Rights Without Remedy

Staff Report
12 Min Read

Summary

  • Traditional clauses on confidentiality, indemnity, limitation of liability and compliance with law are not enough where the contract involves data flows, AI training, automated outputs, cross-border hosting, sub-processors, prompts, logs, deletion rights, audit rights and future regulatory change.
  • AI contracts must define what data can be used, whether training is permitted, whether outputs belong to the client, whether sensitive data can be entered, whether data leaves Pakistan, whether sub-processors are allowed, whether audit rights exist, whether deletion is possible, and whether the customer can terminate if future law makes the arrangement unlawful or commercially unworkable.
  • If there is no enforceable data protection law, the affected person may not know what data was used, whether it was accurate, whether it was lawfully collected, whether it was shared, whether it was transferred abroad, whether an AI system was involved, or whether a human being reviewed the decision.
AI Generated Summary

By Harris Jamil Alam Khan

Ubi jus ibi remedium, where there is a right, there must be a remedy. The age-old legal maxim carries in it an almost absolute truth. Unfortunately, Pakistan’s problem today is that rights are not absent in theory but practice. The problem is that the remedies have not been proactively implemented for the age in which now we find ourselves.
Artificial intelligence is entering business, government, finance, healthcare, education, employment, legal services and public administration. Data is being collected, processed and analysed in systems that can influence decisions about people before those people even know such systems are involved.
Pakistan does have the Prevention of Electronic Crimes Act, 2016. PECA deals with electronic offences, unauthorised access, unauthorised copying or transmission of data, system interference, identity-related misuse and other cyber offences. It is important within its own field, but it is not, and should not be treated as, a substitute for a civil data protection law. Criminal law punishes after an offence has occurred. Data protection law governs the relationship before harm occurs. It asks whether data was collected lawfully, whether consent was valid, whether processing was limited to a defined purpose, whether the data was secure, whether it was transferred outside Pakistan, whether it could be corrected, and whether an automated decision could be challenged.
These are not the same questions, and they cannot be answered by the same legal instrument. A citizen whose data is misused does not only need the possibility of prosecution. They may need correction, deletion, compensation, access, explanation, breach notification, human review, regulatory intervention and a binding order against the person or entity controlling the data. PECA cannot carry that burden. It was never designed to do so.
This is why the absence of a data protection law is becoming a governance problem. Pakistan has had a Personal Data Protection Bill since 2023. The draft contains modern concepts such as consent, sensitive and critical personal data, breach reporting, cross-border transfer controls, data subject rights, a proposed regulator and safeguards against certain automated decisions. But it remains a draft. A draft law does not create an operating regulator, issue guidance, enforce breach reporting, regulate AI vendors, define contractual obligations, or give the ordinary citizen a working remedy.
At the same time, Pakistan is moving toward a National Artificial Intelligence Policy. That, in itself, is not wrong. The country cannot ignore AI. Businesses want efficiency, public bodies want digitisation, hospitals and banks want better systems, and everyone want faster research tools. The attraction is obvious. But adoption without legal architecture is not preparedness. It is risk moving faster than the law.
The danger is not only technological. It is contractual. Companies are entering into technology, cloud, software, outsourcing, automation and AI arrangements in a country where the core data protection law is still missing. Lawyers are being asked to draft around a future where the law fails to provide them a stable drafting foundation. Contracts routinely contain broad phrases such as “the parties shall comply with applicable laws,” “including any future data protection laws,” or “as may be required under AI regulation from time to time.” Such clauses may appear safe, but in many cases, they are placeholders for unresolved risk.
The problem becomes sharper when data moves through vendors, service providers, processors, sub-processors, affiliates and platform tools. Modern data misuse does not always appear as an obvious breach or theft. It often appears as a lawful-looking chain of contracts. The platform says the business is responsible for the data. The vendor says it acts only on instructions. The business says it relied on the platform’s terms. Each party points to the next layer of the arrangement, while the citizen or customer affected by the processing is left with the consequence but not the remedy. The harm may not begin as a cyber offence under PECA. It may begin as an ordinary commercial arrangement that nobody properly understood, negotiated or regulated.
The future-law problem is equally serious. If a future law requires local storage of critical personal data, who bears the cost? If cross-border transfers are restricted, who redesigns the system? If an AI model was trained on client data before the law changed, can that model still be used? If a regulator imposes penalties for unlawful processing, will the vendor indemnify the customer or will liability be capped? These are not academic concerns. These are contract questions. They affect pricing, liability, indemnity, termination, insurance, procurement, governance and board accountability.
A poorly drafted future-laws clause can become a trap. It may leave one party carrying the cost of compliance without knowing it, allow a vendor to avoid obligations by calling them regulatory changes, or leave the customer exposed because the data was collected under its authority. It may also fail to stop the vendor from using customer data to train its own model. In ordinary commercial contracts, uncertainty is dangerous. In AI contracts, uncertainty multiplies because the technology is dynamic, the data flows are layered, and the law is incomplete.
Many legal professionals are being asked to review contracts that are no longer ordinary software arrangements. Traditional clauses on confidentiality, indemnity, limitation of liability and compliance with law are not enough where the contract involves data flows, AI training, automated outputs, cross-border hosting, sub-processors, prompts, logs, deletion rights, audit rights and future regulatory change. A sentence saying “the vendor shall comply with law” is not enough when the law itself has not yet settled the most important questions.
AI contracts must define what data can be used, whether training is permitted, whether outputs belong to the client, whether sensitive data can be entered, whether data leaves Pakistan, whether sub-processors are allowed, whether audit rights exist, whether deletion is possible, and whether the customer can terminate if future law makes the arrangement unlawful or commercially unworkable. Without a data protection law, the market is left to guess. Where the market guesses, the weaker party usually loses.
For citizens, the impact is more serious because they are not sitting at the contract table. A person does not negotiate the terms on which their hospital, bank, employer, school, insurer, public department or service provider uses AI. They do not approve the vendor. They do not inspect the model. They simply experience the outcome. A loan is refused. A job application is filtered out. A public benefit is delayed. A tax record is flagged. A person is treated as a risk category rather than a human being.
If there is no enforceable data protection law, the affected person may not know what data was used, whether it was accurate, whether it was lawfully collected, whether it was shared, whether it was transferred abroad, whether an AI system was involved, or whether a human being reviewed the decision. That is the real meaning of rights without remedy. The person may have dignity, privacy and fairness in principle, but without a functioning law, regulator and remedial framework, those principles remain difficult to enforce in practice.
If Pakistan relies only on criminal law, it will keep arriving after the damage has been done. AI governance requires prevention. Once data is absorbed into a system, copied into a vendor environment, transferred across borders, used for training, combined with other datasets or embedded into a model, the harm may not be easy to reverse. A stolen file can sometimes be traced or blocked. A trained model built on improperly processed data is far harder to unwind.
Pakistan does not need to reject AI. But it must not confuse adoption with readiness. A nation is not prepared for AI merely because it has a policy. It is prepared when its laws define rights, duties, remedies, regulators, accountability and consequences.
The immediate need is clear. Pakistan must enact the Personal Data Protection law as a working legal framework, not merely as a symbolic statute. It must create an independent regulator, recognise PECA for what it is, and require organisations to review AI and technology contracts with future compliance in mind. Data use clauses must prohibit unauthorised training. Cross-border transfer clauses must be specific. Audit rights must be real. Liability caps must not quietly defeat data protection obligations.
AI is not merely another software procurement issue. It touches privacy, evidence, employment, banking, healthcare, intellectual property, consumer protection, cybersecurity, constitutional rights, public procurement and corporate governance. Companies must stop treating AI adoption as a branding exercise and ask basic legal questions before deployment: what data is being used, where is it stored, who can access it, can it be used for training, can it be deleted, can the decision be explained, and what happens when the law changes?
Pakistan cannot afford to discover these questions after harm occurs. Rights without remedy are not rights in any meaningful sense. They are promises without machinery. They create comfort on paper and helplessness in practice. Pakistan’s AI future will not be determined only by engineers, vendors or policymakers. It will also be determined by lawyers, boards, regulators, procurement teams and judges. If they move without a framework, the result will not be innovation with trust. It will be adoption without accountability.
Pakistan does not need to fear AI. It needs to stop pretending that PECA is enough, that policy is enough, that contracts can cure every uncertainty, and that future laws can be handled later. Pakistan cannot simply wait for Godot. Until the law arrives, citizens are left with rights without remedy, and companies are left building their AI future on legal uncertainty.

We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com
Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *