Comprehensive Privacy Law
Law No. 30 of 2018 with respect to Personal Data Protection
Bahrain · August 1, 2019
Verify detailsArticle 2 applies the Law to a data manager who is ordinarily resident in Bahrain or has a place of business there, and — the extraterritorial limb — to one who is neither, but processes personal data using means available in Bahrain other than for mere transit. That equipment-based limb is a pre-GDPR-style test rather than a targeting test, so the trigger below is modeled on established presence only. A foreign data manager caught by the extraterritorial limb must appoint a Bahrain-resident representative approved by the authority. Distinctive obligations include prior written authorization from the Personal Data Protection Authority for certain higher-risk processing (sensitive data, automated profiling, surveillance), notification of other processing, and criminal penalties (including imprisonment) for several violations — a materially higher-stakes profile than a purely administrative-fine regime.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.