Personal Data Privacy Protection Law
Qatar
In force since 29 December 2016
Law No. 13 of 2016 on Protecting Personal Data Privacy was published in Qatar's Official Gazette and took effect on 29 December 2016. Qatar's legal portal currently lists the law as in force.
Asia & Africa
Law No. 13 of 2016 on Protecting Personal Data Privacy
Qatar
Middle East
In force
29 December 2016
Competent department designated under the Qatari framework
Required unless a lawful exception applies, including processing necessary for a legitimate purpose
Access, review, correction, deletion, objection, withdrawal of consent
Subject to additional controls and prior authorisation requirements
Prior consent required for electronic direct marketing
Appropriate administrative, technical, and physical safeguards required
Notification required where a breach may cause serious damage to personal data or an individual's privacy
Cross-border data flows are permitted subject to the law's requirements
Up to QAR 1 million for specified violations; up to QAR 5 million for specified serious violations
Legal persons may also face fines of up to QAR 1 million in specified circumstances
The law applies to organisations that process personal data within its scope. This can include companies operating in Qatar, online businesses and e-commerce platforms, financial and professional service organisations, healthcare organisations, educational institutions, technology companies, telecommunications and digital service providers, employers processing employee information, marketing and advertising organisations, organisations operating websites and mobile applications, controllers using third-party processors, and service providers processing personal data on behalf of other organisations. The exact obligations depend on the nature of the processing, the organisation's role, the type of personal data involved, and whether a statutory exemption applies.
Qatar PDPPL establishes significant financial penalties for specified violations. Article 23 provides for a fine of up to QAR 1,000,000 for violations of specified provisions, including the requirements on processing, controller obligations, transparency, data relevance and retention, governance procedures, disclosures and processors, certain breach-notification obligations, cross-border data flows, and electronic direct marketing. Article 24 provides for fines of up to QAR 5,000,000 for specified violations, including those relating to security safeguards and to the requirements for personal data of a special nature. Article 25 provides that a violating legal person may be fined up to QAR 1,000,000 where specified offences are committed in its name and for its account, without prejudice to the criminal responsibility of the relevant individual. The statutory penalty amounts are set out in Articles 23 to 25 of the law.
Consent is an important legal requirement, but Qatar's PDPPL does not make consent the only possible basis for processing. Article 4 allows processing with the individual's consent unless processing is necessary to achieve a legitimate purpose of the controller or the party to whom the data is transferred. The law also gives individuals rights to access, review, correct, delete, and object to certain processing of their personal data, and organisations must establish internal procedures to handle complaints and requests relating to personal data.
The Qatar Personal Data Privacy Protection Law, commonly referred to as the PDPPL, is Qatar's principal general framework for protecting personal data.
The law establishes obligations for controllers and processors and protects individuals whose personal data is processed.
It applies to personal data when it is processed electronically, collected or obtained in preparation for electronic processing, or processed through a combination of electronic and traditional methods. Personal or family activities and certain official statistical processing are excluded from its scope.
The law is structured around:
The law applies to personal data, including information that can identify an individual directly or indirectly.
Depending on the circumstances, this can include:
The law defines personal-data processing broadly and includes activities such as gathering, receiving, recording, organising, storing, modifying, retrieving, using, disclosing, publishing, transferring, withholding, destroying, erasing, and cancelling personal data.
Is consent required under Qatar PDPPL?
Consent is an important legal basis under Qatar's PDPPL, but it is not universally required for every processing activity.
Article 4 states that a controller may not process personal data unless the individual has provided consent, unless the processing is necessary to achieve a legitimate purpose of the controller or the third party to whom the data is transferred.
This means organisations should identify the legal justification for each processing activity rather than treating consent as a blanket requirement for every form of processing.
Depending on the circumstances, consent may be relevant for:
Organisations should document the basis relied upon for each processing activity.
Where consent is used, organisations should make sure that consent is meaningful and appropriately documented.
A compliant consent mechanism should:
For digital businesses, consent management should be connected to the actual processing environment so that trackers, advertising technologies, and other optional technologies do not operate inconsistently with the user's choice.
Individuals have the right to withdraw previously provided consent.
Article 5 expressly gives individuals the ability to withdraw their prior consent to processing. Individuals may also object to processing where it is unnecessary for the purposes for which data was collected, excessive, discriminatory, unfair, or contrary to law.
Organisations should therefore maintain a process for:
Qatar PDPPL requires controllers to provide information to individuals before beginning to process personal data.
Under Article 9, individuals should be informed about:
A privacy notice should therefore explain what information is collected, why it is collected, how it is used, and with whom it may be shared.
Qatar PDPPL requires controllers to ensure that collected personal data is:
Controllers must also avoid retaining personal data longer than necessary to achieve the relevant purposes.
This creates practical requirements around:
The law gives individuals several rights concerning their personal data.
Right to access. Individuals may access their personal data and request to review it. Article 6 also provides rights to receive information about processing and to obtain a copy of personal data, subject to the statutory framework and applicable service charges.
Right to information. Individuals can request information concerning the processing of their personal data, the purposes for processing, certain disclosures, and inaccuracies in disclosed personal data.
Right to correction. Individuals may request correction of inaccurate personal data and are required to provide supporting evidence for the requested correction under Article 5.
Right to deletion. Individuals may request deletion or erasure in specified circumstances, including where processing is unnecessary, data is excessive for the purpose, the original purpose has ended, or there is no justification for retaining the data.
Right to object. Individuals may object to processing where the processing is unnecessary for the purpose for which data was collected, excessive, discriminatory, unfair, or contrary to law.
Right to withdraw consent. Where processing is based on prior consent, an individual may withdraw that consent.
Qatar PDPPL identifies certain types of personal data as personal data of a special nature.
Article 16 specifically includes information relating to:
The Minister may add additional categories where misuse or disclosure could cause serious harm to an individual.
Processing personal data of a special nature requires authorisation from the competent department under Article 16, following applicable procedures and controls. Additional safeguards may also be imposed for protecting special-category personal data. Organisations should therefore identify special-category data before deploying new processing activities.
Children's data is expressly included within Qatar's definition of personal data of a special nature.
This means organisations processing information relating to children should apply additional controls and carefully evaluate the applicable authorisation and privacy requirements.
For websites, applications, educational platforms, gaming services, and other child-facing services, organisations should consider:
Qatar PDPPL requires controllers and processors to take appropriate measures to protect personal data.
Article 8 requires controllers to adopt appropriate administrative, technical, and physical precautions to protect personal data.
Article 13 further requires controllers and processors to take precautions against:
The safeguards must be proportionate to the nature and importance of the personal data being protected.
Qatar's PDPPL requires controllers to consider privacy protection when designing, changing, or developing products, systems, and services involving personal data.
Controllers must also review privacy-protection measures before introducing new processing operations.
Organisations should therefore incorporate privacy into:
Qatar PDPPL distinguishes between the controller and processor.
The controller determines the relevant processing purposes and is responsible for ensuring that processing is carried out in accordance with the law. Controller obligations include:
Processors handle personal data on behalf of controllers. Controllers must identify processors responsible for protecting personal data and continuously monitor processor compliance with their instructions and appropriate safeguards.
Organisations using cloud providers, analytics services, marketing platforms, SaaS providers, hosting providers, or other third-party processors should maintain appropriate controls.
Key measures include:
Article 12 requires disclosures or transfers to processors to remain consistent with the lawful purposes and the requirements of the law.
Qatar PDPPL contains a specific obligation relating to breaches of the security safeguards required by Article 13.
Where a breach could cause serious damage to personal data or an individual's privacy, the controller must notify the affected individual and the competent administration.
Article 13 also requires processors to notify the controller immediately upon becoming aware of a failure in required safeguards or a risk threatening individuals' personal data.
Organisations should maintain an incident-response process capable of:
Qatar PDPPL recognises cross-border data flows.
The law does not establish a general prohibition on transferring personal data across national borders. Instead, Article 15 restricts controllers from taking measures to limit cross-border flows unless the processing violates the law or could cause serious harm to personal data or an individual's privacy.
Organisations should nevertheless evaluate:
Qatar PDPPL applies to personal data processed through electronic systems, which makes online data collection relevant to privacy compliance.
Website operators should therefore assess cookies and tracking technologies that may collect or enable access to information associated with an identifiable individual.
Examples include:
Where consent is the applicable basis, organisations should obtain consent before activating the relevant processing.
A consent management platform can help separate:
Qatar has an explicit requirement for electronic direct marketing.
Article 22 prohibits sending an electronic communication for direct marketing without the individual's prior consent.
Marketing communications must also:
This applies particularly to:
Consent records should therefore be maintained for marketing databases.
Qatar's PDPPL predates the current wave of generative AI and automated decision-making technologies, so organisations should avoid assuming that it contains a GDPR-style standalone automated-decision-making framework.
However, AI and automated processing can involve extensive collection and processing of personal data.
Qatar's current government AI guidance also highlights the need to safeguard privacy and protect personal data of a special nature when developing and deploying AI systems.
Organisations using AI should therefore assess:
Qatar PDPPL requires controllers not to retain personal data for longer than necessary to achieve the lawful purposes for which it was collected.
A practical retention programme should define:
ConsentX can complement these processes by maintaining records of consent and preference changes, while organisations remain responsible for their wider data-retention programme.
Article 11 establishes several organisational requirements, including:
This makes privacy governance an ongoing organisational responsibility rather than a one-time website exercise.
Individuals may submit complaints to the competent department where they believe the law or decisions issued under it have been violated.
Article 26 expressly provides an avenue for individuals to submit complaints concerning violations of the law.
Organisations should therefore have an internal process for:
Qatar PDPPL establishes significant financial penalties for specified violations.
Article 23 provides for a fine of up to QAR 1,000,000 for violations of specified provisions, including:
Article 24 provides for fines of up to QAR 5,000,000 for specified violations, including:
Article 25 provides that a violating legal person may be fined up to QAR 1,000,000 where specified offences are committed in its name and for its account, without prejudice to the criminal responsibility of the relevant individual.
For organisations collecting personal data through websites and digital platforms, consent management can support several PDPPL compliance requirements.
A robust consent-management implementation should help organisations:
ConsentX can provide the technical layer for these workflows.
Use this checklist to assess your organisation's readiness.
Qatar's PDPPL combines consent requirements with broader obligations covering transparency, legitimate purposes, data minimisation, retention, security, processor oversight, individual rights, special-category data, and direct marketing.
For organisations operating digital properties, privacy compliance therefore needs to extend beyond publishing a privacy policy.
A practical compliance programme should connect privacy notice → consent → tracking control → consent records → withdrawal → marketing preferences → audit evidence.
ConsentX helps organisations operationalise this workflow across their websites and digital experiences.
Create configurable consent notices that explain why data or tracking technologies are being used.
Prevent optional trackers and scripts from firing before the relevant consent decision where consent is the applicable legal basis.
Create records showing what the user consented to, when consent was given, what purposes were presented, which preferences were selected, and when consent was withdrawn.
Give users an accessible mechanism for changing or withdrawing their preferences.
Apply different consent and tracking configurations based on the visitor's location and applicable privacy framework.
Use automated scanning to identify cookies, trackers, scripts, and third-party technologies operating on a website.
Maintain consent records that can help organisations demonstrate how consent preferences were collected and managed.
Provide users with a central mechanism for reviewing and changing their privacy choices.
Build a more transparent and auditable approach to personal-data consent and privacy management. With ConsentX, organisations can scan websites for cookies and trackers, configure privacy consent banners, block optional scripts before consent, capture consent records, manage withdrawal preferences, support direct-marketing consent workflows, apply region-specific privacy rules, maintain audit-ready consent evidence, and monitor changes in website tracking technologies. Start your privacy compliance journey with ConsentX.
This page provides a general, plain-English overview of Qatar's Personal Data Privacy Protection Law and related guidance. It is not legal advice and does not cover every exemption, sector-specific requirement, ministerial decision, regulatory interpretation, or individual compliance circumstance. A cookie banner alone does not establish complete PDPPL compliance: broader compliance also requires legal assessment, governance, security safeguards, processor oversight, individual-rights processes, and breach response. Organisations should review the current Qatari legislation and official guidance and obtain qualified Qatari legal advice where necessary.
Identify cookies, trackers, scripts, pixels, tags, and other technologies that process or facilitate the collection of personal data.
Categorise technologies based on their function and purpose. Examples include:
Determine whether each processing activity relies on:
Do not assume that every processing activity requires consent.
Create a transparent consent interface that explains relevant processing purposes and gives users appropriate choices.
Use prior-script blocking to prevent optional technologies from operating before the required consent decision.
Maintain evidence of:
Allow users to revisit and modify their preferences.
For electronic direct marketing, ensure that marketing databases respect the individual's prior consent and withdrawal choices.
Identify analytics, advertising, cloud, SaaS, and other vendors that receive or process personal data.
Keep appropriate records to support privacy audits, internal governance, complaints, and regulatory enquiries.