Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Law No. 13 of 2016, Arts. 13-14
stage IN FORCE in force since 2017-01-01
binds public and private bodies
source official statute text, National Cyber Security Agency document library
What it requires →
Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.
Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.
Comprehensive regime
cite Law No. 13 of 2016, Chapter One
stage IN FORCE in force since 2017-01-01
binds public and private bodies
source official statute text, National Cyber Security Agency document library
What it requires →
The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.
Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.
Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted in this research pass.
Cross border transfer
cite Law No. 13 of 2016, Art. 15
stage IN FORCE in force since 2017-01-01
binds public and private bodies
source official statute text, National Cyber Security Agency document library
What it requires →
Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.
Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.
Enforcement supervision
cite Law No. 13 of 2016, Arts. 23-26
stage IN FORCE in force since 2017-01-01
binds public and private bodies
source official statute text, National Cyber Security Agency document library
What it requires →
Art. 23 sets fines up to QAR 1,000,000 for violations of Arts. 4, 8, 9, 10, 11, 12, 14, 15, and 22. Art. 24 sets fines up to QAR 5,000,000 for violations of Art. 13, Art. 16(3) (special-nature data processing without permission), and Art. 17 (children's websites). Art. 25 extends liability to a legal person committing these "crimes" in its name, confirming these are framed as criminal offenses rather than purely civil or administrative fines.
Art. 26 gives an Individual a complaint route to the Competent Department, which can issue a binding rectification order for a proven serious complaint, with a grievance route to the Minister (60-day windows both ways, silence treated as implicit rejection); no private civil right of action was found.
The PDPPL's own text names "the Competent Department" (within the Ministry of Transport and Communications) as enforcer; current secondary sources refer to a National Data Privacy Office (NDPO) operating within the National Cyber Security Agency, but whether NDPO has formally assumed the Competent Department's statutory role was not confirmed at primary source in this pass.
Sensitive categories
cite Law No. 13 of 2016, Art. 16
stage IN FORCE in force since 2017-01-01
binds public and private bodies
source official statute text, National Cyber Security Agency document library
What it requires →
Art. 16 lists ethnic origin, children's data, health, physical or psychological condition, religious creeds, marital relations, and criminal offenses as "Personal Data with Special Nature."
Biometric data is not named, unlike the UAE, Saudi, Oman, and Jordan statutes researched in this batch, a real gap rather than a research omission: the Minister may add other categories by decision where misuse could cause serious damage (Art. 16, para. 2), but no evidence that this power has been exercised for biometric data was found.
Processing special-nature data requires "permission from the Competent Department, as per the measures and controls determined by a decision issued by the Minister" (Art. 16, para. 3), and a violation carries the higher QAR 5,000,000 penalty tier under Art. 24.
A voiceprint or faceprint might be captured under "physical... condition" by a stretched reading, but that fit is not textually confirmed, so this document does not code Qatar's PDPPL as reaching biometric identifiers as a heightened category.