Skip to the content
Global Data RulesData governance rules, country by country

Qatar

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Qatar's national privacy law is one of the most open in the world about sending data abroad. It does not just permit cross-border flows, it forbids a company from blocking them. Money is the exception. Anything the central bank licences must keep customer data inside Qatar and needs written permission to move it out. The financial free zone runs a separate regime.

Data governance in Qatar

The eight things that decide how you handle data about people in Qatar. Same eight on every country page, so you can compare.

Who has to follow these rules

The law is silent about foreign companies. It says which activities it covers, but it never says whether it reaches a business with no office in Qatar. There is no size or revenue cut-off, no requirement to register, and no requirement to appoint anyone inside the country. If you handle certain sensitive categories, though, you are supposed to get a permit from the regulator before you start.

Medium confidenceNational rulesRegister or notifyAppoint a local representative

Where the data is allowed to live

It depends completely on your industry. Under the general law data can leave freely, and the law goes further than that: a company is actually banned from taking any step that would restrict data flowing across the border. But if the central bank licences you, personal and financial data must be processed inside Qatar only, and you may not store or send it abroad without the bank's written approval. Companies inside the Qatar Financial Centre follow a third, European-style set of rules.

High confidenceDepends on your industryYes — store it anywhereNo — it stays putYes, with paperworkNo restrictionApproval each timeAllowlist

Sending data out of the country

Under the general law, nothing. There is no destination list, no template contract and no filing, and the law bans you from restricting flows in the first place. If the central bank licences you, the model flips to case-by-case: you need its written approval before data leaves, and before you sign any cloud contract. Inside the Qatar Financial Centre it is an approved-destinations list, and we could not confirm that the list has anything on it yet.

High confidenceNo restrictionApproval each timeAllowlistNothing requiredGovernment sign-off neededOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractLegal claims

The regulator, and whether it actually acts

The National Cyber Security Agency has run the privacy law since 2021. It is real, funded and reports to the Prime Minister, and it signs cybersecurity agreements that are ratified by decree. But we could not find a single published privacy penalty from it, and the only officials ever named to investigate offences under this law sit at a ministry that no longer does the job. The central bank is the regulator that actually bites, because it supervises and inspects the firms it licenses.

Medium confidenceWaking upCriminal liabilityRegulator

How long you must keep it — and when to delete it

The general law only says do not keep data longer than you need it, with no fixed periods. The hard numbers live elsewhere. Internet and telephone providers must keep subscriber details for one year, and must freeze traffic or content data for ninety days when asked. State bodies must keep subscriber and system data for at least one hundred and twenty days. Financial firms must keep customer personal data for ten years.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsTelecom network dataTraffic and access logs

If something goes wrong

Count three clocks. Under the general law you must tell both the person and the regulator, but the law sets no deadline at all, so 'immediately' is the safe reading. A supplier must tell its customer company as soon as it knows. If the central bank licenses you, you report to three bodies at once. Inside the financial free zone the deadline is seventy-two hours.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsSecure the data

What catches people out

Five things bite people here. The fines are criminal, not administrative. Sensitive data needs a government permit before you touch it, and the rules for getting one were never published. There is no age that defines a child. Since August 2025 it is a crime to post a photo of someone in a public place without their knowledge. And a company inside the Qatar Financial Centre is outside the national law entirely.

High confidenceCriminal liabilityGet a parent's consent for childrenChildren's dataSensitive personal dataRegister or notify

What's changing next

Nothing major is scheduled in the next twelve months that we could verify. The most recent change already landed: the public-photography offence took effect in August 2025. The bigger risk is what the government can already do without asking anyone. Several powers sit unused in the existing law and could change the picture overnight.

Medium confidenceIn forceAct of parliament

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Data Handling and Protection Regulation

Directly binding regulation · Qatar Central Bank, Data Handling and Protection Regulation, clauses 11, 15, 16 and 17

In forceNo — it stays put

Every financial institution the Qatar Central Bank supervises is barred from storing or sending customer personal or financial data abroad without the bank's approval, must keep that data for ten years, and must report breaches to three separate bodies.

Enforced by Qatar Central Bank

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Security review needed

Medium confidence
Finance

Cloud Computing Regulation

Directly binding regulation · Qatar Central Bank, Cloud Computing Regulation, clauses 1, 10, 18, 21 and 23

In forceNo — it stays put

Since 15 April 2024 any organisation the Qatar Central Bank regulates must process personal and financial information inside Qatar only, and must get the bank's approval before signing any cloud contract.

In force since 15 April 2024

Enforced by Qatar Central Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

قانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية

Act of parliament · Law No. 13 of 2016 on the Protection of Personal Data Privacy, Articles 4, 5, 6, 8-17, 22-26

In forceYes — store it anywhere

Qatar's general privacy law lets personal data leave the country freely and actually forbids a company from restricting cross-border flows. In exchange it imposes consent, notice, individual rights, security, breach reporting and a permit requirement for sensitive categories, all backed by criminal fines.

In force since 29 January 2017But only enforceable from 29 January 2018

Enforced by National Cyber Security Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Telecoms

قانون رقم (14) لسنة 2014 بإصدار قانون مكافحة الجرائم الإلكترونية

Act of parliament · Law No. 14 of 2014 on Combating Cybercrime, Articles 21 and 22

In forceYes — store it anywhere

Telephone and internet providers must keep subscriber records for a year and freeze traffic or content data for ninety days when asked. Government bodies must keep the same kinds of data for at least a hundred and twenty days and report incidents immediately.

In force since 2 October 2014

Enforced by Ministry of Interior

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Social media and online platforms

قانون رقم (11) لسنة 2025 بتعديل بعض أحكام قانون مكافحة الجرائم الإلكترونية

Act of parliament · Law No. 11 of 2025 amending the Law on Combating Cybercrime, new Article 8 bis

In forceYes — store it anywhere

Since August 2025 it is a crime in Qatar to publish or share photographs or video of people taken while they were in a public place, unless they knew about it or agreed. It carries up to a year in prison.

In force since 4 August 2025

Enforced by Ministry of Interior

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies only in certain states1 rule

Made by a state or province. It only binds you for the people living there.

QFC Data Protection Regulations 2021

Directly binding regulation · QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9

In forceYes, with paperwork

Companies registered in the Qatar Financial Centre sit outside the national privacy law and follow a European-style regime instead, with an approved-destinations list, standard contract clauses, group rules and a seventy-two hour breach clock.

Enforced by Qatar Financial Centre Data Protection Office — not yet operational

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

Medium confidence

Who you would hear from

  • الوكالة الوطنية للأمن السيبراني

    National cyber security, and implementation of the laws, regulations and decisions on the protection of personal data privacy

    Created by Emiri Decision No. 1 of 2021, has its own legal personality and budget and reports to the Prime Minister. Visibly functioning in its cyber security role: cooperation memoranda it signed were ratified by Decrees No. 11 and No. 38 of 2024. We found no published data protection decision, fine, register or guidance from it on an official Qatari domain, and its website serves its content only to a full browser, so its privacy activity could not be observed. Rated waking rather than active.

  • مصرف قطر المركزي

    Banks, insurers, payment service providers, exchange houses, finance companies, investment companies and other licensed financial institutions

    Fully operational and the regulator that actually binds regulated firms on data. It publishes a suite of data, cloud and cyber regulations, requires prior approval for cloud arrangements and foreign data transfers, and supervises compliance through its on-site and off-site supervision departments.

  • هيئة تنظيم الاتصالات

    Telecommunications, postal services, spectrum and trust services; consumer protection including customer data privacy

    Clearly active. It issued the Communications Consumer Protection Policy and Regulation in October 2024 and has published decisions, consultations and reports through mid-2026, including a president's decision in June 2026. It has published non-compliance notices against operators.

  • All entities registered in the Qatar Financial Centre, which is carved out of national data protection law

    The Office and the Data Protection Commissioner are established by Part 6 of the QFC Data Protection Regulations 2021 and given permit, order and penalty powers. We could not verify from any official Qatar Financial Centre source that it has published the list of adequate jurisdictions that Article 23(4) requires it to publish, or that it has issued any decision. Recorded as not verified operational rather than as inactive.

  • وزارة الداخلية

    Criminal enforcement of the cybercrime law, including the retention and assistance duties on service providers and the new public-imagery offence

    The cybercrime law is enforced through the Public Prosecution and the police. Offences under it are prosecuted in the ordinary criminal courts. We did not verify individual prosecutions from an official source in this pass.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether Law No. 13 of 2016 reaches a foreign company with no establishment in Qatar.

    The statute has no territorial-scope article at all. Article 2 sets only the material scope. No official interpretation, guidance or court ruling on the point could be found on a Qatari government domain, checked 18 August 2026.

  • The exact date Law No. 13 of 2016 entered into force.

    The law itself does not state a commencement date. We derived 29 January 2017 from Cabinet Decision No. 1 of 2018, which extends the six-month compliance period in Article 30 'for six months beginning 29/7/2017'. That is a sound inference but it is an inference, not a stated date.

  • Whether the Minister ever issued the implementing decisions the law requires.

    Articles 7, 8(4), 16 and 18 all call for decisions of the Minister, including the procedure for obtaining a permit to process sensitive personal data. Searches of the official legal portal on 18 August 2026 returned no such decisions. Absence from the portal is strong but not conclusive evidence that none exist.

  • Whether the National Cyber Security Agency has issued any data protection penalty, order or guidance.

    The agency's website is a single-page application whose content is served from a host that could not be reached from this environment, and the national services portal was returning a maintenance page. No official Qatari source for its privacy output could be read.

  • The commencement date of the Qatar Central Bank Data Handling and Protection Regulation.

    Unlike the Cloud Computing Regulation, the document contains no short-title or commencement clause. It is published on the central bank's own information security page with a file date of February 2025, which is the only date evidence available.

  • The breach reporting deadline for financial institutions in hours.

    Clause 16.1 of the Data Handling and Protection Regulation defers to 'QCB's incident reporting guidelines'. Those guidelines are not published on the central bank's public website.

  • Whether the Qatar Financial Centre Data Protection Office has published a list of adequate jurisdictions.

    Article 23(4) requires it to publish its adequacy decisions. No such list was found on the Centre's own site, and the rulebook is hosted on a commercial domain rather than a government one.

  • Whether any localisation or data-storage rule exists for health, education, government cloud or mapping data.

    No such rule was found in the official gazette or on the reachable regulator sites, checked 18 August 2026. The Ministry of Public Health site and the national services portal serve their content only to a full browser, and the National Information Assurance Policy referred to by the Cloud Policy Framework could not be obtained from an official source. Recorded as not found, not as absent.

  • The primary text of the QFC Data Protection Regulations is cited from a commercial rulebook host.

    The Qatar Financial Centre publishes its legislation through a Thomson Reuters rulebook site rather than on its own domain. The Centre's own laws and regulations page is used as the government backlink, but the operative wording comes from the rulebook.

  • Whether any Qatari court has decided a case under the personal data privacy law.

    The rulings database on the official legal portal could not be queried successfully during this run. No conclusion should be drawn from that either way.

  • Ordinary commercial, tax and employment record-keeping floors in Qatar.

    Only the privacy, cybercrime and central bank retention periods were verified in this pass. Company and tax law retention periods exist and were not checked.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

Put this next to another country

Qatar versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.