Law note · Qatar
Personal Data Privacy Protection Law, comprehensive regime
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Qatar, including a voiceprint, faceprint, or other biometric identifier, must have a lawful, consent-and-purpose-based basis for processing under the PDPPL; Qatar's special-nature-data list does not name biometric data as its own heightened category, but ordinary personal data duties still apply to it.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.
Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.
Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted in this research pass.