Dr Sahibzada Ali Mahmud, Chief Digital Public Infrastructure Officer at the Pakistan Digital Authority (PDA), has written in The News on how WASL, Pakistan’s National Data Exchange Layer, builds trust directly into its architecture, framing the underlying question as one every citizen has a right to ask: who looked at my data, and why. The piece, the second in his ongoing series on Pakistan’s Digital Public Infrastructure, draws on lessons from Estonia’s X-Road system, widely regarded as one of the most established national data exchange models globally, alongside experiences from the United Kingdom, Australia, and Uganda. Rather than treating trust as an abstract principle, Mahmud’s argument centers on making data access auditable and verifiable in ways that go beyond simple policy assurances.
According to Mahmud, the combination of WASL’s technical architecture with the enforcement powers proposed in the draft National Data Governance Policy makes the answer to “who looked at my data?” something citizens can actually check, and something a court can verify as well. The draft policy, which frames government data as a strategic national asset held in trust for the people rather than the property of individual agencies, establishes public bodies as custodians rather than proprietors of the data they hold, with custodianship carrying specific duties around protection, quality maintenance, discoverability, and lawful, proportionate disclosure. This framing shifts the conversation from a purely technical question of how data moves between systems into a legal and governance question of who bears responsibility when it is accessed or shared.
WASL itself is designed as a governed National Data Exchange through which federal agencies would securely exchange information rather than creating separate copies of the same datasets across different departments, directly addressing the duplication and fragmentation that has long characterized Pakistan’s government data systems. The draft governance framework also introduces a “once-only” principle intended to reduce bureaucratic burden, stating that citizens should not be required to provide the same information to the state more than once unless repetition is necessary by law or for verification purposes. Mahmud’s emphasis on audit trails and enforceable accountability builds directly on this structure, arguing that the technical capability to exchange data securely only translates into public trust when citizens can see how their information is actually being used and know that violations carry real consequences.
Mahmud’s central argument, that trust does not come from simply building new systems but must be visible and felt, reflects a broader challenge facing digital public infrastructure projects globally, where technically sound systems have sometimes struggled to gain public confidence without transparent accountability mechanisms attached. His series on Pakistan’s Digital Public Infrastructure comes as PDA continues rolling out WASL across multiple sectors, including recent engagements with the banking industry and individual digital banks like Raqami Islamic Digital Bank, extending the National Data Exchange Layer’s relevance beyond government agencies into private sector financial services. As the draft National Data Governance Policy moves through further review, Mahmud’s framing suggests PDA is positioning enforceable citizen rights over data access, rather than technical capability alone, as the actual test of whether WASL succeeds in building the kind of public trust large scale government data infrastructure projects have often struggled to establish elsewhere.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.