On 9th July 2026 the World Health Organization and the International Telecommunication Union published for public comment a draft Reference Architecture Guidance for Digital Public Infrastructure for Health, a document of 254 pages which tells a health ministry how to plan, finance and build the registries, exchanges and surveillance platforms on which a digital health system runs. The comment period closes on 6th September 2026. These chambers filed comments on 13th August 2026, and they were confined to a single legal point, because it is the point a document of this kind receives least: the architecture presupposes an enacted data protection statute, and in Pakistan there is none.
A required control that requires nothing
The draft is not careless about law. Section 1.4 states that access to personal health data must be “controlled, lawful, and appropriate”. Section 4.1.2, which is the assessment an implementing country performs before it selects a single component, asks whether “a legal and regulatory framework exists for health data”. Section 4.6.2 names among the conditions of sustainability “the legislation that gives shared infrastructure and its data a durable legal basis”, and adds that the legal dimension deserves equal weight with the technical. That last sentence is the best sentence in the draft.
The difficulty is what the draft does with a negative answer, which is nothing. Throughout Appendix C the controls marked “Required” are defined by incorporation: the Client Registry, which is the component holding the demographic record of every person the health system touches, must give effect to the rights of correction and erasure “in accordance with applicable data protection legislation (e.g., GDPR-equivalent frameworks)” and must be “designed in conformance with applicable data protection legislation and principles”. The Health Management Information System and the Public Health Surveillance Platform carry parallel requirements framed on “national data protection regulations”.
Each of those provisions works where a statute exists. Where none exists, a requirement defined by incorporation incorporates nothing, and the registry is then in conformance with applicable data protection legislation in the empty sense in which any system whatever is in conformance with a null set of obligations. The conformance box is ticked; no right of any person has been engaged. Since the draft’s whole conformance model is built to make architectural claims testable, therefore a Required control which becomes untestable in precisely the jurisdictions of greatest need is a defect in the architecture and not merely a defect in the environment it lands in.
Pakistan is the null case
Pakistan has been attempting a data protection statute since 2005, with published drafts in 2018, 2021 and 2023. The “Personal Data Protection Bill, 2023” was finalised by the Ministry of Information Technology and Telecommunication in May 2023 and approved by the Federal Cabinet in July 2023; it was thereafter introduced in the Senate; it was returned to the Ministry on the procedural objection that it had been moved by a single member of government; and as at today it has not been passed by either House. Twenty one years of drafting have produced no law.
What is in field does not fill the gap and was never meant to. The Prevention of Electronic Crimes Act, 2016 (Act XL of 2016) criminalises unauthorised access to an information system and to data, which is a matter for the prosecutor and not for the data subject; it confers no right of access, no right of correction, no right of erasure, no processing principles and no supervisory authority. Article 14 of the Constitution of the Islamic Republic of Pakistan, 1973 guarantees the dignity of man and, subject to law, the privacy of the home, which is a constitutional guarantee and not a processing regime, and the words “subject to law” are doing a great deal of work in a country where the law has not been made.
The registries did not wait
The sequence the draft presupposes, which is law first and registries second, is in Pakistan running in reverse, and the evidence for that is not speculative.
The Digital Nation Pakistan Act, 2025 (Act No. I of 2025), enacted on 29th January 2025, establishes the National Digital Commission chaired by the Prime Minister and the Pakistan Digital Authority, and charges that Authority with delivering the National Digital Masterplan, with standards, with data governance and with digital public infrastructure. In the health sector the National Immunization Management System, built by the National Database and Registration Authority with the Ministry of National Health Services, Regulations and Coordination, holds the immunisation record of the population keyed to the Computerised National Identity Card and issues verifiable certificates against a search on that number; it was built in 2021 for COVID-19 and it now carries poliomyelitis and yellow fever records for international travel, which is to say that the register outgrew its purpose within four years and did so administratively. The “Sehat Sahulat Programme” operates a centralised beneficiary information system on the same identifier. The District Health Information Software 2 has been scaled across all districts of Balochistan and more than one thousand six hundred and fifty facilities. The Ministry’s own National Digital Health Framework 2022 to 2030 sets the direction.
Every one of those instruments is an administrative act. Not one of them is a statute conferring a right on the person whose record it holds.
What happens when the programme ends and the register does not
The sharpest illustration Pakistan offers is one the draft has no answer to at all. On 30th June 2025 the Punjab Health Initiative Management Company notified the end of the “Sehat Sahulat Programme” in the public hospitals of the province, citing financial inefficiencies, the scheme thereafter surviving only in empanelled private hospitals and on reduced cover. The entitlement went. The database of every resident enrolled against a Computerised National Identity Card did not go, because nothing required it to go and nobody had a right to ask.
That is the null case stated as a fact rather than as an argument. Under the draft Guidance the Client Registry is obliged to implement erasure “in accordance with applicable data protection legislation”; in Punjab in July 2025 there was no applicable data protection legislation, hence there was no erasure obligation, no retention limit, no purpose limitation surviving the purpose, no supervisory authority to complain to and no channel through which a citizen could have asked what was still held about him and why. A conformance assessment run against that registry on the draft’s own terms would have passed it. Since a right that is defined by reference to a statute which does not exist is not a weak right but no right at all, therefore the architecture certifies the registry precisely where it protects nobody.
The four amendments sought
The comments filed on 13th August 2026 asked for four changes, each with proposed wording, and none of them asks anybody to stop building.
First, that Section 2.2.2 name the enacted legal basis for processing personal health data as an enabling condition beside the four technical dimensions it already lists, since a capability governed so as to remain trustworthy is not trustworthy to the citizen as a matter of engineering practice alone. Second, that Section 4.1.2 direct the case of the negative answer, recording the absence of a data protection law as a principal architectural risk, carrying the enactment on the same roadmap as the first components, and requiring any component that goes live before enactment to operate under published interim safeguards. Third, that Section 4.6.2 state that the investment case is incomplete until the legislative step, its sponsor and its timetable are identified as expressly as the technical components are identified, and that a development partner appraising an investment treat the absence of any legislative pathway as it would treat the absence of an operational budget. Fourth, that every Appendix C requirement framed on “applicable data protection legislation” carry a stated minimum baseline against which conformance is assessed where no legislation applies, the deployment being documented as operating under interim safeguards pending enactment.
What Pakistan can do while Parliament does not
Nothing in this argues that construction should halt until Parliament acts, since a health system cannot be asked to stand still for twenty one years, and the interim safeguards are the whole point: subordinate regulation or ministerial rules made under the statutes that are in field; binding data sharing agreements between the National Database and Registration Authority, the federal Ministry and the provincial health departments, published rather than held as internal memoranda; a published statement of the processing principles actually applied to each registry, naming its purpose, its retention period and its lawful basis; and a designated channel by which a person may ask what is held, have it corrected and have it deleted when the purpose has gone. None of that requires an Act. All of it could be done this year, and all of it would be superseded, properly, by the Bill of 2023 whenever Parliament reaches it.
The consultation is open until 6th September 2026 and it is open to development partners and to the clinical and public health communities and not to member states alone. It is highly recommended that Pakistani institutions building on this architecture, the Pakistan Digital Authority and the Ministry of National Health Services, Regulations and Coordination among them, file their own comments while it is open, because a country that says nothing during the comment period will be handed an architecture written for jurisdictions whose statute books are complete, and will then be assessed against it.
Sources
- World Health Organization and International Telecommunication Union, draft Reference Architecture Guidance for Digital Public Infrastructure for Health (DPI-H), Draft V1.0, published for public comment on 9th July 2026, comment period closing 6th September 2026; Sections 1.4, 2.2.2, 3.6, 3.7, 4.1.2 and 4.6.2 and Appendix C, Client Registry requirements 6 and 19.
- Comments of Mohammedan Law Associates on the draft DPI-H Reference Architecture Guidance, filed 13th August 2026 with the World Health Organization Department of Digital Health and Innovation, by letter, comments and completed comment matrix.
- "Personal Data Protection Bill, 2023", Ministry of Information Technology and Telecommunication; approved by the Federal Cabinet in July 2023; not passed by either House as at 25th August 2026.
- Prevention of Electronic Crimes Act, 2016 (Act XL of 2016); Article 14 of the Constitution of the Islamic Republic of Pakistan, 1973.
- Digital Nation Pakistan Act, 2025 (Act No. I of 2025), enacted 29th January 2025, establishing the National Digital Commission and the Pakistan Digital Authority.
- National Immunization Management System, National Database and Registration Authority with the Ministry of National Health Services, Regulations and Coordination, on the issue of immunisation certificates against a Computerised National Identity Card.
- Punjab Health Initiative Management Company, notification ending the "Sehat Sahulat Programme" in public sector hospitals of the Punjab with effect from 30th June 2025; reported by Voicepk on 3rd July 2025 and by Geo Fact Check.
- Ministry of National Health Services, Regulations and Coordination, National Digital Health Framework 2022 to 2030; DHIS2 scaling across all districts of Balochistan to more than 1,650 health facilities, reported by DHIS2 and UNICEF Pakistan.