WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Law No. 30 of 2018 with respect to Personal Data Protection — transfer of personal data outside Bahrain

Bahrain PDPL Art. 12

Bahrain · August 1, 2019 (Law); Ministerial Order No. 42 of 2022

Verify details

Bahrain is one of the few regimes in this dataset that runs a true whitelist plus a permit system. Art. 12's general rule is that personal data may not be transferred outside Bahrain unless the receiving country provides an adequate level of legislative and regulatory protection, and Ministerial Order No. 42 of 2022 publishes the list of countries and territories treated as adequate — expanded to 83 from the 43 originally consulted on. Transfers to a destination NOT on that list require a permit from the Personal Data Protection Authority, and that requirement expressly reaches intra-group transfers and transfers under third-party contracts, with a copy of the contract submitted as part of the permit request. Businesses that treat intra-group data movement as internal and therefore unregulated get caught here. Marked 'check': the operative texts are Arabic-language originals and the whitelist is a ministerial instrument that changes — confirm the current list rather than relying on a count.

Law No. 30 of 2018, Art. 12; Ministerial Order No. 42 of 2022 (countries and territories with adequate protection)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.