Law note · Bahrain

Personal Data Protection Law, cross-border transfer

cite Law No. 30 of 2018, Arts. 12-13 stage IN FORCE in force since 2019-08-01 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Bahrain to a recipient outside Bahrain must confirm the destination is on the PDPA's published adequacy whitelist or has case-by-case PDPA authorisation, or must rely on one of Art. 13's listed exemptions such as the Data Subject's consent.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 12 prohibits transfer of personal data outside Bahrain except to a country on a PDPA-published adequacy whitelist (published in the Official Gazette), or under a case-by-case PDPA authorisation based on an adequacy assessment considering the data's nature, origin and destination, and relevant international agreements.

Art. 13 lists exemptions allowing transfer to a non-adequate destination without going through Art. 12: data-subject consent, a public-register transfer, contract necessity, vital-interest protection, legal obligation or court or prosecution order, and legal-claim preparation. This is a prohibition-with-listed-exceptions structure, the strictest transfer posture read across this batch, and this document departs from the carried moderate seed to record strict.

← Back to the example  ·  Lint your app →