Compliance

Who Does PVARA Share Your Data With? Section 17 Explained

Section 17 of the Virtual Assets Act 2026 names the agencies PVARA must share data with, and the approval route for foreign regulators.

Every licensee submits supervisory information to the Pakistan Virtual Assets Regulatory Authority (PVARA) — customer due diligence records, transaction data, reserve disclosures, incident reports. Section 17 of the Virtual Assets Act 2026 is the provision that determines where that information can go once PVARA has it. It names the domestic agencies PVARA must cooperate with, sets out the route for sharing with foreign regulators, and allows for standing coordination committees.

For a virtual asset service provider (VASP) planning tax and banking arrangements or a market entry strategy, section 17 is worth reading closely — the assumption that data submitted to PVARA stays with PVARA alone is not correct.

Who can PVARA share supervisory information with domestically?

Section 17(1) names five specific bodies, then adds an open category: “For the effective regulation and supervision of Virtual Assets and Virtual Asset Service Providers, and to prevent their misuse, the Authority shall cooperate and share supervisory and enforcement information, in a timely and secure manner, with the State Bank of Pakistan, the Securities and Exchange Commission of Pakistan, the Financial Monitoring Unit, the Federal Investigation Agency, the Federal Board of Revenue, and any other competent regulatory or law-enforcement agencies or bodies.”

Named body Role
State Bank of Pakistan (SBP) Central bank and monetary authority
Securities and Exchange Commission of Pakistan (SECP) Corporate registrar and securities regulator
Financial Monitoring Unit (FMU) Pakistan’s financial intelligence unit, receives suspicious transaction reports
Federal Investigation Agency (FIA) Federal law-enforcement agency
Federal Board of Revenue (FBR) Tax authority

The word “shall” makes this a mandatory duty, not a discretionary option — PVARA is obliged to cooperate and share information with these bodies, not merely permitted to. The closing phrase, “any other competent regulatory or law-enforcement agencies or bodies,” means the named list is illustrative of the kinds of bodies covered rather than exhaustive; a newly created agency with a relevant mandate would fall within scope without requiring an amendment to the Act.

This duty connects directly to obligations elsewhere in the Act. Suspicious transaction reports go to the FMU under section 46; tax compliance obligations under section 66 sit with the FBR; and any criminal investigation under section 56 sits with an authorised officer of PVARA itself, but section 17(1) means the FIA is a standing information-sharing partner regardless of whether a specific case is under investigation.

Does PVARA need permission before sharing with a foreign regulator?

Yes. Section 17(2) draws a clear line between domestic and cross-border sharing: “The Authority may, with the prior approval of the Federal Government, enter into cooperation arrangements or information-sharing arrangements with foreign regulatory or supervisory authorities for cross-border supervision, enforcement and mutual assistance relating to Virtual Assets and Virtual Asset Service Providers.”

“The Authority may, with the prior approval of the Federal Government, enter into cooperation arrangements or information-sharing arrangements with foreign regulatory or supervisory authorities for cross-border supervision, enforcement and mutual assistance relating to Virtual Assets and Virtual Asset Service Providers.”

Two features distinguish this from the domestic duty in section 17(1). First, it is discretionary (“may,” not “shall”) — PVARA is not obliged to enter into any specific foreign arrangement. Second, it requires “prior approval of the Federal Government” before the arrangement is made, giving central government a gatekeeping role over PVARA’s international cooperation that does not apply to its domestic information-sharing duty. This sits alongside section 4(2) of the Act, which separately allows PVARA to enter agreements with foreign regulatory authorities and law-enforcement agencies “for mutual assistance, information sharing, and the recognition and enforcement of regulatory decisions” in the specific context of extraterritorial enforcement, and section 4(3), which requires PVARA to align its extraterritorial enforcement practices with mutual legal assistance treaties and international frameworks including the Financial Action Task Force (FATF) and the International Organization of Securities Commissions (IOSCO).

For a foreign exchange operating into Pakistan, this means supervisory information collected here could, in principle, reach a home regulator abroad — but only through a formal arrangement that has cleared Federal Government approval, not on an ad hoc basis.

What is the regulatory coordination committee?

Section 17(3) gives PVARA a further structural option: “The Authority may establish one or more inter-agency coordination mechanisms, including a regulatory coordination committee, comprising representatives of relevant public authorities, to facilitate policy coordination, information-sharing, supervision, enforcement, and risk mitigation in relation to Virtual Assets and Virtual Asset Service Providers.”

This power is permissive rather than mandatory, and it is broader than a simple information pipeline — a coordination committee under section 17(3) could cover policy coordination and joint risk mitigation, not just data exchange. It also connects to the general committee power in section 9(2)(n), which lets PVARA “constitute as many committees as deemed necessary to conduct its functions.” The Act does not specify which “relevant public authorities” would sit on such a committee, though the bodies named in section 17(1) — SBP, SECP, FMU, FIA and FBR — are the most obvious candidates given their existing statutory cooperation duty.

Does data protection law limit what PVARA can share?

Yes, and this is one of the few places the Act expressly subordinates itself to other legislation. Section 5(2) states: “Where any law prescribes measures relating to data protection, data governance, or cybersecurity, financial secrecy or cross-border transfer of personal data, such provisions shall prevail and be complied with by the Authority and Licensees.”

This means section 17’s information-sharing powers do not override Pakistan’s data protection and financial secrecy law — they operate within it. A licensee’s obligations under section 49, which requires “strict limits on the collection, use, and sharing of customer data, requiring explicit, informed, and revocable consent for any non-essential data processing,” sit alongside PVARA’s own sharing duties rather than being displaced by them. The Act does not resolve every possible tension between mandatory supervisory sharing under section 17(1) and consent-based data protection standards; where a conflict arises in practice, the safer assumption is that data protection law prevails, as section 5(2) directs, and it is worth verifying the current position with counsel before relying on either provision in isolation.

How does this connect to real-time reporting and data localisation?

Section 17 does not operate alone. Section 48 requires licensees to “establish secure reporting channels, and where required secure automated interfaces, enabling the Authority and such other agencies as notified to access prescribed data for supervisory and enforcement purposes” — meaning the sharing contemplated by section 17(1) may, in practice, run through automated interfaces rather than case-by-case requests. Section 40 separately requires licensees to segregate “sensitive information” — customer due-diligence records, transaction-level data, private keys and cryptographic credentials — from other operational data, with strict access controls, which shapes what is available to be shared in the first place.

Section 39’s data localisation framework is also relevant: while a licensee may store or process data outside Pakistan subject to safeguards, section 39(2) allows PVARA to require immediate localisation of specific datasets “where necessary in the interest of national security, financial stability, consumer protection, or enforcement effectiveness” — a power that would plainly be exercised in step with the information-sharing duties in section 17.

What should a VASP take from this?

The practical takeaway is that data submitted to PVARA is not held in isolation. Domestically, section 17(1) creates a mandatory sharing duty with five named agencies plus any other competent body — meaning your supervisory data is realistically visible to the SBP, SECP, FMU, FIA and FBR in the ordinary course of PVARA’s cooperation obligations, not only in an investigation. Internationally, sharing requires a formal arrangement with Federal Government approval under section 17(2), giving a degree of protection against ad hoc cross-border disclosure.

If your business model involves custody of customer assets, cross-border broker-dealer activity, or a structure that touches multiple jurisdictions, build your AML and data-governance framework on the assumption that section 17 sharing will happen, and design your consent and disclosure documentation to the controller and customer accordingly, rather than treating PVARA as a closed information silo.

About this analysis

This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act 2026 as passed by the National Assembly — principally section 17, with cross-references to sections 4, 5, 9, 39, 40, 46, 48, 49 and 66 — read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect