Software houses, business process outsourcing units, and data-processing firms are among the most trust-dependent businesses a country can export.
The client is not buying a product it can inspect on arrival — it is handing over the personal data of its own customers. Precision and accuracy are visible in a surgical instrument. In an IT services contract they are invisible, and the buyer must therefore substitute evidence for inspection.
This is why the European Union’s General Data Protection Regulation (GDPR) imposes a level of rigour on non-EU service providers that most Pakistani small and medium enterprises have not yet internalised. The obligation does not begin when a Pakistani firm opens an office in Europe. In the scope of Article 3(2), it begins the moment that firm processes the personal data of individuals located in the EU, irrespective of where the processor is established.
What GDPR asks of a Pakistani vendor that ISO 27001 does not
The two frameworks are routinely conflated in local practice, and the distinction matters.
ISO/IEC 27001:2022 is a management system standard. It requires risk assessment and treatment in the scope of clauses 6.1.2 and 6.1.3, a Statement of Applicability, and internal audit and management review under clauses 9.2 and 9.3. It is certifiable, and the certificate is what a buyer can verify.
GDPR is a law. It is not certifiable in the same sense, and it imposes obligations ISO 27001 does not reach: a record of processing activities under Article 30, defined processor duties under Article 28, and notification of a personal data breach to the supervisory authority within 72 hours under Article 33. Penalties extend to €20 million or 4% of global annual turnover.
The two are complementary rather than interchangeable, and the bridge sits in Annex A of ISO 27001 — control A.5.31 on legal and regulatory requirements, A.5.34 on protection of personally identifiable information, and A.5.19 to A.5.23 on supplier relationships. An ISO 27001 certificate does not make an organisation GDPR-compliant. It does give the organisation the machinery through which GDPR obligations can be evidenced.
Why this determines market access, not merely legal exposure
Pakistan’s IT and IT-enabled services exports reached a record $4.6 billion in FY2026, up approximately 21% on the previous year’s $3.81 billion, and now constitute roughly 46% of total services exports. The declared national target is $15 billion by 2030.
That target cannot be reached by repeating the current engagement model. It requires moving from staff augmentation toward contracts in which the client entrusts the vendor with processing its customers’ data. And here a structural fact deserves more attention than it receives: Pakistan holds no adequacy decision from the European Commission.
In the scope of Article 45, adequacy permits data to flow to a third country without supplementary safeguards. In its absence, every EU controller engaging a Pakistani processor must execute Standard Contractual Clauses under Article 46 and independently verify that the processor’s technical and organisational measures are adequate under Article 32.
How does a European controller perform that verification on a vendor eight thousand kilometres away? It does not fly an auditor to Karachi. It sends a due diligence questionnaire and asks for documented evidence.
What the evidence pack actually contains
An EU client’s vendor-risk assessment will typically require the following:
Documented security policy set: A policy library covering access control, cryptography, supplier management, and acceptable use, formally approved and version-controlled. Ad hoc practice, however competent, does not satisfy this — the client is auditing the documentation, not the intention.
Recognised certification: ISO/IEC 27001 certification or any compliance framework certification. Procurement teams treat this as shorthand for process maturity because it is issued by an independent certification body rather than asserted by the vendor.
Record of processing activities: A ROPA satisfying Article 30 — categories of data subjects, processing purposes, retention periods, onward transfers. Many local firms discover at this stage that they cannot describe their own data flows.
Incident response procedure: A documented procedure supporting the controller’s 72-hour obligation. The processor’s internal notification window must be considerably shorter, because the controller’s clock starts on its own awareness.
Sub-processor register: Where the vendor uses a cloud provider or a freelance contractor, Article 28(2) requires controller authorisation and equivalent obligations flowed down. Is the freelancer engaged for a two-month sprint captured in that register? Is the data-processing agreement signed before access is granted, or after?
An organisation that cannot produce these does not lose the contract at the negotiation stage. It is eliminated before price is ever discussed.
The constraint is cost and duration, not willingness
The reason most Pakistani SMEs remain outside this framework is neither ignorance nor indifference. Certification has historically been priced and paced for organisations several times their size.
Implementation benchmarks place a typical ISO 27001 programme at up to eight months for an organisation of 10 to 50 employees and up to twelve for one of 50 to 500 — duration alone, before certification body fees and consultant retainers.
The threat environment offers no grace period. Kaspersky’s managed detection telemetry recorded an increase of approximately 300% in spyware incidents in Pakistan in the first quarter of 2024, with IT companies accounting for 15.4% of detected high-severity incidents.
Domestically, the Personal Data Protection Bill has received cabinet approval and a National Commission for Personal Data Protection has been constituted, with reported penalties extending to $2 million.
Call for a lower cost of demonstrable compliance
Every trade facility, regulatory sandbox, and data protection statute introduced without a corresponding reduction in the cost of evidencing compliance simply raises the floor for who may participate. If the documentation required to walk through these doors remains affordable only to large enterprises, they open for a fraction of the firms intended.
The arithmetic is changing. Automation now handles much of what previously required a consultant resident in the organisation for months: gap analysis against the clause structure, drafting of the policy set, control mapping, risk scoring, and assembly of the audit evidence pack. The organisation supplies the context and the decisions; the tooling supplies the documentation discipline.
Compliance framed as an expense will always be deferred. Framed correctly — as the mechanism by which a forty-person software house in Lahore becomes procurable by a European controller — it is not a cost centre at all. It is the difference between competing on price and competing on trust.
The article does not necessarily reflect the opinion of Business Recorder or its owners.
Software houses, business process outsourcing units, and data-processing firms are among the most trust-dependent businesses a country can export.
The client is not buying a product it can inspect on arrival — it is handing over the personal data of its own customers. Precision and accuracy are visible in a surgical instrument. In an IT services contract they are invisible, and the buyer must therefore substitute evidence for inspection.
This is why the European Union’s General Data Protection Regulation (GDPR) imposes a level of rigour on non-EU service providers that most Pakistani small and medium enterprises have not yet internalised. The obligation does not begin when a Pakistani firm opens an office in Europe. In the scope of Article 3(2), it begins the moment that firm processes the personal data of individuals located in the EU, irrespective of where the processor is established.
What GDPR asks of a Pakistani vendor that ISO 27001 does notThe two frameworks are routinely conflated in local practice, and the distinction matters.
ISO/IEC 27001:2022 is a management system standard. It requires risk assessment and treatment in the scope of clauses 6.1.2 and 6.1.3, a Statement of Applicability, and internal audit and management review under clauses 9.2 and 9.3. It is certifiable, and the certificate is what a buyer can verify.
GDPR is a law. It is not certifiable in the same sense, and it imposes obligations ISO 27001 does not reach: a record of processing activities under Article 30, defined processor duties under Article 28, and notification of a personal data breach to the supervisory authority within 72 hours under Article 33. Penalties extend to €20 million or 4% of global annual turnover.
The two are complementary rather than interchangeable, and the bridge sits in Annex A of ISO 27001 — control A.5.31 on legal and regulatory requirements, A.5.34 on protection of personally identifiable information, and A.5.19 to A.5.23 on supplier relationships. An ISO 27001 certificate does not make an organisation GDPR-compliant. It does give the organisation the machinery through which GDPR obligations can be evidenced.
Why this determines market access, not merely legal exposurePakistan’s IT and IT-enabled services exports reached a record $4.6 billion in FY2026, up approximately 21% on the previous year’s $3.81 billion, and now constitute roughly 46% of total services exports. The declared national target is $15 billion by 2030.
That target cannot be reached by repeating the current engagement model. It requires moving from staff augmentation toward contracts in which the client entrusts the vendor with processing its customers’ data. And here a structural fact deserves more attention than it receives: Pakistan holds no adequacy decision from the European Commission.
In the scope of Article 45, adequacy permits data to flow to a third country without supplementary safeguards. In its absence, every EU controller engaging a Pakistani processor must execute Standard Contractual Clauses under Article 46 and independently verify that the processor’s technical and organisational measures are adequate under Article 32.
How does a European controller perform that verification on a vendor eight thousand kilometres away? It does not fly an auditor to Karachi. It sends a due diligence questionnaire and asks for documented evidence.
What the evidence pack actually containsAn EU client’s vendor-risk assessment will typically require the following:
An organisation that cannot produce these does not lose the contract at the negotiation stage. It is eliminated before price is ever discussed.
The constraint is cost and duration, not willingnessThe reason most Pakistani SMEs remain outside this framework is neither ignorance nor indifference. Certification has historically been priced and paced for organisations several times their size.
Implementation benchmarks place a typical ISO 27001 programme at up to eight months for an organisation of 10 to 50 employees and up to twelve for one of 50 to 500 — duration alone, before certification body fees and consultant retainers.
The threat environment offers no grace period. Kaspersky’s managed detection telemetry recorded an increase of approximately 300% in spyware incidents in Pakistan in the first quarter of 2024, with IT companies accounting for 15.4% of detected high-severity incidents.
Domestically, the Personal Data Protection Bill has received cabinet approval and a National Commission for Personal Data Protection has been constituted, with reported penalties extending to $2 million.
Call for a lower cost of demonstrable complianceEvery trade facility, regulatory sandbox, and data protection statute introduced without a corresponding reduction in the cost of evidencing compliance simply raises the floor for who may participate. If the documentation required to walk through these doors remains affordable only to large enterprises, they open for a fraction of the firms intended.
The arithmetic is changing. Automation now handles much of what previously required a consultant resident in the organisation for months: gap analysis against the clause structure, drafting of the policy set, control mapping, risk scoring, and assembly of the audit evidence pack. The organisation supplies the context and the decisions; the tooling supplies the documentation discipline.
Compliance framed as an expense will always be deferred. Framed correctly — as the mechanism by which a forty-person software house in Lahore becomes procurable by a European controller — it is not a cost centre at all. It is the difference between competing on price and competing on trust.
The article does not necessarily reflect the opinion of Business Recorder or its owners.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | SBP’s Sandbox and EU AI Act: a timing advantage for Pakistani fintechs | 0 | 10.61 | 15-08-2026 |
| 2 | The government that talks to itself | 0 | 6.08 | 26-09-2026 |
| 3 | Google in Pakistan: a new chapter in country’s digital ambition | 0 | 6.7 | 03-09-2026 |
| 4 | The illusion of scale in higher education | 0 | 12.46 | 31-08-2026 |
| 5 | Govt moves to strengthen IT education standards | 0 | 5.45 | 19-09-2026 |
| 6 | Farming needs a digital push | 0 | 7.54 | 29-09-2026 |
| 7 | Pakistan doesn’t have a talent shortage. It has a broken hiring system | 0 | 6.7 | 04-09-2026 |
| 8 | Pakistan and Asia’s energy security: lessons from US-Iran conflict | 0 | 9.18 | 07-09-2026 |
| 9 | Huawei’s repair centre inaugurated in Islamabad | 0 | 6.62 | 25-09-2026 |
| 10 | Pakistani tech co Zuma Resources sets up UK subsidiary for global connectivity expansion | 0 | 5.53 | 21-09-2026 |