Jurisdiction Guides / Middle East
Qatar Privacy & Data Protection Laws
Every regime below can apply to a business handling Qatar residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
The first comprehensive data-protection law in the GCC. It applies to personal data processed electronically, or obtained/collected/extracted by electronic means and then processed by a combination of electronic and traditional means, in Qatar — a territorial and medium-based test rather than a targeting test, so the trigger below is modeled on established presence only. Core duties: transparency, purpose limitation, consent for most processing, a mandated set of security controls, breach notification to the CDP and affected individuals, and prior CDP permission for processing data of 'special nature' (health, ethnicity, children's data, criminal records, physical/psychological condition, religious beliefs, marital relations). Note the parallel regime: entities licensed in the Qatar Financial Centre are subject instead to the QFC Data Protection Regulations 2021, a separate GDPR-aligned framework — check which applies before designing a program.
Cross-Border Data Transfer · 1
Transfers out of Qatar are restricted unless the destination affords an adequate level of protection; where it does not, the regulator's guidelines direct controllers to obtain approval or to put contractual safeguards in place giving protections equivalent to those available under Qatari law, and transfers must not cause serious damage to the personal data or privacy of the individual. Cross-border transfer is itself listed in the CDP's guidelines as one of the circumstances that may lead to 'serious harm' to an individual's privacy, which is the trigger for a heightened set of duties. As with the breach entry, the QFC regime is separate: entities licensed in the Qatar Financial Centre follow the QFC Data Protection Regulations 2021 and its own transfer rules instead. Marked 'check': the operative detail sits in guidance rather than in confirmed statutory text, and the article numbering was not verified against a primary source.
Data Security & Breach Notification · 1
The Law requires a controller to notify the supervisory department and the affected individual of a breach that would cause serious damage to the individual's personal data or privacy, and requires a processor that becomes aware of such a breach to notify its controller. The widely-cited 72-hour deadline comes from the regulator's guidelines rather than from the statutory text, which is why it is stated here as regulator expectation rather than as a statutory clock. Note the parallel regime the comprehensive-law entry flags: entities licensed in the Qatar Financial Centre follow the QFC Data Protection Regulations 2021 instead, which have their own separately drafted breach rules. Marked 'check': the operative source for timing is guidance, and the statutory article numbering was not confirmed against a primary text.
Other Middle East jurisdictions