QATAR · LAW NO. 13 OF 2016 AND THE QFC REGULATIONS 2021 · TWO REGULATORS

Qatar PDPL, both regimes.

Qatar runs two data protection regimes side by side, and the first question is which one binds you. Law No. 13 governs personal data processed onshore and expressly exempts the Financial Centre; the QFC Regulations govern inside it and follow the GDPR closely. Different regulators, different penalty currencies, different answers to nearly every practical question.


A governance team reviewing data dashboards on a screen in a darkened boardroom, with papers and notes on the table Illustrative materials
Two regimes, one estate — the fork comes before the programme
Records of processing Special-nature data 72-hour breach clock Transfers Data subject rights
The law

What Qatar PDPL actually is

Two laws, two regulators, one country. Getting the fork right is most of the work, and it is the part that is easiest to get wrong.

Law No. 13 of 2016 concerning Personal Data Privacy Protection was published on 29 December 2016 and was the first comprehensive data protection law in the Gulf. It applies to personal data processed electronically, or prepared for electronic processing, within the State of Qatar, and it is administered by the National Cyber Governance and Assurance Affairs within the National Cyber Security Agency.

It is consent-led. Processing generally needs the individual’s consent, and personal data of a special nature — children, criminal matters, health, ethnic origin, religious belief, marital relations — needs permission from the Competent Department on top. That permission step has no GDPR equivalent and is the obligation international teams most often miss.

Law No. 13 expressly exempts the Financial Centre, and the QFC Data Protection Regulations 2021 occupy the space it leaves. Issued on 21 December 2021 and in force from 19 June 2022, they bind controllers and processors registered in the QFC, follow the GDPR closely, and are administered by the independent QFC Data Protection Office.

The practical consequences diverge immediately. Onshore you have a 72-hour clock to tell the regulator and the affected individuals about a breach causing serious damage, and a penalty ceiling of QAR 5 million with no criminal sanction. Inside the QFC the Data Protection Office can fine up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.

Onshore Law No. 13

In force since 2017, regulated by the NCGAA within the NCSA. Fines to QAR 5 million, no criminal sanction.

In the QFC 19 Jun 2022

GDPR-aligned Regulations administered by the QFC Data Protection Office. Fines to USD 1.5 million.

Who needs to comply

  • Onshore Qatar — Law No. 13

    Personal data processed electronically, or prepared for electronic processing, within the State of Qatar. Regulated by the NCGAA within the National Cyber Security Agency.

  • Inside the QFC — the 2021 Regulations

    Controllers and processors incorporated or registered in the Qatar Financial Centre — and anyone processing through one. Law No. 13 expressly exempts you; the QFC Regulations do not.

  • Financial services and fintech

    Most sit inside the QFC, which means the GDPR-shaped regime rather than the onshore one. Confirm your registration before you build to either.

  • Healthcare providers

    Health data is personal data of a special nature under Law No. 13, and processing it needs permission from the Competent Department rather than consent alone.

  • Employers and HR platforms

    Employee data is squarely in scope, and cross-border HR systems are the most common route by which a Qatari entity exports data without a documented basis.

  • Multinationals processing from abroad

    The trigger for Law No. 13 is processing within Qatar. Where your servers sit matters less than where the processing and the entity do — take advice on the specific structure.

Side by side

Which regime binds you

Start with the entity, not the activity. Registered in the Financial Centre puts you in the right-hand column; everything else onshore puts you in the left.

Comparison of Qatar Law No. 13 of 2016 and the QFC Data Protection Regulations 2021
Attribute Onshore Qatar Law No. 13 of 2016 Qatar Financial Centre QFC Regulations 2021
Instrument Law No. 13 of 2016 concerning Personal Data Privacy Protection QFC Data Protection Regulations 2021
In force Published 29 December 2016 Issued 21 December 2021, effective 19 June 2022
Who it binds Personal data processed electronically within the State of Qatar Controllers and processors incorporated or registered in the QFC, and those processing through them
Regulator National Cyber Governance and Assurance Affairs, within the National Cyber Security Agency The QFC Data Protection Office, an independent institution of the Centre
Relationship Expressly exempts the Financial Centre Occupies the space the exemption leaves. You are in one or the other, not both
Drafting ancestry Consent-led, with a permission regime for data of a special nature Closely aligned to the GDPR — lawful bases, rights, DPIAs, transfer rules
Special category data Children, criminal matters, health, ethnicity, religion, marital status — needs permission from the Competent Department A special-category regime in the GDPR pattern, handled by condition rather than by permission
Breach notification 72 hours from detection, to the regulator and to affected individuals, where serious damage arises Notification obligations in the GDPR pattern
Cross-border transfer Article 15 discourages restricting international flows, except where the law is breached or serious harm results Transfer rules in the GDPR pattern, with the Data Protection Office as the gatekeeper
Maximum penalty QAR 5,000,000 Financial only — no criminal sanction USD 1,500,000 Imposed by the Data Protection Office

Groups usually need both. A Qatari holding company with a QFC-registered subsidiary is in both columns at once, entity by entity — which means two notice sets, two breach routes and two regulators to know. The determination is the first deliverable of any engagement here, and it is cheap to do and expensive to assume.

How we help

How iDharma supports Qatar PDPL compliance

Six workstreams covering both regimes, with the regime each obligation comes from named on the card rather than blurred into a single “Qatar”.

Processing inventory and mapping

A record of every processing activity with purpose, categories, recipients, transfers and retention — the document both regulators open first, and the one almost nobody has current.

Addresses: Law 13 records QFC records

Data subject rights workflow

One intake route, identity verification, a search that actually reaches the backups and the ticketing system, and a decision record per request.

Addresses: Both regimes

Impact assessments

A screening test that says when an assessment is required, the methodology, and completed assessments for the processing that triggers it — before the processing starts, not after.

Addresses: Law 13 DPIA QFC DPIA

Breach response on a 72-hour clock

A detection-to-decision runbook, the notification pack for the regulator and for individuals, and the serious-damage test applied in advance rather than during the incident.

Addresses: Law 13 — 72 hours

Cross-border transfer governance

A transfer register, the basis per route, and the harm assessment Article 15 turns on — plus the QFC mechanism where that is the regime you are in.

Addresses: Law 13 Art. 15 QFC transfers

Policies and DPO documentation

The policy set for whichever regime binds you, the privacy notices, and the written position on whether you need a data protection officer at all.

Addresses: Both regimes

Built for Qatar’s dual regulatory environment

One engagement, scoped across both regimes and their GCC neighbours.

Both regimes

One scope, two rulebooks

We determine which law binds each entity before writing anything, and produce one programme that satisfies whichever applies.

GDPR lineage

Work that carries

The QFC Regulations follow the GDPR closely, so a GDPR programme transfers with mapping rather than rewriting — and vice versa.

GCC reach

Neighbours in the same scope

Saudi, Bahrain and UAE obligations overlap heavily. Scoping them together is materially cheaper than three separate reviews.

Evidence

Regulator-ready artefacts

Records, assessments, notices and decision logs in the form a regulator asks for, not a slide deck about them.

Processing principles

The seven processing principles

Set out as the QFC Regulations set them out, with the onshore analogue named underneath — because Law No. 13 reaches most of the same ground by different drafting.

Principle 1

Lawfulness, fairness and transparency

A basis for every purpose, processing that would not surprise the person, and information they can actually reach.

Onshore consent-led, with narrow exceptions
Principle 2

Purpose limitation

Collected for a specified purpose and not reused for something incompatible with it. The principle secondary AI training most often breaks.

Onshore purpose stated at collection
Principle 3

Data minimisation

Adequate, relevant and limited to what the purpose needs — not to what the system happens to capture.

Onshore same substance, different drafting
Principle 4

Accuracy

Kept accurate and current, with inaccurate data corrected or erased without delay. Inferences and scores count as data.

Onshore right to correction
Principle 5

Storage limitation

Kept in identifiable form no longer than the purpose requires, with a schedule somebody actually executes.

Onshore retention tied to purpose
Principle 6

Integrity and confidentiality

Security appropriate to the risk, argued against that risk rather than asserted as a list of controls.

Onshore technical, financial and administrative measures
Principle 7

Accountability

You must be able to demonstrate all of the above. This is the principle that turns the other six into documents.

Onshore records and assessments

One list, two sources. The QFC Regulations carry these as principles in the GDPR pattern. Law No. 13 has no equivalent numbered article and arrives at most of the same place through its consent regime, its records and assessment duties, and its security obligations. Saying that plainly is more useful than presenting a single list as though one law governed both.

Individual rights

What people can ask you for

And how long you have. Most of these fail on search coverage rather than on willingness — the backups, the ticketing system and the mailboxes are where requests go to die.

Right to be informed

What you do with the data, told in a notice the person can find and understand before you process.

Respond At collection

Right of access

Confirmation that you process their data, a copy of it, and the supplementary information about how and why.

Respond Within 30 days

Right to rectification

Inaccurate data corrected and incomplete data completed — including in the downstream copies people forget.

Respond Without undue delay

Right to erasure

Deletion where the processing is unnecessary or the data was collected unfairly. Not unconditional; the exemptions are real.

Respond Within 30 days

Right to object

To processing that is unnecessary, unfair, or for direct marketing — where marketing objection is effectively absolute.

Respond Immediate for marketing

Right to withdraw consent

As easy to withdraw as it was to give, and withdrawal has to actually stop the processing rather than flag it.

Respond At any time

Thirty days is the working standard, not a statutory universal. Build the process to hit it comfortably under either regime and you have removed the argument entirely. Where a request is complex or the identity is not established, record the reason and the date you told the person — a delay you explained is a different thing from a delay you did not.

Implementation

An 18-week implementation roadmap

Phase one is the one people skip, and here it carries an extra job: deciding which law binds each entity before anything is written.

Weeks 1–4

Scope and gap analysis

Decide which law binds you, then find the data

  • Entity-by-entity determination: onshore or QFC
  • Data mapping from the systems inwards
  • Records of processing drafted
  • Gap assessment against the applicable regime
Weeks 5–9

Documentation and policies

Write what you will be asked for

  • Privacy notices per audience
  • Consent and permission positions recorded
  • Retention schedule with justifications
  • Rights procedure and response templates
Weeks 10–14

Technical implementation

Make the paper true

  • Access control, logging and encryption
  • Deletion routes that reach every copy
  • Transfer register and per-route basis
  • Breach detection wired to the 72-hour clock
Weeks 15–18

Testing and monitoring

Prove it, then keep proving it

  • Rights and breach rehearsals against the clock
  • Role-based training with completion evidence
  • Internal review against the gap list
  • A review cycle with owners and dates

Eighteen weeks is elapsed time for a mid-sized estate, not effort. The phases overlap — documentation starts before mapping finishes, and monitoring starts before the technical work is done. Read as four consecutive sprints the ranges add to more than the total, which is the one way to misread this plate.

Enforcement

Penalties and enforcement

Two ceilings in two currencies. Which one applies to you follows from the regime, and getting it wrong misstates your exposure by a wide margin in either direction.

Onshore — Law No. 13
QAR 5,000,000
Maximum financial penalty

Fines run from QAR 1,000,000 to QAR 5,000,000 depending on the article breached. The law carries no criminal sanction — the exposure is financial and reputational.

Inside the QFC
USD 1,500,000
Maximum fine

Imposed by the Data Protection Office, which also adjudicates complaints and investigates alleged contraventions of the Regulations.

Regulatory direction

Both regulators can require you to change or stop a processing activity. For a live product that is a sharper instrument than a fine.

Reputational exposure

Breach notification under Law No. 13 goes to affected individuals as well as the regulator. The disclosure is part of the penalty.

The neighbourhood

How Qatar compares across the GCC

The obligations overlap heavily. What differs is the regulator, the treatment of consent, whether criminal exposure exists, and whether a free-zone regime sits alongside the national one.

Orientation comparison of Qatar, Saudi Arabia, Bahrain and UAE data protection regimes
Aspect Qatar Saudi Arabia Bahrain UAE
Primary instrument Law No. 13 of 2016, plus the QFC Regulations 2021 PDPL by Royal Decree, with implementing regulations Law No. 30 of 2018 Federal Decree-Law No. 45 of 2021
Regulator NCGAA / NCSA onshore; the QFC Data Protection Office inside the Centre SDAIA The Personal Data Protection Authority The UAE Data Office
Free-zone split Yes — the QFC has its own regime No equivalent split No equivalent split Yes — DIFC and ADGM run their own laws
GDPR alignment Partial onshore; close inside the QFC Substantial, with local departures Substantial Substantial
Primary basis Consent-led onshore; full basis set in the QFC Consent-led, with statutory alternatives Consent-led, with statutory alternatives Consent-led, with statutory alternatives
Criminal exposure None under Law No. 13 Yes, for certain sensitive-data disclosures Yes, imprisonment available Primarily administrative

Read this as orientation, not as citation. Four jurisdictions are moving at different speeds and any table precise enough to rely on would be stale within a quarter. Use it to see the shape of the neighbourhood, then take the country page — and advice — for the one you actually operate in.

Questions

Frequently asked questions

Which law applies, what it asks for, and what it costs to get wrong.

1 Which law applies
What is the difference between Law No. 13 and the QFC Regulations?

They are two separate regimes with two separate regulators. Law No. 13 of 2016 governs personal data processed electronically within the State of Qatar and is enforced by the National Cyber Governance and Assurance Affairs within the NCSA. The QFC Data Protection Regulations 2021 govern controllers and processors registered in the Qatar Financial Centre and are administered by the QFC Data Protection Office. Law No. 13 expressly exempts the Financial Centre, so you are in one or the other.

How do I know which one binds us?

Start with the entity, not the activity. If the entity is incorporated or registered in the QFC — or you process through one that is — you are in the QFC regime. Otherwise, if the processing happens electronically within Qatar, you are under Law No. 13. Groups with both need both, entity by entity.

When did each take effect?

Law No. 13 was published on 29 December 2016 and became effective the following year. The QFC Regulations were issued on 21 December 2021 and took effect on 19 June 2022.

Is Qatar PDPL the same as GDPR?

The QFC Regulations are closely aligned to the GDPR and a GDPR programme transfers into them with mapping rather than rewriting. Law No. 13 reaches much of the same ground but is consent-led and uses a permission regime for data of a special nature, so a GDPR programme needs real adaptation rather than a relabel.

2 Obligations and deadlines
How long do we have to report a breach?

Under Law No. 13, 72 hours from detection to notify both the regulator and the affected individuals, where the breach would cause serious damage. The serious-damage test is one you should have applied in advance — deciding it during an incident is how the clock gets missed.

How long do we have to answer a rights request?

Plan on 30 days as the working standard and build the process to hit it comfortably. The failure mode is almost never willingness; it is a search that does not reach the backups, the ticketing system and the mailboxes.

What is personal data of a special nature?

Under Law No. 13 it covers data relating to children, criminal matters, health, ethnic origin, religious belief and marital relations. Processing it requires permission from the Competent Department — a permission step, not merely a stronger consent.

Do we need a data protection officer?

Take a written position either way rather than assuming. The QFC regime addresses the role directly; onshore the picture is less prescriptive. What matters at an inspection is that somebody is accountable and that you decided this deliberately.

Can we transfer personal data out of Qatar?

Under Law No. 13, Article 15 discourages restricting international flows, with exceptions where the law would be breached or serious harm would result — so the work is a transfer register and a harm assessment per route rather than an adequacy hunt. Inside the QFC the transfer rules follow the GDPR pattern.

3 Penalties and the engagement
What are the penalties?

Onshore, financial penalties from QAR 1,000,000 to QAR 5,000,000 depending on the article breached, with no criminal sanction attached to Law No. 13. Inside the QFC, the Data Protection Office can impose fines up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.

How does Qatar compare with Saudi, Bahrain and the UAE?

The obligations overlap heavily — records, notices, rights, breach reporting and transfer governance appear in all four. What differs is the regulator, the treatment of consent, whether criminal exposure exists, and whether a free-zone regime sits alongside the national one. Scoping the GCC together is materially cheaper than four separate reviews.

We already comply with GDPR. How much work is left?

Inside the QFC, mostly mapping and a few local departures. Onshore, more than teams expect: the consent-led basis, the special-nature permission step and the 72-hour notification to individuals as well as the regulator all need deliberate work rather than a renamed policy.

What does an iDharma review cost and how long does it take?

It is scoped before you are charged. The variables are how many entities you run and on which side of the QFC line, the size of the estate, and whether cross-border transfers are in play; we tell you the shape of all three after a short scoping call.

Further reading

Read it at source

The regulators, the dates and the penalty ceilings on this page came off the official texts. Where a scoping decision turns on the wording, go to them.

Ready when you are

Ready to achieve Qatar PDPL compliance?

We start with the determination — which regime binds each entity — then give you the records, the notices, the rights procedure, the transfer register and the 72-hour breach runbook. Scoped before you are charged.

This page is guidance on how we scope a Qatar readiness review, not legal advice, and it is not a substitute for Qatari counsel on the onshore-or-QFC determination. Where a question is genuinely arguable we say so in writing rather than pick the convenient answer.