Law note · Bahrain
Personal Data Protection Law, enforcement and penalties
What it requires
- An app processing the personal data of an individual in Bahrain without the required lawful basis, prior authorisation, or transfer safeguard risks both criminal penalties (imprisonment and fines up to BD 20,000) and administrative penalties (up to BD 20,000, plus a daily compliance penalty on repeat violation) from the Personal Data Protection Authority, and a data subject who suffers damage from unlawful processing may separately claim compensation directly from the app under Art. 57.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- Yes
What we found
The Personal Data Protection Authority (PDPA), established by Art. 27, enforces the Law.
Penalties are dual-track: under Art. 58, imprisonment up to one year and/or a fine of BD 1,000 to BD 20,000 for a list of violations including unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14), processing without Art. 15 prior authorisation, and providing false information or obstructing inspectors; Art. 58(2)'s separate BD 3,000 to BD 20,000 fine is for a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not a Data Controller's data-handling violation.
Art. 59 doubles these fines for a legal person committing the offense in its name or for its benefit. Art. 55 supplies a separate administrative track: a daily compliance penalty (BD 1,000 per day on a first violation, BD 2,000 per day on a repeat violation within three years) and an administrative penalty up to BD 20,000, plus withdrawal of an Art. 15 authorisation.
Art. 57 gives a Data Subject a private right of action: a party who suffers damage from a Data Controller's or Data Protection Guardian's processing of their personal data, or from a Data Protection Guardian's violation of the Law, is entitled to claim compensation from the Data Controller or Data Protection Guardian, without prejudice to the Civil Law. An earlier version of this document stated no private right of action was found; Art. 57 was in the same stored source text and was missed.