Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Law No. 30 of 2018, Art. 15
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
Art. 15 prohibits, without the PDPA's prior written authorisation, five listed operations including automatic processing of biometric data necessary for the verification of an individual's identity (Art. 15(2)), and processing by means of visual recording used for surveillance purposes (Art. 15(5)).
This sits in its own category distinct from Sensitive Personal Data (Art. 5) and genetic data (Art. 15(3)), gated by a heavier control than mere consent: ex ante regulatory authorisation before processing may begin at all. No modality-specific (voice or face) language was found.
Art. 15(2)'s framing is keyed to a verification use case; it is a genuine, unresolved textual question whether a biometric identifier created for a non-verification purpose (profiling, search, watchlist matching) falls within Art. 15(2) at all, or falls entirely outside both the Sensitive Personal Data consent rule and the Art. 15 prior-authorisation rule. Art. 15(5) independently reaches a faceprint derived from CCTV or similar recorded video used for surveillance. No retention or destruction duty specific to biometric data was found.
Comprehensive regime
cite Law No. 30 of 2018, Arts. 4-9
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
The Personal Data Protection Law is Bahrain's comprehensive, consent-centric statute with enumerated grounds. Processing generally requires the Data Subject's consent or a listed alternative basis. A Controller/Processor structure is present, alongside a "Data Protection Guardian" role, Bahrain's DPO-equivalent. The Personal Data Protection Authority (PDPA), established by Art. 27, supervises compliance.
Roughly ten Ministerial Resolutions (Orders No. 42-51 of 2022) reportedly supply substantial operative detail, but their primary text was not read in this research pass; see the jurisdiction summary.
Cross border transfer
cite Law No. 30 of 2018, Arts. 12-13
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
Art. 12 prohibits transfer of personal data outside Bahrain except to a country on a PDPA-published adequacy whitelist (published in the Official Gazette), or under a case-by-case PDPA authorisation based on an adequacy assessment considering the data's nature, origin and destination, and relevant international agreements.
Art. 13 lists exemptions allowing transfer to a non-adequate destination without going through Art. 12: data-subject consent, a public-register transfer, contract necessity, vital-interest protection, legal obligation or court or prosecution order, and legal-claim preparation. This is a prohibition-with-listed-exceptions structure, the strictest transfer posture read across this batch, and this document departs from the carried moderate seed to record strict.
Data subject rights
cite Law No. 30 of 2018, Arts. 17-23
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
Section Five (Arts. 17-23) sets Bahrain's data-subject rights, each with its own working-day deadline. The Data Controller must notify a Data Subject who requests confirmation of processing within 15 working days (Art. 18(1)). It must halt or decline to begin direct-marketing processing and notify the Data Subject of its decision within 10 working days of a marketing objection (Art. 20(1)-(2)).
It must halt or decline to begin processing that causes material or moral damage within 10 working days of an objection on that ground (Art. 21(1)). It must respond to a rectification, blocking, or erasure request within 10 working days (Art. 23(1)).
Art. 17 separately requires the Data Controller to brief the Data Subject on the purposes of processing at the time data is obtained, Art. 19 requires notice of the right to object to direct marketing, and Art. 22 gives a Data Subject a right against a decision based solely on automated processing.
An earlier version of this document cited these deadlines to Art. 32 (Conflict of Interest, a provision about PDPA Board members with no bearing on data-subject rights); this instrument now cites the Section Five articles that actually carry them.
Enforcement supervision
cite Law No. 30 of 2018, Arts. 55, 57-60
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
The Personal Data Protection Authority (PDPA), established by Art. 27, enforces the Law.
Penalties are dual-track: under Art. 58, imprisonment up to one year and/or a fine of BD 1,000 to BD 20,000 for a list of violations including unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14), processing without Art. 15 prior authorisation, and providing false information or obstructing inspectors; Art. 58(2)'s separate BD 3,000 to BD 20,000 fine is for a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not a Data Controller's data-handling violation.
Art. 59 doubles these fines for a legal person committing the offense in its name or for its benefit. Art. 55 supplies a separate administrative track: a daily compliance penalty (BD 1,000 per day on a first violation, BD 2,000 per day on a repeat violation within three years) and an administrative penalty up to BD 20,000, plus withdrawal of an Art. 15 authorisation.
Art. 57 gives a Data Subject a private right of action: a party who suffers damage from a Data Controller's or Data Protection Guardian's processing of their personal data, or from a Data Protection Guardian's violation of the Law, is entitled to claim compensation from the Data Controller or Data Protection Guardian, without prejudice to the Civil Law. An earlier version of this document stated no private right of action was found; Art. 57 was in the same stored source text and was missed.
Sensitive categories
cite Law No. 30 of 2018, Arts. 1, 5
stage IN FORCE in force since 2019-08-01
binds public and private bodies
source official statute text, Personal Data Protection Authority
What it requires →
Art. 1's Sensitive Personal Data definition covers race, ethnical origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, and health or sexual status. Biometric data is absent from this list, the same gap found in Qatar's PDPPL; it is instead regulated separately under Art. 15 (see the biometric_privacy instrument).
Art. 5(3) exempts data the Data Subject has made publicly available from the Sensitive Personal Data consent rule, but because biometric data is not itself Sensitive Personal Data, this exemption does not textually reach Art. 15's separate biometric prior-authorisation gate.