Law note · Qatar
Personal Data Privacy Protection Law, breach notification
What it requires
- An app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.
Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.