Qatar
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Qatar's national privacy law is one of the most open in the world about sending data abroad. It does not just permit cross-border flows, it forbids a company from blocking them. Money is the exception. Anything the central bank licences must keep customer data inside Qatar and needs written permission to move it out. The financial free zone runs a separate regime.
Data governance in Qatar
The eight things that decide how you handle data about people in Qatar. Same eight on every country page, so you can compare.
Who has to follow these rules
The law is silent about foreign companies. It says which activities it covers, but it never says whether it reaches a business with no office in Qatar. There is no size or revenue cut-off, no requirement to register, and no requirement to appoint anyone inside the country. If you handle certain sensitive categories, though, you are supposed to get a permit from the regulator before you start.
Law No. 13 of 2016 on the Protection of Personal Data Privacy defines its reach by the type of processing, not by where the company sits. Article 2 applies the law to personal data processed electronically, or obtained or collected in any other way in preparation for electronic processing, or processed by a mix of electronic and traditional means. It excludes data processed by individuals for personal or family purposes, and data processed to produce official statistics under Law No. 2 of 2011. There is no territorial-scope article, no threshold, no registration duty and no in-country representative duty anywhere in the 32 articles. Article 16 is the practical catch: data on ethnic origin, children, health or physical or mental condition, religious belief, marital relationship and criminal offences may not be processed at all without a permit from the competent department, under procedures to be set by a decision of the Minister. Because the statute has no extraterritoriality clause, whether it binds an offshore controller is a question of general Qatari law rather than a question the statute answers, and we could not find an official interpretation either way. Inside the Qatar Financial Centre a different rule applies: Article 2 of the QFC Data Protection Regulations 2021 disapplies State of Qatar law on these matters within the Centre.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
Where the data is allowed to live
It depends completely on your industry. Under the general law data can leave freely, and the law goes further than that: a company is actually banned from taking any step that would restrict data flowing across the border. But if the central bank licences you, personal and financial data must be processed inside Qatar only, and you may not store or send it abroad without the bank's written approval. Companies inside the Qatar Financial Centre follow a third, European-style set of rules.
Headline rating: sectoral. Overrides, each with its own rating: - All industries, general law — open. Article 15 of Law No. 13 of 2016 prohibits a controller from taking any decision or measure that would restrict the cross-border flow of personal data, unless the processing breaches the law or would cause serious harm to the data or to the individual's privacy. There is no approved-country list, no filing, and no contract requirement. Breaching Article 15 is punishable by a fine of up to one million Qatari riyals, so the duty runs in the opposite direction from most countries. - Banking, insurance, payments, securities and every other central-bank licensee — closed in practice. Clause 15.1 of the Qatar Central Bank Data Handling and Protection Regulation says a financial institution must not store or transfer personal data, personally identifiable information, sensitive personal information or sensitive financial information to a foreign jurisdiction unless it has received approval from the central bank. Clause 21.4 of the central bank's Cloud Computing Regulation, in force since 15 April 2024, says an entity must ensure that personally identifiable information and financial information is processed within Qatar only, and clause 21.5 requires the bank's approval before entering any cloud arrangement at all. - Payments specifically — closed for encryption keys. Clause 6.8 of the Information and Cyber Security Regulation for Payment Service Providers requires the key management system and private keys to be generated and stored outside the cloud, on premises in Qatar. - Insurance and banking specifically — a person-and-place rule as well. Both the Insurance Sector Cyber Security Regulation and the Technology Risks Regulation for Banks require the round-the-clock security operations centre to be on site or in Qatar. - Qatar Financial Centre — conditional, and outside the national law. Article 23 of the QFC Data Protection Regulations 2021 allows transfers to a jurisdiction the Centre's Data Protection Office has decided is adequate. Article 24 allows transfers elsewhere on standard clauses, binding corporate rules, a permit, or one of a short list of narrow exceptions. - Telecoms — no localisation rule found, checked 18 August 2026. The Communications Regulatory Authority's Communications Consumer Protection Policy and Regulation of 2 October 2024 covers customer data privacy but points back to the Telecommunications By-Law rather than imposing a storage location. - Government and public sector — no published localisation rule found, checked 18 August 2026, confidence low. The Cloud Policy Framework directs government bodies to the National Information Assurance Policy for classifying government data, and we could not obtain that policy from an official source. - Health, education, gambling and mapping — no localisation rule found in the national gazette, checked 18 August 2026, confidence low. Gambling is unlawful in Qatar, so no gaming regime exists to check. The national cloud policy pushes the other way from the banking rules. The Cloud Policy Framework published by the Communications Regulatory Authority on 7 June 2022 recommends that data residency should no longer be a requirement and that localisation be reserved for highly sensitive data. It is a policy document, not a binding instrument.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Information and Cyber Security Regulation for Payment Service Providers — clause 6.8
qcb.gov.qa
“the generation and storage of the private keys outside of the cloud environment, on-premises in Qatar”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Insurance Sector Cyber Security Regulation — clause 8.4.5
qcb.gov.qa
“The Insurance Company shall establish and implement a centralized security event monitoring function such as a Security Operations Centre (SOC) functioning 24x7 onsite or in Qatar”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority, Cloud Policy Framework (7 June 2022) — section 4.3.1 policy recommendation
cra.gov.qa
“Data residency shall not be any longer a requirement as data classification schemes, security and encryption technologies now secure a high level of protection controls. Data localization may be required for highly sensitive data only.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Technology Risks Regulation for Banks (January 2018) — clause 8.4.5, security operations centre onsite or in Qatar
qcb.gov.qa
“The bank shall establish and implement a Security Operations Centre (SOC) functioning 24x7 onsite or in Qatar”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority, Communications Consumer Protection Policy and Regulation (2 October 2024) — section 4.5, protection of customer information
cra.gov.qa
“All customer information must be collected in a manner which complies with the provisions of article 92 of the Telecommunications By-Law.”
Link checked 18 August 2026
Sending data out of the country
Under the general law, nothing. There is no destination list, no template contract and no filing, and the law bans you from restricting flows in the first place. If the central bank licences you, the model flips to case-by-case: you need its written approval before data leaves, and before you sign any cloud contract. Inside the Qatar Financial Centre it is an approved-destinations list, and we could not confirm that the list has anything on it yet.
Three different models sit side by side. General law: unrestricted. Article 15 of Law No. 13 of 2016 does not merely permit cross-border flow, it forbids a controller from restricting it except where the processing breaches the law or would seriously harm the data or the individual's privacy. There is no blocklist and no allowlist to be populated, so there is nothing that can quietly fill up. Note that the exception is drafted as a duty on the controller, not as a power for the regulator to name countries. Central bank licensees: case-by-case government authorisation. Clause 15.1 of the Data Handling and Protection Regulation requires the bank's approval before storing or transferring personal data, personally identifiable information, sensitive personal information or sensitive financial information to a foreign jurisdiction. Clauses 15.2 to 15.4 add a due-diligence and adequacy assessment on the destination. Clause 21.5 of the Cloud Computing Regulation requires approval before entering a cloud arrangement, and clause 23 lets an entity apply for an exemption from any requirement, which the bank must approve and which must carry an expiry date. Neither regulation publishes a list of approved destinations or a public register of approvals. Qatar Financial Centre: allowlist plus safeguards. Article 23 lets the Data Protection Office decide that a jurisdiction is adequate, and requires it to publish those decisions. Article 24 covers everything else: standard data protection clauses adopted by the Data Protection Office, a legally binding arrangement between public bodies, binding corporate rules approved by the Office, another approved international mechanism, a permit from the Office, or one of seven narrow exceptions including explicit informed consent, contract necessity, legal obligation, vital interests, public interest and legal claims. There is also a residual route for one-off, small-volume, non-sensitive transfers backed by a documented assessment. We could not verify from an official source whether the Office has actually published an adequacy list.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 24 — Transfers Out of the QFC in the Absence of an Adequate Level of Protection
qfcra-en.thomsonreuters.com
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
The regulator, and whether it actually acts
The National Cyber Security Agency has run the privacy law since 2021. It is real, funded and reports to the Prime Minister, and it signs cybersecurity agreements that are ratified by decree. But we could not find a single published privacy penalty from it, and the only officials ever named to investigate offences under this law sit at a ministry that no longer does the job. The central bank is the regulator that actually bites, because it supervises and inspects the firms it licenses.
The privacy law was written for the Ministry of Transport and Communications: the Ministry is the 'Ministry' and its administrative unit is the 'competent department'. Emiri Decision No. 1 of 2021, published on 24 March 2021, created the National Cyber Security Agency as a body with its own legal personality and budget reporting to the Prime Minister, and Article 3(21) gives it the job of implementing the laws, regulations and decisions relating to the protection of personal data privacy. Is it operational? Partly. The agency plainly exists and functions in its cybersecurity role: Decrees No. 11 and No. 38 of 2024 ratify cooperation memoranda it signed with foreign cybersecurity agencies. What we could not find is any published data protection decision, fine or guidance document from an official Qatari source. The agency's own website is a single-page application whose content is served from a host we could not reach, and the national services portal was returning a maintenance page when checked on 18 August 2026. On observable evidence this is a waking regulator, not an active one. A structural point that is easy to miss: the penalties in Articles 23 to 25 of the privacy law are criminal fines, not administrative ones. Article 29 of the law lets the Attorney-General, in agreement with the Minister, give Ministry staff the status of judicial officers so they can detect and record offences under it. That was done once, by Attorney-General Decision No. 106 of 2017, and it named exactly six people, among them digital-evidence specialists and a network security specialist, all at the Ministry of Transport and Communications. That ministry no longer holds the data protection function, and no equivalent appointment at the National Cyber Security Agency could be found, so the criminal-enforcement machinery for this law appears to have no named officers behind it today. Article 26 gives the competent department a separate, softer route: it can investigate a complaint and order a controller or processor to fix the breach within a set time, with an appeal to the Minister within sixty days and no further appeal after the Minister decides. Other regulators. The Qatar Central Bank supervises every licensed financial institution and enforces its own data, cloud and cyber regulations through its supervision function; its regulations state that breaches must be reported to it, to the National Cyber Security Agency and to the Ministry of Interior. The Communications Regulatory Authority regulates telecoms and is visibly active, publishing decisions and consultations through 2026. Inside the Qatar Financial Centre the Data Protection Office has its own powers under Part 6 of the QFC Data Protection Regulations, including permits, orders and penalties.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Emiri Decision No. 1 of 2021 establishing the National Cyber Security Agency — Article 3(21)
almeezan.qa
“تنفيذ القوانين واللوائح والقرارات المتعلقة بحماية خصوصية البيانات الشخصية”
Link checked 18 August 2026
- Official sourceNational Cyber Security Agency, State of QatarNational Cyber Security Agency — official website
ncsa.gov.qa
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Attorney-General Decision No. 106 of 2017 naming six employees of the Ministry of Transport and Communications as judicial officers for offences under Law No. 13 of 2016
almeezan.qa
“يكون لموظفي وزارة المواصلات والاتصالات التالية أسماؤهم صفة مأموري الضبط القضائي، في ضبط واثبات الجرائم التي تقع بالمخالفة لأحكام القانون رقم (13) لسنة 2016”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority — Active Consultations, checked 18 August 2026
cra.gov.qa
Link checked 18 August 2026
How long you must keep it — and when to delete it
The general law only says do not keep data longer than you need it, with no fixed periods. The hard numbers live elsewhere. Internet and telephone providers must keep subscriber details for one year, and must freeze traffic or content data for ninety days when asked. State bodies must keep subscriber and system data for at least one hundred and twenty days. Financial firms must keep customer personal data for ten years.
The ceiling. Article 10 of Law No. 13 of 2016 requires a controller to check that personal data is relevant, adequate, accurate, complete and up to date for the legitimate purpose, and not to keep it longer than necessary to achieve that purpose. Article 5(3) lets a person demand deletion once the purpose has ended or where there is no justification for the controller to keep it. No maximum period is stated anywhere in the statute. The floor. Article 21 of the cybercrime law, Law No. 14 of 2014, requires a service provider to keep subscriber information for one year, and to preserve information-technology data, traffic data or content information for ninety days, renewable, when the competent authority or the investigating and prosecuting bodies ask. Article 22 requires state organs, institutions, bodies and their subsidiary entities and companies to keep information-technology data and subscriber information for at least one hundred and twenty days and to hand it over on request. For financial institutions, clause 11.3 of the Qatar Central Bank Data Handling and Protection Regulation sets minimum periods of ten years for sensitive financial information and for personal data, personally identifiable information and sensitive personal information, and one year for technical information, with everything else left to the institution. Clause 11.4 requires longer where another law demands it. Ordinary company and tax record-keeping periods under Qatari commercial and tax law are additional and were not verified in this pass. What happens when they conflict. Nothing in the privacy law resolves a clash between a person's deletion request and a retention duty. In practice the specific retention rule wins, because Article 19 of the privacy law exempts a controller from the consent and rights provisions where it is performing a legal obligation or a court order. We could not find an official ruling or guidance saying so in terms.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
If something goes wrong
Count three clocks. Under the general law you must tell both the person and the regulator, but the law sets no deadline at all, so 'immediately' is the safe reading. A supplier must tell its customer company as soon as it knows. If the central bank licenses you, you report to three bodies at once. Inside the financial free zone the deadline is seventy-two hours.
Clock one, the general law. Article 13 of Law No. 13 of 2016 requires the processor to notify the controller of any failure of the protective measures, or of any risk threatening individuals' personal data, as soon as it becomes aware. Article 14 requires the controller to inform both the individual and the competent department of any such failure where it would cause serious harm to the personal data or to the individual's privacy. No hour count appears in the statute, and no implementing decision setting one could be found. Breaching Article 14 attracts a fine of up to one million Qatari riyals, about two hundred and seventy-five thousand United States dollars; breaching the security duty in Article 13 attracts up to five million riyals, about one and a third million dollars. Clock two, financial services. Clauses 16.1 to 16.3 of the Qatar Central Bank Data Handling and Protection Regulation require a financial institution to classify any data breach or data privacy breach as an incident, to report it under the bank's incident reporting guidelines, and to report it to the central bank and to the authorised agencies in Qatar, which the regulation names as the National Cyber Security Agency and the Ministry of Interior. The incident reporting guidelines themselves are not published on the bank's public site, so the actual hour count is not publicly verifiable. Clock three, the Qatar Financial Centre. Article 31 of the QFC Data Protection Regulations requires notification of a personal data breach, and DATA 9 of the QFC Data Protection Rules requires the notification to explain the delay if it is not made within seventy-two hours of becoming aware. The notification must describe the categories and approximate numbers of individuals and records affected, the likely consequences, and the measures taken. A fourth clock applies to the public sector. Article 22 of the cybercrime law requires state bodies to report promptly to the competent authority any offence under that law as soon as it is discovered, including any attempted unlawful interception or eavesdropping, and to supply all information needed to establish the facts.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Rules, DATA 9 — Notification of Personal Data Breaches
qfcra-en.thomsonreuters.com
“if the notification is not made within 72 hours after becoming aware of the Personal Data Breach, give reasons for the delay”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
What catches people out
Five things bite people here. The fines are criminal, not administrative. Sensitive data needs a government permit before you touch it, and the rules for getting one were never published. There is no age that defines a child. Since August 2025 it is a crime to post a photo of someone in a public place without their knowledge. And a company inside the Qatar Financial Centre is outside the national law entirely.
1. The fines are criminal. Articles 23 to 25 of Law No. 13 of 2016 are drafted as penal provisions: a person is 'punished' with a fine of up to one million riyals for breaching the core duties, up to five million riyals for breaching the security duty, the sensitive-data permit duty or the children's website duty, and a company faces up to one million riyals where an offence is committed in its name and for its account without prejudice to the criminal liability of the individual responsible. That means prosecution, a criminal record and personal exposure for named individuals, not an administrative penalty notice. 2. Sensitive data needs a permit you cannot apply for. Article 16 forbids processing data on ethnic origin, children, health or physical or mental condition, religious belief, marital relationship or criminal offences without a permit from the competent department, under procedures to be fixed by a decision of the Minister. We found no such Minister's decision published in the official gazette. The prohibition is drafted as absolute and carries the five-million-riyal penalty, so the gap is a live commercial risk rather than a technicality. The Minister can also add new categories of sensitive data by decision at any time. 3. There is no defined age for a child. Article 17 imposes real duties on any website aimed at children: publish what children's data you collect and how you use it, obtain the express consent of the child's guardian by electronic or other suitable means, give the guardian a description and a copy of the data on request, delete or stop processing on the guardian's request, and never make participation in a game or a prize offer conditional on handing over more data than the activity needs. The definitions article does not define 'child'. Under general Qatari law the age of majority is eighteen, which is higher than the thirteen used by many global platforms. 4. Photographing people in public is now a crime. Law No. 11 of 2025, published on 4 August 2025, inserted Article 8 bis into the cybercrime law. Publishing or circulating photographs or video of people while they are in public places, without their knowledge or consent or outside the cases permitted by law, over the information network or by any information technology means, is punishable by up to one year in prison and a fine of up to one hundred thousand riyals, about twenty-seven thousand United States dollars, or both. This catches ordinary marketing footage, event photography and street-level product imagery. 5. The free zone is a different country for this purpose. Article 2 of the QFC Data Protection Regulations 2021 states that, to the fullest extent the QFC Law permits, the laws, rules and regulations of the State of Qatar on these matters do not apply inside the Centre. A group with entities on both sides of that line needs two compliance programmes, not one. 6. A bonus trap that runs backwards. Article 15 makes it an offence for a controller to restrict cross-border data flow. A well-meaning internal policy that blocks all offshore processing is, read literally, the thing the statute punishes.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
What's changing next
Nothing major is scheduled in the next twelve months that we could verify. The most recent change already landed: the public-photography offence took effect in August 2025. The bigger risk is what the government can already do without asking anyone. Several powers sit unused in the existing law and could change the picture overnight.
Confirmed and already in force: Law No. 11 of 2025, dated 21 July 2025 and published in Official Gazette issue 20 of 4 August 2025, added the public-place photography offence to the cybercrime law. The Qatar Central Bank Cloud Computing Regulation has been in force since 15 April 2024 and the Data Handling and Protection Regulation was published on the bank's site in February 2025. Pending: the Communications Regulatory Authority has issued a Spam Regulation and has consulted on an amended draft, but the two live consultations on its site on 18 August 2026 concerned radio spectrum fees and postal licence fees, neither of which touches data. No amendment to Law No. 13 of 2016 has been gazetted since it was passed, and the law's card on the official legal portal shows no amendments. Dormant switches, which matter more than pending bills: - Article 16 lets the Minister add new categories of sensitive personal data by decision alone, and impose additional protective measures for them. Whole datasets could move into permit-only territory with no consultation. - Articles 7, 8(4), 16 and 18 all require decisions of the Minister that we could not find published. Issuing them would convert a broadly worded statute into a detailed compliance regime overnight. - Article 30 lets the Cabinet extend the compliance period 'for a similar period or periods' on the Minister's proposal, a power it has already used once. - Article 18 lets any competent government body disapply the consent rule, the notice rule, the cross-border flow rule and the children's rule for national security, public security, international relations, the State's economic or financial interests, or the prevention, detection or investigation of crime, keeping only an internal register of what it did. - Clause 23 of the central bank's Cloud Computing Regulation and clause 17 of its Data Handling and Protection Regulation make every exemption revocable and time-limited, so a bank's permission to process abroad can lapse or be withdrawn. - Under Article 23 of the QFC Data Protection Regulations, a jurisdiction can lose adequacy status at any time and the Data Protection Office simply issues an amended list.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority — Active Consultations, checked 18 August 2026
cra.gov.qa
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clause 1 (commencement)
qcb.gov.qa
“The instructions set forth herein are titled the Cloud Computing Regulation and will enter into force as of 15/04/2024.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Data Handling and Protection Regulation
Directly binding regulation · Qatar Central Bank, Data Handling and Protection Regulation, clauses 11, 15, 16 and 17
Every financial institution the Qatar Central Bank supervises is barred from storing or sending customer personal or financial data abroad without the bank's approval, must keep that data for ten years, and must report breaches to three separate bodies.
Enforced by Qatar Central Bank
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Keep the data in the countryNo storage or transfer of personal data, personally identifiable information, sensitive personal information or sensitive financial information to a foreign jurisdiction without the central bank's approval.
- Put a transfer safeguard in placeRisk assessment of the destination country and of the third party, plus an examination of that country's data protection framework, before any foreign transfer.
- Keep data for a minimum period — 10 yearsTen years for sensitive financial information and for personal data, personally identifiable information and sensitive personal information; one year for technical information.
- Report breaches to the regulatorReport to the central bank and to the authorised agencies in Qatar, named in the regulation as the National Cyber Security Agency and the Ministry of Interior.
- Keep records of processingA documented inventory of how the institution collects, processes, stores and shares personal data.
- Assess high-risk projects
- Independent audit
- Get consentConsent records must capture purpose, identity, date, method and the privacy policy in force at the time.
What it costs if you get it wrong
- Order to stopSupervisory action by the Qatar Central Bank under the QCB Law
- Loss of your licenceSupervisory action by the Qatar Central Bank under the QCB Law
Sources
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
Cloud Computing Regulation
Directly binding regulation · Qatar Central Bank, Cloud Computing Regulation, clauses 1, 10, 18, 21 and 23
Since 15 April 2024 any organisation the Qatar Central Bank regulates must process personal and financial information inside Qatar only, and must get the bank's approval before signing any cloud contract.
Enforced by Qatar Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — from 15 April 2024Personally identifiable information and financial information must be processed within Qatar only.
- Register or notify — from 15 April 2024Central bank approval is required before entering into any cloud arrangement, and every cloud arrangement must be entered in a register.
- Written vendor contractTermination rights on change of control, insolvency, material data or security breach, or if the provider proposes to move data to an unacceptable location.
- Secure the data
- Make switching cloud provider possibleA documented exit plan covering both a managed exit and a stressed exit.
- Independent auditRegular architecture, configuration, compliance, source-code, vulnerability and penetration testing according to the service model.
What it costs if you get it wrong
- Order to stopSupervisory action by the Qatar Central Bank
Sources
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clause 1 (commencement)
qcb.gov.qa
“The instructions set forth herein are titled the Cloud Computing Regulation and will enter into force as of 15/04/2024.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Information and Cyber Security Regulation for Payment Service Providers — clause 6.8
qcb.gov.qa
“the generation and storage of the private keys outside of the cloud environment, on-premises in Qatar”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
قانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية
Act of parliament · Law No. 13 of 2016 on the Protection of Personal Data Privacy, Articles 4, 5, 6, 8-17, 22-26
Qatar's general privacy law lets personal data leave the country freely and actually forbids a company from restricting cross-border flows. In exchange it imposes consent, notice, individual rights, security, breach reporting and a permit requirement for sensitive categories, all backed by criminal fines.
Enforced by National Cyber Security Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consentConsent is the default basis; processing without it is allowed only where necessary for a legitimate purpose of the controller or of the party the data is sent to.
- Tell people what you doBefore processing starts, tell the person who the controller is, the legitimate purposes, and a full and accurate description of the processing and disclosures.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulatorRequired where the failure would cause serious harm to the data or to the person's privacy. No deadline is stated in the statute.
- Tell affected peopleSame trigger and same absence of a deadline.
- Independent auditThe controller must run comprehensive audits and reviews of its own compliance.
- Written vendor contractThe controller must verify that the processor follows its instructions and takes suitable protective measures, and must monitor this continuously.
- Get a parent's consent for childrenExpress consent of the child's guardian for any website directed at children. No age is defined.
- Register or notifyA permit from the competent department is required before processing sensitive categories, under procedures to be set by a Minister's decision that we could not find published.
- Publish a complaints contactInternal systems to receive and examine complaints and access, correction and deletion requests, made available to individuals.
What it costs if you get it wrong
- Criminal liability: QAR 1,000,000 — about $275 thousandBreach of Articles 4, 8, 9, 10, 11, 12, 14, 15 or 22, including restricting cross-border data flow
- Criminal liability: QAR 5,000,000 — about $1 millionBreach of the security duty, the sensitive-data permit duty or the children's website duty
- Criminal liability: QAR 1,000,000 — about $275 thousandOffence committed in the name and for the account of a company, without prejudice to the individual's own liability
- Order to stopThe competent department can order a controller or processor to remedy a breach within a set period
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Cabinet Decision No. 1 of 2018 extending the compliance period under Article 30 of Law No. 13 of 2016
almeezan.qa
“تُمد مهلة توفيق الأوضاع المنصوص عليها في المادة (30) من القانون رقم (13) لسنة 2016 المشار إليه، لمدة ستة أشهر تبدأ من 29/7/2017”
Link checked 18 August 2026
قانون رقم (14) لسنة 2014 بإصدار قانون مكافحة الجرائم الإلكترونية
Act of parliament · Law No. 14 of 2014 on Combating Cybercrime, Articles 21 and 22
Telephone and internet providers must keep subscriber records for a year and freeze traffic or content data for ninety days when asked. Government bodies must keep the same kinds of data for at least a hundred and twenty days and report incidents immediately.
Enforced by Ministry of Interior
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 1 yearService providers must keep subscriber information for one year.
- Keep logsService providers must preserve information-technology data, traffic data or content information for ninety days, renewable, on the request of the competent authority or the investigating and prosecuting bodies.
- Keep data for a minimum period — 4 monthsState organs, institutions, bodies and their subsidiary entities and companies must keep information-technology data and subscriber information for at least one hundred and twenty days.
- Report cyber incidentsState bodies must report any offence under this law to the competent authority as soon as it is discovered, including attempted unlawful interception or eavesdropping.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityOffences under the cybercrime law
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
قانون رقم (11) لسنة 2025 بتعديل بعض أحكام قانون مكافحة الجرائم الإلكترونية
Act of parliament · Law No. 11 of 2025 amending the Law on Combating Cybercrime, new Article 8 bis
Since August 2025 it is a crime in Qatar to publish or share photographs or video of people taken while they were in a public place, unless they knew about it or agreed. It carries up to a year in prison.
Enforced by Ministry of Interior
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consent — from 4 August 2025Knowledge or consent of the people shown is required before publishing or circulating photographs or video taken of them in public places.
What it costs if you get it wrong
- Criminal liability: QAR 100,000 — about $27 thousandPublishing or circulating photographs or video of people in public places without their knowledge or consent, over the information network or by any information technology means. Up to one year in prison, the fine, or both.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
Applies only in certain states1 rule
Made by a state or province. It only binds you for the people living there.
QFC Data Protection Regulations 2021
Directly binding regulation · QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9
Companies registered in the Qatar Financial Centre sit outside the national privacy law and follow a European-style regime instead, with an approved-destinations list, standard contract clauses, group rules and a seventy-two hour breach clock.
Enforced by Qatar Financial Centre Data Protection Office — not yet operational
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hoursA notification made later than seventy-two hours after becoming aware must explain the delay.
- Assess high-risk projects
- Keep records of processing
- Written vendor contract
- Let people take their data elsewhere
- Limit automated decisions
- Register or notifyA permit from the Data Protection Office is needed to process sensitive personal data.
What it costs if you get it wrong
- Fixed maximum finePenalties must be effective, proportionate and dissuasive; they may be imposed instead of or in addition to orders of the Data Protection Office
- Claims by individualsIndividuals have a right to compensation for damage
- Order to stopOrders of the Data Protection Office
Sources
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 24 — Transfers Out of the QFC in the Absence of an Adequate Level of Protection
qfcra-en.thomsonreuters.com
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Rules, DATA 9 — Notification of Personal Data Breaches
qfcra-en.thomsonreuters.com
“if the notification is not made within 72 hours after becoming aware of the Personal Data Breach, give reasons for the delay”
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether Law No. 13 of 2016 reaches a foreign company with no establishment in Qatar.
The statute has no territorial-scope article at all. Article 2 sets only the material scope. No official interpretation, guidance or court ruling on the point could be found on a Qatari government domain, checked 18 August 2026.
The exact date Law No. 13 of 2016 entered into force.
The law itself does not state a commencement date. We derived 29 January 2017 from Cabinet Decision No. 1 of 2018, which extends the six-month compliance period in Article 30 'for six months beginning 29/7/2017'. That is a sound inference but it is an inference, not a stated date.
Whether the Minister ever issued the implementing decisions the law requires.
Articles 7, 8(4), 16 and 18 all call for decisions of the Minister, including the procedure for obtaining a permit to process sensitive personal data. Searches of the official legal portal on 18 August 2026 returned no such decisions. Absence from the portal is strong but not conclusive evidence that none exist.
Whether the National Cyber Security Agency has issued any data protection penalty, order or guidance.
The agency's website is a single-page application whose content is served from a host that could not be reached from this environment, and the national services portal was returning a maintenance page. No official Qatari source for its privacy output could be read.
The commencement date of the Qatar Central Bank Data Handling and Protection Regulation.
Unlike the Cloud Computing Regulation, the document contains no short-title or commencement clause. It is published on the central bank's own information security page with a file date of February 2025, which is the only date evidence available.
The breach reporting deadline for financial institutions in hours.
Clause 16.1 of the Data Handling and Protection Regulation defers to 'QCB's incident reporting guidelines'. Those guidelines are not published on the central bank's public website.
Whether the Qatar Financial Centre Data Protection Office has published a list of adequate jurisdictions.
Article 23(4) requires it to publish its adequacy decisions. No such list was found on the Centre's own site, and the rulebook is hosted on a commercial domain rather than a government one.
Whether any localisation or data-storage rule exists for health, education, government cloud or mapping data.
No such rule was found in the official gazette or on the reachable regulator sites, checked 18 August 2026. The Ministry of Public Health site and the national services portal serve their content only to a full browser, and the National Information Assurance Policy referred to by the Cloud Policy Framework could not be obtained from an official source. Recorded as not found, not as absent.
The primary text of the QFC Data Protection Regulations is cited from a commercial rulebook host.
The Qatar Financial Centre publishes its legislation through a Thomson Reuters rulebook site rather than on its own domain. The Centre's own laws and regulations page is used as the government backlink, but the operative wording comes from the rulebook.
Whether any Qatari court has decided a case under the personal data privacy law.
The rulings database on the official legal portal could not be queried successfully during this run. No conclusion should be drawn from that either way.
Ordinary commercial, tax and employment record-keeping floors in Qatar.
Only the privacy, cybercrime and central bank retention periods were verified in this pass. Company and tax law retention periods exist and were not checked.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.
Put this next to another country
Qatar versus
Compare