@hijakamran
Hija Kamran
11 months
The law that's supposed to protect your data punishes you if you wish to protect your data (and yourself). A recent Lahore High Court judgement can give some perspective into what this means for your privacy. See here:
@hijakamran
Hija Kamran
11 months
The Lahore High Court just ruled that analysis of mobile phone data without court order is unconstitutional, and hence illegal. The court said that mobile phone is like a home of the person, and right to privacy in home in a fundamental right (A.14).
5
83
233
2
35
224

Replies

@hijakamran
Hija Kamran
11 months
🚨 The Pakistan govt just approved the data protection law that you must pay attention to. I read it so you don't have to (even though you should). Here's a long thread on the law and just some of the things that are very worrying.
44
629
2K
@hijakamran
Hija Kamran
11 months
- Starting w the process of passing the law: No one has seen the officially passed law. We got a copy titled "Final Draft" with no date through sources in media. Laws that are passed behind closed doors are always intended to stifle civil liberties & never in favour of citizens.
2
39
297
@hijakamran
Hija Kamran
11 months
- Riddled with ambiguous terms like "vital interests", "legitimate interests", "national security", the law is pretty interesting. - S.7(1)(i) that says if a person fails to provide mandatory data to data controller demanding that data, the person will face "consequences".
4
31
242
@hijakamran
Hija Kamran
11 months
Side note: Article 13 of the Constitution protects citizens from self-incrimination.
1
12
172
@hijakamran
Hija Kamran
11 months
- The law says data controller & processor will notify in writing to citizens about data collection, processing, purpose, sharing etc. This just means that you'll have to read Terms of Services before you agree to them.
1
13
147
@hijakamran
Hija Kamran
11 months
- This is IMPORTANT: The law enables citizens to withdraw consent to process or collect more data at any point but does not say how and what will be the conditions. In previous drafts, there was a lengthy process of submitting application+fee when withdrawing consent (contd.)
1
14
152
@hijakamran
Hija Kamran
11 months
Civil society worked to have it changed in the last draft that was shared for public consultations in 2021. Our rec was to make the process of withdrawing consent as simple as giving consent, AND there should be no monetary charges or "fee" for doing so.
1
9
119
@hijakamran
Hija Kamran
11 months
On another note, if the data controller fails to respect the request to withdraw consent for data processing, it will be liable to pay a fine of upto 50,000 USD.
1
11
105
@hijakamran
Hija Kamran
11 months
- This law is quite vague, especially in terms of timeline. It says data controllers have to retain records of all requests/applications but doesn't specify for how long. But what caught my eye is the requirement of data controller to "regularly" update the Commission abt
2
15
103
@hijakamran
Hija Kamran
11 months
the type of data they are collecting & why. How regularly and at what interval this update needs to happen, is not specified. Will this be a public document? Transparency is important, not just for data controllers and processors, but for the commission too.
1
11
97
@hijakamran
Hija Kamran
11 months
- Data controller has to inform the Commission and the data subject about any data breach within 72 hours, but it's not important if the data breach doesn't infringe on the subjects' rights or freedoms. Wonder who decides which privacy violation is violation of rights/freedoms?
1
10
87
@hijakamran
Hija Kamran
11 months
If the data controller does not inform of the breach within 72 hour, they can do it at any time afterwards with a valid reason for the delay. What constitutes a "valid" reason? & why is there no penalty for not informing citizens immediately that their data has been compromised?
2
11
81
@hijakamran
Hija Kamran
11 months
Careem's 2018 data breach was reported to the public months after it happened. There were no consequences of this delay.
1
8
80
@hijakamran
Hija Kamran
11 months
- S.16(3) says that if a person wants to access their data that the data controller has, they will have to pay a fee (how much?) to controller. My question here is whether the data subject will be paid when the data controller like tech companies will sell this data for profits?
2
10
76
@hijakamran
Hija Kamran
11 months
Giving rights to people and then putting a fee to exercise those rights is not actually granting rights. You're still barring people from accessing/exercising their rights that the law in question is supposed to be granting unconditionally.
2
11
83
@hijakamran
Hija Kamran
11 months
🚨 - S.24 says that scope of data disclosure can be broaden in some cases, & can go beyond what data subject agreed to. One of these instances is if the data disclosure is important to curb or "detecting a crime, or for investigations".
1
7
61
@hijakamran
Hija Kamran
11 months
Its implications will directly be seen when and if journalists, activists, human rights defenders or dissidents are targeted and their data is accessed without their consent or knowledge to stifle their civil liberties.
1
7
66
@hijakamran
Hija Kamran
11 months
- The law mandates data controllers to process Critical Personal Data of data subjects on servers or digital infrastructures located within Pakistan, which means servers will have to be localised. Critical Personal Data definition in the photo:
Tweet media one
1
8
58
@hijakamran
Hija Kamran
11 months
Localising servers comes w significant problems pertain to the impact to digital economy which PK can't afford at the moment given the situation of the country. The high cost of setting up & maintaining servers will act as a deterrent for companies to do business in the country.
2
12
68
@hijakamran
Hija Kamran
11 months
Not to mention, it impacts small businesses significantly who might not have resources to setup and maintain their own servers and rely on servers located elsewhere in the world to store data and provide services. PK can't afford to pass legislations with impact of such nature.
1
6
62
@hijakamran
Hija Kamran
11 months
- The law also gives powers to commission to make mechanism to share sensitive personal data of individuals w the govt when it's a matter of "national security" or "public order". This is another way of weaponising law against those who exercise their right to freedom of speech.
Tweet media one
1
28
81
@hijakamran
Hija Kamran
11 months
This is especially important since the Commission is being formed under the administrative control of the Federal Government. So the govt can influence these mechanisms to have something that favours them and not necessarily the citizens.
1
8
53
@hijakamran
Hija Kamran
11 months
- PENALTIES The penalties in case of violation of this law entail fines of upto 125,000 USD, and repeated violation fined at upto 250,000 USD (or equivalent PKR). Those pertaining to sensitive personal data are fined at upto 500,000 USD (or equivalent in PKR).
1
8
50
@hijakamran
Hija Kamran
11 months
Where the offence pertains to critical personal data (which is the data controlled by public service providers), the fine is upto 1,000,000 USD or equivalent. Interestingly this is the only section that mentions "as the Commission deems appropriate."
1
7
53
@hijakamran
Hija Kamran
11 months
Penalties are probably not as worrying as the rest of the law, but did catch my eye especially since the government being the largest data collector in the country is also liable to comply with the law. Would be interesting to see how exemptions are created.
8
7
69