Bahrain
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Bahrain bans sending personal data abroad unless you fit an exception. The main exception is an official list of more than eighty approved countries, which includes the United States, China, Russia and every Gulf neighbour. Nothing has to be stored inside Bahrain. The paperwork is heavy: you usually tell the regulator before you start, and breaking the rules is a crime.
Data governance in Bahrain
The eight things that decide how you handle data about people in Bahrain. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law catches a company anywhere in the world if it handles people's data using equipment sitting inside Bahrain, even with no office and no staff there. There is no size, revenue or headcount threshold to fall below. A foreign company in that position must appoint a representative in Bahrain who takes on its duties, and must tell the regulator who that is.
Article 2 applies the law to processing by a data controller with a place of business in Bahrain, to a person habitually resident in Bahrain, and to 'every natural or legal person not habitually resident nor maintains a place of business in the Kingdom, but processes data by using means situated in the Kingdom' unless those means are used only to transmit data through Bahrain. Article 2(3) requires the appointment of an authorised representative and immediate notification of that appointment to the Authority. The extraterritorial hook is equipment-based rather than targeting-based, so it is narrower than the European or Indian tests but wider than it looks for anyone using Bahraini infrastructure.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceLink may be brokenLegislation and Legal Opinion CommissionOfficial Gazette copy of Law No. (30) of 2018 (linked from the regulator's own site)
legalaffairs.gov.bh
Link checked 18 August 2026
Where the data is allowed to live
Yes, but only through a defined gate. The starting position is that moving personal data out of Bahrain is forbidden. It becomes legal if the destination is on the government's approved-country list, which names more than eighty places including the United States, China, Russia, India and all of Bahrain's Gulf neighbours. If your destination is not on that list, you ask the regulator for permission for that specific transfer, or you rely on one of six narrow exceptions such as the person's consent.
SECTOR BY SECTOR, checked 18 August 2026. Banking, insurance, securities and payments (all supervised by the Central Bank of Bahrain): no rule requiring data to stay in Bahrain, but a licensee needs the central bank's prior approval to outsource anything to a third party outside Bahrain, and must notify the central bank after the fact for cloud arrangements inside or outside Bahrain; cloud rules require a risk-based choice of hosting country and forbid hosting where the regulator's access to information could be blocked, or in countries under United Nations sanctions. Government: the state's own Cloud First Policy openly rejects residency restrictions for government workloads, subject to classification and state-secrets rules. Health, telecommunications, education, geospatial and mapping, and defence: no localisation or sector transfer rule found on the regulators' own sites, checked 18 August 2026, medium confidence - see the unconfirmed list. Gambling: commercial gambling is not licensed in Bahrain, so there is no gaming data regime to check. The single most important point is that the general law does the work here: Bahrain restricts transfers at the national level and then leaves industries alone, which is the reverse of the pattern in India or Saudi Arabia.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCBB Rulebook Volume 1, Module OM, Chapter OM-2A: Cloud Outsourcing Arrangements, rule OM-2A.2.1
cbb.gov.bh
“Adopt a risk-based approach to data storage and data processing locations (country or region) ensuring that the data is not stored in jurisdictions where prompt access to information by licensee or CBB representatives may be impeded by legal or administrative restrictions, or jurisdictions that are subject to United Nations sanctions.”
Link checked 18 August 2026
- Official sourceInformation and eGovernment AuthorityCloud First Policy, version 1.0, 24 April 2017 - Data Sovereignty section
iga.gov.bh
“The benefits of cloud are best realized when there are no data residency restrictions placed on data. Such restrictions undermine the economies of scale and security benefits to be gained from shared computing infrastructure.”
Link checked 18 August 2026
Sending data out of the country
This is an approved-list system: banned unless allowed. The list is real and full, not empty, and it was published in March 2022 with more than eighty countries and territories on it. Send data to a listed place and you need no paperwork and no permission. Send it anywhere else and you need written permission from the regulator for that transfer, or one of six exceptions: the person agreed, the data came from a public register, the transfer is needed for a contract, to protect someone's life, to obey a law or court order, or to bring or defend a legal claim.
Article 12 bans transfer outside Bahrain except to a country the Authority has listed as offering adequate legislative and regulatory protection, or with a case-by-case authorisation which may be made conditional or time-limited. Order No. 42 of 2022 is the list. Article 13 sets out the exceptions. There is no standard contract clause regime, no binding corporate rules, no certification route: Bahrain never built one. Note that 'adequate' in Bahrain does not mean what it means in Europe - the same order lists the United States, China and Russia - so a transfer that is lawful under Bahraini law can still breach European rules, and vice versa.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
The regulator, and whether it actually acts
On paper the Personal Data Protection Authority. In practice there is no separate authority: a royal decree in 2019 handed its powers to the Ministry of Justice, with the minister acting as the board and the ministry's undersecretary as chief executive, until money and a board decree arrive. That arrangement is still in place in August 2026. It does work - it publishes ten binding orders and runs live forms for registrations, permissions, breach reports and complaints - but we found no published fines or decisions, so treat enforcement as switched on and quiet rather than aggressive. The central bank, by contrast, supervises finance actively and consults on new rules constantly.
Royal Decree No. 78 of 2019, in force 29 September 2019, states that the Minister of Justice, Islamic Affairs and Waqf assumes the duties and powers of the Authority's board of directors and chairman, and the ministry's undersecretary the role of chief executive, pending a financial allocation in the state budget and a decree forming the board. The Authority's own website still shows that decree as the governing arrangement and names no board members or chief executive. Enforcement of the criminal penalties in the law runs through the Public Prosecution and the courts rather than through administrative fining powers, which is one reason the public record is thin. We could not find any published enforcement decision, fine or annual report, and record that as an explicit gap rather than as evidence that nothing has happened.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfRoyal Decree No. (78) of 2019 - the administrative entity assuming the duties and powers of the Personal Data Protection Authority
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfMinistry of Justice, Islamic Affairs and Waqf - portal linking to the Personal Data Protection Authority
moj.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a ceiling in the general law and floors in specific industries. The ceiling: once you have done what you collected the data for, you may not keep it in a form that still identifies the person, and anything held long term should be anonymous or encrypted. You must also set and follow your own written retention and deletion schedule. The clearest floor we could verify is in finance, where security event logs must be kept for at least five years.
Article 3(5) of the law is the ceiling. Order No. 43 of 2022 requires controllers to regulate their data retention and disposal periods as part of the technical and organisational measures. The five-year floor sits in the Financial Cybersecurity Controls issued by the National Cyber Security Centre for financial entities: control 6.1.8 requires a security information and event management system with a log retention period of five years or longer, and control 6.1.10 makes log retention track the cyber centre's requirements. The draft payment service provider module the central bank put out for consultation in February 2026 also uses a five-year record floor. Tax and company-law floors almost certainly exist - Bahrain runs value added tax and a commercial companies law - but the government legislation portal was unreachable from our network, so we do not assert them here. Where a floor and the ceiling collide, the specific keeping obligation wins and the general delete-when-done rule bends around it; we could not find an official Bahraini statement of that principle, so it is reasoning, not a quoted rule.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre / Central Bank of BahrainFinancial Cybersecurity Controls (National Cyber Security Centre, October 2022), controls 6.1.8 and 6.1.10
cbb.gov.bh
“The financial entity must implement a Security Information and Event Management “SIEM” system with a log retention period 5 years or longer.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainConsultation draft, CBB Rulebook Volume 5, Payment Service Provider Module, 5 February 2026
cbb.gov.bh
Link checked 18 August 2026
If something goes wrong
You have 72 hours. From the moment you discover a personal data breach, you must tell the regulator, using its online breach form, and you must also tell the people affected unless the data was unreadable to outsiders, for example properly encrypted, or the risk has since been removed. You must keep your own written record of every breach, its causes, its effects and what you did about it. Financial firms have a second, separate reporting line to their supervisor and to the national cyber centre.
The 72-hour clock is not in the statute - the law itself is silent on breach reporting - it comes from article 4 of Order No. 43 of 2022 on technical and organisational measures. That order also sets out what the notification must contain for both the regulator and the individual, and lets a controller replace individual notice with a public announcement where individual notice would take disproportionate effort. Financial entities additionally sit under the Financial Cybersecurity Controls, which require an incident response plan, incident classification and reporting arrangements; the copy published by the central bank is a scanned document whose specific reporting deadline we could not extract, so we do not state one. The practical trap is the overlap: one incident, two regulators, and the shorter clock is the one that governs.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre / Central Bank of BahrainFinancial Cybersecurity Controls (National Cyber Security Centre, October 2022), controls 6.1.8 and 6.1.10
cbb.gov.bh
“The financial entity must implement a Security Information and Event Management “SIEM” system with a log retention period 5 years or longer.”
Link checked 18 August 2026
What catches people out
Five things catch people out. First, breaking these rules is a crime: up to one year in prison and a fine of 1,000 to 20,000 Bahraini dinars, roughly 2,600 to 53,000 US dollars, including for sending data abroad unlawfully. Second, you normally have to tell the regulator before you start automated processing at all, and get written permission first for sensitive data, biometrics, genetic data, security cameras and linking databases. Third, if the regulator says nothing within thirty days, that counts as a refusal, not approval. Fourth, a foreign company using equipment in Bahrain must appoint a local representative. Fifth, banks and insurers need central bank sign-off thirty days before signing an offshore supplier.
Penalties sit in article 58: imprisonment up to one year and/or a fine of not less than 1,000 and not more than 20,000 Bahraini dinars for a list of breaches that expressly includes transferring data outside Bahrain contrary to articles 12 and 13, processing without the required notification or prior authorisation, and unlawful disclosure. Prior notification is article 14, with narrow exemptions including where a data protection guardian has been appointed and registered - that appointment is the standard way to escape the notification treadmill. Prior authorisation is article 15 and covers sensitive personal data, biometric data used to identify people, genetic data, linking data sets held by different controllers, and visual surveillance recording; Order No. 44 of 2022 confirms the thirty-day decision window and that silence is an implied rejection, and requires a data protection impact assessment for biometrics and surveillance. Sensitive data in Bahrain expressly includes race, political or philosophical opinions, religious belief, union membership, criminal record and health data.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (44) of 2022 on submitting notifications and prior authorisation requests, 17 March 2022
pdp.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
What's changing next
Nothing new is scheduled to hit the general privacy law in the next twelve months as far as we can see. The action is in finance: the central bank is rewriting its payments rules, with a new payment service provider module out for comment in February 2026 and a buy-now-pay-later module from November 2025. The bigger risks are two switches the government can flip without warning: the approved-country list can be changed by a ministerial order, and a single decree could finally stand up a real data protection authority with its own board.
DORMANT SWITCHES. One: the list of adequate countries is an executive order of the Minister of Justice, so a country can be added or removed overnight with no consultation - a company routing data to a country that comes off the list would be exposed to criminal liability, not just an order to stop. Two: Royal Decree No. 78 of 2019 is expressly interim, conditional on a budget allocation and a decree forming the board; once that decree issues, Bahrain goes from a ministry side-desk to a standing regulator, and the ten orders already on the books become enforceable by a body with staff. Three: the National Cyber Security Centre is operating a national strategy for 2025 to 2028 and issues controls documents for critical sectors, which is the most likely source of new hard obligations. We found no bill amending Law No. 30 of 2018 - but note that the government legislation portal was unreachable from our network, so a pending bill could exist that we did not see.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfRoyal Decree No. (78) of 2019 - the administrative entity assuming the duties and powers of the Personal Data Protection Authority
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainConsultation draft, CBB Rulebook Volume 5, Payment Service Provider Module, 5 February 2026
cbb.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre - National Cyber Security Strategy 2025-2028 and guidance
ncsc.gov.bh
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
CBB Rulebook - Outsourcing Requirements (chapter on outsourcing arrangements)
Government rules · Central Bank of Bahrain, Outsourcing Requirements 2022, rules 1.1.6 and 1.1.7
Banks, insurers, investment firms and payment companies must get the central bank's written approval before outsourcing anything to a third party outside Bahrain, applying at least thirty days ahead. Cloud services are carved out of the approval requirement but must be notified to the central bank afterwards, whether the provider is inside or outside Bahrain.
Enforced by Central Bank of Bahrain
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractA service level agreement is mandatory and must give the central bank, external auditors and the licensee's own audit and compliance staff unrestricted access to the supplier's records.
- Independent audit
- Register or notifyPrior approval application at least 30 calendar days before committing to an offshore third-party arrangement; the central bank answers within 15 calendar days. Cloud arrangements and intragroup arrangements are notified after the fact instead.
Sources
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
CBB Rulebook Volume 1, Module OM (Operational Risk Management), Chapter OM-2A: Cloud Outsourcing Arrangements
Government rules · OM-2A.1 and OM-2A.2, CBB Rulebook Volume 1
Bahrain's banks may put customer data in the public cloud abroad, but they must choose the country on a risk basis, avoid anywhere that could block the regulator's access to information or that is under United Nations sanctions, encrypt the data and hold their own encryption keys. If a foreign government tries to force the cloud provider to hand data over, the bank should tell the customer.
Enforced by Central Bank of Bahrain
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Secure the dataEncryption in transit, in memory, at rest and in backups, with key management kept away from the cloud provider; tenant isolation; recognised international security standards.
- Do not hand data to foreign authorities on demandThe bank should tell the customer promptly if authorities in the country where the data sits are trying to compel the cloud provider to hand it over.
- Prove the data stays under local controlHosting country chosen on a risk basis; must not be a place where regulator access could be blocked, nor a country under United Nations sanctions.
- Independent audit
Sources
- Official sourceCentral Bank of BahrainCBB Rulebook Volume 1, Module OM, Chapter OM-2A: Cloud Outsourcing Arrangements, rule OM-2A.2.1
cbb.gov.bh
“Adopt a risk-based approach to data storage and data processing locations (country or region) ensuring that the data is not stored in jurisdictions where prompt access to information by licensee or CBB representatives may be impeded by legal or administrative restrictions, or jurisdictions that are subject to United Nations sanctions.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
Cloud First Policy
Government policy document · Cloud First Policy, version 1.0, 24 April 2017, approved by the Supreme Committee for Information and Communication Technology
Bahrain's government tells its own agencies to buy cloud first and says plainly that data residency restrictions are counterproductive. Government workloads may therefore sit outside the country, subject to data classification rules and the state secrets regime. This is the opposite of the government-cloud localisation rules common elsewhere in the region.
Enforced by Information and eGovernment Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataSecurity controls must match the government data classification level; agencies coordinate with the national information security body.
- Hold a security certificate
Sources
- Official sourceInformation and eGovernment AuthorityCloud First Policy, version 1.0, 24 April 2017 - Data Sovereignty section
iga.gov.bh
“The benefits of cloud are best realized when there are no data residency restrictions placed on data. Such restrictions undermine the economies of scale and security benefits to be gained from shared computing infrastructure.”
Link checked 18 August 2026
- Official sourceInformation and eGovernment AuthorityInformation and eGovernment Authority - national digital policies library
iga.gov.bh
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
قانون رقم (30) لسنة 2018 بشأن حماية البيانات الشخصية (Law No. 30 of 2018 with respect to Personal Data Protection)
Act of parliament · Law No. (30) of 2018, published in the Official Gazette on 12 July 2018
Bahrain's general privacy law. It bans sending personal data out of the country unless the destination is on an official approved list, the regulator authorises the specific transfer, or a narrow exception applies. It also requires you to tell the regulator before most automated processing and to get written permission before handling sensitive data. Breaches are criminal offences.
Enforced by Personal Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Get consent
- Tell people what you do
- Register or notifyPrior notification to the regulator of automated processing under article 14, unless an exemption applies or a registered data protection guardian has been appointed.
- Appoint a local representativeRequired where the controller has no place of business or habitual residence in Bahrain but processes using means located there.
- Appoint a data protection officerOptional 'data protection guardian'; appointing and registering one removes the prior-notification duty.
- Let people see their data
- Let people correct their data
- Let people object
- Put a transfer safeguard in place
- Delete data after a period
- Assess high-risk projects — applies at: Biometric processing and visual surveillance recording
What it costs if you get it wrong
- Criminal liability: 1 year imprisonmentUnlawful transfer abroad, processing without required notification or prior authorisation, unlawful disclosure (article 58)
- Fixed maximum fine: BHD 20,000 — about $53 thousandSame offences; minimum fine BHD 1,000, about 2,600 US dollars
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceLink may be brokenLegislation and Legal Opinion CommissionOfficial Gazette copy of Law No. (30) of 2018 (linked from the regulator's own site)
legalaffairs.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
قرار رقم (42) لسنة 2022 (Order No. 42 of 2022 on countries and territories with adequate protection)
Government rules · Order No. (42) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022
The approved-country list. More than eighty countries and territories are named, including the United States, China, Russia, India, the United Kingdom, every European Union state and all of Bahrain's Gulf neighbours. Data may go to any of them with no permission and no contract. The list is a ministerial order, so it can be changed at any time without consultation.
Enforced by Personal Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeNo paperwork needed for a listed destination; anything else needs case-by-case authorisation or an article 13 exception.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
قرار رقم (43) لسنة 2022 (Order No. 43 of 2022 on technical and organisational measures)
Government rules · Order No. (43) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022
The security rulebook, and the only place the 72-hour breach clock actually appears - the statute itself says nothing about breach reporting. It requires privacy by design, encryption, penetration testing, a written breach log, notice to the regulator within 72 hours of discovery and, in most cases, notice to the people affected.
Enforced by Personal Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Secure the dataPrivacy by design and by default, access control, anti-virus and firewalls, encryption, periodic vulnerability assessment and penetration testing, staff training.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleNot required where the breached data is unintelligible to unauthorised people, for example encrypted, where later measures remove the high risk, or where individual notice would take disproportionate effort - then a public announcement is used.
- Keep records of processingWritten record of every breach: causes, effects, remedial action.
- Delete data after a periodControllers must set and apply retention and disposal periods.
- Written vendor contract
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The full and current contents of the approved-country list in Order No. 42 of 2022
We read the regulator's own English PDF, but through an automated text extraction, and the order is amendable at any time by ministerial order. Countries that appear absent - for example Qatar, Turkey and Indonesia - should be re-checked against the PDF before anyone relies on their absence.
Whether any enforcement decision, fine or prosecution has ever been published under Law No. 30 of 2018
No decisions register, case list or annual report is published on the Authority's site. Absence of evidence is not evidence of absence; this is why enforcement is rated waking rather than dormant or active.
Sector rules for health, telecommunications, education, geospatial or defence data
The Legislation and Legal Opinion Commission portal, which hosts the official text of every Bahraini law, was blocked from our network, and the telecommunications regulator's and health regulator's document databases render only with JavaScript. We found no localisation or sector transfer rule, checked 18 August 2026, but this is the weakest part of the record.
Legislative Decree No. 56 of 2018 on providing cloud computing services to foreign parties
Bahrain is understood to have a law letting foreign customers store data in Bahrain under their own home law, which would be a notable reverse-localisation feature. We could not open the official text on the government legislation portal, so it is deliberately not recorded as a rule.
The binding status of the Financial Cybersecurity Controls
The copy published on the central bank's website is headed 'Draft v 0.1, October 2022' although it was circulated to licensees by circular in November 2022. The covering circular is a scanned image with no extractable text, so we cite the five-year log retention control with medium confidence.
Minimum record-keeping periods under Bahraini tax and company law
The National Bureau for Revenue site refused our requests and the legislation portal was blocked, so we do not state the value added tax or commercial companies retention floors.
Whether the cyber incident reporting deadline for financial entities differs from the 72-hour privacy deadline
The relevant central bank and cyber centre documents we could read describe incident response and classification duties but no extractable hour figure.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Bahrain versus
Compare