Who rules the rules in cyberspace
In cyberspace, where digital “state of nature” indicates a presence of hackers, trolls, cyber threats, and misinformation, English philosopher Thomas Hobbes would argue for a strong central authority to create order through the enforcement of law and regulation by way of moderation, surveillance, and firewalls. T he feeling of security provides the basis for surrendering some freedoms to these…
In the digital realm, the question of who governs the rules of cyberspace remains a complex and contentious issue. Renowned philosophers Thomas Hobbes, John Locke, and Jean-Jacques Rousseau offer distinct perspectives on the matter. Hobbes advocates for a strong central authority to maintain order through regulation, surveillance, and firewalls, while Locke argues that users have inherent rights to their privacy and data, safeguarded by reasonable terms of service.
Rousseau champions decentralised governance, emphasizing community-driven decision-making and self-governance.
The current state of the internet reflects a blend of these philosophies, resulting in a patchwork of authorities and regulations. Comparative studies reveal that cultural, political, and socio-economic factors shape each country's approach to digital issues on a global scale. Pakistan's primary legislation addressing cybercrime, the Prevention of Electronic Crimes Act (PECA) of 2016, outlines illegal access to computers, cyber terrorism, and identity theft.
Amendments in 2025 introduced further oversight measures concerning internet content and penalties for spreading false information.
Pakistan's criminal administrative framework for PECA mirrors that of China's Cybersecurity Law and India's Data Security Law, both imposing national control over data flows and implementing rapid responses to malicious activity. However, these frameworks have faced criticism for their broad language, which some argue infringes upon freedom of expression.
In contrast, the European Union (EU) has established directives for cybercrime through the Directive on Attacks against Information Systems and the NIS2 Directive, providing more harmonised standards for infrastructure protection while respecting fundamental rights.
The UK has also implemented standards through the Computer Misuse Act and the Online Safety Act 2023, promoting platform accountability through a risk-based approach. The United States, on the other hand, relies on Section 230 of the Communications Decency Act, offering less liability to intermediaries but increasingly leaning towards a market-based approach that protects freedom of speech.
India, similarly, has grappled with the IT Act of 2000, leading to the creation of intermediary guidelines that balance enforcement with free speech protections.
Pakistan has not signed the Budapest Convention on Cybercrime and lacks fully implemented comprehensive data protection laws. While the Personal Data Protection Bill, based on the General Data Protection Regulation (GDPR), incorporates provisions like consent, purpose limitation, and individual rights, its effectiveness remains uncertain due to limited capacity and piecemeal implementation.
As a result, Pakistan's approach to digital governance is a hybrid of GDPR principles and domestic concerns, falling short of the EU's well-established model.
The GDPR has emerged as the international benchmark for data protection, boasting a wide jurisdictional reach, substantial fines, and a focus on individual rights. However, challenges persist in adapting its principles to varying national contexts, with India and Pakistan actively looking towards the GDPR as a model, despite facing practical difficulties in implementation and enforcement.
Written by urgent.news from Business Recorder's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.