Lawful intercept (LI) is the legally authorised capability for government agencies to access specific subscriber communications or connection data through the licensed operator's infrastructure. For Pakistani ISPs, LI compliance is an obligation under the Telecommunications Act and PTA licensing conditions, operating alongside and integrated with the CTDISR-2025 framework.

This article covers the technical and procedural requirements of LI compliance for Pakistani ISPs, with the important caveat that LI is a legally sensitive area where your obligations and the specific mechanisms for meeting them should be confirmed with legal counsel familiar with Pakistani telecommunications law, in addition to the technical information here.

The Legal Basis

Pakistani ISPs are subject to lawful intercept obligations under the Pakistan Telecommunication (Re-organisation) Act 1996 and subsequent regulations. PTA has the authority to direct licensed operators to provide access to subscriber communications and connection data for authorised government agencies including intelligence services and law enforcement under appropriate legal authority.

The obligation is not to actively monitor all subscriber traffic at all times but to have the capability to intercept specific subscriber communications or provide specific subscriber data when legally directed to do so. The distinction matters: LI capability is the infrastructure readiness to respond to a legal direction, not ongoing surveillance.

Technical Capability Requirements

The technical components of LI capability for an ISP are: the ability to identify the specific subscriber based on a selector (a phone number, IP address, subscriber account identifier, or CNIC), the ability to extract that subscriber's connection metadata (authentication logs, session records, CGNAT translation logs showing which public IP and ports were assigned at what time) or in some cases live traffic, and a secure mechanism for delivering that data to the requesting agency.

For metadata delivery, the RADIUS accounting records and CGNAT port allocation logs discussed in other articles on this site are the practical source: given a specific public IP and port at a specific time, RADIUS accounting and CGNAT logs should be queryable to identify the subscriber account. This requires that those logs are retained for a sufficient period and are queryable by the identifiers that a legal request would specify.

For live traffic interception, more specialised infrastructure is required: equipment capable of directing a copy of a specific subscriber's traffic to an LI mediation device. This capability is typically required for larger operators and may not be practically required from day one for small district-level CVAS licensees, but the capability expectation scales with the operator's size and subscriber base. Confirm the specific technical standard required for your license category with PTA's relevant directorate.

Procedural Requirements

LI compliance requires defined internal procedures covering: how a lawful intercept request is received and verified (confirming the request is from an authorised agency with appropriate legal authority), who internally is authorised to initiate technical LI implementation, how the extracted data is securely delivered to the requesting agency, and how the LI event is recorded internally (without compromising the confidentiality of the interception).

The internal record of LI events, maintained confidentially, serves both as an audit trail of your compliance with legal requests and as evidence that the LI capability is functioning operationally. The record should note that a direction was received and complied with, without necessarily documenting the content of the interception (which may itself be subject to confidentiality obligations).

Intersection with CTDISR-2025

CTDISR-2025 does not directly govern LI capability as a named section, but the controls that support LI compliance are embedded throughout the framework: RADIUS accounting log retention (Section 9 and Section 7), CGNAT logging (Section 9), data localisation of subscriber records (Section 7), and access controls on the systems that hold subscriber data and LI infrastructure (Section 2). An operator who is CTDISR compliant in these areas has the technical foundation that LI compliance depends on.

The intersection point that requires specific attention is that LI-related systems and their log records must not be accessible to general operations staff, and the existence of an LI request must be handled confidentially. The access control principles of Section 2 apply with particular strictness to LI infrastructure.

For network design that incorporates LI capability planning from the start, Network Design & Optimization covers the architectural considerations. For the broader regulatory compliance programme, ISP Consulting & Advisory covers LI compliance alongside PTA licensing and CTDISR requirements. For managing the policy and procedure documentation that governs LI response procedures, ComplianceIQ provides the framework.