Skip to the content
Global Data RulesData governance rules, country by country

Qatar

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Qatar — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

Qatar's national privacy law is one of the most open in the world about sending data abroad. It does not just allow data to cross the border. It bans a company from blocking it. Money is the exception. Anything the central bank licences must keep customer data inside Qatar. Moving that data out needs written permission. The financial free zone has its own separate rules.

Data governance in Qatar

The eight things that decide how you handle data about people in Qatar. Same eight on every country page, so you can compare.

Who has to follow these rules

The law says nothing about foreign companies. It lists which activities it covers. It never says whether it reaches a business with no office in Qatar. There is no size or revenue cut-off. You do not have to register. You do not have to appoint anyone inside the country. But if you handle certain sensitive types of data, you are supposed to get a permit from the regulator before you start.

What you have to do here:
Register or notify
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

It depends completely on your industry. Under the general law, data can leave freely. The law goes further than that. It bans a company from taking any step that would restrict data crossing the border. But if the central bank licences you, personal and financial data must be handled inside Qatar only. You may not store or send it abroad without the bank's written approval. Companies inside the Qatar Financial Centre follow a third, European-style set of rules.

What to do: Plan for a database inside Qatar: this data is not allowed to leave.

Sending data out of the country

Under the general law, nothing. There is no list of approved countries, no template contract and no filing. The law bans you from restricting data flows in the first place. If the central bank licences you, it works case by case. You need its written approval before data leaves, and before you sign any cloud contract. Inside the Qatar Financial Centre you may only send data to approved countries. We could not confirm that the approved list has anything on it yet.

Ways to send data out:
Nothing required · Government sign-off needed · Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Cyber Security Agency has run the privacy law since 2021. It is real, funded and reports to the Prime Minister. It signs cybersecurity agreements that are ratified by decree. But we could not find a single published privacy penalty from it. The only officials ever named to investigate offences under this law sit at a ministry that no longer does the job. The central bank is the regulator that actually acts. It supervises and inspects the firms it licenses.

What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The general law only says do not keep data longer than you need it, with no fixed periods. The hard numbers live elsewhere. Internet and telephone providers must keep subscriber details for one year, and must freeze traffic or content data for ninety days when asked. State bodies must keep subscriber and system data for at least one hundred and twenty days. Financial firms must keep customer personal data for ten years.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three clocks. Under the general law you must tell both the person and the regulator. The law sets no deadline at all, so treat it as immediately. A supplier must tell its customer company as soon as it knows. If the central bank licenses you, you report to three bodies at once. Inside the financial free zone the deadline is seventy-two hours.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people here. The fines are criminal, not administrative. Sensitive data needs a government permit before you touch it, and the rules for getting one were never published. There is no age that defines a child. Since August 2025 it is a crime to post a photo of someone in a public place without their knowledge. And a company inside the Qatar Financial Centre is outside the national law entirely.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing major is scheduled in the next twelve months that we could verify. The most recent change has already landed. The public-photography offence took effect in August 2025. The bigger risk is what the government can already do without asking anyone. Several powers sit unused in the existing law and could change the answer overnight.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Banking rules

Official name: Data Handling and Protection Regulation · Qatar Central Bank, Data Handling and Protection Regulation, clauses 11, 15, 16 and 17 · Directly binding regulation

In forceNo — it stays put

Every financial institution the Qatar Central Bank supervises is banned from storing or sending customer personal or financial data abroad without the bank's approval. It must keep that data for ten years. It must report breaches to three separate bodies.

Enforced by Qatar Central Bank

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Security review needed

Not fully verified — see “What we're not sure about” below.
Finance

Finance data must stay in the country

Official name: Cloud Computing Regulation · Qatar Central Bank, Cloud Computing Regulation, clauses 1, 10, 18, 21 and 23 · Directly binding regulation

In forceNo — it stays put

Since 15 April 2024 any organisation the Qatar Central Bank regulates must handle personal and financial information inside Qatar only. It must get the bank's approval before signing any cloud contract.

In force since 15 April 2024

Enforced by Qatar Central Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: قانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية · Law No. 13 of 2016 on the Protection of Personal Data Privacy, Articles 4, 5, 6, 8-17, 22-26 · Act of parliament

In forceYes — store it anywhere

Qatar's general privacy law lets personal data leave the country freely. It even bans a company from restricting data flowing across the border. In exchange it requires consent, notice, individual rights, security and breach reporting. It also requires a permit for sensitive types of data. All of it is backed by criminal fines.

In force since 29 January 2017Enforced from 29 January 2018

Enforced by National Cyber Security Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Telecoms

Breach reporting rules (Telecoms)

Official name: قانون رقم (14) لسنة 2014 بإصدار قانون مكافحة الجرائم الإلكترونية · Law No. 14 of 2014 on Combating Cybercrime, Articles 21 and 22 · Act of parliament

In forceYes — store it anywhere

Telephone and internet providers must keep subscriber records for a year and freeze traffic or content data for ninety days when asked. Government bodies must keep the same kinds of data for at least a hundred and twenty days and report incidents immediately.

In force since 2 October 2014

Enforced by Ministry of Interior

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Social media and online platforms

Social media and online platforms data rules

Official name: قانون رقم (11) لسنة 2025 بتعديل بعض أحكام قانون مكافحة الجرائم الإلكترونية · Law No. 11 of 2025 amending the Law on Combating Cybercrime, new Article 8 bis · Act of parliament

In forceYes — store it anywhere

Since August 2025 it is a crime in Qatar to publish or share photographs or video of people in a public place. That applies unless they knew about it or agreed. It carries up to a year in prison.

In force since 4 August 2025

Enforced by Ministry of Interior

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only in certain states1 rule

Made by a state or province. It only binds you for the people living there.

Breach reporting rules (QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9)

Official name: QFC Data Protection Regulations 2021 · QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9 · Directly binding regulation

In forceYes, with paperwork

Companies registered in the Qatar Financial Centre sit outside the national privacy law. They follow European-style rules instead. Those include a list of approved countries, standard contract clauses, group-wide rules and a seventy-two hour deadline for reporting breaches.

Enforced by Qatar Financial Centre Data Protection Office — not yet operational

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • الوكالة الوطنية للأمن السيبراني

    National cyber security, and implementation of the laws, regulations and decisions on the protection of personal data privacy

    Created by Emiri Decision No. 1 of 2021. It has its own legal identity and budget and reports to the Prime Minister. It is visibly working on cyber security. Cooperation agreements it signed were ratified by Decrees No. 11 and No. 38 of 2024. We found no published data protection decision, fine, register or guidance from it on an official Qatari website. Its own site serves content only to a full browser, so we could not observe its privacy work. Rated waking up rather than active.

  • مصرف قطر المركزي

    Banks, insurers, payment service providers, exchange houses, finance companies, investment companies and other licensed financial institutions

    Fully working, and the regulator that actually binds regulated firms on data. It publishes a set of data, cloud and cyber rules. It requires its approval before cloud arrangements and before data goes abroad. It supervises compliance through its on-site and off-site supervision departments.

  • هيئة تنظيم الاتصالات

    Telecommunications, postal services, spectrum and trust services; consumer protection including customer data privacy

    Clearly active. It issued the Communications Consumer Protection Policy and Regulation in October 2024. It has published decisions, consultations and reports through mid-2026, including a president's decision in June 2026. It has published non-compliance notices against operators.

  • All entities registered in the Qatar Financial Centre, which is carved out of national data protection law

    Part 6 of the QFC Data Protection Regulations 2021 sets up the Office and the Data Protection Commissioner. It gives them permit, order and penalty powers. Article 23(4) requires the Office to publish the countries it treats as safe enough. We could not confirm from any official Qatar Financial Centre source that it has published that list. We also found no decision from it. Recorded as unverified rather than inactive.

  • وزارة الداخلية

    Criminal enforcement of the cybercrime law, including the retention and assistance duties on service providers and the new public-imagery offence

    The cybercrime law is enforced through the Public Prosecution and the police. Offences under it are prosecuted in the ordinary criminal courts. We did not check individual prosecutions against an official source.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether Law No. 13 of 2016 reaches a foreign company with no establishment in Qatar.

    We could not confirm whether this law reaches companies with no office in Qatar. The law has no article about which territory it covers. Article 2 sets only what kinds of data it covers. We found no official interpretation, guidance or court ruling on a Qatari government website, checked 18 August 2026.

  • The exact date Law No. 13 of 2016 entered into force.

    The law does not state when it started. We worked out 29 January 2017 from Cabinet Decision No. 1 of 2018. That decision extends the six-month compliance period in Article 30 'for six months beginning 29/7/2017'. The reasoning is sound, but it is our inference, not a stated date.

  • Whether the Minister ever issued the implementing decisions the law requires.

    We could not confirm that the Minister ever issued the decisions the law calls for. Articles 7, 8(4), 16 and 18 all require them. That includes the procedure for getting a permit to handle sensitive personal data. Searches of the official legal portal on 18 August 2026 found none. That is strong evidence but not proof.

  • Whether the National Cyber Security Agency has issued any data protection penalty, order or guidance.

    We could not read any official Qatari source for the agency's privacy work. Its website serves content from a host we could not reach. The national services portal was showing a maintenance page. Ask the agency directly if you need its current position.

  • The commencement date of the Qatar Central Bank Data Handling and Protection Regulation.

    We could not confirm when this document took effect. Unlike the Cloud Computing Regulation, it has no short-title or start-date clause. It is published on the central bank's own information security page with a file date of February 2025. That is the only date evidence available.

  • The breach reporting deadline for financial institutions in hours.

    We could not confirm the deadline for reporting an incident to the central bank. Clause 16.1 of the Data Handling and Protection Regulation points to 'QCB's incident reporting guidelines'. Those guidelines are not on the central bank's public website. Ask the bank for them.

  • Whether the Qatar Financial Centre Data Protection Office has published a list of adequate jurisdictions.

    We could not confirm that the Qatar Financial Centre has published the countries it treats as safe enough. Article 23(4) requires it to publish those decisions. We found no such list on the Centre's own site. Its rulebook sits on a commercial website, not a government one.

  • Whether any localisation or data-storage rule exists for health, education, government cloud or mapping data.

    We found no such rule in the official gazette or on the regulator sites we could reach, checked 18 August 2026. But we could not confirm this against every government source. The Ministry of Public Health site and the national services portal serve content only to a full browser. We could not obtain the National Information Assurance Policy that the Cloud Policy Framework refers to. If you work in these industries, check before you rely on this.

  • The primary text of the QFC Data Protection Regulations is cited from a commercial rulebook host.

    The Qatar Financial Centre publishes its legislation on a Thomson Reuters rulebook site, not on its own website. We use the Centre's own laws and regulations page as the government link. But the working wording comes from that rulebook.

  • Whether any Qatari court has decided a case under the personal data privacy law.

    We could not search the rulings database on the official legal portal. Draw no conclusion from that either way.

  • Ordinary commercial, tax and employment record-keeping floors in Qatar.

    We only checked the privacy, cybercrime and central bank keeping periods. Company and tax law keeping periods also exist. We did not check them, so confirm those separately.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.