Background:

The protection of natural persons in relation to the processing of personal data is a fundamental right enshrined in Article 14(1) of the Constitution of the Islamic Republic of Pakistan (1973). Therefore, security institutions like the Punjab Safe Cities Authority (PSCA) must have well-defined Data and Privacy Protection Procedures (DP3) that provide detailed guidelines for users and recipients of PSCA data. This is particularly critical due to the implications for multiple stakeholders involved in the process.

The PSCA is responsible for meeting the requirements of law enforcement agencies while simultaneously ensuring the protection of the data it generates, gathers, stores, and shares with lawful authorities. This must be done not only for safety and security purposes but also while safeguarding the rights of individuals whose data is involved. In this digital age, personal data can easily be misused, modified, or shared for criminal or malicious purposes. Data must be secured according to designated parameters and should not be shared internally or externally without prior approval from the courts or a competent authority, following due process. The DP3 is subject to periodic updates and is made publicly available.


1. Introduction

In 2016, through a consultative process, the PSCA requested the Federal Government of Pakistan, via the Government of Punjab, to address the issue of admissibility of evidence collected through electronic devices in all criminal law cases. As part of the Punjab Police, the PSCA has a constitutional obligation to protect citizens. Consequently, the PSCA introduced Pakistan’s first Data Protection and Privacy Procedures (DP3) in 2016. These procedures were implemented to harmonize the protection of fundamental rights and freedoms of individuals regarding the processing of data generated and maintained by the PSCA, in line with the following legal instruments:

  • Article 14(1) of The Constitution of the Islamic Republic of Pakistan (1973) – Ensuring the dignity of individuals and the privacy of homes as inviolable rights.
  • Convention on the Rights of the Child – Recognizing the need for special care and assistance for children due to their physical and mental immaturity.
  • Pakistan Penal Code (1860) – Addressing offenses such as harassment (Section 509), defamation (Section 499), public nuisance (Section 268), and criminal breach of trust (Section 409).
  • The Prevention of Electronic Crimes Act (PECA) (2016) – Preventing unauthorized acts such as electronic forgery, fraud, cybercrime, hate speech, child pornography, spamming, and spoofing.
  • International Covenant on Civil and Political Rights (ICCPR) – Defining human dignity, civil and political freedoms, and safeguarding economic, social, and cultural rights.
  • General Data Protection Regulation (GDPR) (2016/679) of the European Union – Regulating free data movement within the EU while protecting personal data.
  • Cairo Declaration on Human Rights in Islam (1990) (CDHRI) – Affirming equality among all human beings regardless of race, color, language, or religion.
  • PSCA Electronic Data Regulations (2016) – Establishing guidelines for evidence collection, storage, and sharing.
  • The Investigation for Fair Trial Act (2013) – Outlining modern techniques and devices for lawful evidence collection and the prevention of misuse of intercepted materials.

Since its inception, the PSCA has been mindful of privacy concerns and has developed procedures for data collection and sharing, ensuring compliance with human rights frameworks and international obligations. In 2018, the PSCA recommended expanding the concept of privacy to public spaces as well.


2. Objectives

The DP3 and its guidelines are designed to:

  1. Protect the privacy rights of individuals using PSCA systems.
  2. Secure the data of individuals and events collected and maintained by the PSCA for security and public safety.
  3. Maintain the integrity of evidence/data delivered to courts, forums, and law enforcement agencies (LEAs) via PSCA infrastructure.
  4. Establish protocols for the retention, preservation, storage, and destruction of electronic data collected through PSCA electronic devices.

3. Installation of Surveillance Networks/Sensors by PSCA

  1. PSCA cameras and sensors will not be installed in locations that infringe on individuals’ privacy without due authorization.
  2. These devices shall only be placed in public areas or as directed by government authorities.
  3. Surveillance equipment will be positioned conspicuously to inform the public of their presence.
  4. Information regarding camera and sensor locations in Punjab shall be publicly shared to balance deterrence, privacy, and law enforcement requirements.
  5. Data collected through these devices shall only be used as per the guidelines set by the PSCA and relevant policies.

4. PSCA’s Data Users Guidelines

  1. Only authorized persons or entities can access, use, modify, or share PSCA data.
  2. Data shall only be shared internally or externally with authorized personnel following due process.
  3. Investigating officers or security agency representatives may access incident data only with prior approval.
  4. Data shared externally must include watermarks and clear tracking identifiers.
  5. Unauthorized data storage or sharing is strictly prohibited.
  6. LEAs or courts must ensure data handling procedures prevent unauthorized dissemination.
  7. An approved Electronic Data Analysis procedure must be followed for all data sharing.
  8. Only trained personnel with requisite knowledge of PSCA regulations may handle data.
  9. Live feeds shall not be shared with any external entity without lawful authorization.
  10. Any misuse of data will result in civil and/or criminal liability.

5. Data Handling Procedure

  1. All PSCA data users must adhere to DP3 policies.
  2. PSCA personnel shall not deliberately record personal activities unless related to a crime.
  3. Special care must be taken when handling data involving women and children.
  4. Data storage in personal devices is prohibited unless authorized.
  5. Monitoring of private spaces is only allowed when legally justified.
  6. No objectionable images/videos shall be disseminated through any medium.
  7. Data access logs shall be maintained for all personnel.
  8. Violations of DP3 will be considered misconduct and may lead to disciplinary action, including termination.

6. Data Sharing Terms & Conditions

  1. Electronic Data Application Forms are freely available on the PSCA website.
  2. Requests for electronic evidence must be for lawful purposes, such as court proceedings or investigations.
  3. Applicants must provide accurate details when requesting data.
  4. Any false information or concealment in an application will result in liability.
  5. Electronic data must only be used for its intended legal purpose.
  6. The applicant assumes responsibility for data integrity after receiving it.
  7. Data shall only be viewed within PSCA premises before delivery.
  8. Received data must be securely stored and submitted to the relevant court or authority.
  9. Unauthorized alteration of data is strictly prohibited.
  10. Data will be retained for 30 days, while archived evidence may be stored for up to 7 years.
  11. Copyright and ownership of all recorded material remain with the PSCA.
  12. Any relevant court ruling must be communicated to the PSCA to determine the status of stored data.

Join us for Data & Privacy Protection:
If you have any suggestions or you notice any violation of DP3, please inform us through email Privacy.Protection@psca.gop.pk or call 15 for complaint.


Note: These DP3 guidelines are subject to periodic review and updates by the PSCA to ensure compliance with legal and security standards.

When registering on our site / mobile app, as appropriate, you may be asked to enter your name, email address, phone number or other details to help you with your experience. In addition we may collect details about your location. IMEI number, hardware ID or any other parameters separately explained to you in privacy statement inside the application you are using.

We collect information from you when you or enter information on our site or use our mobile app.

We may use the information we collect from you when you register, sign up for our newsletter, respond to a survey or fill any forms, surf the website, use our mobile app or use certain other site features to allow us to better service you.

We only provide articles and information. We never ask for credit card numbers.
We use regular Malware Scanning.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition all sensitive / credit information you supply is encrypt via Secure Socket Layer (SSL) technology.
We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information.
We do not process any money transcation on our website.

Yes. Cookies are small files that a site or its services provider transfer to your computer hard drive through your web browser that enables the sites or service provider system to recognize your browser and capture and remember certain information. For instance, we use cookies to help us remember and process the job applicant information. Ther are also used to help us understand your preferences based on previous or current site activity, which enables us to provide you with improved services. We also use cookies to help us compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future.
We use cookies to:
Understand and save user’s preferences for future visits.
You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookie. You do this your browser settings. Since browser is a little different, look at your browser’s help menu to learn the correct way to modify your cookies.
If you turn cookies off, some features will be disabled. It won’t affect the user’s experience that make your site experience more efficient and may not function properly.
However, you will still be able to browse our website.
Third party disclosure.
We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information.
Google:
We have not enabled Google AdSense on our site.
Misc:
User can visit our site anonymously.
Once this privacy policy is created, we will add a link to it on our homepage or as a minimum, on the first significant page after entering our website.
Our privacy policy link includes the world ‘Privacy’ and can easily be found on the page specified above.
You will be notified of any Privacy Policy Changes:
On our Privacy Policy Page
Can change your personal information:
By emailing us
By calling us
By logging in to your account

We honor Do Not Track signals and Do Not Track, plant cookie, or use advertising when a Do Not Track (DNT) browser mechanism is in place.
COOPA Compliance
We do not specifically market anything to children under the age of 13 years old.
Fair Information Practices
We will take the following responsive action, should a data breach occur:
We will notify you via email
1) Within 7 business days
We will notify the users via in-site notification 2) Within 1 business day
If at any time you would like to unsubscribe from receiving future emails, you can email us at.
Follow the instructions at the bottom of each email.
And we will promptly remove you from ALL correspondence.