Skip to the content
Global Data RulesData governance rules, country by country

Bahrain

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Bahrain — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Bahrain bans sending personal data abroad unless you fit an exception. The main exception is an official list of more than eighty approved countries. It includes the United States, China, Russia and every Gulf neighbour. Nothing has to be stored inside Bahrain. The paperwork is heavy. You usually tell the regulator before you start, and breaking the rules is a crime.

Data governance in Bahrain

The eight things that decide how you handle data about people in Bahrain. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law catches a company anywhere in the world if it handles people's data using equipment sitting inside Bahrain. That is true even with no office and no staff there. There is no size, revenue or staff-count threshold to fall below. A foreign company in that position must appoint a representative in Bahrain who takes on its duties. It must also tell the regulator who that is.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, but only through a few defined routes. The starting position is that moving personal data out of Bahrain is forbidden. It becomes legal if the destination is on the government's approved-country list. That list names more than eighty places, including the United States, China, Russia, India and all of Bahrain's Gulf neighbours. If your destination is not on the list, you ask the regulator for permission for that specific transfer. Or you rely on one of six narrow exceptions, such as the person's consent.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed

What to do: Get the paperwork for one of the routes below signed before any data leaves Bahrain.

Sending data out of the country

This is an approved-list system: banned unless allowed. The list is real and full, not empty. It was published in March 2022 with more than eighty countries and territories on it. Send data to a listed place and you need no paperwork and no permission. Send it anywhere else and you need written permission from the regulator for that transfer. Or you use one of six exceptions. The person agreed. The data came from a public register. The transfer is needed for a contract, to protect someone's life, to obey a law or court order, or to bring or defend a legal claim.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · To save someone’s life

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

On paper, the Personal Data Protection Authority. But there is no separate authority. A royal decree in 2019 handed its powers to the Ministry of Justice. The minister acts as the board, and the ministry's undersecretary acts as chief executive, until money and a board decree arrive. That arrangement is still in place in August 2026. It does work. It publishes ten binding orders and runs live forms for registrations, permissions, breach reports and complaints. But we found no published fines or decisions. So treat enforcement as switched on and quiet, not aggressive. The central bank, by contrast, supervises finance actively and consults on new rules constantly.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The general law says when to delete, and specific industries say how long to keep. On deleting: once you have done what you collected the data for, you may not keep it in a form that still identifies the person. Anything held long term should be anonymous or encrypted. You must also set and follow your own written keeping and deletion schedule. The clearest minimum we could verify is in finance. Security event logs must be kept for at least five years.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

You have 72 hours. From the moment you discover a personal data breach, you must tell the regulator, using its online breach form. You must also tell the people affected. There are two exceptions. The data was unreadable to outsiders, for example properly encrypted. Or the risk has since been removed. You must keep your own written record of every breach, its causes, its effects and what you did about it. Financial firms have a second, separate reporting line to their supervisor and to the national cyber centre.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, breaking these rules is a crime. You face up to one year in prison and a fine of 1,000 to 20,000 Bahraini dinars, roughly 2,600 to 53,000 US dollars. That includes sending data abroad unlawfully. Second, you normally have to tell the regulator before you start using data automatically at all. You need written permission first for sensitive data, biometrics, genetic data, security cameras and linking databases. Third, if the regulator says nothing within thirty days, that counts as a refusal, not approval. Fourth, a foreign company using equipment in Bahrain must appoint a local representative. Fifth, banks and insurers need central bank sign-off thirty days before signing an offshore supplier.

What you have to do here:
Register or notify · Assess high-risk projects · Appoint a representative
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing new is scheduled to hit the general privacy law in the next twelve months, as far as we can see. The action is in finance. The central bank is rewriting its payments rules. A new payment service provider module went out for comment in February 2026, and a buy-now-pay-later module came out in November 2025. The bigger risks are two powers the government can use without warning. The approved-country list can be changed by a ministerial order. And a single decree could finally stand up a real data protection authority with its own board.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Cloud and outsourcing rules

Official name: CBB Rulebook - Outsourcing Requirements (chapter on outsourcing arrangements) · Central Bank of Bahrain, Outsourcing Requirements 2022, rules 1.1.6 and 1.1.7 · Government rules

In forceYes, with paperwork

Banks, insurers, investment firms and payment companies must get the central bank's written approval before handing any work to a supplier outside Bahrain. They must apply at least thirty days ahead. Cloud services do not need that approval. But you must tell the central bank about them afterwards, whether the provider is inside or outside Bahrain.

In force since 1 January 2022

Enforced by Central Bank of Bahrain

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Cloud and outsourcing rules (Banking)

Official name: CBB Rulebook Volume 1, Module OM (Operational Risk Management), Chapter OM-2A: Cloud Outsourcing Arrangements · OM-2A.1 and OM-2A.2, CBB Rulebook Volume 1 · Government rules

In forceYes, with paperwork

Bahrain's banks may put customer data in the public cloud abroad. But they must choose the country on a risk basis. They must avoid anywhere that could block the regulator's access to information, and anywhere under United Nations sanctions. They must encrypt the data and hold their own encryption keys. If a foreign government tries to force the cloud provider to hand data over, the bank should tell the customer.

In force since 1 January 2022

Enforced by Central Bank of Bahrain

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Cloud and outsourcing rules (Government)

Official name: Cloud First Policy · Cloud First Policy, version 1.0, 24 April 2017, approved by the Supreme Committee for Information and Communication Technology · Government policy document

In forceYes — store it anywhere

Bahrain's government tells its own agencies to buy cloud first. It says plainly that forcing data to stay in the country is counterproductive. Government systems may therefore sit outside the country, subject to data classification rules and the state secrets rules. This is the opposite of the government-cloud rules common elsewhere in the region.

In force since 24 April 2017

Enforced by Information and eGovernment Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: قانون رقم (30) لسنة 2018 بشأن حماية البيانات الشخصية (Law No. 30 of 2018 with respect to Personal Data Protection) · Law No. (30) of 2018, published in the Official Gazette on 12 July 2018 · Act of parliament

In forceYes, with paperwork

Bahrain's general privacy law. It bans sending personal data out of the country. There are three ways round that: the destination is on an official approved list, the regulator authorises the specific transfer, or a narrow exception applies. You must also tell the regulator before you use data automatically, in most cases. You need written permission before handling sensitive data. Breaches are criminal offences.

In force since 1 August 2019

Enforced by Personal Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Paperwork before personal data leaves

Official name: قرار رقم (42) لسنة 2022 (Order No. 42 of 2022 on countries and territories with adequate protection) · Order No. (42) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022 · Government rules

In forceYes, with paperwork

The approved-country list. More than eighty countries and territories are named, including the United States, China, Russia, India, the United Kingdom, every European Union state and all of Bahrain's Gulf neighbours. Data may go to any of them with no permission and no contract. The list is a ministerial order, so it can be changed at any time without consultation.

In force since 17 March 2022

Enforced by Personal Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Breach reporting rules (2022)

Official name: قرار رقم (43) لسنة 2022 (Order No. 43 of 2022 on technical and organisational measures) · Order No. (43) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022 · Government rules

In forceYes, with paperwork

The security rulebook. It is the only place the 72-hour breach deadline actually appears. The statute itself says nothing about breach reporting. It requires privacy by design, encryption, penetration testing, a written breach log, and notice to the regulator within 72 hours of discovery. In most cases you must also tell the people affected.

In force since 17 March 2022

Enforced by Personal Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Who you would hear from

  • هيئة حماية البيانات الشخصية

    General personal data protection law

    Exists in law under article 27, but was never set up as a separate body. Royal Decree No. 78 of 2019 gives its powers to the Minister of Justice, Islamic Affairs and Waqf. The ministry's undersecretary acts as chief executive. That lasts until a budget line and a board decree arrive, and it was still the position on 18 August 2026. It issues orders and runs live notification, authorisation, breach and complaint forms. We found no published fines or decisions.

  • Holds the data protection authority's powers; issues the executive orders

  • مصرف البحرين المركزي

    Banking, insurance, investment business, capital markets, payments, crypto-assets

    Highly active: runs a continuous public consultation programme, with payment services, buy-now-pay-later and payment service provider rules consulted on between October 2025 and February 2026.

  • Government technology policy, government cloud, open data, national digital policies

  • National cyber security, critical national infrastructure controls including the financial sector

    Publishing: National Cyber Security Strategy 2025-2028, sector control documents and small-business guidance.

  • Telecommunications licensing and regulation

    Long-established regulator under Legislative Decree No. 48 of 2002.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The full and current contents of the approved-country list in Order No. 42 of 2022

    We could not fully confirm the current contents of the approved-country list. We read the regulator's own English PDF, but through automated text extraction. The order can be amended at any time by ministerial order. Countries that look absent, for example Qatar, Turkey and Indonesia, should be re-checked against the PDF before you rely on their absence.

  • Whether any enforcement decision, fine or prosecution has ever been published under Law No. 30 of 2018

    We could not confirm whether any fine or prosecution has ever been published under this law. The Authority's site has no decisions register, no case list and no annual report. Finding nothing is not proof that nothing happened. That is why enforcement is rated waking rather than dormant or active.

  • Sector rules for health, telecommunications, education, geospatial or defence data

    We could not check the industry rules for health, telecommunications, education, geospatial or defence data. The Legislation and Legal Opinion Commission portal, which hosts the official text of every Bahraini law, was blocked from our network. We found no rule forcing data to stay in the country and no separate transfer rule, checked 18 August 2026. This is the weakest part of the record, so check before you rely on it.

  • Legislative Decree No. 56 of 2018 on providing cloud computing services to foreign parties

    We could not confirm what this decree says. Bahrain is understood to have a law letting foreign customers store data in Bahrain under their own home law. That would be an unusual feature, working in the opposite direction to most such rules. We could not open the official text on the government legislation portal, so we have deliberately not recorded it as a rule.

  • The binding status of the Financial Cybersecurity Controls

    We could not confirm whether these controls are binding. The copy published on the central bank's website is headed 'Draft v 0.1, October 2022', although it was sent to licence holders by circular in November 2022. The covering circular is a scanned image with no readable text. So we cite the five-year log keeping control with medium confidence.

  • Minimum record-keeping periods under Bahraini tax and company law

    We could not confirm the minimum record-keeping periods under Bahraini tax and company law. The National Bureau for Revenue site refused our requests, and the legislation portal was blocked. So we do not state the value added tax or commercial companies periods. Check them before you delete anything.

  • Whether the cyber incident reporting deadline for financial entities differs from the 72-hour privacy deadline

    We could not confirm whether financial firms have a different cyber incident deadline from the 72-hour privacy deadline. The central bank and cyber centre documents we could read describe incident response and classification duties, but give no readable hour figure.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.