Pakistani ISPs handle personally identifiable information at scale: subscriber names, addresses, CNICs, contact details, payment information, and usage data that can reveal sensitive details about individual behaviour. CTDISR-2025 Section 7 governs how this data must be handled, where it must be stored, and what governance processes must be in place around it.

Section 7 requirements have four main components: data localisation compliance, PII handling procedures, data retention and disposal policies, and privacy impact assessments for new systems. Each of these is audited, and the common gap is having implicit practices that aren't documented rather than having genuinely bad practices.

Data Localisation

Data localisation means that specified categories of subscriber data must be stored on infrastructure physically located within Pakistan rather than in overseas cloud storage or data centres. This reflects a regulatory policy of keeping Pakistani citizens' data under Pakistani jurisdiction and within reach of lawful disclosure requirements.

For ISPs, the data most clearly in scope for localisation includes subscriber identity data (name, CNIC, contact details, address as collected during subscriber onboarding) and connection data (authentication logs, session records, allocation of IP addresses to subscribers at specific times). Operational data like router configurations, internal communications, and billing records are more nuanced, but the conservative position is to treat any data that could identify a subscriber's activity as subject to localisation requirements.

The practical compliance path for most Pakistani ISPs is to ensure that RADIUS authentication logs, subscriber databases, and billing records are hosted on servers physically located in Pakistan. If you're using cloud platforms, the specific data centre region matters: a cloud service that offers a Pakistan region or a Middle East region with data residency commitments may satisfy the requirement where a service hosted exclusively in Europe or the US does not.

Where cloud services are used for systems that touch subscriber data, you need documented evidence that you've assessed the data residency position and either confirmed compliance or migrated the relevant data to compliant infrastructure. An auditor finding subscriber data in an overseas-only cloud platform without any documented assessment of localisation requirements will record it as a finding.

PII Handling Procedures

Handling procedures cover how PII is collected, stored, accessed, transmitted, and shared. For each category of PII you hold, there should be a documented procedure covering: what data is collected and why (the legal basis and business purpose), where it's stored and on what systems, who has access and under what authorisation, how it's protected in transit and at rest, and what triggers an obligation to disclose it to a third party (such as a law enforcement request).

The access control dimension of PII handling intersects directly with Section 2: the people who have access to subscriber databases and authentication logs should have that access because their role requires it, and that access should be reviewed periodically. An IT administrator with read access to the full subscriber database for no documented operational reason is a Section 7 finding regardless of whether they've done anything inappropriate with it.

Transmission protection means that subscriber data moving between systems, between your network and cloud services, or between your systems and third parties, is encrypted in transit. TLS for API calls and database connections, and encrypted file transfer protocols for any bulk data transfers, are the standard implementation.

Data Retention and Disposal Policies

Section 7 requires documented policies covering how long different categories of data are retained and how they're disposed of when retention periods expire. For Pakistani telecom operators, retention requirements for subscriber data and connection records are influenced both by CTDISR-2025 and by PTA's lawful intercept and data disclosure obligations, which require that certain records be available for a defined period following subscriber activity.

A compliant retention policy covers: the categories of data retained, the retention period for each category, the legal or regulatory basis for that retention period, where retained data is stored, who has access to retained data, and the disposal procedure when the retention period expires.

Disposal procedures for subscriber data need to be actual deletion rather than just archiving: data that is retained indefinitely because nobody got around to deleting it is both a compliance gap and an unnecessary liability. For digital records, secure deletion (overwriting storage rather than just removing file system references) is the standard. For physical records like printed subscriber agreements, secure shredding with a destruction certificate is appropriate.

Privacy Impact Assessments

Privacy Impact Assessments are required for new systems that process PII. The purpose is to identify privacy risks in a new system's design before it's deployed rather than after, when remediation is much harder.

A PIA for a new ISP system should cover: what PII the system collects or processes, why it's necessary for the system to process that data, where the data is stored and for how long, who has access, what the risks to subscriber privacy are if the data is compromised or misused, and what controls are in place to mitigate those risks. This doesn't need to be a lengthy document: a structured one to two page assessment per system is adequate for most ISP deployments.

The trigger for a PIA is deploying a new system that processes subscriber data: a new billing platform, a new NOC ticketing system that logs subscriber details, a new analytics platform, or a new customer portal. Existing systems don't retroactively require PIAs, but when existing systems are significantly upgraded or reconfigured in ways that affect data handling, a PIA is good practice even if it's not strictly required.

For tracking PIA status, retention policy compliance, and all other Section 7 evidence alongside the full CTDISR framework, ComplianceIQ provides the evidence management and compliance tracking platform. For a scored gap assessment of your Section 7 posture alongside all 19 sections, ISP Audit identifies where the gaps are before an auditor does. For operators who need governance support including data privacy policy development, CISO-as-a-Service covers privacy policy work as part of the overall governance programme.