QATAR · LAW No. 13 · QFC REGULATIONS 2021

Qatar has two data protection laws. You are in one of them.

Law No. 13 exempts the Financial Centre and the QFC runs its own regime, so which of the two binds you decides everything after it.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Two rulebooks, and only one of them is yours
Law No. 13 QFC Regulations 72-hour clock Special nature Two regulators

Our promise

“A guess at the regime is a risk. Mapping is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

Qatar, in three chapters

The Laws

Qatar runs two data protection regimes. Law No. 13 of 2016 governs personal data processed electronically within the State, under the National Cyber Security Agency. The QFC Regulations 2021 govern inside the Financial Centre, under its own Data Protection Office and its own rules.

The Gap

Most programmes are built to one column without anybody deciding which. The two have different regulators, different penalty currencies and different drafting ancestry - so a programme built to the wrong one is not a partial programme at all. It is simply the wrong programme.

The Office

Which regime binds each entity is the first thing we settle, in writing, before a word of the programme is drafted. Then the obligations of that regime are tested against the estate as it actually runs, rather than as somebody drew it - and a group spanning the line gets one review, not two.

Which law applies

Two regimes, one line between them.

Start with the entity, not the activity - and the answer is one of them, never both at once.

Onshore – Law No. 13 № 01
  • Data processed electronically within Qatar
  • Regulated by the NCGAA, inside the NCSA
  • Consent-led, with a permission regime beside it
  • Ceiling of QAR 5,000,000, and no criminal sanction
Qatar · iDharma · Presented for review
Inside the QFC – the 2021 Regulations № 02
  • Entities registered in the Financial Centre
  • Regulated by the QFC Data Protection Office
  • Closely aligned to the GDPR in shape
  • Ceiling of USD 1,500,000, set by that Office
Qatar · iDharma · Presented for review
Whose duty is it

The duty is yours. Which duty is the question.

Onshore

Law No. 13 of 2016, onshore

Personal data processed electronically within the State of Qatar, under the National Cyber Governance and Assurance Affairs. Consent-led, with permission from the Competent Department for data of a special nature and 72 hours to notify a breach that would cause serious damage to the individual.

Inside the Centre

The QFC Regulations 2021

Controllers and processors incorporated or registered in the Qatar Financial Centre, and anyone processing through one. Closely aligned to the GDPR - lawful bases, rights, impact assessments and transfer rules - under an independent Data Protection Office of its own, sitting inside the Centre itself.

The catch

You are in one, not both

Law No. 13 expressly exempts the Financial Centre, and the QFC Regulations occupy the space that exemption leaves. The determination is made entity by entity - and a group with companies on each side of the line owes both, over the same shared systems and the same shared people.

What most teams assume

“Qatar PDPL. We will build to that.”

What the laws say

There is no single Qatar PDPL to build to.

It is the first thing we have to correct.

  • Who it is for
  • Financial services & fintech
  • Healthcare providers
  • Employers & HR platforms
  • Multinational groups
  • Cloud & data vendors
Why this matters
A brushed steel shield lying on a dark textured surface under a raking light, engraved with the word AUDIT above the words integrity, transparency and assurance, and a raised tick beneath them.
01 Two ceilings in two currencies: QAR 5,000,000 onshore, USD 1,500,000 inside the Centre. Quote the wrong one to a board and you are out by a factor of several.
02

Law No. 13 carries no criminal sanction. The exposure is financial and reputational - and the breach notice goes to individuals too.

03

Both regulators can require you to change or stop a processing activity. For a live product that is a sharper instrument than a fine is.

04

Saudi Arabia, Bahrain and the UAE each run their own regime. Only Qatar and the UAE also carry a free-zone law beside the national one.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Processing in Qatar -

Electronically, and within the State. That is Law No. 13’s trigger. The QFC Regulations reach an entity registered in the Financial Centre wherever the processing happens.

Which side of the line -

This is the question the page turns on. Law No. 13 expressly exempts the Financial Centre, so a programme built to the wrong column is not a partial programme - it is the wrong one.

Record of processing -

Both regimes turn on it. It is the document either regulator opens first, and the basis, transfer and retention positions are all argued out of it.

The calendar

Four clocks, and one runs before you start.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Permission

    Before you start

    Data of a special nature needs the Competent Department’s permission first. It cannot be obtained afterwards, and onshore health and HR estates hit it early.

  2. Notify

    72 hours

    From detection, to the regulator and to the affected individuals, where the breach would cause serious damage. Both, not one.

  3. Answer

    Plan on 30 days

    Build the rights process to answer comfortably inside a month. What fails is almost never willingness - it is the reach of the search.

  4. Demonstrate

    Continuously

    Records, assessments and notices have to describe the estate on the day, not the estate that existed when they were written.

The trap

Teams treat the special-nature step as a stronger consent and collect it at the form. It is a permission, granted by the Competent Department, and it runs in front of the processing - so it cannot be obtained retrospectively, least of all during an incident.

Requirement & coverage

What the law says, what we ship

12 obligations, each carrying the regime it arises under where the two diverge.

Records of processing Both regimes
A record per activity with purpose, categories, recipients, transfers and retention filled in rather than left as headings. The document both regulators open first.
Lawfulness and basis Consent onshore
The consent position recorded per purpose under Law No. 13, or the lawful basis per purpose inside the QFC, where the full GDPR-pattern basis set is available.
Special-nature permission Law No. 13 only
The Competent Department permission for children, criminal matters, health, ethnic origin, religious belief and marital relations - obtained before the processing starts.
Purpose limitation Both regimes
Purposes fixed before collection, with a compatibility test for any new use - including the secondary model training that most often breaks this one.
Data minimisation Both regimes
Adequate, relevant and limited to what the purpose needs, with field-level justification rather than whatever the system happens to capture.
Accuracy Right to correction
A correction route that reaches the downstream copies, with inferences and scores treated as data and the source of truth named per category.
Storage limitation Tied to purpose
A retention period per category with its justification beside it, and a deletion route that is named rather than assumed to exist.
Security measures Technical & admin
The measures you actually run, argued against the risk they address, so “appropriate” is a position on paper rather than an adjective.
Data subject rights Plan on 30 days
One intake route, identity verification, a search that reaches the backups and the ticketing system, and a decision record per request.
Impact assessments Both regimes
A screening test that says when an assessment is required, the methodology, and completed assessments for the processing that triggers it.
Breach response 72 hours onshore
A detection-to-decision runbook, the notification pack for the regulator and for individuals, and the serious-damage test applied in advance.
Cross-border transfers Article 15 onshore
A transfer register, the basis per route, and the harm assessment Article 15 turns on - plus the QFC mechanism where that is the regime you are in.
The engagement

Personal data, independently reviewed

From the onshore estate to the QFC entity.

  1. Determine

    Which regime binds each entity - onshore, or inside the Centre.

  2. Test

    The obligations of that regime against the estate as it runs.

  3. Sign off and evidence

    You see the draft first. Then the records, notices and drills - dated.

Request a Qatar review
An auditor in a black trouser suit and cream blouse, with dark hair in a low bun, standing against a warm pale wall and pointing into the open space alongside.
The determination is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their Qatar review

The fork, settled first

We determine which regime binds each entity before a word of the programme is written.

One scope, two rulebooks

A group spanning the line gets one programme that satisfies whichever law reaches it.

GDPR work carries over

The QFC Regulations follow the GDPR closely, so an existing programme maps rather than restarts.

The GCC in one scope

Saudi, Bahrain and UAE obligations overlap enough to be worth scoping in the same review.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Qatar readiness report

The full review: which regime binds each entity, what you process under it, and where every obligation is evidenced or is not - written obligation by obligation. Findings carry the regime they arise under, so a group spanning the QFC line reads one report rather than two, with the transfer position and the special-nature permissions stated separately.

Memo

Regime determination

Entity by entity, taken from the register rather than from custom - with the reasoning recorded where a shared system serves both sides of the line.

Workbook

Processing inventory

Every activity with purpose, categories, recipients, transfers and retention - built from the systems inwards rather than from a questionnaire outwards.

Register

Consent and permission log

The consent position per purpose onshore, or the basis inside the QFC - with Competent Department permissions tracked where they are needed.

Runbooks

Rights and breach runbooks

One intake route with identity verification, plus a detection-to-decision breach pack written against the 72-hour clock and rehearsed once.

Assessment

Transfer register and assessment

Where the data actually lands, the basis for each route, and the harm assessment Article 15 turns on - checked against your own notice.

Documents

Policy template pack

The core set, the security and breach set and the governance set - written to whichever regime binds you rather than handed over as a generic pack.

Format & fee

Real numbers, upfront.

Scope
Set by the regime
Inputs
Your entities and your records
Re-review
Every twelve months - $10,500 against your known baseline

The regime fixed the obligations, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
Qatar · Named engagement $12,500 flat
  • Regime determination per entity
  • Processing inventory and register
  • Breach drill on the 72-hour clock
  • 28 policy templates, tailored
Show your hand

Four things you have to be able to produce

Neither regime is graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The regime,
decided

A written determination for each entity: onshore under Law No. 13, or inside the Centre under the QFC Regulations. Everything else on this page depends on the answer.

The record,
current

A record of processing that matches what the systems do. It is the first thing either regulator opens, and the document every other position is argued out of.

The clock,
rehearsed

Seventy-two hours from detection, to the regulator and to the individuals. The serious-damage test decided in advance, because deciding it live is how it is missed.

The route,
papered

A transfer register with the basis for each route out of Qatar, and the harm assessment that Article 15 actually turns on rather than an adequacy list that does not exist.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Which law binds you, the breach clock, the two ceilings, and what the review costs. Answered straight.

Request this review
What is the difference between Law No. 13 and the QFC Regulations?

Two separate regimes with two separate regulators. Law No. 13 of 2016 governs personal data processed electronically within the State of Qatar; the QFC Data Protection Regulations 2021 govern controllers and processors registered in the Financial Centre. Law No. 13 expressly exempts the Centre, so you are in one or the other.

How do I know which one binds us?

Start with the entity, not the activity. If the entity is incorporated or registered in the QFC - or you process through one that is - you are in the QFC regime. Otherwise, if the processing happens electronically within Qatar, you are under Law No. 13. Groups with both need both, entity by entity.

How long do we have to report a breach?

Under Law No. 13, 72 hours from detection to notify both the regulator and the affected individuals, where the breach would cause serious damage. The serious-damage test is one to apply in advance - deciding it during an incident is how the clock gets missed.

What are the penalties?

Onshore, financial penalties from QAR 1,000,000 to QAR 5,000,000 depending on the article breached, with no criminal sanction attached to Law No. 13. Inside the QFC, the Data Protection Office can impose fines up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.

What does an iDharma Qatar review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the readiness report, the regime determination, the processing inventory, the consent and permission log, the rights and breach runbooks, the transfer register and the policy template pack.

Get started

Request your Qatar review

Tell us where the entities sit and we come back with a scoping call in a day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.

  1. Which entities process, and where each is registered
  2. Which systems hold personal data, and what for
  3. Your record of processing, if one already exists
  4. Whether data of a special nature is in play
  5. Where data leaves Qatar, and on what basis

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a Qatar review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Law No. 13 of 2016, on the NCSA assurance portal
  • The QFC Regulations 2021 and the Data Protection Office
Law No. 13
29 December 2016
QFC in force
19 June 2022

What it means

  • General information about what each regime requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • The regulators, the dates and the two penalty ceilings were checked. The article-level detail beneath them — the permission step, the transfer posture, the response window — is written from the discipline.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us