Every licensed business in Pakistan sits under more than one statute at once. A virtual asset service provider answers to the Virtual Assets Act, 2026, but also to company law, tax law, foreign exchange control, and — increasingly — data protection rules. When two of those regimes point in different directions, something has to give way. Section 5 of the Act is the provision that settles that question, and it is shorter and more specific than most compliance teams assume.
Getting this wrong has real consequences. A licensee that assumes the Act automatically overrides every other statute it touches will misjudge its foreign-exchange obligations. One that assumes data protection law is simply absorbed into PVARA’s mandate will misjudge its data-handling duties. Section 5 draws the line precisely, in three subsections.
Does the Virtual Assets Act override other Pakistani laws?
Generally, yes, with one named exception. Section 5(1) states that “the provisions of this Act are in addition to, and not in derogation of, any other law for the time being enforce. In the event of any inconsistency with any other law, other than the Foreign Exchange Regulation Act, 1947 (VII of 1947), this Act shall prevail except as provided in sub-section (2) below.” In plain terms: where the Virtual Assets Act conflicts with most other Pakistani legislation, the Virtual Assets Act wins — but foreign exchange law is carved out entirely, and data protection law is carved out through sub-section (2).
This is an overriding clause, a common device in framework legislation that regulates a genuinely new sector. It exists because a business built entirely around a novel technology and a specific 2026 statute could otherwise be constrained by older laws never written with virtual assets in mind. The clause resolves that friction in the Act’s favour — except where the legislature specifically decided not to.
Why does the Foreign Exchange Regulation Act stay outside the Act’s reach?
Because section 5(1) names it as the one statute the Virtual Assets Act does not override. The Foreign Exchange Regulation Act, 1947 (FERA) governs how foreign currency moves into, out of, and within Pakistan, and it sits under the State Bank of Pakistan’s mandate. Where a virtual asset transaction — a customer’s fiat on-ramp, an issuer’s offshore reserve custody, a cross-border settlement — engages FERA, FERA’s rules apply on their own terms, regardless of what the Virtual Assets Act separately requires for licensing or conduct.
The practical effect is that PVARA licensing does not substitute for foreign-exchange compliance. A licensed VASP moving fiat currency across Pakistan’s border, or holding foreign-currency reserves for a fiat-referenced token, still needs to satisfy FERA and any State Bank of Pakistan directives issued under it, in parallel with — not instead of — its obligations under the Act.
What happens when the Act conflicts with data protection or cybersecurity law?
Here the Act steps back rather than forward. Section 5(2) provides: “where any law prescribes measures relating to data protection, data governance, or cybersecurity, financial secrecy or cross-border transfer of personal data, such provisions shall prevail and be complied with by the Authority and Licensees.” This is a direct carve-back from the overriding clause in sub-section (1) — on these five specific topics, the other law wins, and both PVARA itself and every licensee must comply with it.
This matters because virtual asset businesses are, by nature, data-intensive. Onboarding under fit-and-proper and customer due-diligence rules collects identity documents, transaction histories and financial records; custody operations handle cryptographic keys; cross-border groups move that data between jurisdictions. Section 5(2) means none of that activity gets a free pass under the Virtual Assets Act if it conflicts with Pakistan’s data protection, data governance, cybersecurity, financial secrecy, or cross-border data transfer laws. Those regimes govern on their own terms, and PVARA itself is bound by them, not just the licensees it regulates.
The topics carved out under section 5(2), read directly from the text, are:
- Data protection.
- Data governance.
- Cybersecurity.
- Financial secrecy.
- Cross-border transfer of personal data.
Does this mean PVARA shares jurisdiction with other regulators?
In a coordinated rather than competing sense, yes. Section 5(3) states that “the regulation and supervision of Virtual Assets, Virtual Asset Service Providers, tokenization of real-world assets, and blockchain technology shall vest primarily in the Authority under this Act, in coordination with other relevant regulators where applicable.” The word “primarily” is doing real work here — it establishes PVARA as the lead regulator for this subject matter, without claiming exclusive jurisdiction to the total exclusion of bodies such as the State Bank of Pakistan or the Securities and Exchange Commission of Pakistan, where their existing mandates genuinely overlap.
This coordination duty is not confined to section 5. It echoes structural features found elsewhere in the Act — the Authority’s board includes the Governor of the State Bank of Pakistan and the Chairperson of the Securities and Exchange Commission of Pakistan among its members, and the Authority’s classification power for borderline assets requires consultation with those same bodies where an asset exhibits characteristics within their mandates. Section 5(3) is the general statement of that same coordinated-but-lead-regulator model, applied to the relationship between statutes rather than between institutions.
How does the hierarchy actually work in practice?
The clearest way to hold these three subsections together is as a decision sequence, applied whenever a licensee finds two Pakistani laws pointing in different directions on the same question:
| Step | Question | Outcome |
|---|---|---|
| 1 | Does the conflicting law relate to foreign exchange? | If yes, the Foreign Exchange Regulation Act, 1947 governs — the Virtual Assets Act does not override it. |
| 2 | Does the conflicting law relate to data protection, data governance, cybersecurity, financial secrecy, or cross-border personal data transfer? | If yes, that other law governs, and PVARA and the licensee must both comply with it. |
| 3 | Neither of the above applies. | The Virtual Assets Act prevails over the inconsistent provision of the other law. |
A worked example makes this concrete. Suppose a licensed exchange’s board-approved AML/CFT policy under the PVARA No Objection Certificate Regulations requires retaining customer transaction data for a period that a separate Pakistani data protection statute treats as excessive retention for personal data. Under section 5(2), the data protection statute’s retention limit prevails, and the licensee’s AML/CFT recordkeeping practice would need to be built to satisfy both regimes simultaneously — not to treat the Act’s recordkeeping duty under section 47 as automatically overriding the data protection limit.
What should a compliance team check before assuming the Act controls?
Before relying on the Virtual Assets Act to settle a cross-statute conflict, confirm which of these applies:
- Whether the point in question touches foreign-currency movement, in which case FERA governs regardless of what the Act says.
- Whether the point in question touches data protection, data governance, cybersecurity, financial secrecy, or cross-border personal data transfer, in which case the relevant data or cybersecurity statute governs.
- Whether another regulator’s existing mandate — most obviously the State Bank of Pakistan on currency and reserve matters, or the Securities and Exchange Commission of Pakistan on instruments within its jurisdiction — is engaged, in which case section 5(3) anticipates coordination rather than PVARA acting alone.
- Only once the first three are cleared does the general overriding rule in section 5(1) resolve the remaining conflict in the Act’s favour.
Where any of the first three genuinely applies and the position is not clear from the statute alone, that is a case for specific legal advice rather than a general reading of section 5 — the Act itself does not attempt to resolve every possible conflict between named regimes and leaves plenty for Regulations still to be issued.
About this analysis
This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act, 2026, the PVARA No Objection Certificate Regulations 2025, and the PVARA Sandbox Guidelines 2026, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect