Law note · Bahrain

Personal Data Protection Law, biometric data prior authorisation

cite Law No. 30 of 2018, Art. 15 stage IN FORCE in force since 2019-08-01 kind Biometric privacy binds public and private bodies reviewed 2026-08-29

What it requires

  • An app must obtain the Personal Data Protection Authority's prior written authorisation before automatically processing biometric data to verify an individual's identity in Bahrain, and before processing a visual recording used for surveillance purposes; consent alone is not a sufficient basis for either activity.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models
Excludes recording-derived identifiers
No

What we found

Art. 15 prohibits, without the PDPA's prior written authorisation, five listed operations including automatic processing of biometric data necessary for the verification of an individual's identity (Art. 15(2)), and processing by means of visual recording used for surveillance purposes (Art. 15(5)).

This sits in its own category distinct from Sensitive Personal Data (Art. 5) and genetic data (Art. 15(3)), gated by a heavier control than mere consent: ex ante regulatory authorisation before processing may begin at all. No modality-specific (voice or face) language was found.

Art. 15(2)'s framing is keyed to a verification use case; it is a genuine, unresolved textual question whether a biometric identifier created for a non-verification purpose (profiling, search, watchlist matching) falls within Art. 15(2) at all, or falls entirely outside both the Sensitive Personal Data consent rule and the Art. 15 prior-authorisation rule. Art. 15(5) independently reaches a faceprint derived from CCTV or similar recorded video used for surveillance. No retention or destruction duty specific to biometric data was found.

← Back to the example  ·  Lint your app →