WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Law No. 13 of 2016 concerning Personal Data Privacy Protection — breach notification

Qatar PDPPL breach duty

Qatar · January 2017

Verify details

The Law requires a controller to notify the supervisory department and the affected individual of a breach that would cause serious damage to the individual's personal data or privacy, and requires a processor that becomes aware of such a breach to notify its controller. The widely-cited 72-hour deadline comes from the regulator's guidelines rather than from the statutory text, which is why it is stated here as regulator expectation rather than as a statutory clock. Note the parallel regime the comprehensive-law entry flags: entities licensed in the Qatar Financial Centre follow the QFC Data Protection Regulations 2021 instead, which have their own separately drafted breach rules. Marked 'check': the operative source for timing is guidance, and the statutory article numbering was not confirmed against a primary text.

Law No. 13 of 2016; guidelines issued by the Compliance and Data Protection Department, National Cyber Governance and Assurance AffairsRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.