Bahrain
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Bahrain — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Bahrain bans sending personal data abroad unless you fit an exception. The main exception is an official list of more than eighty approved countries. It includes the United States, China, Russia and every Gulf neighbour. Nothing has to be stored inside Bahrain. The paperwork is heavy. You usually tell the regulator before you start, and breaking the rules is a crime.
Data governance in Bahrain
The eight things that decide how you handle data about people in Bahrain. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law catches a company anywhere in the world if it handles people's data using equipment sitting inside Bahrain. That is true even with no office and no staff there. There is no size, revenue or staff-count threshold to fall below. A foreign company in that position must appoint a representative in Bahrain who takes on its duties. It must also tell the regulator who that is.
- What you have to do here:
- Appoint a representative
Article 2 applies the law to three groups. First, a company that decides how data is used and has a place of business in Bahrain. Second, a person who normally lives in Bahrain. Third, 'every natural or legal person not habitually resident nor maintains a place of business in the Kingdom, but processes data by using means situated in the Kingdom'. That third group is excluded where those means are used only to pass data through Bahrain. Article 2(3) requires you to appoint an authorised representative and tell the Authority about the appointment immediately. The law reaches you through the equipment you use, not through who you sell to. That makes it narrower than the European or Indian tests. But it is wider than it looks for anyone using Bahraini infrastructure.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceLink may be brokenLegislation and Legal Opinion CommissionOfficial Gazette copy of Law No. (30) of 2018 (linked from the regulator's own site)
legalaffairs.gov.bh
Link checked 18 August 2026
Where the data is allowed to live
Yes, but only through a few defined routes. The starting position is that moving personal data out of Bahrain is forbidden. It becomes legal if the destination is on the government's approved-country list. That list names more than eighty places, including the United States, China, Russia, India and all of Bahrain's Gulf neighbours. If your destination is not on the list, you ask the regulator for permission for that specific transfer. Or you rely on one of six narrow exceptions, such as the person's consent.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed
INDUSTRY BY INDUSTRY, checked 18 August 2026. Banking, insurance, securities and payments, all supervised by the Central Bank of Bahrain: no rule requires data to stay in Bahrain. But a licence holder needs the central bank's prior approval to hand any work to a supplier outside Bahrain. For cloud arrangements, inside or outside Bahrain, it must tell the central bank afterwards. The cloud rules make you pick the hosting country on a risk basis. You may not host where the regulator's access to information could be blocked, or in countries under United Nations sanctions. Government: the state's own Cloud First Policy openly rejects any rule that data must stay in the country for government systems. That is subject to classification and state-secrets rules. Health, telecommunications, education, geospatial and mapping, and defence: we found no rule forcing data to stay in the country, and no separate transfer rule, on the regulators' own sites. Checked 18 August 2026, medium confidence. See the unconfirmed list. Gambling: commercial gambling is not licensed in Bahrain, so there are no gaming data rules to check. The single most important point is that the general law does the work here. Bahrain restricts transfers at national level and then leaves industries alone. That is the reverse of the pattern in India or Saudi Arabia.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCBB Rulebook Volume 1, Module OM, Chapter OM-2A: Cloud Outsourcing Arrangements, rule OM-2A.2.1
cbb.gov.bh
“Adopt a risk-based approach to data storage and data processing locations (country or region) ensuring that the data is not stored in jurisdictions where prompt access to information by licensee or CBB representatives may be impeded by legal or administrative restrictions, or jurisdictions that are subject to United Nations sanctions.”
Link checked 18 August 2026
- Official sourceInformation and eGovernment AuthorityCloud First Policy, version 1.0, 24 April 2017 - Data Sovereignty section
iga.gov.bh
“The benefits of cloud are best realized when there are no data residency restrictions placed on data. Such restrictions undermine the economies of scale and security benefits to be gained from shared computing infrastructure.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Bahrain.
Sending data out of the country
This is an approved-list system: banned unless allowed. The list is real and full, not empty. It was published in March 2022 with more than eighty countries and territories on it. Send data to a listed place and you need no paperwork and no permission. Send it anywhere else and you need written permission from the regulator for that transfer. Or you use one of six exceptions. The person agreed. The data came from a public register. The transfer is needed for a contract, to protect someone's life, to obey a law or court order, or to bring or defend a legal claim.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Legal claims · To save someone’s life
Article 12 bans sending data outside Bahrain. There are two ways round it. The country is on the Authority's list of places offering adequate legislative and regulatory protection. Or you get a one-off authorisation, which may come with conditions or a time limit. Order No. 42 of 2022 is the list. Article 13 sets out the exceptions. There is no standard contract clause system, no group-wide rules and no certification route. Bahrain never built one. Watch out: 'adequate' in Bahrain does not mean what it means in Europe. The same order lists the United States, China and Russia. So a transfer that is lawful under Bahraini law can still break European rules, and the other way round.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
On paper, the Personal Data Protection Authority. But there is no separate authority. A royal decree in 2019 handed its powers to the Ministry of Justice. The minister acts as the board, and the ministry's undersecretary acts as chief executive, until money and a board decree arrive. That arrangement is still in place in August 2026. It does work. It publishes ten binding orders and runs live forms for registrations, permissions, breach reports and complaints. But we found no published fines or decisions. So treat enforcement as switched on and quiet, not aggressive. The central bank, by contrast, supervises finance actively and consults on new rules constantly.
Royal Decree No. 78 of 2019 came into force on 29 September 2019. It says the Minister of Justice, Islamic Affairs and Waqf takes on the duties and powers of the Authority's board of directors and chairman. The ministry's undersecretary takes the role of chief executive. This lasts until the state budget allocates money and a decree forms the board. The Authority's own website still shows that decree as the governing arrangement, and names no board members or chief executive. The criminal penalties in the law are enforced through the Public Prosecution and the courts, not through administrative fining powers. That is one reason the public record is thin. We could not find any published enforcement decision, fine or annual report. We record that as a gap, not as evidence that nothing has happened.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfRoyal Decree No. (78) of 2019 - the administrative entity assuming the duties and powers of the Personal Data Protection Authority
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfMinistry of Justice, Islamic Affairs and Waqf - portal linking to the Personal Data Protection Authority
moj.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
How long you must keep it — and when to delete it
The general law says when to delete, and specific industries say how long to keep. On deleting: once you have done what you collected the data for, you may not keep it in a form that still identifies the person. Anything held long term should be anonymous or encrypted. You must also set and follow your own written keeping and deletion schedule. The clearest minimum we could verify is in finance. Security event logs must be kept for at least five years.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs
Article 3(5) of the law is the deletion rule. Order No. 43 of 2022 makes you set your own data keeping and disposal periods, as part of your technical and organisational measures. The five-year minimum sits in the Financial Cybersecurity Controls, issued by the National Cyber Security Centre for financial firms. Control 6.1.8 requires a security information and event management system with a log keeping period of five years or longer. Control 6.1.10 makes log keeping follow the cyber centre's requirements. The draft payment service provider module the central bank put out for comment in February 2026 also uses a five-year record minimum. Tax and company-law minimums almost certainly exist. Bahrain runs value added tax and has a commercial companies law. But the government legislation portal was unreachable from our network, so we do not state them here. Where a minimum keeping period and the delete-when-done rule clash, the specific keeping duty wins. We could not find an official Bahraini statement of that, so it is our reasoning, not a quoted rule.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre / Central Bank of BahrainFinancial Cybersecurity Controls (National Cyber Security Centre, October 2022), controls 6.1.8 and 6.1.10
cbb.gov.bh
“The financial entity must implement a Security Information and Event Management “SIEM” system with a log retention period 5 years or longer.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainConsultation draft, CBB Rulebook Volume 5, Payment Service Provider Module, 5 February 2026
cbb.gov.bh
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
You have 72 hours. From the moment you discover a personal data breach, you must tell the regulator, using its online breach form. You must also tell the people affected. There are two exceptions. The data was unreadable to outsiders, for example properly encrypted. Or the risk has since been removed. You must keep your own written record of every breach, its causes, its effects and what you did about it. Financial firms have a second, separate reporting line to their supervisor and to the national cyber centre.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 72-hour deadline is not in the statute. The law itself says nothing about breach reporting. The deadline comes from article 4 of Order No. 43 of 2022 on technical and organisational measures. That order also sets out what the notice must contain, both for the regulator and for the individual. It lets you replace individual notices with a public announcement where individual notice would take disproportionate effort. Financial firms also sit under the Financial Cybersecurity Controls. Those require an incident response plan, incident classification and reporting arrangements. The copy published by the central bank is a scanned document. We could not extract its specific reporting deadline, so we do not state one. The trap is the overlap. One incident, two regulators, and the shorter deadline is the one that governs.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre / Central Bank of BahrainFinancial Cybersecurity Controls (National Cyber Security Centre, October 2022), controls 6.1.8 and 6.1.10
cbb.gov.bh
“The financial entity must implement a Security Information and Event Management “SIEM” system with a log retention period 5 years or longer.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, breaking these rules is a crime. You face up to one year in prison and a fine of 1,000 to 20,000 Bahraini dinars, roughly 2,600 to 53,000 US dollars. That includes sending data abroad unlawfully. Second, you normally have to tell the regulator before you start using data automatically at all. You need written permission first for sensitive data, biometrics, genetic data, security cameras and linking databases. Third, if the regulator says nothing within thirty days, that counts as a refusal, not approval. Fourth, a foreign company using equipment in Bahrain must appoint a local representative. Fifth, banks and insurers need central bank sign-off thirty days before signing an offshore supplier.
- What you have to do here:
- Register or notify · Assess high-risk projects · Appoint a representative
- What it costs if you get it wrong:
- Criminal liability
Penalties sit in article 58. They are imprisonment up to one year and/or a fine of not less than 1,000 and not more than 20,000 Bahraini dinars. They apply to a list of breaches. That list expressly includes sending data outside Bahrain contrary to articles 12 and 13, using data without the required notification or prior authorisation, and unlawful disclosure. Prior notification is article 14. Its exemptions are narrow. One of them is where a data protection guardian has been appointed and registered. Appointing one is the standard way to escape the repeated notification duty. Prior authorisation is article 15. It covers sensitive personal data, biometric data used to identify people, genetic data, linking data sets held by different companies, and visual surveillance recording. Order No. 44 of 2022 confirms the thirty-day decision window, and that silence counts as a refusal. It also requires a data protection impact assessment for biometrics and surveillance. Sensitive data in Bahrain expressly includes race, political or philosophical opinions, religious belief, union membership, criminal record and health data.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (44) of 2022 on submitting notifications and prior authorisation requests, 17 March 2022
pdp.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
What's changing next
Nothing new is scheduled to hit the general privacy law in the next twelve months, as far as we can see. The action is in finance. The central bank is rewriting its payments rules. A new payment service provider module went out for comment in February 2026, and a buy-now-pay-later module came out in November 2025. The bigger risks are two powers the government can use without warning. The approved-country list can be changed by a ministerial order. And a single decree could finally stand up a real data protection authority with its own board.
POWERS THE GOVERNMENT CAN USE WITHOUT WARNING. One: the list of adequate countries is an executive order of the Minister of Justice. A country can be added or removed overnight with no consultation. A company routing data to a country that comes off the list would face criminal liability, not just an order to stop. Two: Royal Decree No. 78 of 2019 is expressly temporary. It depends on a budget allocation and a decree forming the board. Once that decree issues, Bahrain goes from a ministry side-desk to a standing regulator. The ten orders already on the books become enforceable by a body with staff. Three: the National Cyber Security Centre is running a national strategy for 2025 to 2028 and issues control documents for critical industries. That is the most likely source of new hard duties. We found no bill amending Law No. 30 of 2018. But the government legislation portal was unreachable from our network, so a pending bill could exist that we did not see.
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfRoyal Decree No. (78) of 2019 - the administrative entity assuming the duties and powers of the Personal Data Protection Authority
pdp.gov.bh
Link checked 18 August 2026
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainConsultation draft, CBB Rulebook Volume 5, Payment Service Provider Module, 5 February 2026
cbb.gov.bh
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre - National Cyber Security Strategy 2025-2028 and guidance
ncsc.gov.bh
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: CBB Rulebook - Outsourcing Requirements (chapter on outsourcing arrangements) · Central Bank of Bahrain, Outsourcing Requirements 2022, rules 1.1.6 and 1.1.7 · Government rules
Banks, insurers, investment firms and payment companies must get the central bank's written approval before handing any work to a supplier outside Bahrain. They must apply at least thirty days ahead. Cloud services do not need that approval. But you must tell the central bank about them afterwards, whether the provider is inside or outside Bahrain.
Enforced by Central Bank of Bahrain
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractA service level agreement is mandatory and must give the central bank, external auditors and the licensee's own audit and compliance staff unrestricted access to the supplier's records.
- Independent audit
- Register or notifyPrior approval application at least 30 calendar days before committing to an offshore third-party arrangement; the central bank answers within 15 calendar days. Cloud arrangements and intragroup arrangements are notified after the fact instead.
Sources
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain - open and past consultations register
cbb.gov.bh
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: CBB Rulebook Volume 1, Module OM (Operational Risk Management), Chapter OM-2A: Cloud Outsourcing Arrangements · OM-2A.1 and OM-2A.2, CBB Rulebook Volume 1 · Government rules
Bahrain's banks may put customer data in the public cloud abroad. But they must choose the country on a risk basis. They must avoid anywhere that could block the regulator's access to information, and anywhere under United Nations sanctions. They must encrypt the data and hold their own encryption keys. If a foreign government tries to force the cloud provider to hand data over, the bank should tell the customer.
Enforced by Central Bank of Bahrain
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Secure the dataEncryption in transit, in memory, at rest and in backups, with key management kept away from the cloud provider; tenant isolation; recognised international security standards.
- Do not hand data to foreign authorities on demandThe bank should tell the customer promptly if authorities in the country where the data sits are trying to compel the cloud provider to hand it over.
- Prove the data stays under local controlHosting country chosen on a risk basis; must not be a place where regulator access could be blocked, nor a country under United Nations sanctions.
- Independent audit
Sources
- Official sourceCentral Bank of BahrainCBB Rulebook Volume 1, Module OM, Chapter OM-2A: Cloud Outsourcing Arrangements, rule OM-2A.2.1
cbb.gov.bh
“Adopt a risk-based approach to data storage and data processing locations (country or region) ensuring that the data is not stored in jurisdictions where prompt access to information by licensee or CBB representatives may be impeded by legal or administrative restrictions, or jurisdictions that are subject to United Nations sanctions.”
Link checked 18 August 2026
- Official sourceCentral Bank of BahrainCentral Bank of Bahrain, Outsourcing Requirements (2022), rule 1.1.6
cbb.gov.bh
“Prior CBB approval is required on any outsourcing to a third-party outside Bahrain (excluding cloud data services).”
Link checked 18 August 2026
Cloud and outsourcing rules (Government)
Official name: Cloud First Policy · Cloud First Policy, version 1.0, 24 April 2017, approved by the Supreme Committee for Information and Communication Technology · Government policy document
Bahrain's government tells its own agencies to buy cloud first. It says plainly that forcing data to stay in the country is counterproductive. Government systems may therefore sit outside the country, subject to data classification rules and the state secrets rules. This is the opposite of the government-cloud rules common elsewhere in the region.
Enforced by Information and eGovernment Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataSecurity controls must match the government data classification level; agencies coordinate with the national information security body.
- Hold a security certificate
Sources
- Official sourceInformation and eGovernment AuthorityCloud First Policy, version 1.0, 24 April 2017 - Data Sovereignty section
iga.gov.bh
“The benefits of cloud are best realized when there are no data residency restrictions placed on data. Such restrictions undermine the economies of scale and security benefits to be gained from shared computing infrastructure.”
Link checked 18 August 2026
- Official sourceInformation and eGovernment AuthorityInformation and eGovernment Authority - national digital policies library
iga.gov.bh
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: قانون رقم (30) لسنة 2018 بشأن حماية البيانات الشخصية (Law No. 30 of 2018 with respect to Personal Data Protection) · Law No. (30) of 2018, published in the Official Gazette on 12 July 2018 · Act of parliament
Bahrain's general privacy law. It bans sending personal data out of the country. There are three ways round that: the destination is on an official approved list, the regulator authorises the specific transfer, or a narrow exception applies. You must also tell the regulator before you use data automatically, in most cases. You need written permission before handling sensitive data. Breaches are criminal offences.
Enforced by Personal Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Get consent
- Tell people what you do
- Register or notifyYou must tell the regulator before you use data automatically, under article 14. That does not apply if an exemption covers you, or if you have appointed and registered a data protection guardian.
- Appoint a representativeRequired where the company has no place of business in Bahrain, and does not normally live there, but uses equipment located there.
- Appoint a data protection officerOptional 'data protection guardian'; appointing and registering one removes the prior-notification duty.
- Let people see their data
- Let people correct their data
- Let people object
- Put a transfer safeguard in place
- Delete data after a period
- Assess high-risk projects — applies at: Biometric processing and visual surveillance recording
What it costs if you get it wrong
- Criminal liability: 1 year imprisonmentUnlawful transfer abroad, processing without required notification or prior authorisation, unlawful disclosure (article 58)
- Fixed maximum fine: BHD 20,000 — about $53 thousandSame offences; minimum fine BHD 1,000, about 2,600 US dollars
Sources
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
- Official sourceLink may be brokenLegislation and Legal Opinion CommissionOfficial Gazette copy of Law No. (30) of 2018 (linked from the regulator's own site)
legalaffairs.gov.bh
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - index of the ten executive orders issued under the law
pdp.gov.bh
Link checked 18 August 2026
Paperwork before personal data leaves
Official name: قرار رقم (42) لسنة 2022 (Order No. 42 of 2022 on countries and territories with adequate protection) · Order No. (42) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022 · Government rules
The approved-country list. More than eighty countries and territories are named, including the United States, China, Russia, India, the United Kingdom, every European Union state and all of Bahrain's Gulf neighbours. Data may go to any of them with no permission and no contract. The list is a ministerial order, so it can be changed at any time without consultation.
Enforced by Personal Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeNo paperwork needed for a listed destination; anything else needs case-by-case authorisation or an article 13 exception.
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (42) of 2022 on countries and territories with adequate protection, 17 March 2022
pdp.gov.bh
“The Data Controller may transfer personal data directly to countries and territories stipulated in the record attached to this Order without the need to obtain prior authorization from the Authority.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Authority / Ministry of Justice, Islamic Affairs and WaqfLaw No. (30) of 2018 with respect to Personal Data Protection - official English text
pdp.gov.bh
Link checked 18 August 2026
Breach reporting rules (2022)
Official name: قرار رقم (43) لسنة 2022 (Order No. 43 of 2022 on technical and organisational measures) · Order No. (43) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022 · Government rules
The security rulebook. It is the only place the 72-hour breach deadline actually appears. The statute itself says nothing about breach reporting. It requires privacy by design, encryption, penetration testing, a written breach log, and notice to the regulator within 72 hours of discovery. In most cases you must also tell the people affected.
Enforced by Personal Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Secure the dataPrivacy by design and by default, access control, anti-virus and firewalls, encryption, periodic vulnerability assessment and penetration testing, staff training.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleNot required where the breached data is unreadable to unauthorised people, for example encrypted. It is also not required where later measures remove the high risk. Where individual notice would take disproportionate effort, you make a public announcement instead.
- Keep records of how you use dataWritten record of every breach: causes, effects, remedial action.
- Delete data after a periodYou must set and apply your own keeping and disposal periods.
- Written vendor contract
Sources
- Official sourceMinistry of Justice, Islamic Affairs and WaqfOrder No. (43) of 2022 on technical and organisational measures, 17 March 2022, article 4
pdp.gov.bh
“The Controller shall establish specific procedures to inform the Authority of the occurrence of any violation or breach of data within a period not exceeding (72) hours from the date of its discovery.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection AuthorityPersonal Data Protection Authority - live forms (notification, prior authorisation, data breach report, complaint, data guardian registration)
pdp.gov.bh
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The full and current contents of the approved-country list in Order No. 42 of 2022
We could not fully confirm the current contents of the approved-country list. We read the regulator's own English PDF, but through automated text extraction. The order can be amended at any time by ministerial order. Countries that look absent, for example Qatar, Turkey and Indonesia, should be re-checked against the PDF before you rely on their absence.
Whether any enforcement decision, fine or prosecution has ever been published under Law No. 30 of 2018
We could not confirm whether any fine or prosecution has ever been published under this law. The Authority's site has no decisions register, no case list and no annual report. Finding nothing is not proof that nothing happened. That is why enforcement is rated waking rather than dormant or active.
Sector rules for health, telecommunications, education, geospatial or defence data
We could not check the industry rules for health, telecommunications, education, geospatial or defence data. The Legislation and Legal Opinion Commission portal, which hosts the official text of every Bahraini law, was blocked from our network. We found no rule forcing data to stay in the country and no separate transfer rule, checked 18 August 2026. This is the weakest part of the record, so check before you rely on it.
Legislative Decree No. 56 of 2018 on providing cloud computing services to foreign parties
We could not confirm what this decree says. Bahrain is understood to have a law letting foreign customers store data in Bahrain under their own home law. That would be an unusual feature, working in the opposite direction to most such rules. We could not open the official text on the government legislation portal, so we have deliberately not recorded it as a rule.
The binding status of the Financial Cybersecurity Controls
We could not confirm whether these controls are binding. The copy published on the central bank's website is headed 'Draft v 0.1, October 2022', although it was sent to licence holders by circular in November 2022. The covering circular is a scanned image with no readable text. So we cite the five-year log keeping control with medium confidence.
Minimum record-keeping periods under Bahraini tax and company law
We could not confirm the minimum record-keeping periods under Bahraini tax and company law. The National Bureau for Revenue site refused our requests, and the legislation portal was blocked. So we do not state the value added tax or commercial companies periods. Check them before you delete anything.
Whether the cyber incident reporting deadline for financial entities differs from the 72-hour privacy deadline
We could not confirm whether financial firms have a different cyber incident deadline from the 72-hour privacy deadline. The central bank and cyber centre documents we could read describe incident response and classification duties, but give no readable hour figure.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.