Law / Qatar

Qatar

privacy

Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, PDPPL) is the Gulf's first data-protection statute and, read at primary source, is markedly shorter and more high-level than the UAE or Saudi PDPLs. It is a comprehensive regime: Art. 1's broad, technology-neutral Personal Data definition reaches a voiceprint or faceprint like any other identifying data, so an app deriving one from an individual in Qatar is bound by the PDPPL's ordinary duties.

A real gap relative to its Gulf peers remains: Article 16's "Personal Data with Special Nature" list, the closest thing the PDPPL has to a sensitive-category provision, does not name biometric data at all, unlike the newer UAE, Saudi, Omani, and Jordanian statutes, so a biometric identifier does not trigger the Art. 16(3) heightened Competent Department permission requirement the way it does in those regimes, though the Minister may add categories by decision and no evidence such a decision has added biometric data was found.

Cross-border data flow is governed by Article 15, whose plain text bars the Controller from restricting flow except where the underlying processing already breaches the Law or risks serious damage, a permissive default rather than an adequacy gate, arguably lighter than the carried moderate seed.

A 2025 Cybercrime Law amendment (Law No. 11 of 2025, reportedly adding Art. 8 bis to Law No. 14 of 2014) is referenced by secondary trackers, but its own Official Gazette text was not read at primary source in this pass, so this document does not describe its content and does not author it as an instrument.

Qatar also runs a separate Qatar Financial Centre (QFC) Data Protection Regulations free-zone regime; only the superseded 2005 QFC text could be located, not the reported 2021 General Data Protection Regulation (GDPR)-aligned replacement, so it is likewise not authored here.

12 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Privacy Protection Law, breach notification

cite Law No. 13 of 2016, Arts. 13-14 stage IN FORCE in force since 2017-01-01 binds public and private bodies source official statute text, National Cyber Security Agency document library
What it requires

Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.

Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.

Comprehensive regime

Personal Data Privacy Protection Law, comprehensive regime

cite Law No. 13 of 2016, Chapter One stage IN FORCE in force since 2017-01-01 binds public and private bodies source official statute text, National Cyber Security Agency document library
What it requires

The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.

Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.

Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted in this research pass.

Cross border transfer

Personal Data Privacy Protection Law, cross-border data flow

cite Law No. 13 of 2016, Art. 15 stage IN FORCE in force since 2017-01-01 binds public and private bodies source official statute text, National Cyber Security Agency document library
What it requires

Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.

Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.

Enforcement supervision

Personal Data Privacy Protection Law, enforcement and penalties

cite Law No. 13 of 2016, Arts. 23-26 stage IN FORCE in force since 2017-01-01 binds public and private bodies source official statute text, National Cyber Security Agency document library
What it requires

Art. 23 sets fines up to QAR 1,000,000 for violations of Arts. 4, 8, 9, 10, 11, 12, 14, 15, and 22. Art. 24 sets fines up to QAR 5,000,000 for violations of Art. 13, Art. 16(3) (special-nature data processing without permission), and Art. 17 (children's websites). Art. 25 extends liability to a legal person committing these "crimes" in its name, confirming these are framed as criminal offenses rather than purely civil or administrative fines.

Art. 26 gives an Individual a complaint route to the Competent Department, which can issue a binding rectification order for a proven serious complaint, with a grievance route to the Minister (60-day windows both ways, silence treated as implicit rejection); no private civil right of action was found.

The PDPPL's own text names "the Competent Department" (within the Ministry of Transport and Communications) as enforcer; current secondary sources refer to a National Data Privacy Office (NDPO) operating within the National Cyber Security Agency, but whether NDPO has formally assumed the Competent Department's statutory role was not confirmed at primary source in this pass.

Sensitive categories

Personal Data Privacy Protection Law, special-nature personal data

cite Law No. 13 of 2016, Art. 16 stage IN FORCE in force since 2017-01-01 binds public and private bodies source official statute text, National Cyber Security Agency document library
What it requires

Art. 16 lists ethnic origin, children's data, health, physical or psychological condition, religious creeds, marital relations, and criminal offenses as "Personal Data with Special Nature."

Biometric data is not named, unlike the UAE, Saudi, Oman, and Jordan statutes researched in this batch, a real gap rather than a research omission: the Minister may add other categories by decision where misuse could cause serious damage (Art. 16, para. 2), but no evidence that this power has been exercised for biometric data was found.

Processing special-nature data requires "permission from the Competent Department, as per the measures and controls determined by a decision issued by the Minister" (Art. 16, para. 3), and a violation carries the higher QAR 5,000,000 penalty tier under Art. 24.

A voiceprint or faceprint might be captured under "physical... condition" by a stretched reading, but that fit is not textually confirmed, so this document does not code Qatar's PDPPL as reaching biometric identifiers as a heightened category.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.