Skip to the content
Global Data RulesData governance rules, country by country

Bahrain

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Bahrain bans sending personal data abroad unless you fit an exception. The main exception is an official list of more than eighty approved countries, which includes the United States, China, Russia and every Gulf neighbour. Nothing has to be stored inside Bahrain. The paperwork is heavy: you usually tell the regulator before you start, and breaking the rules is a crime.

Data governance in Bahrain

The eight things that decide how you handle data about people in Bahrain. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law catches a company anywhere in the world if it handles people's data using equipment sitting inside Bahrain, even with no office and no staff there. There is no size, revenue or headcount threshold to fall below. A foreign company in that position must appoint a representative in Bahrain who takes on its duties, and must tell the regulator who that is.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

Yes, but only through a defined gate. The starting position is that moving personal data out of Bahrain is forbidden. It becomes legal if the destination is on the government's approved-country list, which names more than eighty places including the United States, China, Russia, India and all of Bahrain's Gulf neighbours. If your destination is not on that list, you ask the regulator for permission for that specific transfer, or you rely on one of six narrow exceptions such as the person's consent.

High confidenceYes, with paperworkAllowlistOfficial 'this country is safe' decisionGovernment sign-off needed

Sending data out of the country

This is an approved-list system: banned unless allowed. The list is real and full, not empty, and it was published in March 2022 with more than eighty countries and territories on it. Send data to a listed place and you need no paperwork and no permission. Send it anywhere else and you need written permission from the regulator for that transfer, or one of six exceptions: the person agreed, the data came from a public register, the transfer is needed for a contract, to protect someone's life, to obey a law or court order, or to bring or defend a legal claim.

High confidenceAllowlistOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentNeeded for a contractLegal claimsSomeone's life is at risk

The regulator, and whether it actually acts

On paper the Personal Data Protection Authority. In practice there is no separate authority: a royal decree in 2019 handed its powers to the Ministry of Justice, with the minister acting as the board and the ministry's undersecretary as chief executive, until money and a board decree arrive. That arrangement is still in place in August 2026. It does work - it publishes ten binding orders and runs live forms for registrations, permissions, breach reports and complaints - but we found no published fines or decisions, so treat enforcement as switched on and quiet rather than aggressive. The central bank, by contrast, supervises finance actively and consults on new rules constantly.

Medium confidenceWaking up

How long you must keep it — and when to delete it

There is a ceiling in the general law and floors in specific industries. The ceiling: once you have done what you collected the data for, you may not keep it in a form that still identifies the person, and anything held long term should be anonymous or encrypted. You must also set and follow your own written retention and deletion schedule. The clearest floor we could verify is in finance, where security event logs must be kept for at least five years.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logs

If something goes wrong

You have 72 hours. From the moment you discover a personal data breach, you must tell the regulator, using its online breach form, and you must also tell the people affected unless the data was unreadable to outsiders, for example properly encrypted, or the risk has since been removed. You must keep your own written record of every breach, its causes, its effects and what you did about it. Financial firms have a second, separate reporting line to their supervisor and to the national cyber centre.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things catch people out. First, breaking these rules is a crime: up to one year in prison and a fine of 1,000 to 20,000 Bahraini dinars, roughly 2,600 to 53,000 US dollars, including for sending data abroad unlawfully. Second, you normally have to tell the regulator before you start automated processing at all, and get written permission first for sensitive data, biometrics, genetic data, security cameras and linking databases. Third, if the regulator says nothing within thirty days, that counts as a refusal, not approval. Fourth, a foreign company using equipment in Bahrain must appoint a local representative. Fifth, banks and insurers need central bank sign-off thirty days before signing an offshore supplier.

High confidenceRegister or notifyAssess high-risk projectsAppoint a local representativeAppoint a data protection officerCriminal liability

What's changing next

Nothing new is scheduled to hit the general privacy law in the next twelve months as far as we can see. The action is in finance: the central bank is rewriting its payments rules, with a new payment service provider module out for comment in February 2026 and a buy-now-pay-later module from November 2025. The bigger risks are two switches the government can flip without warning: the approved-country list can be changed by a ministerial order, and a single decree could finally stand up a real data protection authority with its own board.

Medium confidenceIn force

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

CBB Rulebook - Outsourcing Requirements (chapter on outsourcing arrangements)

Government rules · Central Bank of Bahrain, Outsourcing Requirements 2022, rules 1.1.6 and 1.1.7

In forceYes, with paperwork

Banks, insurers, investment firms and payment companies must get the central bank's written approval before outsourcing anything to a third party outside Bahrain, applying at least thirty days ahead. Cloud services are carved out of the approval requirement but must be notified to the central bank afterwards, whether the provider is inside or outside Bahrain.

In force since 1 January 2022

Enforced by Central Bank of Bahrain

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

CBB Rulebook Volume 1, Module OM (Operational Risk Management), Chapter OM-2A: Cloud Outsourcing Arrangements

Government rules · OM-2A.1 and OM-2A.2, CBB Rulebook Volume 1

In forceYes, with paperwork

Bahrain's banks may put customer data in the public cloud abroad, but they must choose the country on a risk basis, avoid anywhere that could block the regulator's access to information or that is under United Nations sanctions, encrypt the data and hold their own encryption keys. If a foreign government tries to force the cloud provider to hand data over, the bank should tell the customer.

In force since 1 January 2022

Enforced by Central Bank of Bahrain

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Government

Cloud First Policy

Government policy document · Cloud First Policy, version 1.0, 24 April 2017, approved by the Supreme Committee for Information and Communication Technology

In forceYes — store it anywhere

Bahrain's government tells its own agencies to buy cloud first and says plainly that data residency restrictions are counterproductive. Government workloads may therefore sit outside the country, subject to data classification rules and the state secrets regime. This is the opposite of the government-cloud localisation rules common elsewhere in the region.

In force since 24 April 2017

Enforced by Information and eGovernment Authority

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

قانون رقم (30) لسنة 2018 بشأن حماية البيانات الشخصية (Law No. 30 of 2018 with respect to Personal Data Protection)

Act of parliament · Law No. (30) of 2018, published in the Official Gazette on 12 July 2018

In forceYes, with paperwork

Bahrain's general privacy law. It bans sending personal data out of the country unless the destination is on an official approved list, the regulator authorises the specific transfer, or a narrow exception applies. It also requires you to tell the regulator before most automated processing and to get written permission before handling sensitive data. Breaches are criminal offences.

In force since 1 August 2019

Enforced by Personal Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

قرار رقم (42) لسنة 2022 (Order No. 42 of 2022 on countries and territories with adequate protection)

Government rules · Order No. (42) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022

In forceYes, with paperwork

The approved-country list. More than eighty countries and territories are named, including the United States, China, Russia, India, the United Kingdom, every European Union state and all of Bahrain's Gulf neighbours. Data may go to any of them with no permission and no contract. The list is a ministerial order, so it can be changed at any time without consultation.

In force since 17 March 2022

Enforced by Personal Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

High confidence

قرار رقم (43) لسنة 2022 (Order No. 43 of 2022 on technical and organisational measures)

Government rules · Order No. (43) of 2022, Minister of Justice, Islamic Affairs and Waqf, 17 March 2022

In forceYes, with paperwork

The security rulebook, and the only place the 72-hour breach clock actually appears - the statute itself says nothing about breach reporting. It requires privacy by design, encryption, penetration testing, a written breach log, notice to the regulator within 72 hours of discovery and, in most cases, notice to the people affected.

In force since 17 March 2022

Enforced by Personal Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

High confidence

Who you would hear from

  • هيئة حماية البيانات الشخصية

    General personal data protection law

    Exists in law under article 27 but was never stood up as a separate body. Royal Decree No. 78 of 2019 gives its powers to the Minister of Justice, Islamic Affairs and Waqf, with the ministry's undersecretary as chief executive, pending a budget line and a board decree - still the position on 18 August 2026. It issues orders and runs live notification, authorisation, breach and complaint forms, but we found no published fines or decisions.

  • Holds the data protection authority's powers; issues the executive orders

  • مصرف البحرين المركزي

    Banking, insurance, investment business, capital markets, payments, crypto-assets

    Highly active: runs a continuous public consultation programme, with payment services, buy-now-pay-later and payment service provider rules consulted on between October 2025 and February 2026.

  • Government technology policy, government cloud, open data, national digital policies

  • National cyber security, critical national infrastructure controls including the financial sector

    Publishing: National Cyber Security Strategy 2025-2028, sector control documents and small-business guidance.

  • Telecommunications licensing and regulation

    Long-established regulator under Legislative Decree No. 48 of 2002. Its regulations database loads only with JavaScript, so we could not enumerate its instruments from the site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The full and current contents of the approved-country list in Order No. 42 of 2022

    We read the regulator's own English PDF, but through an automated text extraction, and the order is amendable at any time by ministerial order. Countries that appear absent - for example Qatar, Turkey and Indonesia - should be re-checked against the PDF before anyone relies on their absence.

  • Whether any enforcement decision, fine or prosecution has ever been published under Law No. 30 of 2018

    No decisions register, case list or annual report is published on the Authority's site. Absence of evidence is not evidence of absence; this is why enforcement is rated waking rather than dormant or active.

  • Sector rules for health, telecommunications, education, geospatial or defence data

    The Legislation and Legal Opinion Commission portal, which hosts the official text of every Bahraini law, was blocked from our network, and the telecommunications regulator's and health regulator's document databases render only with JavaScript. We found no localisation or sector transfer rule, checked 18 August 2026, but this is the weakest part of the record.

  • Legislative Decree No. 56 of 2018 on providing cloud computing services to foreign parties

    Bahrain is understood to have a law letting foreign customers store data in Bahrain under their own home law, which would be a notable reverse-localisation feature. We could not open the official text on the government legislation portal, so it is deliberately not recorded as a rule.

  • The binding status of the Financial Cybersecurity Controls

    The copy published on the central bank's website is headed 'Draft v 0.1, October 2022' although it was circulated to licensees by circular in November 2022. The covering circular is a scanned image with no extractable text, so we cite the five-year log retention control with medium confidence.

  • Minimum record-keeping periods under Bahraini tax and company law

    The National Bureau for Revenue site refused our requests and the legislation portal was blocked, so we do not state the value added tax or commercial companies retention floors.

  • Whether the cyber incident reporting deadline for financial entities differs from the 72-hour privacy deadline

    The relevant central bank and cyber centre documents we could read describe incident response and classification duties but no extractable hour figure.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Bahrain versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.