Pakistan’s Data Center Boom Runs Without Licensing Framework, Audit Raises Alarm

Pakistan’s growing data center market continues to operate without a dedicated licensing framework, despite the country’s Cloud First Policy and existing telecom laws requiring regulatory oversight of infrastructure linked to communication systems, according to audit observations.
The issue has raised serious concerns over weak regulatory governance, cybersecurity exposure, and the protection of critical digital infrastructure at a time when cloud computing, data storage, and digital services are becoming increasingly important for government departments, businesses, and citizens.
According to audit findings, the Pakistan Telecommunication Authority did not bring data center services under the licensing regime and did not submit any licensing template or information package to the federal government for approval. The audit observed that this failure left data centers outside formal regulatory control, even as the sector expanded across the country.
The matter is linked to the Pakistan Telecommunication Re-Organization Act, 1996, which provides the legal basis for telecom licensing in Pakistan. Under Section 20(1) of the Act, no person is allowed to establish, maintain or operate any telecommunication system, or provide any telecommunication service, unless a licence has been obtained under the law.
The audit also referred to Section 2(h) and 2(u) of the Act, which define “licence” and “telecommunication system.” The definition of a telecommunication system includes electrical, electromagnetic, electronic, optical or opto-electronic systems used for the conveyance, switching or reception of information. On this basis, the audit argued that data centers fall within the scope of telecom systems and should not have been left outside the licensing framework.
The audit noted that the non-inclusion of data centers in the licensing regime not only deprived the national exchequer of potential revenue but also left the market segment unregulated and vulnerable with respect to the security of critical telecom infrastructure.
The findings come nearly four years after the federal government introduced the Pakistan Cloud First Policy 2022, which was designed to encourage cloud adoption and treat data centers and cloud data centers as part of the country’s ICT infrastructure. The policy was aimed at reducing duplication of government-owned data centers, improving efficiency, strengthening data security, and encouraging the migration of public-sector data to secure cloud platforms.
However, the audit observed that implementation has remained weak. It said that despite the policy’s objectives, a proper licensing regime for data centers has still not been put in place. The policy was expected to support data center licensing, cloud infrastructure development, data security standards, and the movement of government data to cloud-based systems.
PTA’s position, according to the audit record, was that the federal government had issued the Cloud First Policy 2022 to encourage cloud adoption and that data centers and cloud data centers were being considered as ICT infrastructure. The authority also stated that a revised licensing framework was under preparation and that the Ministry of Information Technology and Telecommunication was already in the process of acquiring the services of a consultant for the matter.
PTA further maintained that the current licensing regime already distinguishes between operators providing infrastructure and services and those providing services alone. It said there was a need to further enhance and optimize the licensing framework to address emerging technological market trends, adding that revised licence templates and information packages would be prepared with the approval of the federal government.
The audit, however, rejected the reply as “not plausible,” stating that data centers come under the definition of telecommunication systems as per the Pakistan Telecommunication Re-Organization Act, 1996. It also pointed out that PTA had already issued the Critical Telecom Data and Infrastructure Security Regulations, 2020, for the security of critical telecom data and infrastructure related to the telecom sector.
The audit further noted that PTA is mandated to conduct a bi-annual assessment to review the licensing policy framework under Clause 5.2 of the Telecom Policy 2015. It said the regulator was required to enhance and optimize the licensing regime to cater to emerging technological markets and trends with the approval of the federal government.
The absence of licensing has become more significant as data centers continue to emerge in different parts of the country. Sources said that unregistered or weakly monitored data centers may expose sensitive citizen, business, and government data to cybersecurity risks, particularly where there is no uniform framework for infrastructure standards, compliance, service continuity, disaster recovery, and data protection.
The issue was discussed in a Departmental Accounts Committee meeting held on December 26 and 27, 2024. The audit recommended that the matter be referred to the federal government for necessary clarification, with intimation to audit authorities.
The development highlights a wider gap between Pakistan’s digital policy ambitions and regulatory implementation. While the government has promoted cloud adoption, digital transformation and cybersecurity as national priorities, the lack of a data center licensing framework suggests that regulatory systems have not kept pace with the country’s expanding digital infrastructure.
Mobile Phone Taxes Portal
Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.
Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).
Explore NowFollow us on Google News!