Law / Bahrain

Bahrain

privacy

Bahrain's Personal Data Protection Law (Law No. 30 of 2018, PDPL), read in full at primary source, was the first standalone data-protection statute in the Gulf. Its most distinctive structural feature: biometric data is not part of the "Sensitive Personal Data" definition, but it gets its own, separate, and arguably stronger control.

Article 15's "Prior Authorisation" provision prohibits, without the Personal Data Protection Authority's (PDPA) prior written authorisation, automatic processing of biometric data necessary for identity verification, and separately, visual-recording processing used for surveillance purposes, a heavier gate than mere consent, distinct from the Sensitive Personal Data consent rule in Art. 5.

Because biometric data sits outside the Sensitive Personal Data definition, Art. 5(3)'s publicly-available-data consent exemption plausibly does not reach the Art. 15 prior-authorisation requirement at all, even for data the individual made public. Cross-border transfer is a prohibition-with-listed-exceptions structure (Arts. 12-13), read as stricter than the carried moderate seed. The base Law's own text contains no General Data Protection Regulation (GDPR)-style incident-notification duty with a fixed timeline.

Bahrain arms a private plaintiff: Art. 57 lets a party who suffers damage from a Data Controller's processing, or from a Data Protection Guardian's violation of the Law, claim compensation directly, without prejudice to the Civil Law. Roughly ten Ministerial Resolutions (Orders No. 42-51 of 2022) reportedly supply substantial further operative detail, but their own primary text was not read in this pass, so this document does not describe their content and does not author them as instruments.

14 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Personal Data Protection Law, biometric data prior authorisation

cite Law No. 30 of 2018, Art. 15 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

Art. 15 prohibits, without the PDPA's prior written authorisation, five listed operations including automatic processing of biometric data necessary for the verification of an individual's identity (Art. 15(2)), and processing by means of visual recording used for surveillance purposes (Art. 15(5)).

This sits in its own category distinct from Sensitive Personal Data (Art. 5) and genetic data (Art. 15(3)), gated by a heavier control than mere consent: ex ante regulatory authorisation before processing may begin at all. No modality-specific (voice or face) language was found.

Art. 15(2)'s framing is keyed to a verification use case; it is a genuine, unresolved textual question whether a biometric identifier created for a non-verification purpose (profiling, search, watchlist matching) falls within Art. 15(2) at all, or falls entirely outside both the Sensitive Personal Data consent rule and the Art. 15 prior-authorisation rule. Art. 15(5) independently reaches a faceprint derived from CCTV or similar recorded video used for surveillance. No retention or destruction duty specific to biometric data was found.

Comprehensive regime

Personal Data Protection Law, comprehensive regime and lawful basis

cite Law No. 30 of 2018, Arts. 4-9 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

The Personal Data Protection Law is Bahrain's comprehensive, consent-centric statute with enumerated grounds. Processing generally requires the Data Subject's consent or a listed alternative basis. A Controller/Processor structure is present, alongside a "Data Protection Guardian" role, Bahrain's DPO-equivalent. The Personal Data Protection Authority (PDPA), established by Art. 27, supervises compliance.

Roughly ten Ministerial Resolutions (Orders No. 42-51 of 2022) reportedly supply substantial operative detail, but their primary text was not read in this research pass; see the jurisdiction summary.

Cross border transfer

Personal Data Protection Law, cross-border transfer

cite Law No. 30 of 2018, Arts. 12-13 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

Art. 12 prohibits transfer of personal data outside Bahrain except to a country on a PDPA-published adequacy whitelist (published in the Official Gazette), or under a case-by-case PDPA authorisation based on an adequacy assessment considering the data's nature, origin and destination, and relevant international agreements.

Art. 13 lists exemptions allowing transfer to a non-adequate destination without going through Art. 12: data-subject consent, a public-register transfer, contract necessity, vital-interest protection, legal obligation or court or prosecution order, and legal-claim preparation. This is a prohibition-with-listed-exceptions structure, the strictest transfer posture read across this batch, and this document departs from the carried moderate seed to record strict.

Data subject rights

Personal Data Protection Law, data subject rights

cite Law No. 30 of 2018, Arts. 17-23 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

Section Five (Arts. 17-23) sets Bahrain's data-subject rights, each with its own working-day deadline. The Data Controller must notify a Data Subject who requests confirmation of processing within 15 working days (Art. 18(1)). It must halt or decline to begin direct-marketing processing and notify the Data Subject of its decision within 10 working days of a marketing objection (Art. 20(1)-(2)).

It must halt or decline to begin processing that causes material or moral damage within 10 working days of an objection on that ground (Art. 21(1)). It must respond to a rectification, blocking, or erasure request within 10 working days (Art. 23(1)).

Art. 17 separately requires the Data Controller to brief the Data Subject on the purposes of processing at the time data is obtained, Art. 19 requires notice of the right to object to direct marketing, and Art. 22 gives a Data Subject a right against a decision based solely on automated processing.

An earlier version of this document cited these deadlines to Art. 32 (Conflict of Interest, a provision about PDPA Board members with no bearing on data-subject rights); this instrument now cites the Section Five articles that actually carry them.

Enforcement supervision

Personal Data Protection Law, enforcement and penalties

cite Law No. 30 of 2018, Arts. 55, 57-60 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

The Personal Data Protection Authority (PDPA), established by Art. 27, enforces the Law.

Penalties are dual-track: under Art. 58, imprisonment up to one year and/or a fine of BD 1,000 to BD 20,000 for a list of violations including unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14), processing without Art. 15 prior authorisation, and providing false information or obstructing inspectors; Art. 58(2)'s separate BD 3,000 to BD 20,000 fine is for a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not a Data Controller's data-handling violation.

Art. 59 doubles these fines for a legal person committing the offense in its name or for its benefit. Art. 55 supplies a separate administrative track: a daily compliance penalty (BD 1,000 per day on a first violation, BD 2,000 per day on a repeat violation within three years) and an administrative penalty up to BD 20,000, plus withdrawal of an Art. 15 authorisation.

Art. 57 gives a Data Subject a private right of action: a party who suffers damage from a Data Controller's or Data Protection Guardian's processing of their personal data, or from a Data Protection Guardian's violation of the Law, is entitled to claim compensation from the Data Controller or Data Protection Guardian, without prejudice to the Civil Law. An earlier version of this document stated no private right of action was found; Art. 57 was in the same stored source text and was missed.

Sensitive categories

Personal Data Protection Law, sensitive personal data

cite Law No. 30 of 2018, Arts. 1, 5 stage IN FORCE in force since 2019-08-01 binds public and private bodies source official statute text, Personal Data Protection Authority
What it requires

Art. 1's Sensitive Personal Data definition covers race, ethnical origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, and health or sexual status. Biometric data is absent from this list, the same gap found in Qatar's PDPPL; it is instead regulated separately under Art. 15 (see the biometric_privacy instrument).

Art. 5(3) exempts data the Data Subject has made publicly available from the Sensitive Personal Data consent rule, but because biometric data is not itself Sensitive Personal Data, this exemption does not textually reach Art. 15's separate biometric prior-authorisation gate.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.