Law note · Qatar
Personal Data Privacy Protection Law, cross-border data flow
What it requires
- An app transferring the personal data of an individual in Qatar out of the country, including a voiceprint or faceprint, is not itself restricted by the Controller absent an underlying breach of the PDPPL or a risk of serious damage to the data or the individual's privacy; Qatar's PDPPL, read plainly, does not impose an adequacy or whitelist gate on outbound transfer the way the UAE's or Saudi Arabia's do.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.
Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.