✕
Perspectives

Who rules the rules in cyberspace

Published Updated
7 min
Summary new

In cyberspace, where digital “state of nature” indicates a presence of hackers, trolls, cyber threats, and misinformation, English philosopher Thomas Hobbes would argue for a strong central authority to create order through the enforcement of law and regulation by way of moderation, surveillance, and firewalls.

The feeling of security provides the basis for surrendering some freedoms to these “Leviathans” of the digital world. John Locke would argue that users possess natural rights to their lives, liberty, property (tangible and intangible) and privacy as a result of establishing their social contract with whichever platform or government is acting as their limiting trustee.

In this regard, these platforms and governments become the trustee that will protect the contract’s natural rights through users’ consent via reasonable terms of service. However, if a platform or government breaches this trust by overreaching their authority, the user’s right to exit the platform/government or to reform it is exercised.

Jean-Jacques Rousseau’s notion of self-governance would take the form of “General Will” - the idea being the collective decision-making of a community; therefore, Rousseau favours decentralised support for governance and moderation whereby members of a community (or their representatives) create their own government through creating their own user communities, open-source governance, and democratically moderated user-created forums versus their community’s governing elite dependent upon a technology corporation or government.

The current internet exemplifies a hybrid of these three philosophies creating a chaotic combination of multiple operating authorities and regulations, which creates an ongoing battle between safety, individual rights, and collective digital democracy.

Comparative studies have demonstrated that cultural, political, and socio-economic variables in each country colour their respective approach to addressing digital issues that are the same worldwide.

The Prevention of Electronic Crimes Act (PECA) of 2016 is Pakistan’s primary legislation concerning cybercrime, and it outlines illegal access to computers, cyber terrorism, forgery and identity theft. The amendments to PECA in 2025 brought additional oversight measures into play concerning content on the internet, as well as penalties for the provision of “false or fake information,” which may carry up to three years of imprisonment.

The criminal administrative framework for PECA is similar to that of the Cybersecurity Law of China and the Data Security Law, which both impose national control over data flows. Both frameworks include rapid responses to malicious activity, yet have been subject to criticism based upon their broad language that is perceived by some to infringe upon expression.

On the other hand, the European Union (EU) has created directives for cybercrime through the Directive on Attacks against Information Systems and the NIS2 Directive which provide some level of harmonised standards for the protection of infrastructure, proportionate to the level of the threat, with consideration given to the fundamental rights established under the EU Charter.

The UK has similarly implemented standards through the Computer Misuse Act and the Online Safety Act 2023, which will promote the accountability of electronic platforms for their overall protection via a risk-based approach. Conversely, the United States relies on Section 230 of the Communications Decency Act, which provided less liability to the disinterested party, but is currently evolving into something more likely to protect freedom of speech and rely on a market-based approach.

Finally, India has had a similar experience with the IT Act of 2000, including the finding of illegality with respect to Section66A (due to vagueness) and the creation of intermediary guidelines that strive to balance the needs of enforcement with the constitutional guarantee of free speech.

Pakistan has not signed the Budapest Convention on Cybercrime and this demonstrates a non-alignment with likelihood of cyber criminality jurisdiction across national frontiers. Pakistan does not have any fully implemented comprehensive laws on data protection. Different drafts of the Personal Data Protection Bill, all based on the General Data Protection Regulation (GDPR), were developed and are still under consideration.

These drafts of the Personal Data Protection Bill incorporate provisions such as consent, purpose limitation, data minimisation and individual rights to access, correct and remove their own personal data. Currently, implementation will be governed by piecemeal provisions of PECA (the Pakistan Electronic Crimes Act) and telecommunications law; in addition, there is currently a developing National Commission for Personal Data Protection, but lack of capacity limits its ability to be effective.

This means that Pakistan is closer to India’s developmental model than to the EU’s well established approach. Various factors make the GDPR the international benchmark for data protection laws including: its jurisdictional reach, up to 4% of global revenues in fines, requirement that companies/organisations appoint Data Protection Officers, and requirement for Data Protection Impact Assessments (DPIAs).

India’s DPDP Act and Pakistan’s Bill continue to look towards the GDPR as a model. The US has a collection of sector based regulations (for example HIPAA and COPPA) and state regulations (like CCPA), which generally focus on consumer choice/flexibility for companies/organisations. China’s Personal Information Protection Law (PIPL) (2021) includes individual protections, but also requires that any cross-border transfer of data undergo strict security assessments, which also demonstrates that China is still focused on data sovereignty.

Thus, it is apparent that Pakistan has a hybrid of the GDPR principles (on paper) but faces practical difficulties in institutions and surveillance in fully implementing these provisions; therefore, the country needs to consider creating a stronger independent monitor to develop digital trust.

Moderation of content under the PMRA amendments to PECA requires that any posting of “objectionable” material be removed. Such a requirement raises similar proportionality concerns as seen under India’s IT Rules 2021 and Pakistan’s own AI Governance adds another level of compliance. The EU AI Act utilises a risk based classification method that includes prohibitions and strict compliance requirements. The United States is taking a flexible approach that promotes innovation but relies heavily on sector-specific rules.

China has taken state controlled action to moderate content and maintain social stability. In 2025, Pakistan launched its National AI Policy that focuses on developmental and pro-innovation outcomes while implementing ethical boundaries, regulatory sandboxes, and promoting skill development, inclusion, and national advancement.

The Pakistani government intends to participate in international forums while continuing to emphasise its sovereignty, similar to an increasing number of Global South countries. The judicial system in Pakistan has allowed for AI tools to be used in the courts under appropriate safeguards. Compared to its Global South peers, Pakistan’s AI Governance framework is less restrictive than the EU or China but more policy focused than binding legislation, with similar capacity development aspects as India, Singapore, Bangladesh, and Sri Lanka.

As a typical Global South nation, Pakistan continues to grapple with enforcement gaps, the digital divide, capacity deficits, and the balance between security and rights amid intense geopolitical pressure. On the other hand, there are some strengths regarding Pakistan’s ability to address new threats through rapidly evolving legislation; however, there are also substantial weaknesses in institutional maturity and legal protections compared to the EU and the UK.

The way forward for Pakistan involves fully agreeing, implementing and funding GDPR-compliant data protection laws with local variations; signing and rectifying the Budapest Convention; providing increased training for judges in digital forensics; developing multi-stakeholder content standards; and creating public private partnerships for cybersecurity.


The article does not necessarily reflect the opinion of Business Recorder or its owners.

Dr Sanaullah Abbasi

The author is former IGP KPK/Gilgit-Baltistan/ex DG FIA and PhD in law, currently visiting faculty in law university Karachi.

Read Also