Law No. 30 of 2018 was early among the Gulf regimes, and in shape it is familiar - consent-led processing, a set of principles, individual rights, transfer conditions and a breach duty. What sets it apart is a requirement to obtain authorisation before certain kinds of processing may begin at all.
Processing needs approval first? Then it is a schedule problem.
Under Bahrain's PDPL some processing needs authorisation before it begins, not after - so the approval sets your start date.
Our promise
“A view is not a position. The memo is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditBahrain PDPL, in three chapters
Most programmes treat that authorisation as paperwork and find out otherwise in launch week. It is a dependency with a lead time: the date you can go live is the date the application is answered, not the date you sent it - and nobody plans for it until it is the last one.
We answer the approval question first, in writing and with its reasoning, so it lands as a schedule input rather than a finding. Then every principle is tested for the evidence it should produce, and each rights route is tried from the outside rather than described from the inside by its owner.
Whose decision, not where you sit.
Personal data processed under your decisions about why and how - wherever your head office happens to sit.
- Whoever decides why and how data is processed
- Processors acting on those instructions
- Model vendors holding prompts and logs
- Anyone evaluating individuals automatically
- Before processing begins, where approval is needed
- At collection, purpose by purpose, for the basis
- On becoming aware, for the breach assessment
- Before the data lands outside Bahrain
The duty is yours. So is the machine’s.
Whoever decides the purpose
The organisation deciding why and how personal data is processed carries every duty on this page - the basis, the notices, the rights routes, the records, the retention schedule - and deciding it from outside Bahrain moves the duty neither somewhere else nor on to somebody else who runs it.
The people who process for you
A processor acting on your instructions is bound by what those instructions say, and by controls you were supposed to have verified rather than accepted. A model vendor holding your prompts and your logs is a processor, whatever the contract happens to call it and whatever it prefers to call itself.
Some processing needs asking first
Bahrain requires authorisation before certain processing begins rather than a notification afterwards, and automated evaluation of individuals is the kind that raises it. That makes it a dependency with a lead time on your plan, rather than a form that somebody files once the build is already finished.
“We will file the paperwork at launch.”
Approval is asked for beforehand.
It is the first thing we have to correct.
- Who it is for
- Retail & e-commerce
- Banks & insurers
- Health & education
- SaaS serving Bahrain
- Scoring & eligibility teams
Administrative penalties are banded by how serious the contravention is. This page prints no figure for any band; none is ours to state.
The outcome that arrives most often is neither a fine nor a headline - it is a direction to change or to stop what you are already doing.
Four Gulf regimes, similar in shape and different in exactly the details that set your schedule. The region is not one programme, and never was.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Ask it early, or explain it late.
Four moments where the approval question lands, and only the first one is cheap to answer.
-
Ask the question
At designWhich activities may need authorisation before they begin. Asked while the design can still change cheaply.
-
Take the position
Before you buildThe answer written down with its reasoning, so a later reviewer sees a decision rather than an omission.
-
Leave the lead time
Before you launchAn application is not instant. The date you can go live is the date it is answered, not the date you applied.
-
Re-ask it
On every changeA new purpose, model or data source can re-open the question a closed programme thinks is settled.
A programme that files the approval question under paperwork will have notices, a basis and a rights inbox - and no answer in launch week, when the only remaining option is to delay the launch or to start without the authorisation.
What the law says, what we ship
12 duties: six processing principles, then the six rights people can exercise.
- Lawful basis Recorded per purpose
- The basis relied on for each purpose, with consent informed and specific where it is the basis, exceptions argued explicitly rather than assumed, and withdrawal that propagates.
- Purpose limitation Fixed before collection
- Purposes stated at the point of collection and secondary use assessed rather than absorbed - training a model on data collected for something else is usually a new purpose.
- Data minimisation The judgement recorded
- Fields collected because they are needed, training sets scoped rather than maximised, prompt context trimmed at the edge, and the reasoning kept where a reviewer can read it.
- Accuracy Higher where it decides
- A bar proportionate to the consequence, with source and currency recorded, corrections reaching downstream copies, and model output never treated as a source of truth.
- Retention limitation Disposal that runs
- A schedule with named owners and disposal that actually executes - covering backups, archives and logs, and the prompt and response logs people forget are records.
- Security Tested, not attested
- Access control over data and model artefacts, encryption in transit and at rest, processor controls that were verified rather than accepted, and output treated as an egress path.
- Information and transparency Before collection
- What is collected, why, who receives it and where it goes - owed at or before the point of collection rather than produced on request when somebody asks.
- Access to their data A route from outside
- Confirmation of processing and a copy of what is held, through a route a member of the public can find and use without help from somebody who works there.
- Correction Reaching the copies
- Inaccurate or incomplete data corrected, with the correction reaching processors and downstream copies rather than the primary record alone and nothing else.
- Erasure And what it means
- Deletion where the conditions are met, plus a written position on what deletion means for a model already trained on the data - taken before somebody asks, not after.
- Objection Marketing separately
- A working objection route, including to direct marketing, which generally carries its own consent regime separate from the basis relied on for the processing itself.
- Withdrawal of consent As easy as giving
- As easy to withdraw as it was to give, and effective downstream - a withdrawal that stops the front door and not the pipeline is not a withdrawal at all.
Personal information, independently reviewed
From the CRM to the model in the decision path.
-
Intake
Which systems hold personal data reaching a model, and what each is for.
-
Test
Every duty against the estate as it runs - approval question first.
-
Sign off and evidence
You see the draft first. Then the records, notices and drills - dated.
Why teams choose iDharma for their Bahrain PDPL review
Approval, up front
A schedule dependency from day one, not a compliance item found at launch.
GDPR work carries over
Findings tagged across, so a team with GDPR experience sees what transfers.
Mapped Gulf-wide
Tagged to the Qatar, Saudi and UAE regimes too, for estates spanning the region.
Evidence, not narrative
Records and decisions assembled in the shape asked for, not reconstructed later.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Bahrain PDPL review report
The full review: what you process, on what basis, and where each duty is evidenced or is not - written duty by duty rather than as a score. The prior-approval position is stated first and separately, because it is the finding most likely to move a launch date rather than a backlog item.
Prior-approval assessment
Which activities may require authorisation before they begin, and roughly how long that takes - a schedule input rather than a paperwork task.
Data inventory and map
Every flow of personal data that reaches a model - training corpora, prompts, retrieval indexes, logs and vendor endpoints - traced inwards.
Basis and consent record
The basis relied on for each purpose, and whether the record would survive being asked for - including whether a withdrawal actually propagates.
Rights request runbook
Access, correction, erasure, objection and withdrawal, each with a route tested from the outside in rather than described from the inside out.
Transfer and breach pack
Where the data lands and on what condition, plus an assessment procedure, a named decision-maker and a notification path, rehearsed once.
Policy template pack
The core set, the rights and procedures set and the security set - written to Bahrain rather than handed over as a generic regional privacy pack.
Real numbers, upfront.
- Scope
- Set by the statute
- Inputs
- Your systems and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The statute fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Prior-approval position
- Basis and consent record
- The breach path, walked once
- 26 policy templates, tailored
Four things you have to be able to produce
The PDPL is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The answer,
in writing
Whether any of your processing needs authorisation before it begins, answered in writing. A programme that never asked cannot show the answer was no.
The basis,
per purpose
Not one basis for the organisation but one per purpose, with consent informed and specific where it is relied on, and a withdrawal that actually reaches the pipeline.
The route,
usable
A request route a member of the public can find and use without help, tested from the outside in rather than described from the inside out by the team that built it.
The records,
current
Records of processing kept current, a named contact for data protection, and decisions documented when they were taken rather than reconstructed later.
Four cards, and each one is evidence or it is nothing.
Plain answers
What the law is, whether it reaches you, the clock, and where AI lands. Answered straight.
Request this reviewWhat is Bahrain PDPL?
Bahrain’s Personal Data Protection Law, Law No. 30 of 2018. It was early among the Gulf regimes and it is stricter than most of its neighbours in one specific way: certain processing requires authorisation before it begins rather than a notification afterwards.
Who must comply with Bahrain PDPL?
The organisation that decides why and how personal data is processed, whether or not it is established in Bahrain. Processors acting on instructions are bound by those instructions and by controls you were supposed to have verified rather than accepted on trust.
When is prior approval required, and how long does it take?
For defined categories of processing, authorisation has to be obtained before the processing begins. Which categories reach your estate is the question worth settling at design time: the date you can go live is the date the application is answered, not the date you sent it.
How does Bahrain PDPL apply to AI and automated decisions?
There is no standalone automated-decision regime as there is in some other jurisdictions. The exposure arrives through the prior-approval route instead: automated evaluation of individuals is the kind of processing that raises the authorisation question, which is why it belongs at design time.
What does an iDharma Bahrain PDPL review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the prior-approval assessment, the data inventory and map, the basis and consent record, the rights request runbook, the transfer and breach pack and the policy template pack.
Request your Bahrain PDPL review
Tell us where the personal data lives and we come back in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.
- Which systems hold personal data reaching a model
- Whether the approval question has ever been asked
- Your current privacy notice and consent wording
- Where individuals are evaluated automatically
- Where data leaves Bahrain, and on what condition
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Law No. 30 of 2018, as enacted
- The supervisory authority for personal data, on its guidance
- Enacted
- Law No. 30 of 2018
- Distinctive
- Prior approval
What it means
- General information about what the statute requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- No penalty figure appears here. Our own source and the reference this page was written against state the administrative and penal ceilings the other way round from each other — so for a number, go to the Commission.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom