Qatar PDPL, both regimes.
Qatar runs two data protection regimes side by side, and the first question is which one binds you. Law No. 13 governs personal data processed onshore and expressly exempts the Financial Centre; the QFC Regulations govern inside it and follow the GDPR closely. Different regulators, different penalty currencies, different answers to nearly every practical question.
What Qatar PDPL actually is
Two laws, two regulators, one country. Getting the fork right is most of the work, and it is the part that is easiest to get wrong.
Law No. 13 of 2016 concerning Personal Data Privacy Protection was published on 29 December 2016 and was the first comprehensive data protection law in the Gulf. It applies to personal data processed electronically, or prepared for electronic processing, within the State of Qatar, and it is administered by the National Cyber Governance and Assurance Affairs within the National Cyber Security Agency.
It is consent-led. Processing generally needs the individual’s consent, and personal data of a special nature — children, criminal matters, health, ethnic origin, religious belief, marital relations — needs permission from the Competent Department on top. That permission step has no GDPR equivalent and is the obligation international teams most often miss.
Law No. 13 expressly exempts the Financial Centre, and the QFC Data Protection Regulations 2021 occupy the space it leaves. Issued on 21 December 2021 and in force from 19 June 2022, they bind controllers and processors registered in the QFC, follow the GDPR closely, and are administered by the independent QFC Data Protection Office.
The practical consequences diverge immediately. Onshore you have a 72-hour clock to tell the regulator and the affected individuals about a breach causing serious damage, and a penalty ceiling of QAR 5 million with no criminal sanction. Inside the QFC the Data Protection Office can fine up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.
In force since 2017, regulated by the NCGAA within the NCSA. Fines to QAR 5 million, no criminal sanction.
GDPR-aligned Regulations administered by the QFC Data Protection Office. Fines to USD 1.5 million.
Who needs to comply
-
Onshore Qatar — Law No. 13
Personal data processed electronically, or prepared for electronic processing, within the State of Qatar. Regulated by the NCGAA within the National Cyber Security Agency.
-
Inside the QFC — the 2021 Regulations
Controllers and processors incorporated or registered in the Qatar Financial Centre — and anyone processing through one. Law No. 13 expressly exempts you; the QFC Regulations do not.
-
Financial services and fintech
Most sit inside the QFC, which means the GDPR-shaped regime rather than the onshore one. Confirm your registration before you build to either.
-
Healthcare providers
Health data is personal data of a special nature under Law No. 13, and processing it needs permission from the Competent Department rather than consent alone.
-
Employers and HR platforms
Employee data is squarely in scope, and cross-border HR systems are the most common route by which a Qatari entity exports data without a documented basis.
-
Multinationals processing from abroad
The trigger for Law No. 13 is processing within Qatar. Where your servers sit matters less than where the processing and the entity do — take advice on the specific structure.
Which regime binds you
Start with the entity, not the activity. Registered in the Financial Centre puts you in the right-hand column; everything else onshore puts you in the left.
| Attribute | Onshore Qatar Law No. 13 of 2016 | Qatar Financial Centre QFC Regulations 2021 |
|---|---|---|
| Instrument | Law No. 13 of 2016 concerning Personal Data Privacy Protection | QFC Data Protection Regulations 2021 |
| In force | Published 29 December 2016 | Issued 21 December 2021, effective 19 June 2022 |
| Who it binds | Personal data processed electronically within the State of Qatar | Controllers and processors incorporated or registered in the QFC, and those processing through them |
| Regulator | National Cyber Governance and Assurance Affairs, within the National Cyber Security Agency | The QFC Data Protection Office, an independent institution of the Centre |
| Relationship | Expressly exempts the Financial Centre | Occupies the space the exemption leaves. You are in one or the other, not both |
| Drafting ancestry | Consent-led, with a permission regime for data of a special nature | Closely aligned to the GDPR — lawful bases, rights, DPIAs, transfer rules |
| Special category data | Children, criminal matters, health, ethnicity, religion, marital status — needs permission from the Competent Department | A special-category regime in the GDPR pattern, handled by condition rather than by permission |
| Breach notification | 72 hours from detection, to the regulator and to affected individuals, where serious damage arises | Notification obligations in the GDPR pattern |
| Cross-border transfer | Article 15 discourages restricting international flows, except where the law is breached or serious harm results | Transfer rules in the GDPR pattern, with the Data Protection Office as the gatekeeper |
| Maximum penalty | QAR 5,000,000 Financial only — no criminal sanction | USD 1,500,000 Imposed by the Data Protection Office |
Groups usually need both. A Qatari holding company with a QFC-registered subsidiary is in both columns at once, entity by entity — which means two notice sets, two breach routes and two regulators to know. The determination is the first deliverable of any engagement here, and it is cheap to do and expensive to assume.
How iDharma supports Qatar PDPL compliance
Six workstreams covering both regimes, with the regime each obligation comes from named on the card rather than blurred into a single “Qatar”.
Processing inventory and mapping
A record of every processing activity with purpose, categories, recipients, transfers and retention — the document both regulators open first, and the one almost nobody has current.
Addresses: Law 13 records QFC records
Data subject rights workflow
One intake route, identity verification, a search that actually reaches the backups and the ticketing system, and a decision record per request.
Addresses: Both regimes
Impact assessments
A screening test that says when an assessment is required, the methodology, and completed assessments for the processing that triggers it — before the processing starts, not after.
Addresses: Law 13 DPIA QFC DPIA
Breach response on a 72-hour clock
A detection-to-decision runbook, the notification pack for the regulator and for individuals, and the serious-damage test applied in advance rather than during the incident.
Addresses: Law 13 — 72 hours
Cross-border transfer governance
A transfer register, the basis per route, and the harm assessment Article 15 turns on — plus the QFC mechanism where that is the regime you are in.
Addresses: Law 13 Art. 15 QFC transfers
Policies and DPO documentation
The policy set for whichever regime binds you, the privacy notices, and the written position on whether you need a data protection officer at all.
Addresses: Both regimes
Built for Qatar’s dual regulatory environment
One engagement, scoped across both regimes and their GCC neighbours.
One scope, two rulebooks
We determine which law binds each entity before writing anything, and produce one programme that satisfies whichever applies.
Work that carries
The QFC Regulations follow the GDPR closely, so a GDPR programme transfers with mapping rather than rewriting — and vice versa.
Neighbours in the same scope
Saudi, Bahrain and UAE obligations overlap heavily. Scoping them together is materially cheaper than three separate reviews.
Regulator-ready artefacts
Records, assessments, notices and decision logs in the form a regulator asks for, not a slide deck about them.
The seven processing principles
Set out as the QFC Regulations set them out, with the onshore analogue named underneath — because Law No. 13 reaches most of the same ground by different drafting.
Lawfulness, fairness and transparency
A basis for every purpose, processing that would not surprise the person, and information they can actually reach.
Purpose limitation
Collected for a specified purpose and not reused for something incompatible with it. The principle secondary AI training most often breaks.
Data minimisation
Adequate, relevant and limited to what the purpose needs — not to what the system happens to capture.
Accuracy
Kept accurate and current, with inaccurate data corrected or erased without delay. Inferences and scores count as data.
Storage limitation
Kept in identifiable form no longer than the purpose requires, with a schedule somebody actually executes.
Integrity and confidentiality
Security appropriate to the risk, argued against that risk rather than asserted as a list of controls.
Accountability
You must be able to demonstrate all of the above. This is the principle that turns the other six into documents.
One list, two sources. The QFC Regulations carry these as principles in the GDPR pattern. Law No. 13 has no equivalent numbered article and arrives at most of the same place through its consent regime, its records and assessment duties, and its security obligations. Saying that plainly is more useful than presenting a single list as though one law governed both.
What people can ask you for
And how long you have. Most of these fail on search coverage rather than on willingness — the backups, the ticketing system and the mailboxes are where requests go to die.
Right to be informed
What you do with the data, told in a notice the person can find and understand before you process.
Right of access
Confirmation that you process their data, a copy of it, and the supplementary information about how and why.
Right to rectification
Inaccurate data corrected and incomplete data completed — including in the downstream copies people forget.
Right to erasure
Deletion where the processing is unnecessary or the data was collected unfairly. Not unconditional; the exemptions are real.
Right to object
To processing that is unnecessary, unfair, or for direct marketing — where marketing objection is effectively absolute.
Right to withdraw consent
As easy to withdraw as it was to give, and withdrawal has to actually stop the processing rather than flag it.
Thirty days is the working standard, not a statutory universal. Build the process to hit it comfortably under either regime and you have removed the argument entirely. Where a request is complex or the identity is not established, record the reason and the date you told the person — a delay you explained is a different thing from a delay you did not.
An 18-week implementation roadmap
Phase one is the one people skip, and here it carries an extra job: deciding which law binds each entity before anything is written.
Scope and gap analysis
Decide which law binds you, then find the data
- Entity-by-entity determination: onshore or QFC
- Data mapping from the systems inwards
- Records of processing drafted
- Gap assessment against the applicable regime
Documentation and policies
Write what you will be asked for
- Privacy notices per audience
- Consent and permission positions recorded
- Retention schedule with justifications
- Rights procedure and response templates
Technical implementation
Make the paper true
- Access control, logging and encryption
- Deletion routes that reach every copy
- Transfer register and per-route basis
- Breach detection wired to the 72-hour clock
Testing and monitoring
Prove it, then keep proving it
- Rights and breach rehearsals against the clock
- Role-based training with completion evidence
- Internal review against the gap list
- A review cycle with owners and dates
Eighteen weeks is elapsed time for a mid-sized estate, not effort. The phases overlap — documentation starts before mapping finishes, and monitoring starts before the technical work is done. Read as four consecutive sprints the ranges add to more than the total, which is the one way to misread this plate.
Penalties and enforcement
Two ceilings in two currencies. Which one applies to you follows from the regime, and getting it wrong misstates your exposure by a wide margin in either direction.
Fines run from QAR 1,000,000 to QAR 5,000,000 depending on the article breached. The law carries no criminal sanction — the exposure is financial and reputational.
Imposed by the Data Protection Office, which also adjudicates complaints and investigates alleged contraventions of the Regulations.
Regulatory direction
Both regulators can require you to change or stop a processing activity. For a live product that is a sharper instrument than a fine.
Reputational exposure
Breach notification under Law No. 13 goes to affected individuals as well as the regulator. The disclosure is part of the penalty.
How Qatar compares across the GCC
The obligations overlap heavily. What differs is the regulator, the treatment of consent, whether criminal exposure exists, and whether a free-zone regime sits alongside the national one.
| Aspect | Qatar | Saudi Arabia | Bahrain | UAE |
|---|---|---|---|---|
| Primary instrument | Law No. 13 of 2016, plus the QFC Regulations 2021 | PDPL by Royal Decree, with implementing regulations | Law No. 30 of 2018 | Federal Decree-Law No. 45 of 2021 |
| Regulator | NCGAA / NCSA onshore; the QFC Data Protection Office inside the Centre | SDAIA | The Personal Data Protection Authority | The UAE Data Office |
| Free-zone split | Yes — the QFC has its own regime | No equivalent split | No equivalent split | Yes — DIFC and ADGM run their own laws |
| GDPR alignment | Partial onshore; close inside the QFC | Substantial, with local departures | Substantial | Substantial |
| Primary basis | Consent-led onshore; full basis set in the QFC | Consent-led, with statutory alternatives | Consent-led, with statutory alternatives | Consent-led, with statutory alternatives |
| Criminal exposure | None under Law No. 13 | Yes, for certain sensitive-data disclosures | Yes, imprisonment available | Primarily administrative |
Read this as orientation, not as citation. Four jurisdictions are moving at different speeds and any table precise enough to rely on would be stale within a quarter. Use it to see the shape of the neighbourhood, then take the country page — and advice — for the one you actually operate in.
Frequently asked questions
Which law applies, what it asks for, and what it costs to get wrong.
What is the difference between Law No. 13 and the QFC Regulations?
They are two separate regimes with two separate regulators. Law No. 13 of 2016 governs personal data processed electronically within the State of Qatar and is enforced by the National Cyber Governance and Assurance Affairs within the NCSA. The QFC Data Protection Regulations 2021 govern controllers and processors registered in the Qatar Financial Centre and are administered by the QFC Data Protection Office. Law No. 13 expressly exempts the Financial Centre, so you are in one or the other.
How do I know which one binds us?
Start with the entity, not the activity. If the entity is incorporated or registered in the QFC — or you process through one that is — you are in the QFC regime. Otherwise, if the processing happens electronically within Qatar, you are under Law No. 13. Groups with both need both, entity by entity.
When did each take effect?
Law No. 13 was published on 29 December 2016 and became effective the following year. The QFC Regulations were issued on 21 December 2021 and took effect on 19 June 2022.
Is Qatar PDPL the same as GDPR?
The QFC Regulations are closely aligned to the GDPR and a GDPR programme transfers into them with mapping rather than rewriting. Law No. 13 reaches much of the same ground but is consent-led and uses a permission regime for data of a special nature, so a GDPR programme needs real adaptation rather than a relabel.
How long do we have to report a breach?
Under Law No. 13, 72 hours from detection to notify both the regulator and the affected individuals, where the breach would cause serious damage. The serious-damage test is one you should have applied in advance — deciding it during an incident is how the clock gets missed.
How long do we have to answer a rights request?
Plan on 30 days as the working standard and build the process to hit it comfortably. The failure mode is almost never willingness; it is a search that does not reach the backups, the ticketing system and the mailboxes.
What is personal data of a special nature?
Under Law No. 13 it covers data relating to children, criminal matters, health, ethnic origin, religious belief and marital relations. Processing it requires permission from the Competent Department — a permission step, not merely a stronger consent.
Do we need a data protection officer?
Take a written position either way rather than assuming. The QFC regime addresses the role directly; onshore the picture is less prescriptive. What matters at an inspection is that somebody is accountable and that you decided this deliberately.
Can we transfer personal data out of Qatar?
Under Law No. 13, Article 15 discourages restricting international flows, with exceptions where the law would be breached or serious harm would result — so the work is a transfer register and a harm assessment per route rather than an adequacy hunt. Inside the QFC the transfer rules follow the GDPR pattern.
What are the penalties?
Onshore, financial penalties from QAR 1,000,000 to QAR 5,000,000 depending on the article breached, with no criminal sanction attached to Law No. 13. Inside the QFC, the Data Protection Office can impose fines up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.
How does Qatar compare with Saudi, Bahrain and the UAE?
The obligations overlap heavily — records, notices, rights, breach reporting and transfer governance appear in all four. What differs is the regulator, the treatment of consent, whether criminal exposure exists, and whether a free-zone regime sits alongside the national one. Scoping the GCC together is materially cheaper than four separate reviews.
We already comply with GDPR. How much work is left?
Inside the QFC, mostly mapping and a few local departures. Onshore, more than teams expect: the consent-led basis, the special-nature permission step and the 72-hour notification to individuals as well as the regulator all need deliberate work rather than a renamed policy.
What does an iDharma review cost and how long does it take?
It is scoped before you are charged. The variables are how many entities you run and on which side of the QFC line, the size of the estate, and whether cross-border transfers are in play; we tell you the shape of all three after a short scoping call.
Read it at source
The regulators, the dates and the penalty ceilings on this page came off the official texts. Where a scoping decision turns on the wording, go to them.
Primary sources
The NCSA assurance portal and the QFC. External links.
Related on this site
The neighbouring regimes, and the framework Qatar’s QFC rules are modelled on.
- Saudi PDPL Personal data protection duties for AI processing
- Bahrain PDPL Personal data protection duties for AI processing
- UAE PDPL Personal data protection duties for AI processing
- GDPR Lawful basis, DPIAs, data subject rights and Article 22
- AI governance policy templates The document set behind the programme, mapped obligation by obligation
Ready to achieve Qatar PDPL compliance?
We start with the determination — which regime binds each entity — then give you the records, the notices, the rights procedure, the transfer register and the 72-hour breach runbook. Scoped before you are charged.
This page is guidance on how we scope a Qatar readiness review, not legal advice, and it is not a substitute for Qatari counsel on the onshore-or-QFC determination. Where a question is genuinely arguable we say so in writing rather than pick the convenient answer.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide