Jurisdiction Guides / Middle East
Bahrain Privacy & Data Protection Laws
Every regime below can apply to a business handling Bahrain residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Article 2 applies the Law to a data manager who is ordinarily resident in Bahrain or has a place of business there, and — the extraterritorial limb — to one who is neither, but processes personal data using means available in Bahrain other than for mere transit. That equipment-based limb is a pre-GDPR-style test rather than a targeting test, so the trigger below is modeled on established presence only. A foreign data manager caught by the extraterritorial limb must appoint a Bahrain-resident representative approved by the authority. Distinctive obligations include prior written authorization from the Personal Data Protection Authority for certain higher-risk processing (sensitive data, automated profiling, surveillance), notification of other processing, and criminal penalties (including imprisonment) for several violations — a materially higher-stakes profile than a purely administrative-fine regime.
Cross-Border Data Transfer · 1
Bahrain is one of the few regimes in this dataset that runs a true whitelist plus a permit system. Art. 12's general rule is that personal data may not be transferred outside Bahrain unless the receiving country provides an adequate level of legislative and regulatory protection, and Ministerial Order No. 42 of 2022 publishes the list of countries and territories treated as adequate — expanded to 83 from the 43 originally consulted on. Transfers to a destination NOT on that list require a permit from the Personal Data Protection Authority, and that requirement expressly reaches intra-group transfers and transfers under third-party contracts, with a copy of the contract submitted as part of the permit request. Businesses that treat intra-group data movement as internal and therefore unregulated get caught here. Marked 'check': the operative texts are Arabic-language originals and the whitelist is a ministerial instrument that changes — confirm the current list rather than relying on a count.
Data Security & Breach Notification · 1
Controllers must inform the Personal Data Protection Authority of a data breach within 72 hours of discovery, unless the breach is unlikely to affect data subjects' rights, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and interests. Bahrain follows the GDPR in excusing individual notification where the controller had applied protective measures such as encryption that render the data unintelligible, or where subsequent measures mean the high risk is no longer likely to materialise. Marked 'check': the 72-hour deadline and the notification conditions sit in the implementing Ministerial Orders rather than plainly in the Law, and the operative texts are Arabic-language originals — confirm the provision your obligation actually rests on before citing it.
Other Middle East jurisdictions