Law note · Qatar

Personal Data Privacy Protection Law, cross-border data flow

cite Law No. 13 of 2016, Art. 15 stage IN FORCE in force since 2017-01-01 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Qatar out of the country, including a voiceprint or faceprint, is not itself restricted by the Controller absent an underlying breach of the PDPPL or a risk of serious damage to the data or the individual's privacy; Qatar's PDPPL, read plainly, does not impose an adequacy or whitelist gate on outbound transfer the way the UAE's or Saudi Arabia's do.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.

Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.

← Back to the example  ·  Lint your app →