Data localisation, the requirement that certain categories of data be stored on infrastructure physically located within Pakistan, is embedded in CTDISR-2025's data privacy requirements and reflects a broader Pakistani regulatory policy of keeping citizens' data under Pakistani jurisdiction. For ISPs, this creates practical questions about cloud service use: which services can be used freely, which require specific configuration, and which are incompatible with localisation requirements for the data types they handle.
What Data Must Stay in Pakistan
The data categories most clearly subject to localisation requirements for Pakistani ISPs are subscriber identity data (names, CNICs, contact details, addresses collected at subscriber onboarding) and subscriber connection records (authentication logs, session records, CGNAT translation logs that associate subscribers with IP addresses and timestamps).
These categories are subject to localisation because they are the data most directly tied to Pakistani citizens' identity and activity, and because they are the data required for lawful intercept requests, abuse complaints, and regulatory investigations that Pakistani authorities need to be able to access.
Operational data that does not directly identify subscribers or their activity is generally not subject to the same localisation requirements: internal business communications, non-subscriber financial records, and generic technical logs without subscriber attribution are lower priority for localisation purposes.
Assessing Cloud Services
The cloud service assessment question is: for this specific service, where does the data I send to it actually reside, and is that compatible with localisation requirements given the type of data involved?
For services that process subscriber identity or connection data, the data must reside on infrastructure in Pakistan. Cloud providers offering a Pakistan region or allowing data residency configuration to keep data in the Middle East under certain legal frameworks may be assessed case by case, but the conservative and defensible position is in-Pakistan infrastructure for these data categories.
For major platforms commonly used by Pakistani ISPs: Microsoft 365 for staff email is generally not subject to subscriber data localisation because staff email does not contain subscriber data systematically. The Microsoft 365 admin portal and any integrations that pull subscriber data into cloud-hosted systems require assessment. Similarly, a cloud-hosted billing platform that stores subscriber CNICs and payment records requires localisation assessment: if the platform's servers are exclusively overseas, either the data needs to be migrated to a compliant platform or the compliance gap needs to be formally documented with a remediation plan.
Assess each significant cloud service by: identifying what subscriber data it processes, determining where that data is stored (provider documentation, data processing agreements, and terms of service are the sources), and determining whether that storage location satisfies localisation requirements. Document the assessment with a date.
Documentation for Compliance
The documentation that satisfies the data localisation element of a CTDISR audit is: a register of cloud services and significant data processors used by the organisation, for each service an assessment of what subscriber data it processes and where it stores it, and for any service where localisation compliance requires specific configuration, evidence that the configuration is in place.
For services where full localisation is not achievable (a specific tool with no Pakistani data centre option), document the gap, the risk acceptance decision, and any compensating controls or migration plan. Proactive documentation of a known gap with a remediation plan is a significantly better audit position than a gap discovered by the auditor without prior acknowledgement.
The data localisation assessment also informs your Section 7 Privacy Impact Assessment process: any new cloud service that processes subscriber data should have a localisation assessment as part of the PIA conducted before the service is adopted.
For cloud service assessment and configuration as part of a security posture review, Cloud & Email Security covers the assessment and remediation work. For managing data localisation assessment records alongside all CTDISR compliance evidence, ComplianceIQ provides the structured tracking framework.