Data Protection in the Age of AI: A Legal Analysis of the Impact of Foreign Data Protection Laws on Pakistani Businesses

Authors

DOI:

https://doi.org/10.32350/lpr.52.06

Keywords:

data protection, small and medium-sized enterprises, cross-border data transfers, General Data Protection Regulation (GDPR), compliance strategies, Standard Contractual Clauses (SCCs), data transfer impact assessment

Abstract

Data protection is one of the critical concerns for small and medium-sized enterprises (SMEs) in Pakistan in the context of the dynamic global digital economy. This research explores the complexities of enforcing foreign data protection laws in the international arena, specifically with respect to extraterritorial coverage of the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The main contribution of the study is the documentation of the troubles faced by Pakistani SMEs that are seeking to transfer data across borders, notwithstanding the challenges of conflicting legal obligations imposed on them for such a transfer. The paper then conducts qualitative analysis, including case studies on successful Pakistani SMEs, which help identify successful legal strategies, including the use of Standard Contractual Clauses (SCCs), Data Transfer Impact Assessment (DPIA) and the development of robust privacy policies. The results highlight the importance of good planning, employee training, and partnerships with industry professionals to obtain compliance in addition to improving data security. In addition, the research stresses the importance of having a comprehensive national data protection framework set in place to keep pace with international standards and help encourage SME compliance. This paper seeks to provide actionable recommendations and insights to Pakistani organizations to protect them against the complexity and rigor of data protection regulations and to help them become operationally resilient in the global market.

Downloads

Download data is not yet available.
0

References

Abdelkarim, Y. A. (2024). A multi-dimensional approach to impose universal jurisdiction in international legal practice. International Journal of Law in Changing World, 3(1), 21–52. https://doi.org/10.54934/ijlcw.v3i1.87

Abdul, A., & Goyayi, M. L. J. (2023). Potential risks of cloud computing in financial institutions in Tanzania: Perspectives from CRDB Bank Plc. European Journal of Theoretical and Applied Sciences, 1(6), 43–53. https://doi.org/10.59324/ejtas.2023.1(6).05

Aldoseri, A., Al-Khalifa, K. N., & Hamouda, A. M. (2023). Re-thinking data strategy and integration for artificial intelligence: Concepts, opportunities, and challenges. Applied Sciences, 13(12), Article e7082. https://doi.org/10.3390/app13127082

Al-Mutawa, B., & Al Mubarak, M. M. S. (2024). Impact of cloud computing as a digital technology on SMEs sustainability. Competitiveness Review: An International Business Journal, 34(1), 72–91. https://doi.org/10.1108/CR-09-2022-0142

Asgary, A., Özdemir, A. İ., & Özyürek, H. (2020). Small and medium enterprises and global risks: Evidence from manufacturing SMEs in Turkey. International Journal of Disaster Risk Science, 11(1), 59–73. https://doi.org/10.1007/s13753-020-00247-0

Chukwurah, E. G. (2024). Agile privacy in practice: Integrating CCPA and GDPR within agile frameworks in the U.S. tech scene. International Journal of Scientific Research Updates, 7(2), 24–36. https://doi.org/10.53430/ijsru.2024.7.2.0035

Dhar, T. (2021). The California Consumer Privacy Act: The ethos, similarities and differences vis-à-vis the General Data Protection Regulation and the road ahead in light of California Privacy Rights Act. Journal of Data Protection & Privacy, 4(2), 170–192. https://doi.org/10.69554/GLSA8501

Dorner, M., Capraro, M., Treidler, O., Kunz, T.-E., Šmite, D., Zabardast, E., Méndez, D., & Wnuk, K. (2024). Taxing collaborative software engineering: The challenges for tax compliance in software engineering. IEEE Software, 41(4), 143–150. https://doi.org/10.1109/MS.2023.3346646

Ehimuan, B., Obi, O. C., Akagha, O. V., Reis, O., & Oguejiofor, B. B. (2024). Global data privacy laws: A critical review of technology’s impact on user rights. World Journal of Advanced Research and Reviews, 21(2), 1058–1070. https://doi.org/10.30574/wjarr.2024.21.2.0369

Gorondutse, A. H., Arshad, D., & Alshuaibi, A. S. A. (2021). Driving sustainability in SMEs’ performance: The effect of strategic flexibility. Journal of Strategy and Management, 14(1), 64–81. https://doi.org/10.1108/JSMA-03-2020-0064

Halim, W., Upadhyay, A., & Coflan, C. (2022). Data access and protection laws in Pakistan: A technical review. EdTech Hub. https://doi.org/10.53832/edtechhub.0098

Harding, E. L., Vanto, J. J., Clark, R., Ji, L. H., & Ainsworth, S. C. (2019). Understanding the scope and impact of the California Consumer Privacy Act of 2018. Journal of Data Protection & Privacy, 2(3), 234–253. https://doi.org/10.69554/TCFN5165

Herce, C., Martini, C., Toro, C., Biele, E., & Salvio, M. (2024). Energy efficiency policies for small and medium-sized enterprises: A review. Sustainability, 16(3), Article e1023. https://doi.org/10.3390/su16031023

Hindle, A. (2020). Impact of GDPR on identity and access management. IDPro Body of Knowledge,. https://doi.org/10.55621/idpro.24

Hou, X., Wang, B., & Gao, Y. (2020). Stakeholder protection, public trust, and corporate social responsibility: Evidence from listed SMEs in China. Sustainability, 12(15), Article e6085. https://doi.org/10.3390/su12156085

Igbinenikaro, E., & Adewusi, A. O. (2024). Developing international policy guidelines for managing cross-border insolvencies in the digital economy. International Journal of Management & Entrepreneurship Research, 6(4), 1034–1048. https://doi.org/10.51594/ijmer.v6i4.983

Junejo, I., Kazi, S., Siddiqui, M. B., Ramish, M. S., & Malokani, D. K. A. K. (2023). Impact of legal framework and SCM policies on supply chain collaboration: Role of information technology. Russian Law Journal, 11(10S), 76–84. https://doi.org/10.52783/rlj.v11i10s.1653

Kisavi, S. M., & Rotich, A. (2023). Effect of corporate social responsibility on the financial performance of small and medium enterprises in Makueni Sub-County. Journal of Finance and Accounting, 7(11), 139–161. https://doi.org/10.53819/81018102t5294

Kretschmer, M., Pennekamp, J., & Wehrle, K. (2021). Cookie banners and privacy policies: Measuring the impact of the GDPR on the web. ACM Transactions on the Web, 15(4), 1–42. https://doi.org/10.1145/3466722

Krimmer, R., Dedovic, S., Schmidt, C., & Corici, A.-A. (2021). Developing cross-border e-governance: Exploring interoperability and cross-border integration. In R. Krimmer & M. R. Johannessen (Eds.), Electronic participation (Lecture Notes in Computer Science, Vol. 12849, pp. 107–124). Springer. https://doi.org/10.1007/978-3-030-82824-0_9

Kuner, C. (2019). The internet and the global reach of EU law. In M. Cremona & J. Scott (Eds.), EU law beyond EU borders: The extraterritorial reach of EU law (pp. 112–145). Oxford University Press. https://doi.org/10.1093/oso/9780198842170.003.0004

Kununka, S., Mehandjiev, N., & Sampaio, P. (2018). A comparative study of Android and iOS mobile applications’ data handling practices versus compliance to privacy policy. In M. Hansen, E. Kosta, I. Nai-Fovino, & S. Fischer-Hübner (Eds.), Privacy and identity management. The smart revolution (IFIP Advances in Information and Communication Technology, Vol. 526, pp. 301–313). Springer. https://doi.org/10.1007/978-3-319-92925-5_20

Malgieri, G. (2023). In/acceptable marketing and consumers’ privacy expectations: Four tests from EU data protection law. Journal of Consumer Marketing, 40(2), 209–223. https://doi.org/10.1108/JCM-03-2021-4571

Marques, A. L., & Alvim, A. T. B. (2021). Construction of sustainable territories and the multiple dimensions of sustainability: An assessment of urban and environmental instruments in the Juqueri-Cantareira Sub-basin of the São Paulo Metropolitan Region. Frontiers in Sustainable Cities, 3, Article e670985. https://doi.org/10.3389/frsc.2021.670985

Masudi, J. A., & Mustafa, N. (2023). Cyber security and data privacy law in Pakistan: Protecting information and privacy in the digital age. Pakistan Journal of International Affairs, 6(3), 356–366. https://doi.org/10.52337/pjia.v6i3.906

Mausa, O. H., & Safina, M. (2024). Perceptions of tax compliance willingness among SME owners in KCCA, Uganda. International Journal for Multidisciplinary Research, 6(4), 1–8. https://doi.org/10.36948/ijfmr.2024.v06i04.23334

Men, F., Yaqub, R. M. S., Yan, R., Irfan, M., & Haider, A. (2023). The impact of top management support, perceived justice, supplier management, and sustainable supply chain management on moderating the role of supply chain agility. Frontiers in Environmental Science, 10, Article e1006029. https://doi.org/10.3389/fenvs.2022.1006029

Millagala, K. (2023). Navigating the confluence of artificial intelligence and social media marketing. International Journal of Research Publications, 133(1), 19–35. https://doi.org/10.47119/IJRP1001331920235473

Ngesa, J. (2024). Tackling security and privacy challenges in the realm of big data analytics. World Journal of Advanced Research and Reviews, 21(2), 552–576. https://doi.org/10.30574/wjarr.2024.21.2.0429

Njilu, M. (2023). Tax compliance among small and medium manufacturing enterprises in Kenya: Does tax morale matter? Rowter Journal, 2(1), 46–55. https://doi.org/10.33258/rowter.v2i1.836

Nuryyev, G., Wang, Y.-P., Achyldurdyyeva, J., Jaw, B.-S., Yeh, Y.-S., Lin, H.-T., & Wu, L.-F. (2020). Blockchain technology adoption behavior and sustainability of the business in tourism and hospitality SMEs: An empirical study. Sustainability, 12(3), Article e1256. https://doi.org/10.3390/su12031256

Nyamwesa, A. (2024). Cloud computing technology adoption: Challenges for SMEs, a case of selected SMEs in Tanzania. International Journal of Advanced Business Studies, 3(2), 1–12. https://doi.org/10.59857/IJABS.3118

Ogbeide, V. O., Omorogiuwa, O., & Salami, E. E. (2023). An empirical survey to substantiate the need for a cyber security framework for SMEs in Nigeria. International Journal of Research Publications, 128(1), 281–296. https://doi.org/10.47119/IJRP1001281720235221

Okoli, U. I., Obi, O. C., Adewusi, A. O., & Abrahams, T. O. (2024). Machine learning in cybersecurity: A review of threat detection and defense mechanisms. World Journal of Advanced Research and Reviews, 21(1), 2286–2295. https://doi.org/10.30574/wjarr.2024.21.1.0315

Oyeniran, O. C., Modupe, O. T., Otitoola, A. A., Abiona, O. O., Adewusi, A. O., & Oladapo, O. J. (2024). A comprehensive review of leveraging cloud-native technologies for scalability and resilience in software development. International Journal of Science and Research Archive, 11(2), 330–337. https://doi.org/10.30574/ijsra.2024.11.2.0432

Qamar, A., Javed, T., & Beg, M. O. (2021). Detecting compliance of privacy policies with data protection laws. ArXiv Preprint. https://arxiv.org/abs/2102.12362

Rehman, S. U., Al-Shaikh, M., Washington, P. B., Lee, E., Song, Z., Abu-AlSondos, I. A., Shehadeh, M., & Allahham, M. (2023). Fintech adoption in SMEs and bank credit supplies: A study on manufacturing SMEs. Economies, 11(8), Article 213. https://doi.org/10.3390/economies11080213

Santema, P., & Kempenaers, B. (2023). Patterns of extra-territorial nest-box visits in a songbird suggest a role in extra-pair mating. Behavioral Ecology, 34(1), 150–159. https://doi.org/10.1093/beheco/arac111

Staunton, C., Edgcumbe, A., Abdulrauf, L., Gooden, A., Ogendi, P., & Thaldar, D. (2025). Cross-border data sharing for research in Africa: An analysis of the data protection and research ethics requirements in 12 jurisdictions. Journal of Law and the Biosciences, 12(1), Article elsaf002. https://doi.org/10.1093/jlb/lsaf002

Thomas, A., Scandurra, G., & Carfora, A. (2022). Adoption of green innovations by SMEs: An investigation about the influence of stakeholders. European Journal of Innovation Management, 25(6), 44–63. https://doi.org/10.1108/EJIM-07-2020-0292

Younas, A., & Mirzaraimov, B. T. O. (2021). To what extent are consumers harmed in the digital market from the perspective of the GDPR? International Journal of Multidisciplinary Research and Analysis, 4(8), 1187–1192. https://doi.org/10.47191/ijmra/v4-i8-17

Zamani, S. Z. (2022). Small and medium enterprises (SMEs) facing an evolving technological era: A systematic literature review on the adoption of technologies in SMEs. European Journal of Innovation Management, 25(6), 735–757. https://doi.org/10.1108/EJIM-07-2021-0360

Downloads

Published

2026-06-30

How to Cite

Nawang, N. I., Ali, S. S., & Awang, M. B. B. (2026). Data Protection in the Age of AI: A Legal Analysis of the Impact of Foreign Data Protection Laws on Pakistani Businesses. Law and Policy Review, 5(1), 106–127. https://doi.org/10.32350/lpr.52.06

Issue

Section

Articles

Similar Articles

1 2 3 4 > >> 

You may also start an advanced similarity search for this article.