WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Law No. 13 of 2016 concerning Personal Data Privacy Protection — transfer of personal data outside Qatar

Qatar PDPPL transfer rules

Qatar · January 2017

Verify details

Transfers out of Qatar are restricted unless the destination affords an adequate level of protection; where it does not, the regulator's guidelines direct controllers to obtain approval or to put contractual safeguards in place giving protections equivalent to those available under Qatari law, and transfers must not cause serious damage to the personal data or privacy of the individual. Cross-border transfer is itself listed in the CDP's guidelines as one of the circumstances that may lead to 'serious harm' to an individual's privacy, which is the trigger for a heightened set of duties. As with the breach entry, the QFC regime is separate: entities licensed in the Qatar Financial Centre follow the QFC Data Protection Regulations 2021 and its own transfer rules instead. Marked 'check': the operative detail sits in guidance rather than in confirmed statutory text, and the article numbering was not verified against a primary source.

Law No. 13 of 2016; guidelines issued by the Compliance and Data Protection Department, National Cyber Governance and Assurance AffairsRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.