Law note · Qatar

Personal Data Privacy Protection Law, comprehensive regime

cite Law No. 13 of 2016, Chapter One stage IN FORCE in force since 2017-01-01 kind Comprehensive regime binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that collects, uses, or discloses the personal data of an individual in Qatar, including a voiceprint, faceprint, or other biometric identifier, must have a lawful, consent-and-purpose-based basis for processing under the PDPPL; Qatar's special-nature-data list does not name biometric data as its own heightened category, but ordinary personal data duties still apply to it.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.

Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.

Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted in this research pass.

← Back to the example  ·  Lint your app →