Qatar runs two data protection regimes. Law No. 13 of 2016 governs personal data processed electronically within the State, under the National Cyber Security Agency. The QFC Regulations 2021 govern inside the Financial Centre, under its own Data Protection Office and its own rules.
Qatar has two data protection laws. You are in one of them.
Law No. 13 exempts the Financial Centre and the QFC runs its own regime, so which of the two binds you decides everything after it.
Our promise
“A guess at the regime is a risk. Mapping is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditQatar, in three chapters
Most programmes are built to one column without anybody deciding which. The two have different regulators, different penalty currencies and different drafting ancestry - so a programme built to the wrong one is not a partial programme at all. It is simply the wrong programme.
Which regime binds each entity is the first thing we settle, in writing, before a word of the programme is drafted. Then the obligations of that regime are tested against the estate as it actually runs, rather than as somebody drew it - and a group spanning the line gets one review, not two.
Two regimes, one line between them.
Start with the entity, not the activity - and the answer is one of them, never both at once.
- Data processed electronically within Qatar
- Regulated by the NCGAA, inside the NCSA
- Consent-led, with a permission regime beside it
- Ceiling of QAR 5,000,000, and no criminal sanction
- Entities registered in the Financial Centre
- Regulated by the QFC Data Protection Office
- Closely aligned to the GDPR in shape
- Ceiling of USD 1,500,000, set by that Office
The duty is yours. Which duty is the question.
Law No. 13 of 2016, onshore
Personal data processed electronically within the State of Qatar, under the National Cyber Governance and Assurance Affairs. Consent-led, with permission from the Competent Department for data of a special nature and 72 hours to notify a breach that would cause serious damage to the individual.
The QFC Regulations 2021
Controllers and processors incorporated or registered in the Qatar Financial Centre, and anyone processing through one. Closely aligned to the GDPR - lawful bases, rights, impact assessments and transfer rules - under an independent Data Protection Office of its own, sitting inside the Centre itself.
You are in one, not both
Law No. 13 expressly exempts the Financial Centre, and the QFC Regulations occupy the space that exemption leaves. The determination is made entity by entity - and a group with companies on each side of the line owes both, over the same shared systems and the same shared people.
“Qatar PDPL. We will build to that.”
There is no single Qatar PDPL to build to.
It is the first thing we have to correct.
- Who it is for
- Financial services & fintech
- Healthcare providers
- Employers & HR platforms
- Multinational groups
- Cloud & data vendors
Law No. 13 carries no criminal sanction. The exposure is financial and reputational - and the breach notice goes to individuals too.
Both regulators can require you to change or stop a processing activity. For a live product that is a sharper instrument than a fine is.
Saudi Arabia, Bahrain and the UAE each run their own regime. Only Qatar and the UAE also carry a free-zone law beside the national one.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and one runs before you start.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Permission
Before you startData of a special nature needs the Competent Department’s permission first. It cannot be obtained afterwards, and onshore health and HR estates hit it early.
-
Notify
72 hoursFrom detection, to the regulator and to the affected individuals, where the breach would cause serious damage. Both, not one.
-
Answer
Plan on 30 daysBuild the rights process to answer comfortably inside a month. What fails is almost never willingness - it is the reach of the search.
-
Demonstrate
ContinuouslyRecords, assessments and notices have to describe the estate on the day, not the estate that existed when they were written.
Teams treat the special-nature step as a stronger consent and collect it at the form. It is a permission, granted by the Competent Department, and it runs in front of the processing - so it cannot be obtained retrospectively, least of all during an incident.
What the law says, what we ship
12 obligations, each carrying the regime it arises under where the two diverge.
- Records of processing Both regimes
- A record per activity with purpose, categories, recipients, transfers and retention filled in rather than left as headings. The document both regulators open first.
- Lawfulness and basis Consent onshore
- The consent position recorded per purpose under Law No. 13, or the lawful basis per purpose inside the QFC, where the full GDPR-pattern basis set is available.
- Special-nature permission Law No. 13 only
- The Competent Department permission for children, criminal matters, health, ethnic origin, religious belief and marital relations - obtained before the processing starts.
- Purpose limitation Both regimes
- Purposes fixed before collection, with a compatibility test for any new use - including the secondary model training that most often breaks this one.
- Data minimisation Both regimes
- Adequate, relevant and limited to what the purpose needs, with field-level justification rather than whatever the system happens to capture.
- Accuracy Right to correction
- A correction route that reaches the downstream copies, with inferences and scores treated as data and the source of truth named per category.
- Storage limitation Tied to purpose
- A retention period per category with its justification beside it, and a deletion route that is named rather than assumed to exist.
- Security measures Technical & admin
- The measures you actually run, argued against the risk they address, so “appropriate” is a position on paper rather than an adjective.
- Data subject rights Plan on 30 days
- One intake route, identity verification, a search that reaches the backups and the ticketing system, and a decision record per request.
- Impact assessments Both regimes
- A screening test that says when an assessment is required, the methodology, and completed assessments for the processing that triggers it.
- Breach response 72 hours onshore
- A detection-to-decision runbook, the notification pack for the regulator and for individuals, and the serious-damage test applied in advance.
- Cross-border transfers Article 15 onshore
- A transfer register, the basis per route, and the harm assessment Article 15 turns on - plus the QFC mechanism where that is the regime you are in.
Personal data, independently reviewed
From the onshore estate to the QFC entity.
-
Determine
Which regime binds each entity - onshore, or inside the Centre.
-
Test
The obligations of that regime against the estate as it runs.
-
Sign off and evidence
You see the draft first. Then the records, notices and drills - dated.
Why teams choose iDharma for their Qatar review
The fork, settled first
We determine which regime binds each entity before a word of the programme is written.
One scope, two rulebooks
A group spanning the line gets one programme that satisfies whichever law reaches it.
GDPR work carries over
The QFC Regulations follow the GDPR closely, so an existing programme maps rather than restarts.
The GCC in one scope
Saudi, Bahrain and UAE obligations overlap enough to be worth scoping in the same review.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Qatar readiness report
The full review: which regime binds each entity, what you process under it, and where every obligation is evidenced or is not - written obligation by obligation. Findings carry the regime they arise under, so a group spanning the QFC line reads one report rather than two, with the transfer position and the special-nature permissions stated separately.
Regime determination
Entity by entity, taken from the register rather than from custom - with the reasoning recorded where a shared system serves both sides of the line.
Processing inventory
Every activity with purpose, categories, recipients, transfers and retention - built from the systems inwards rather than from a questionnaire outwards.
Consent and permission log
The consent position per purpose onshore, or the basis inside the QFC - with Competent Department permissions tracked where they are needed.
Rights and breach runbooks
One intake route with identity verification, plus a detection-to-decision breach pack written against the 72-hour clock and rehearsed once.
Transfer register and assessment
Where the data actually lands, the basis for each route, and the harm assessment Article 15 turns on - checked against your own notice.
Policy template pack
The core set, the security and breach set and the governance set - written to whichever regime binds you rather than handed over as a generic pack.
Real numbers, upfront.
- Scope
- Set by the regime
- Inputs
- Your entities and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The regime fixed the obligations, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Regime determination per entity
- Processing inventory and register
- Breach drill on the 72-hour clock
- 28 policy templates, tailored
Four things you have to be able to produce
Neither regime is graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The regime,
decided
A written determination for each entity: onshore under Law No. 13, or inside the Centre under the QFC Regulations. Everything else on this page depends on the answer.
The record,
current
A record of processing that matches what the systems do. It is the first thing either regulator opens, and the document every other position is argued out of.
The clock,
rehearsed
Seventy-two hours from detection, to the regulator and to the individuals. The serious-damage test decided in advance, because deciding it live is how it is missed.
The route,
papered
A transfer register with the basis for each route out of Qatar, and the harm assessment that Article 15 actually turns on rather than an adequacy list that does not exist.
Four cards, and the date on each one is part of the card.
Plain answers
Which law binds you, the breach clock, the two ceilings, and what the review costs. Answered straight.
Request this reviewWhat is the difference between Law No. 13 and the QFC Regulations?
Two separate regimes with two separate regulators. Law No. 13 of 2016 governs personal data processed electronically within the State of Qatar; the QFC Data Protection Regulations 2021 govern controllers and processors registered in the Financial Centre. Law No. 13 expressly exempts the Centre, so you are in one or the other.
How do I know which one binds us?
Start with the entity, not the activity. If the entity is incorporated or registered in the QFC - or you process through one that is - you are in the QFC regime. Otherwise, if the processing happens electronically within Qatar, you are under Law No. 13. Groups with both need both, entity by entity.
How long do we have to report a breach?
Under Law No. 13, 72 hours from detection to notify both the regulator and the affected individuals, where the breach would cause serious damage. The serious-damage test is one to apply in advance - deciding it during an incident is how the clock gets missed.
What are the penalties?
Onshore, financial penalties from QAR 1,000,000 to QAR 5,000,000 depending on the article breached, with no criminal sanction attached to Law No. 13. Inside the QFC, the Data Protection Office can impose fines up to USD 1.5 million. Quoting the wrong ceiling to a board is a common and expensive error.
What does an iDharma Qatar review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the readiness report, the regime determination, the processing inventory, the consent and permission log, the rights and breach runbooks, the transfer register and the policy template pack.
Request your Qatar review
Tell us where the entities sit and we come back with a scoping call in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.
- Which entities process, and where each is registered
- Which systems hold personal data, and what for
- Your record of processing, if one already exists
- Whether data of a special nature is in play
- Where data leaves Qatar, and on what basis
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Law No. 13 of 2016, on the NCSA assurance portal
- The QFC Regulations 2021 and the Data Protection Office
- Law No. 13
- 29 December 2016
- QFC in force
- 19 June 2022
What it means
- General information about what each regime requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- The regulators, the dates and the two penalty ceilings were checked. The article-level detail beneath them — the permission step, the transfer posture, the response window — is written from the discipline.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom