mandatory requirements outlined in the Digital ID Regulations. (3) To ensure interoperability between NDEL and Digital ID, and any other information systems the Authority may, from time to time, issue technical standards, guidelines and other requirements for efficient operations. (4) The NDEL shall provide seamless and secure information exchange between boarded entities to verify citizens’ credentials, and exchange of data from the Authority to on boarded entities, as well as between the on boarded entities, which shall be stored in a digital vault as verifiable credentials.

  6. Establishment of Secure NDEL Connectivity.—(1) Before initiating secure access to NDEL, each on boarded entity shall be required to deploy security protocols on its information systems for establishing a protected data exchange channel, as issued by the Authority. (2) Each on boarded entity shall ensure compliance with the following measures: (a) ensure the safety of its private keys; (b) acquire a PKI Certificate from the National Certification Authority; (c) ensure the confidentiality, integrity, and protection of information systems and data from any disruption, security risks and provide regular backup in case of destruction; (d) ensure safe and effective operation of the information systems connected with NDEL, and comply with the provisions of the Data Sharing Regulations and Data Sharing Agreement between the Authority and on boarded entities; (e) hardware, software or any other technical components of any type, model, or make connected with NDEL, shall comply with the technical standards and security protocols specified or approved by the Authority; (f) shall meet the minimum technical and legal compliance requirements, as specified by the Authority from time to time; (g) in case, the server or any information system of an on boarded entity is shared by its subsidiary, the connection must be encrypted or any other security protocols specified by the Authority; (h) regularly update the security server software as per the internal security guidelines of an on boarded entity or according to instructions rendered by the Authority; (i) shall ensure that while data is exchanged through NDEL, the integrity and confidentiality of the data remain unchanged; (j) the management of connectivity with NDEL shall be governed by standards and protocols, etc., specified by the Authority; (k) ensure the implementation of the principle of privacy by design; (l) follow common operational security standards. (2) Any information system, including associated databases, servers or any other infrastructural components or functions of NDEL, including but not limited to data exchange, shall be hosted exclusively within the territorial jurisdiction of Pakistan. Under no circumstances shall any part of the NDEL infrastructure, or any data associated therewith, be hosted, mirrored, transferred, or processed outside the territorial jurisdiction of Pakistan to ensure national data sovereignty and compliance with applicable data protection laws, and mitigate risks associated with cross-border data exchange.

CHAPTER-II: DATA SHARING BETWEEN AUTHORITY & ON BOARDED ENTITIES

  1. Lawful Sharing of Data.—(1) The Authority shall ensure that the data of citizens shall only be shared with the on boarded entities for legitimate purposes in compliance with the Data Sharing Regulation, and strictly subject to the explicit consent of the citizen obtained through the consent management mechanism prescribed under the Digital ID Rules. (2) On boarded entities shall comply with the following obligations in the course of sharing data with other on boarded entities through the NDEL: (a) the collection and sharing of data shall be for lawful purposes as per the Ordinance, rules, regulations, or any other applicable laws; (b) the sharing of citizens’ verifiable credentials shall strictly adhere to the Data Sharing Regulations; (c) any citizen’s data shared between the on boarded entities shall be performed with the explicit consent of the citizen; (d) the citizen shall be informed about the purpose of shared data; (e) to carry out authentication and verification services; however, any secondary purpose, including, but not limited to re-sharing, selling, or unauthorised disclosure is strictly prohibited; (f) data with third parties shall only be shared after executing the Data Sharing Agreement as per the Data Sharing Regulations; (g) the minimum amount of data must be shared to achieve the defined purpose; (h) all data sharing transactions through NDEL shall be auditable and traceable via secure logs maintained for a period to be specified by the Authority; (i) for any other purposes as defined under the Data Sharing Regulations. (3) No on boarded entity data or related documents shall be stored or maintained by the Authority; storage and management of such data shall rest solely with the respective on boarded entity. (4) All other aspects of data sharing, including but not limited to principles, process, restrictions, format and prohibitions, shall be governed by the Data Sharing Regulations. (5) Notwithstanding anything to the contrary contained in these Regulations, the data of a citizen may be shared with a law enforcement agency on boarded on NDEL or any agency authorised by the Authority, where such disclosure is: (a) mandated under any applicable law; (b) necessary for national security, maintenance of public order, or public safety; (c) required for the prevention, detection, investigation, or prosecution of a criminal offence; (d) for obtaining legal advice while ensuring its integrity and secrecy; (e) required for or in connection with any legal proceedings; (f) for the administration of justice under orders of a court of competent jurisdiction, not inferior to the High Court. In such cases, the requirement for obtaining the explicit consent of the citizen may be exempted, subject to prior review and written approval by the Authority, which shall assess the legality and necessity of the request as per applicable laws, policies, and directives.

  2. Data breach notification.—(1) In the event of a data breach affecting the confidentiality, integrity and data, information systems, or databases connected to the NDEL or affecting any data sharing transaction carried out through NDEL, the on boarded entity shall, without undue delay and where reasonably possible, within 12 hours of becoming aware of the breach, notify the Authority of such incident. (2) If the notification is delayed beyond 12 hours, the on boarded entity shall provide the Authority with a notification of a data breach, accompanied by documented justification for the delay. (3) Upon receipt of a data breach, the Authority with a notification of a data breach, accompanied by documented justification for the notification, the Authority shall evaluate the nature and extent of the breach and may, at its discretion, direct the implementation of additional remedial measures. The Authority also reserves the right to initiate an investigation and/or commission an independent external audit, as deemed necessary. (4) The data breach notification shall provide at least the following information:— (a) a description of the nature of the breach, including, where possible, the categories and approximate number of data records affected; (b) name and contact details of the designated data protection officer or another point of contact for additional information if required; (c) potential consequences of the data breach; (d) corrective measures adopted or proposed to be taken by the on boarded entity to address the breach and limit adverse impacts. (5) All on boarded entities shall maintain a mandatory Data Breach Response Plan and shall conduct periodic simulations to ensure its effectiveness. The response plan shall be provided to the Authority upon request for review, to ensure compliance or approval, if required. (6) The on boarded entity shall maintain a register for recording all data breaches, comprising the facts concerning data breaches; their effects, and the remedial action taken. The documentation shall be accurate and sufficient to enable the Authority to verify compliance.

  3. Conditions for Cross-Border Transfer.—(1) On boarded entities shall ensure that their data centres or cloud storage facilities and servers or any other information system or databases connected with NDEL, which are used for handling the data of users and authentication services or any other data of citizens, must be located within the territorial jurisdiction of Pakistan. (2) Each on boarded entity shall be required to report its daily and monthly transaction volumes to the Authority to enable the implementation and enforcement of applicable quota limits by the Authority. (3) All on boarded entities shall ensure that any cross-border data transfer complies with the applicable data protection laws. In the absence of such laws, all cross-border data sharing shall adhere to the Data Sharing Regulations or any relevant rules, standards, policies, procedures, and guidelines issued by the Authority from time to time. In all cases, explicit and informed user consent shall be obtained prior to the transfer of personal data across borders.

CHAPTER-III: TRANSACTION LOGS & AUDIT

  1. NDEL Transaction Logs.—(1) The Authority shall be responsible for storing and maintaining transaction logs solely for those services where the Authority’s APIs are accessed through the NDEL, and where such access involves databases maintained by the NDW. (2) The Authority shall retain only the minimum necessary transaction data for an indefinite period. The integrity and originality of such logs shall be preserved as per Sections 5 and 6 of the Electronic Transactions Ordinance, 2002

  2. Storage and Maintenance of Transaction Logs.—(1) Each on boarded entity shall maintain immutable logs of all its data transactions processed through NDEL, the logs shall include, but not be limited to, the following: (a) details of the on boarded entity initiating the transaction; (b) the purpose for which the transaction was performed, as well as the time and date of the transaction and the user’s consent; (c) any other requirement as specified by the Authority from time to time; (2) The logs in sub-regulation (1) shall be maintained to ensure integrity, accuracy, and tamper-evidence, and protected against un-authorised access, alteration or deletion. (3) The on boarded entity shall retain the logs of transactions for five years from the date of each respective transaction, unless a longer period is required by order of the Authority. (4) The on boarded entity shall ensure that access to logs shall only be limited to authorised personnel and shall only be used for regulatory, security monitoring, audit, or lawful investigation purposes. (5) Upon expiry of the duration specified in sub-regulation (3), the logs shall be archived or permanently deleted except where retention of logs is required pursuant to a judgment passed by a court not inferior to that of the High Court or where the court has rendered explicit direction to retain logs in subjudice matters.

  3. Audits and Inspections of Entities.—(1) All the entities on boarded by the Authority on NDEL, shall get their systems and operations audited by an information systems auditor certified by a recognised accreditation body to ensure compliance with the technical standards and specifications for NDEL to be specified by the Authority, and furnish the audit report to the Authority, upon request or at such time as specified by the Authority. (2) Without prejudice to sub-regulation (1), the Authority may conduct audits of the operations or inspections of entities’ systems and infrastructure, either directly or through a certified auditor appointed by the Authority. The frequency, time and manner of such audits shall be as may be specified by the Authority from time to time. (3) Any on boarded entity subject to audit shall extend full co-operation to the Authority or any agency duly approved and/or appointed by the Authority to carry out the audit process. Such entity shall grant unrestricted access to its procedures, records and information in relation to services availed through NDEL. The cost and any allied expenses associated with audits shall be borne by the concerned on boarded entity. (4) Upon identification of any deficiency, the Authority may, by written notice, direct the concerned on boarded entity to: i. furnish clarifications or information as required by the Authority ii. rectify the identified deficiencies or take action necessary corrective measures as specified by the Authority within the communicated stipulated time frame (5) Notwithstanding anything contained in sub-regulation 4 and without prejudice to any action that may be taken under the Ordinance, the Authority may initiate action on its own motion on identification of any deficiency based on the findings of the audit.

SECURITY OBLIGATIONS & CYBER INCIDENT RESPONSE

  1. Security Obligations of the Personnel.—(1) All personnel of the Authority engaged in the management, operations, or maintenance of NDEL shall comply with the information security policies, technical guidelines and specifications, standard operating procedures, and any other security protocols issued by the Authority from time to time. (2) In the event of a breach involving any personnel, such individual shall be liable to disciplinary action as per the procedures specified by the Authority for this purpose: Provided that no such action shall be taken without affording the concerned personnel a reasonable opportunity of hearing.

  2. Security Obligations of On boarded Entities.—(1) The entities on boarded by the Authority for dispensing services in relation to NDEL shall: (a) ensure full compliance with the information security policy or any other security policy or standards specified by the Authority; (b) periodically report compliance status as required by the Authority from time to time; (d) ensure that data, records, and any critical information exchanged through NDEL shall be protected from loss, destruction, falsification, unauthorised access and unauthorised disclosure; (e) maintain confidentiality of any technicalities or critical information shared by the Authority for the smooth functioning of the operations of NDEL during the term and on termination of the agreement for a period to be specified by the Authority; (f) ensure their employees and other associated personnel dealing with NDEL must sign a non-disclosure agreement containing robust provisions to maintain confidentiality, security, and penalties in case of breach; (g) ensure that the employees, having access to the information system connected to the NDEL, undergo necessary background checks, and only authorised personnel are granted access to such restricted areas to prevent data leakage, compromise or misuse. (2) The CISO is responsible for overseeing and coordinating the implementation of information security strategies, policies and programmes across the Authority. (3) The CISO or any other designated officer, with the approval of the Authority, may develop any other security-related programmes and initiatives to ensure proper dissemination of such programmes, including monitoring and compliance.

  3. Cyber Incident Response Measures by Authority.—(1) The Authority must ensure the implementation and enforcement of robust security standards and protocols to be followed at all times to protect the reliability of NDEL as well as ensure secure interoperability of information systems connected through NDEL for secure transactions, from any security breach, compromise or cyber-attack. (2) In case of a security breach, compromise, or any attempt made to breach or partly compromise the reliability of NDEL, the Authority, without undue delay, will follow the following steps: (a) incident reporting; (b) incident response and recovery; (c) incident investigation, analysis and adequate remedial measures shall be taken; (d) any other function as assigned by the Authority from time to time.

  4. Cyber security Incident Response for On boarded Entities.—(1) This applies to the following: (a) any on boarded entity participating in NDEL; (b) any on boarded entity whose participation in the NDEL has been temporarily suspended. (2) Any on boarded entity referred to in sub-regulation (1) shall notify the Authority of the following incidents in accordance with this regulation: (a) a cyber security incident; or (b) any breach, compromise or fraud incident. (3) The notification must include the following information: (a) the on boarded entity’s name; (b) the contact details of the on boarded entity, including name and contact details of the designated officer responsible for incident reporting; (c) the NDEL services impacted by the incident; (d) a description of the nature and scope incident; (e) the following details of the incident, as known to the on boarded entity: (i) the date and time of the incident; (ii) the date of detection or occurrence of the incident; (iii) the method or source of detection of the incident; (iv) the severity level of the incident; (v) whether the incident has been resolved; and (vi) if the incident has been resolved, a summary of the remediation process and time taken to resolve. (f) Any remedial or mitigation measures that the on boarded entity has taken or plans to take to deal with the incident or risk to connected NDEL services; (g) Whether the incident has been referred to any law enforcement agency or to any other cybercrime investigation agency, and if so, the name of such authority, along with the date and time of referral. (4) The notification shall be made as soon as practicable, but no later than twelve (12) hours after the on boarded entity becomes aware of the incident or has reasonable grounds to suspect that an incident has occurred. (5) In a case where it is not practicable to provide complete or some information required by sub-regulation (3) within the time specified in sub-regulation (4), the on boarded entity shall be deemed complied with sub-regulation (3) if the on boarded entity: (a) submits an interim notification within the required time under sub-regulation (3), including reasonably available information at that time; (b) takes reasonable steps to obtain the remaining information at the earliest possible time; (c) provides any outstanding information within twenty-four (24) hours of it becoming available. (6) Without prejudice to the generality of the foregoing clauses, any cyber attack, threat, or an attempt to breach or compromise the information system of any on boarded entity shall also be reported to the Sectoral CERT, which shall provide the responsive services to its constituents, including incident management, vulnerability management and artefact handling, as per sub-rule (2) of rule 12 of CERT Rules, 2023.

CHAPTER-V: COMPLIANCE & PENALTIES

  1. Compliance by On boarded Entities.—(1) Each on boarded entity connected with the NDEL will ensure seamless and secure data exchange services across Government and on boarded private institutions in a lawful manner, shall comply with the following obligations: (a) establish and maintain necessary infrastructure, including systems, hardware systems, interoperability standards, processes, standardised protocols and technologies, as well as ensure adequate security measures and adhere to Pakistan Security Standards, as specified by the Authority from time to time; (b) establish secure network connectivity with the Authority through NDEL for sharing citizens’ data, and providing Digital ID services, including authentication, and also sharing of data between two or more on boarded entities; (c) employ only those software and technologies that are registered and approved by, or certified by, the Authority and comply with the applicable standards and technical specifications as laid down by the Authority for this purpose; (d) regularly monitor the operations and test the performance and compliance of its services with the terms and conditions, technical standards, directives, and specifications issued and communicated by the Authority in this regard, from time to time; (e) employ only personnel with the requisite qualifications and expertise to manage systems, infrastructure and processes and undertake such works; (f) obtain prior approval from the Authority before appointing any third party to conduct any part of the operations or services employing the use of NDEL on its behalf; (g) in the event of any investigation involving any NDEL services or data sharing related fraud (s) or dispute (s), the on boarded entity shall extend full cooperation to the Authority or any agency appointed or any other designated investigation agency, including, but not limited to granting access to premises, records, systems, personnel and all other relevant resources or documentation. Failure to cooperate shall be considered an offence and penalised under section 30(1) of the Ordinance. (h) the on boarded entity shall be solely responsible for the security and accuracy of part of its NDEL operations, including any operations or services that have been subcontracted to third parties, if approved by the Authority. The on boarded entity shall ensure that the NDEL-related operations of such third parties shall comply with all applicable technical standards and specifications provided by the Authority. (i) on boarded entities shall, at all times, adhere to applicable provisions of the Ordinance, rules, regulations, policies, manuals, procedures, specifications, standards, and directions issued by the Authority for the management of the NDEL services.

  2. Non-Compliance by On boarded Entities.—(1) Where any on boarded entity under these regulations, as the case may be— (a) fails to comply with procedures, technical standards, protocols, specifications, security and interoperability standards, standardised protocols or directives issued by the Authority from time to time; (b) breaches any of its obligations or contravenes any applicable provisions of the Ordinance, rules and regulations; (c) employ NDEL services for any purposes besides those outlined in these regulations; (d) fails to provide any information as required by the Authority; (e) fails to cooperate in any inspection, investigation, inquiry or technical audit initiated by the Authority; shall, in addition to any other penalty to which he may be liable under any other law, be penalised under sub-section (1)(f) of section 30 of the Ordinance, including suspension of such on boarded entity’s operations: Provided that no termination of the on boarded entity’s service shall occur without giving the opportunity of hearing before the Authority. (2) Upon termination of services, the on boarded entity’s accreditation status will be revoked, and NDEL connection or any services routed through it shall cease immediately. The on boarded entity shall cease to provide all sorts of services for Digital ID, or remove any affiliated branding or associated logos of Digital ID services and shall comply with the Authority requirements for closure as specified from time to time.

  3. Liability for Contravention of the Regulations.—Without prejudice to any action that may be taken under the Ordinance and rules, any contravention of these regulations shall constitute a violation of Sections 30(1)(f) and 28 and 29 of the Ordinance, as the case may be.

  4. Offences and Enforcement.—Any person who engages in, unauthorized access, use, transmission, electronic fraud, tampering, interception, data breach, cyber attack, or any other unlawful activity involving the Authority, or involving two or more information systems of entities interconnected through NDEL, or who misuses the NDEL in any manner, shall be deemed to have committed an offence under the Prevention of Electronic Crimes Act, 2016 (XL of 2016) and shall be dealt with as per the applicable provisions thereof

CHAPTER-VI: MISCELLANEOUS

  1. Confidentiality.—(1) All procedures, policies, criteria, specifications, technical standards and security protocols or any critical document pertaining to NDEL designated as confidential, shall be treated as such by all personnel of the Authority. Disclosure of such information shall be limited to the concerned parties, as approved by the Authority, only to the extent necessary for implementation and for giving effect to the security measures. (2) Without prejudice to the generality of the foregoing, any information not expressly permitted under the Act, rules, or regulations shall not be shared outside the Authority. It includes, but is not limited to, concept paper, technology details, and design, network architecture, information security policy and processes, software codes, specification, internal reports, audit and assessment reports, applications details, asset details, contractual agreements, current and future planned infrastructure details, protection mechanism, and system operational capabilities. (3) Failure to comply with sub-rules (1) and (2), shall be subject to enforcement action under section 28 of the Ordinance.

  2. Power to Issue Clarifications and Guidelines.—To ensure effective implementation of these regulations, in any matters arising due to the application or interpretation, the Authority shall have the power to issue clarifications and guidelines from time to time.

  3. Power to issue Policies, Directives, etc.—The Authority may, from time to time, issue policies, technical standards and procedures, specifications, directives, criteria or any other instruments not inconsistent with the provisions of these regulations to give full effect to the purposes and objectives of these regulations.

  4. Delegation of Powers or Functions.—(1) Any act or thing which is required to be or May be done by the Authority to carry out the purposes and objective of these regulations may also be carried out by the chairman or a member or a registration officer, or any member of its staff, or an expert, consultant, adviser, or other officer or employee of the Authority to whom the Authority has delegated the related power or function by general or special order in writing under section 37 of the Ordinance. (2) The Authority shall retain the discretion to determine whether such act or thing carried out under sub-regulation (1) by the personnel mentioned therein falls within the scope of the delegated authority.

  5. Periodic Review.—The Authority shall periodically review these regulations and, when necessary, propose amendments to address emerging technological advancements, mitigate threats and risks, and cater for changes in applicable laws or policies.

  6. Severability.—If any provision of these regulations, or the application thereof, stands invalid or unenforceable, such provision shall be severed, and it shall not affect the remaining provisions or their application, which shall continue to be in full force and effect.