Bahrain Personal Data Protection Law (PDPL)
The Bahrain Personal Data Protection Law (PDPL), Law No. 30 of 2018, establishes the Kingdom of Bahrain’s national framework for protecting personal data and regulating how organisations collect, process, store, disclose, and transfer personal information.
The law applies to organisations and individuals processing personal data in Bahrain, including certain organisations outside Bahrain that process personal data using means located in the Kingdom. It became effective on 1 August 2019.
Bahrain has also issued a series of implementing resolutions, including rules on international data transfers, technical and organisational security measures, prior authorisation, sensitive personal data, data protection monitors, data-subject rights, and related compliance procedures.
Bahrain's PDPL generally requires a lawful basis for processing personal data, with consent serving as the primary rule and specific statutory exceptions allowing processing without consent. Consent must meet defined requirements when it is relied upon.
The law also establishes:
| Requirement | Bahrain PDPL |
|---|---|
| Regulation | Personal Data Protection Law |
| Law number | Law No. 30 of 2018 |
| Country | Bahrain |
| Region | Middle East / GCC |
| Effective date | 1 August 2019 |
| Regulator | Personal Data Protection Authority (PDPA) |
| Core terminology | Data Controller, Data Processor, Data Subject |
| Consent | Generally required unless a statutory exception applies |
| Sensitive data | Additional requirements and prior authorisation may apply |
| International transfers | Subject to adequacy rules, authorisation and statutory exceptions |
| Prior notification | Required for certain automated processing, subject to exemptions |
| Prior authorisation | Required for specified processing activities |
| Data Protection Guardian | Required in circumstances specified by the law and implementing rules |
| Automated decisions | Data-subject objection rights apply in specified circumstances |
| Maximum statutory fine | Up to BHD 20,000 for specified offences |
| Imprisonment | Up to one year for specified offences |
The law established the Personal Data Protection Authority as an independent public authority with regulatory, supervisory, investigative and authorisation functions. Royal Decree No. 78 of 2019 subsequently identified the administrative body responsible for carrying out the Authority's functions.
The Bahrain Personal Data Protection Law (PDPL) is Bahrain's principal general privacy law.
Law No. 30 of 2018 creates rules governing the processing of personal data and establishes rights for individuals whose data is processed. It also establishes the regulatory framework for the Personal Data Protection Authority.
The law covers automated processing as well as certain non-automated processing where personal data forms part of, or is intended to form part of, a filing system.
The PDPL was promulgated on 12 July 2018 and entered into force on 1 August 2019.
Bahrain
In force since 2019
Asia & Africa
The PDPL has broad territorial and personal scope.
It applies to:
This means organisations should assess their Bahrain exposure based not only on where the organisation is incorporated, but also on where processing activities and processing infrastructure occur.
Businesses that operate websites, applications, customer platforms, e-commerce services, HR systems, marketing platforms or other digital services involving people in Bahrain should assess whether the PDPL applies to their processing activities.
The PDPL defines personal data broadly as information concerning an identified individual or an individual who can be identified directly or indirectly.
Examples may include:
The assessment of whether an individual is identifiable takes into account the means available to the controller or another person.
The PDPL provides additional protection for sensitive personal data.
Sensitive personal data includes information revealing, directly or indirectly:
Processing sensitive personal data is generally prohibited without the data subject's consent unless one of the statutory exceptions applies.
The exceptions include certain employment-related processing, protection of individuals who cannot legally provide consent, publicly available information made public by the data subject, legal claims or defences, healthcare-related processing, specified non-profit activities, certain public-body activities, and certain equality-of-opportunity processing involving racial, ethnic or religious information.
Bahrain also issued Resolution No. 45 of 2022, which establishes additional rules and procedures for processing sensitive personal data.
Consent is an important component of Bahrain's PDPL, but consent is not the only lawful basis.
Article 4 allows processing without consent where processing is necessary for specified purposes, including:
Therefore, businesses should avoid implementing a blanket "consent for everything" model. Instead, they should identify the applicable legal basis for each processing activity and use consent where the PDPL requires or permits it.
Where consent is relied upon under the PDPL, Article 24 establishes specific requirements.
Consent must generally be:
Consent may be provided electronically where the applicable requirements are satisfied.
For digital businesses, this means consent mechanisms should avoid ambiguous wording, bundled choices and unclear purposes.
A well-designed consent interface should clearly communicate:
Yes.
A data subject may withdraw consent at any time by notifying the data controller.
Implementing rules further address procedures for withdrawing consent and require organisations relying on consent to provide an appropriate mechanism for doing so. Withdrawal generally affects future processing based on consent and does not retrospectively invalidate processing that was lawful before withdrawal.
For websites and applications, organisations should therefore provide a practical way for users to change or withdraw consent rather than treating consent as permanent.
Bahrain's PDPL establishes transparency requirements for data controllers.
Individuals should receive information necessary to understand how their personal data is being processed.
The information framework includes matters such as:
Privacy notices should therefore be written in clear and accessible language and should accurately reflect the organisation's actual processing activities.
The PDPL contains data-quality requirements designed to prevent organisations from collecting and maintaining unnecessary or inaccurate personal data.
Organisations should consider whether personal data is:
Businesses should maintain data inventories and retention procedures that allow them to identify why information is collected and how long it should remain in their systems.
Bahrain's PDPL provides individuals with several important rights.
Individuals can request information about whether their personal data is being processed.
An access-related request must generally be supported by proof of identity and must be handled free of charge within the statutory period. Article 18 provides a 15-working-day period for responding to qualifying requests.
A data subject can request information concerning personal data being processed, including relevant information about:
Individuals can request correction where personal data is inaccurate, incomplete or outdated.
A data subject may request blocking of personal data where the statutory requirements are met.
Individuals may request erasure where processing breaches the PDPL, including circumstances involving inaccurate, incomplete, outdated or unlawfully processed data.
Article 23 generally requires controllers to respond to qualifying rectification, blocking or erasure requests within 10 working days, subject to the statutory framework.
Individuals have a specific right to object to processing for direct marketing purposes.
The controller must stop or refrain from beginning the relevant direct-marketing processing within the applicable statutory period after receiving a qualifying request.
A data subject can object to processing that causes, or is likely to cause, unwarranted substantial material or moral damage to the individual or another person.
The PDPL gives individuals a right to object to certain decisions based solely on automated processing.
Where a decision is based solely on automated processing to assess matters such as:
the data subject may request that the decision be reconsidered without relying solely on automated processing. Reconsideration is generally required to be carried out free of charge.
The Bahrain PDPL is relevant to AI systems whenever they process personal data.
Article 22 is particularly relevant to automated decision-making that evaluates individuals.
Organisations using AI, profiling or automated decision systems should therefore assess:
Certain biometric, genetic and surveillance-related processing activities may require prior written authorisation from the Authority.
Bahrain's PDPL contains an important prior authorisation regime.
Article 15 requires prior written authorisation for specified processing activities, including:
Organisations should identify these processing activities before deploying the relevant systems.
Article 14 establishes a notification requirement for certain wholly or partially automated processing operations.
The notification can include information such as:
The law also provides exemptions from prior notification in specified circumstances, including certain public registers, certain non-profit activities, specified employee processing and situations where a Data Protection Guardian has been appointed.
Bahrain's privacy framework includes a Data Protection Guardian (DPG) regime.
Resolution No. 46 of 2022 establishes rules for appointing internal or external Data Protection Guardians, including requirements relating to registration, accreditation and oversight.
The DPG framework should not automatically be treated as a universal requirement for every organisation. Businesses should assess whether the circumstances of their processing bring them within the applicable requirements.
The PDPL requires appropriate technical and organisational measures to protect personal data.
Security measures should address risks including:
Article 8 requires organisations to consider factors such as the latest technological security measures, implementation costs, the nature of the data and potential risks.
Bahrain's Resolution No. 43 of 2022 provides additional requirements for technical and organisational measures and addresses data-protection impact assessment, breach notification, processor arrangements, internal investigation procedures and staff training.
Privacy compliance should be incorporated into systems and processes rather than treated only as a documentation exercise.
Organisations should consider privacy controls when:
A documented privacy assessment can help identify whether a new processing activity requires notification, prior authorisation, consent, contractual controls or additional security safeguards.
Organisations frequently rely on external service providers to process personal data.
Examples include:
Controllers should carefully assess processor arrangements and ensure appropriate contractual and security controls are in place.
The implementing framework specifically addresses arrangements involving external processors and third parties, including their relationship to international data-transfer requirements.
Bahrain does not impose a blanket requirement that all personal data remain physically inside Bahrain.
Instead, Articles 12 and 13 establish rules for transferring personal data outside the Kingdom.
A transfer may generally take place where the destination provides an adequate level of protection or where an applicable statutory exception or authorisation mechanism applies.
The Authority maintains a framework for identifying countries and territories considered to provide adequate protection.
Bahrain also issued Resolution No. 42 of 2022, which provides additional rules for transferring personal data outside the Kingdom, including transfers to listed countries and territories and certain transfers based on contracts and regulatory authorisation.
Before transferring personal data internationally, organisations should identify:
Bahrain's PDPL requires organisations to maintain appropriate security controls and provides regulatory requirements concerning data breaches.
Resolution No. 43 of 2022 specifically addresses the obligation to notify data breaches or violations and requires organisations to establish appropriate internal processes for investigating security incidents.
The Bahrain framework should not be presented as a universal 72-hour breach-notification rule. Organisations should assess the applicable statutory and implementing requirements for the specific incident.
A practical breach-response process should include:
Direct marketing is specifically addressed by the Bahrain PDPL.
Where a controller anticipates that personal data may be processed for direct marketing, the data subject must be informed of their right to object.
Individuals can exercise their objection to direct marketing free of charge, and controllers are subject to statutory response requirements.
Businesses using:
should therefore ensure that their marketing practices, privacy notices and opt-out mechanisms align with Bahrain's requirements.
The Bahrain PDPL applies to personal-data processing carried out electronically.
Cookies, pixels, SDKs, advertising technologies and analytics tools may therefore fall within the law when they process information that identifies or can identify an individual.
However, organisations should not automatically assume that every cookie requires consent under Bahrain PDPL.
The correct approach is to:
This is particularly important for advertising and behavioural-tracking technologies.
For websites operating in Bahrain, consent management should be designed around the actual processing activities rather than simply displaying a generic cookie banner.
A compliant consent experience can include:
ConsentX can help organisations operationalise these controls across websites and digital products.
ConsentX can support organisations in implementing technical consent and privacy workflows for Bahrain.
Scan your website to identify cookies, trackers and third-party technologies that may collect or process personal data.
Configure consent notices according to the processing activities and legal basis applicable to visitors in Bahrain.
Where consent is the applicable legal basis, ConsentX can help prevent non-essential tracking technologies from firing before consent is provided.
Use purpose-specific consent controls instead of relying on a single generic acceptance button.
Store records of user choices so organisations can demonstrate what was presented and what the individual selected.
Provide mechanisms that allow individuals to change or withdraw consent where consent is the basis for processing.
Centralise incoming privacy requests and help teams manage access, objection, rectification, blocking and erasure workflows.
Maintain structured records that can assist privacy teams in documenting consent and related processing decisions.
Run a ConsentX scan to identify cookies, trackers, scripts and third-party technologies.
Identify what personal data is collected, why it is collected, who receives it and whether it is transferred outside Bahrain.
Do not assume every processing activity requires consent. Determine whether the processing relies on consent, contractual necessity, legal obligations, vital interests or legitimate interests under the PDPL.
For processing that relies on consent, present clear and specific choices to users.
Ensure optional trackers do not execute before the required consent is obtained.
Maintain evidence of consent, including the relevant purpose, timestamp and consent state.
Make it easy for individuals to change their choices or withdraw consent.
Maintain workflows for requests relating to access, objections, correction, blocking and erasure.
Identify third-party services receiving Bahrain personal data and assess the applicable cross-border transfer mechanism.
Check whether sensitive data, biometrics, genetic data, automated data linking or surveillance processing triggers prior authorisation requirements.
Use the following checklist as a starting point for a Bahrain privacy compliance programme:
The PDPL contains criminal penalties for specified violations.
Article 58 provides for imprisonment of up to one year and/or a fine between BHD 1,000 and BHD 20,000 for specified offences, including certain unlawful processing of sensitive personal data, unlawful international transfers, failure to make required regulatory notifications, processing without required prior authorisation, and providing incorrect or misleading information to the Authority or data subject.
The penalty framework should therefore not be reduced to a single "maximum fine for every violation." The applicable penalty depends on the specific offence and provision involved.
Organisations should also consider potential compensation and other regulatory consequences arising from unlawful processing.
The Personal Data Protection Authority (PDPA) is established under the law as the competent data-protection authority.
Its statutory functions include:
Bahrain's official government portal identifies the Personal Data Protection Law and its associated implementing resolutions as part of the Kingdom's data-protection framework.
Individuals and other persons with a legitimate interest or capacity may lodge a written complaint where they believe personal data is being processed in violation of the PDPL.
The law provides for complaints to be submitted to the Authority, with procedures established for receiving and processing such complaints.
Consent management is particularly relevant to Bahrain organisations because the PDPL establishes specific requirements for consent when consent is relied upon.
A modern consent-management platform can help organisations:
ConsentX provides a technical layer for managing these workflows while organisations remain responsible for determining their legal obligations.
A privacy compliance programme should extend beyond a privacy-policy page.
Organisations need to understand the relationship between:
Data collection → Purpose → Legal basis → Consent → Processing → Third parties → International transfers → Retention → Data-subject rights
A consent management platform can help connect these operational steps.
For websites in particular, ConsentX can help translate privacy requirements into practical controls for cookies, trackers and other online technologies.
Country: Bahrain
Official regulation: Personal Data Protection Law
Law: Law No. 30 of 2018
Effective: 1 August 2019
Region: Middle East / GCC
Regulatory authority: Personal Data Protection Authority
Businesses operating across multiple jurisdictions may also need to assess:
A multi-jurisdictional consent strategy should account for differences in legal bases, consent requirements, cookies, international transfers, data-subject rights and regulatory obligations.
Bahrain's PDPL requires organisations to take a structured approach to personal-data processing, consent, transparency, security, individual rights and international data transfers.
ConsentX helps turn these privacy requirements into practical website controls.
Scan your website. Identify trackers. Configure consent. Record user choices. Manage privacy requests.
Get started with ConsentX or book a demo.