Law note · Qatar

Personal Data Privacy Protection Law, breach notification

cite Law No. 13 of 2016, Arts. 13-14 stage IN FORCE in force since 2017-01-01 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.

Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.

← Back to the example  ·  Lint your app →