Qatar
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Qatar — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Qatar's national privacy law is one of the most open in the world about sending data abroad. It does not just allow data to cross the border. It bans a company from blocking it. Money is the exception. Anything the central bank licences must keep customer data inside Qatar. Moving that data out needs written permission. The financial free zone has its own separate rules.
Data governance in Qatar
The eight things that decide how you handle data about people in Qatar. Same eight on every country page, so you can compare.
Who has to follow these rules
The law says nothing about foreign companies. It lists which activities it covers. It never says whether it reaches a business with no office in Qatar. There is no size or revenue cut-off. You do not have to register. You do not have to appoint anyone inside the country. But if you handle certain sensitive types of data, you are supposed to get a permit from the regulator before you start.
- What you have to do here:
- Register or notify
Law No. 13 of 2016 on the Protection of Personal Data Privacy defines its reach by the type of work being done. It does not define it by where the company sits. Article 2 covers personal data handled electronically. It also covers data obtained or collected any other way in preparation for electronic handling. And it covers data handled by a mix of electronic and traditional means. It does not cover data used by individuals for personal or family purposes. It also does not cover data used to produce official statistics under Law No. 2 of 2011. None of the 32 articles says which territory the law applies to. There is no threshold, no duty to register and no duty to appoint someone in the country. Article 16 is the practical catch. Some data may not be handled at all without a permit from the competent department. That covers ethnic origin, children, health or physical or mental condition, religious belief, marital relationship and criminal offences. The procedures for that permit are to be set by a decision of the Minister. The law has no clause about reaching outside Qatar. So whether it binds a company based abroad is a question of general Qatari law. The law itself does not answer it, and we found no official interpretation either way. Inside the Qatar Financial Centre a different rule applies. Article 2 of the QFC Data Protection Regulations 2021 switches off State of Qatar law on these matters within the Centre.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
Where the data is allowed to live
It depends completely on your industry. Under the general law, data can leave freely. The law goes further than that. It bans a company from taking any step that would restrict data crossing the border. But if the central bank licences you, personal and financial data must be handled inside Qatar only. You may not store or send it abroad without the bank's written approval. Companies inside the Qatar Financial Centre follow a third, European-style set of rules.
Overall rating: it depends on your industry. Here are the exceptions, each with its own rating. - All industries, general law: open. Article 15 of Law No. 13 of 2016 bans a company from taking any decision or step that would restrict personal data flowing across the border. The only exceptions are where the use of the data breaks the law, or would seriously harm the data or the person's privacy. There is no approved-country list, no filing and no contract requirement. Breaking Article 15 carries a fine of up to one million Qatari riyals. So the duty runs the opposite way from most countries. - Banking, insurance, payments, securities and every other central-bank licensee: closed. Clause 15.1 of the Qatar Central Bank Data Handling and Protection Regulation covers financial institutions. They must not store or send personal data, personally identifiable information, sensitive personal information or sensitive financial information to another country. They may only do so with the central bank's approval. Clause 21.4 of the central bank's Cloud Computing Regulation has been in force since 15 April 2024. It says personally identifiable information and financial information must be handled within Qatar only. Clause 21.5 requires the bank's approval before you enter any cloud arrangement at all. - Payments, specifically: closed for encryption keys. Clause 6.8 of the Information and Cyber Security Regulation for Payment Service Providers applies. The key management system and private keys must be created and stored outside the cloud, on premises in Qatar. - Insurance and banking, specifically: a people-and-place rule as well. Two rules apply here: the Insurance Sector Cyber Security Regulation and the Technology Risks Regulation for Banks. Both require the round-the-clock security operations centre to be on site or in Qatar. - Qatar Financial Centre: conditional, and outside the national law. Article 23 of the QFC Data Protection Regulations 2021 allows transfers to a country the Centre's Data Protection Office has officially decided is safe enough. Article 24 allows transfers elsewhere on standard clauses, group-wide rules, a permit, or one of a short list of narrow exceptions. - Telecoms: we found no rule forcing data to stay in the country, checked 18 August 2026. The Communications Regulatory Authority issued its Communications Consumer Protection Policy and Regulation on 2 October 2024. It covers customer data privacy but points back to the Telecommunications By-Law. It sets no storage location. - Government and public sector: we found no published rule forcing data to stay in the country, checked 18 August 2026, confidence low. The Cloud Policy Framework points government bodies to the National Information Assurance Policy for classifying government data. We could not get that policy from an official source. - Health, education, gambling and mapping: we searched the national gazette on 18 August 2026 and found no rule forcing data to stay in the country. Confidence low. Gambling is unlawful in Qatar, so there are no gaming rules to check. The national cloud policy pushes the other way from the banking rules. The Communications Regulatory Authority published its Cloud Policy Framework on 7 June 2022. It recommends dropping the requirement that data stay in the country. It says data should only be kept inside Qatar when it is highly sensitive. But it is a policy document, not a binding law.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Information and Cyber Security Regulation for Payment Service Providers — clause 6.8
qcb.gov.qa
“the generation and storage of the private keys outside of the cloud environment, on-premises in Qatar”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Insurance Sector Cyber Security Regulation — clause 8.4.5
qcb.gov.qa
“The Insurance Company shall establish and implement a centralized security event monitoring function such as a Security Operations Centre (SOC) functioning 24x7 onsite or in Qatar”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority, Cloud Policy Framework (7 June 2022) — section 4.3.1 policy recommendation
cra.gov.qa
“Data residency shall not be any longer a requirement as data classification schemes, security and encryption technologies now secure a high level of protection controls. Data localization may be required for highly sensitive data only.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Technology Risks Regulation for Banks (January 2018) — clause 8.4.5, security operations centre onsite or in Qatar
qcb.gov.qa
“The bank shall establish and implement a Security Operations Centre (SOC) functioning 24x7 onsite or in Qatar”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority, Communications Consumer Protection Policy and Regulation (2 October 2024) — section 4.5, protection of customer information
cra.gov.qa
“All customer information must be collected in a manner which complies with the provisions of article 92 of the Telecommunications By-Law.”
Link checked 18 August 2026
What to do: Plan for a database inside Qatar: this data is not allowed to leave.
Sending data out of the country
Under the general law, nothing. There is no list of approved countries, no template contract and no filing. The law bans you from restricting data flows in the first place. If the central bank licences you, it works case by case. You need its written approval before data leaves, and before you sign any cloud contract. Inside the Qatar Financial Centre you may only send data to approved countries. We could not confirm that the approved list has anything on it yet.
- Ways to send data out:
- Nothing required · Government sign-off needed · Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims
Three different models sit side by side. General law: no restrictions. Article 15 of Law No. 13 of 2016 does more than allow data to cross the border. It bans a company from restricting it. The only exceptions are where the use of the data breaks the law, or would seriously harm the data or the person's privacy. There is no list of banned countries and no list of approved ones. So there is nothing here that can quietly fill up. The exception is written as a duty on the company. It is not a power for the regulator to name countries. Central bank licensees: government permission, case by case. Clause 15.1 of the Data Handling and Protection Regulation requires the bank's approval first. That applies before you store or send personal data, personally identifiable information, sensitive personal information or sensitive financial information to another country. Clauses 15.2 to 15.4 add checks on the destination and on how safe it is. Clause 21.5 of the Cloud Computing Regulation requires approval before you enter a cloud arrangement. Clause 23 lets a firm apply to be excused from any requirement. The bank must approve that, and the excuse must carry an expiry date. Neither regulation publishes a list of approved countries or a public register of approvals. Qatar Financial Centre: approved countries plus safeguards. Article 23 lets the Data Protection Office decide that a country is safe enough. It must publish those decisions. Article 24 covers everything else. You have six options. Standard data protection clauses adopted by the Data Protection Office. A legally binding arrangement between public bodies. Group-wide rules approved by the Office. Another approved international method. A permit from the Office. Or one of seven narrow exceptions. Those exceptions include explicit informed consent, need to perform a contract, a legal duty, vital interests, public interest and legal claims. There is also a fallback route for one-off transfers of small amounts of non-sensitive data, backed by a written assessment. We could not check from an official source whether the Office has actually published a list of approved countries.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 24 — Transfers Out of the QFC in the Absence of an Adequate Level of Protection
qfcra-en.thomsonreuters.com
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Cyber Security Agency has run the privacy law since 2021. It is real, funded and reports to the Prime Minister. It signs cybersecurity agreements that are ratified by decree. But we could not find a single published privacy penalty from it. The only officials ever named to investigate offences under this law sit at a ministry that no longer does the job. The central bank is the regulator that actually acts. It supervises and inspects the firms it licenses.
- What it costs if you get it wrong:
- Criminal liability
The privacy law was written for the Ministry of Transport and Communications. The Ministry is the 'Ministry' and its administrative unit is the 'competent department'. Emiri Decision No. 1 of 2021 was published on 24 March 2021. It created the National Cyber Security Agency as a body with its own legal identity and budget. The agency reports to the Prime Minister. Article 3(21) gives it the job of applying the laws, rules and decisions on personal data privacy. Is it working? Partly. The agency clearly exists and functions on cyber security. Decrees No. 11 and No. 38 of 2024 ratify cooperation agreements it signed with foreign cybersecurity agencies. What we could not find is any published data protection decision, fine or guidance from an official Qatari source. The agency's website serves its content from a host we could not reach. The national services portal was showing a maintenance page when we checked on 18 August 2026. On the evidence we can see, this regulator is waking up rather than active. One structural point is easy to miss. The penalties in Articles 23 to 25 of the privacy law are criminal fines, not administrative ones. Article 29 lets the Attorney-General, agreeing with the Minister, give Ministry staff the status of judicial officers. They can then detect and record offences under the law. That was done once, by Attorney-General Decision No. 106 of 2017. It named exactly six people, including digital-evidence specialists and a network security specialist. All six sat at the Ministry of Transport and Communications. That ministry no longer holds the data protection job. We found no equivalent appointment at the National Cyber Security Agency. So the criminal enforcement machinery for this law appears to have no named officers behind it today. Article 26 gives the competent department a separate, softer route. It can investigate a complaint and order a company or its supplier to fix the breach within a set time. You can appeal to the Minister within sixty days. Once the Minister decides, there is no further appeal. Other regulators. The Qatar Central Bank supervises every licensed financial institution. It enforces its own data, cloud and cyber rules through its supervision teams. Its rules say breaches must be reported to it, to the National Cyber Security Agency and to the Ministry of Interior. The Communications Regulatory Authority regulates telecoms and is visibly active. It published decisions and consultations through 2026. Inside the Qatar Financial Centre, the Data Protection Office has its own powers under Part 6 of the QFC Data Protection Regulations. Those include permits, orders and penalties.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Emiri Decision No. 1 of 2021 establishing the National Cyber Security Agency — Article 3(21)
almeezan.qa
“تنفيذ القوانين واللوائح والقرارات المتعلقة بحماية خصوصية البيانات الشخصية”
Link checked 18 August 2026
- Official sourceNational Cyber Security Agency, State of QatarNational Cyber Security Agency — official website
ncsa.gov.qa
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Attorney-General Decision No. 106 of 2017 naming six employees of the Ministry of Transport and Communications as judicial officers for offences under Law No. 13 of 2016
almeezan.qa
“يكون لموظفي وزارة المواصلات والاتصالات التالية أسماؤهم صفة مأموري الضبط القضائي، في ضبط واثبات الجرائم التي تقع بالمخالفة لأحكام القانون رقم (13) لسنة 2016”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority — Active Consultations, checked 18 August 2026
cra.gov.qa
Link checked 18 August 2026
How long you must keep it — and when to delete it
The general law only says do not keep data longer than you need it, with no fixed periods. The hard numbers live elsewhere. Internet and telephone providers must keep subscriber details for one year, and must freeze traffic or content data for ninety days when asked. State bodies must keep subscriber and system data for at least one hundred and twenty days. Financial firms must keep customer personal data for ten years.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
The maximum. Article 10 of Law No. 13 of 2016 says you must check that personal data is relevant, adequate, accurate, complete and up to date for the purpose you hold it for. You must not keep it longer than you need it for that purpose. Article 5(3) lets a person demand deletion once the purpose has ended. The same applies where you have no justification for keeping the data. The law states no maximum period anywhere. The minimum. Article 21 of the cybercrime law, Law No. 14 of 2014, requires a service provider to keep subscriber information for one year. It must also preserve information-technology data, traffic data or content information for ninety days, renewable. That applies when the competent authority or the investigating and prosecuting bodies ask. Article 22 covers state organs, institutions, bodies and their subsidiaries and companies. They must keep information-technology data and subscriber information for at least one hundred and twenty days, and hand it over on request. For financial institutions, clause 11.3 of the Qatar Central Bank Data Handling and Protection Regulation sets minimum periods. They are ten years for sensitive financial information, and for personal data, personally identifiable information and sensitive personal information. Technical information is one year. Everything else is left to the institution. Clause 11.4 requires longer where another law demands it. Ordinary company and tax record-keeping periods under Qatari commercial and tax law apply on top. We did not check those. What happens when they clash. Nothing in the privacy law settles a clash between a deletion request and a duty to keep data. The specific duty to keep the record wins. Article 19 of the privacy law helps here. It excuses you from the consent and rights rules when you are carrying out a legal duty or a court order. We could not find an official ruling or guidance saying this in so many words.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three clocks. Under the general law you must tell both the person and the regulator. The law sets no deadline at all, so treat it as immediately. A supplier must tell its customer company as soon as it knows. If the central bank licenses you, you report to three bodies at once. Inside the financial free zone the deadline is seventy-two hours.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data
Clock one, the general law. Article 13 of Law No. 13 of 2016 covers suppliers. A supplier must tell the company it works for about any failure of the security measures. The same applies to any risk threatening people's personal data. It must do so as soon as it knows. Article 14 requires the company itself to tell both the person and the competent department about any such failure. That duty applies where the failure would cause serious harm to the data or to the person's privacy. No hour count appears in the law. We found no decision setting one. Breaking Article 14 carries a fine of up to one million Qatari riyals, about two hundred and seventy-five thousand United States dollars. Breaking the security duty in Article 13 carries up to five million riyals, about one and a third million dollars. Clock two, financial services. Clauses 16.1 to 16.3 of the Qatar Central Bank Data Handling and Protection Regulation apply to financial institutions. They must treat any data breach or data privacy breach as an incident. They must report it under the bank's incident reporting guidelines. They must report it to the central bank and to the authorised agencies in Qatar. The regulation names those as the National Cyber Security Agency and the Ministry of Interior. The incident reporting guidelines are not on the bank's public site. So the actual hour count cannot be checked publicly. Clock three, the Qatar Financial Centre. Article 31 of the QFC Data Protection Regulations requires you to report a personal data breach. DATA 9 of the QFC Data Protection Rules adds a deadline. A report made more than seventy-two hours after you became aware must explain the delay. The report must describe the types and rough numbers of people and records affected, the likely consequences, and what you have done about it. A fourth clock applies to the public sector. Article 22 of the cybercrime law covers state bodies. They must report any offence under that law to the competent authority as soon as they discover it. That includes any attempted unlawful interception or eavesdropping. They must supply all the information needed to establish the facts.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Rules, DATA 9 — Notification of Personal Data Breaches
qfcra-en.thomsonreuters.com
“if the notification is not made within 72 hours after becoming aware of the Personal Data Breach, give reasons for the delay”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people here. The fines are criminal, not administrative. Sensitive data needs a government permit before you touch it, and the rules for getting one were never published. There is no age that defines a child. Since August 2025 it is a crime to post a photo of someone in a public place without their knowledge. And a company inside the Qatar Financial Centre is outside the national law entirely.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. The fines are criminal. Articles 23 to 25 of Law No. 13 of 2016 are written as criminal penalties. A person is 'punished' with a fine of up to one million riyals for breaking the core duties. The fine rises to five million riyals for breaking the security duty, the sensitive-data permit duty or the children's website duty. A company faces up to one million riyals where an offence is committed in its name and for its account. That does not remove the criminal liability of the individual responsible. So this means prosecution, a criminal record and personal exposure for named people. It is not an administrative penalty notice. 2. Sensitive data needs a permit you cannot apply for. Article 16 bans handling data on ethnic origin, children, health or physical or mental condition, religious belief, marital relationship or criminal offences. You need a permit from the competent department first. The procedure is to be fixed by a decision of the Minister. We found no such decision published in the official gazette. The ban is written as absolute and carries the five-million-riyal penalty. So the gap is a live commercial risk, not a technicality. The Minister can also add new types of sensitive data by decision at any time. 3. There is no defined age for a child. Article 17 places real duties on any website aimed at children. Publish what children's data you collect and how you use it. Get the express consent of the child's guardian, electronically or by another suitable means. Give the guardian a description and a copy of the data on request. Delete the data or stop using it if the guardian asks. Never make joining a game or a prize offer conditional on handing over more data than the activity needs. The definitions article does not define 'child'. Under general Qatari law the age of majority is eighteen. That is higher than the thirteen many global platforms use. 4. Photographing people in public is now a crime. Law No. 11 of 2025 was published on 4 August 2025. It added Article 8 bis to the cybercrime law. It is now an offence to publish or share photographs or video of people while they are in public places. That applies where they did not know or did not agree, and outside the cases the law allows. It covers publishing over the internet or by any information technology means. The penalty is up to one year in prison, a fine of up to one hundred thousand riyals, or both. That fine is about twenty-seven thousand United States dollars. This catches ordinary marketing footage, event photography and street-level product images. 5. The free zone is a different country for this purpose. Article 2 of the QFC Data Protection Regulations 2021 is clear. As far as the QFC Law permits, the laws, rules and regulations of the State of Qatar on these matters do not apply inside the Centre. A group with companies on both sides of that line needs two compliance programmes, not one. 6. A bonus trap that runs backwards. Article 15 makes it an offence for a company to restrict data flowing across the border. A well-meaning internal policy that blocks all use of data abroad is, read literally, the thing the law punishes.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
What's changing next
Nothing major is scheduled in the next twelve months that we could verify. The most recent change has already landed. The public-photography offence took effect in August 2025. The bigger risk is what the government can already do without asking anyone. Several powers sit unused in the existing law and could change the answer overnight.
Confirmed and already in force. Law No. 11 of 2025 is dated 21 July 2025. It was published in Official Gazette issue 20 of 4 August 2025. It added the public-place photography offence to the cybercrime law. The Qatar Central Bank Cloud Computing Regulation has been in force since 15 April 2024. The Data Handling and Protection Regulation was published on the bank's site in February 2025. Pending. The Communications Regulatory Authority has issued a Spam Regulation and consulted on an amended draft. But the two live consultations on its site on 18 August 2026 were about radio spectrum fees and postal licence fees. Neither touches data. No change to Law No. 13 of 2016 has been gazetted since it was passed. The law's card on the official legal portal shows no amendments. Powers that already exist and could be switched on. These matter more than pending bills. - Article 16 lets the Minister add new types of sensitive personal data by decision alone, and set extra protective measures for them. Whole datasets could move into permit-only territory with no consultation. - Articles 7, 8(4), 16 and 18 all call for decisions of the Minister that we could not find published. Issuing them would turn a broadly worded law into a detailed set of rules overnight. - Article 30 lets the Cabinet extend the compliance period 'for a similar period or periods' on the Minister's proposal. It has already used that power once. - Article 18 lets any competent government body switch off the consent rule, the notice rule, the cross-border flow rule and the children's rule. The grounds are national security, public security, international relations, the State's economic or financial interests, or preventing, detecting or investigating crime. The body only has to keep an internal record of what it did. - Clause 23 of the central bank's Cloud Computing Regulation and clause 17 of its Data Handling and Protection Regulation make every exemption time-limited and revocable. A bank's permission to handle data abroad can lapse or be withdrawn. - Under Article 23 of the QFC Data Protection Regulations, a country can lose its safe-enough status at any time. The Data Protection Office simply issues an updated list.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Official sourceCommunications Regulatory Authority, State of QatarCommunications Regulatory Authority — Active Consultations, checked 18 August 2026
cra.gov.qa
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clause 1 (commencement)
qcb.gov.qa
“The instructions set forth herein are titled the Cloud Computing Regulation and will enter into force as of 15/04/2024.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking rules
Official name: Data Handling and Protection Regulation · Qatar Central Bank, Data Handling and Protection Regulation, clauses 11, 15, 16 and 17 · Directly binding regulation
Every financial institution the Qatar Central Bank supervises is banned from storing or sending customer personal or financial data abroad without the bank's approval. It must keep that data for ten years. It must report breaches to three separate bodies.
Enforced by Qatar Central Bank
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Keep the data in the countryNo storing or sending of personal data, personally identifiable information, sensitive personal information or sensitive financial information to another country without the central bank's approval.
- Put a transfer safeguard in placeBefore any transfer abroad, assess the risk of the destination country and of the other party. Also examine that country's data protection rules.
- Keep data for a minimum period — 10 yearsTen years for sensitive financial information, and for personal data, personally identifiable information and sensitive personal information. One year for technical information.
- Report breaches to the regulatorReport to the central bank and to the authorised agencies in Qatar. The regulation names those as the National Cyber Security Agency and the Ministry of Interior.
- Keep records of how you use dataA written record of how the institution collects, uses, stores and shares personal data.
- Assess high-risk projects
- Independent audit
- Get consentConsent records must capture purpose, identity, date, method and the privacy policy in force at the time.
What it costs if you get it wrong
- Order to stopSupervisory action by the Qatar Central Bank under the QCB Law
- Loss of your licenceSupervisory action by the Qatar Central Bank under the QCB Law
Sources
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clause 15.1
qcb.gov.qa
“A Financial Institution must not store or transfer Personal Data, PII, SPI and SFI to a foreign jurisdiction unless it has received approval from QCB.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Data Handling and Protection Regulation — clauses 11.3 and 16.3
qcb.gov.qa
“A Financial Institution must report Data Breaches and Data Privacy Breaches to QCB and the authorized agencies in Qatar which includes the National Cyber Security Agency and the Ministry of Interior.”
Link checked 18 August 2026
Finance data must stay in the country
Official name: Cloud Computing Regulation · Qatar Central Bank, Cloud Computing Regulation, clauses 1, 10, 18, 21 and 23 · Directly binding regulation
Since 15 April 2024 any organisation the Qatar Central Bank regulates must handle personal and financial information inside Qatar only. It must get the bank's approval before signing any cloud contract.
Enforced by Qatar Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — from 15 April 2024Personally identifiable information and financial information must be handled within Qatar only.
- Register or notify — from 15 April 2024Central bank approval is required before entering into any cloud arrangement, and every cloud arrangement must be entered in a register.
- Written vendor contractYou must be able to end the contract on change of control, insolvency, or a serious data or security breach. The same applies if the provider proposes to move data to an unacceptable location.
- Secure the data
- Make switching cloud provider possibleA documented exit plan covering both a managed exit and a stressed exit.
- Independent auditRegular architecture, configuration, compliance, source-code, vulnerability and penetration testing according to the service model.
What it costs if you get it wrong
- Order to stopSupervisory action by the Qatar Central Bank
Sources
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clauses 1, 21.4, 21.5 and 23
qcb.gov.qa
“An Entity must ensure that PII and financial information is processed within Qatar only.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Cloud Computing Regulation — clause 1 (commencement)
qcb.gov.qa
“The instructions set forth herein are titled the Cloud Computing Regulation and will enter into force as of 15/04/2024.”
Link checked 18 August 2026
- Official sourceQatar Central BankQatar Central Bank, Information and Cyber Security Regulation for Payment Service Providers — clause 6.8
qcb.gov.qa
“the generation and storage of the private keys outside of the cloud environment, on-premises in Qatar”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: قانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية · Law No. 13 of 2016 on the Protection of Personal Data Privacy, Articles 4, 5, 6, 8-17, 22-26 · Act of parliament
Qatar's general privacy law lets personal data leave the country freely. It even bans a company from restricting data flowing across the border. In exchange it requires consent, notice, individual rights, security and breach reporting. It also requires a permit for sensitive types of data. All of it is backed by criminal fines.
Enforced by National Cyber Security Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consentConsent is the default. You may use data without consent only where it is necessary for a legitimate purpose of yours, or of the party you send the data to.
- Tell people what you doBefore you start, tell the person who your company is and why you want the data. Give a full and accurate description of what you will do with it and who you will share it with.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulatorRequired where the failure would cause serious harm to the data or to the person's privacy. The law states no deadline.
- Tell affected peopleSame trigger, and again no deadline.
- Independent auditYou must run full audits and reviews of your own compliance.
- Written vendor contractYou must check that your suppliers follow your instructions and take suitable protective measures. You must keep checking.
- Get a parent's consent for childrenExpress consent of the child's guardian for any website directed at children. No age is defined.
- Register or notifyYou need a permit from the competent department before you handle sensitive types of data. The procedure comes from a Minister's decision that we could not find published.
- Publish a complaints contactYou must have systems to receive and review complaints, and requests to see, correct or delete data. People must be able to use them.
What it costs if you get it wrong
- Criminal liability: QAR 1,000,000 — about $275 thousandBreach of Articles 4, 8, 9, 10, 11, 12, 14, 15 or 22, including restricting cross-border data flow
- Criminal liability: QAR 5,000,000 — about $1 millionBreach of the security duty, the sensitive-data permit duty or the children's website duty
- Criminal liability: QAR 1,000,000 — about $275 thousandOffence committed in the name and for the account of a company, without prejudice to the individual's own liability
- Order to stopThe competent department can order a controller or processor to remedy a breach within a set period
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 on the Protection of Personal Data Privacy — full consolidated text
almeezan.qa
“يُحظر على المراقب اتخاذ أي قرار أو إجراء من شأنه الحد من تدفق البيانات الشخصية عبر الحدود”
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 13 of 2016 — legislation card: dated 3 November 2016, Official Gazette issue 15 of 29 December 2016, 32 articles, status 'in force'
almeezan.qa
Link checked 18 August 2026
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Cabinet Decision No. 1 of 2018 extending the compliance period under Article 30 of Law No. 13 of 2016
almeezan.qa
“تُمد مهلة توفيق الأوضاع المنصوص عليها في المادة (30) من القانون رقم (13) لسنة 2016 المشار إليه، لمدة ستة أشهر تبدأ من 29/7/2017”
Link checked 18 August 2026
Breach reporting rules (Telecoms)
Official name: قانون رقم (14) لسنة 2014 بإصدار قانون مكافحة الجرائم الإلكترونية · Law No. 14 of 2014 on Combating Cybercrime, Articles 21 and 22 · Act of parliament
Telephone and internet providers must keep subscriber records for a year and freeze traffic or content data for ninety days when asked. Government bodies must keep the same kinds of data for at least a hundred and twenty days and report incidents immediately.
Enforced by Ministry of Interior
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 1 yearService providers must keep subscriber information for one year.
- Keep logsService providers must preserve information-technology data, traffic data or content information for ninety days, renewable. This applies when the competent authority or the investigating and prosecuting bodies ask.
- Keep data for a minimum period — 4 monthsState organs, institutions, bodies and their subsidiary entities and companies must keep information-technology data and subscriber information for at least one hundred and twenty days.
- Report cyber incidentsState bodies must report any offence under this law to the competent authority as soon as it is discovered, including attempted unlawful interception or eavesdropping.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityOffences under the cybercrime law
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 14 of 2014 issuing the Law on Combating Cybercrime — Articles 21 and 22
almeezan.qa
“الاحتفاظ بمعلومات المشترك لمدة سنة”
Link checked 18 August 2026
Social media and online platforms data rules
Official name: قانون رقم (11) لسنة 2025 بتعديل بعض أحكام قانون مكافحة الجرائم الإلكترونية · Law No. 11 of 2025 amending the Law on Combating Cybercrime, new Article 8 bis · Act of parliament
Since August 2025 it is a crime in Qatar to publish or share photographs or video of people in a public place. That applies unless they knew about it or agreed. It carries up to a year in prison.
Enforced by Ministry of Interior
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consent — from 4 August 2025Knowledge or consent of the people shown is required before publishing or circulating photographs or video taken of them in public places.
What it costs if you get it wrong
- Criminal liability: QAR 100,000 — about $27 thousandPublishing or circulating photographs or video of people in public places without their knowledge or consent, over the information network or by any information technology means. Up to one year in prison, the fine, or both.
Sources
- Official sourceAl Meezan, Qatari Legal Portal (Ministry of Justice)Law No. 11 of 2025 amending the Law on Combating Cybercrime — new Article 8 bis
almeezan.qa
“يعاقب بالحبس مدة لا تجاوز سنة، وبالغرامة التي لا تزيد على (100,000) مائة ألف ريال”
Link checked 18 August 2026
Applies only in certain states1 rule
Made by a state or province. It only binds you for the people living there.
Breach reporting rules (QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9)
Official name: QFC Data Protection Regulations 2021 · QFC Data Protection Regulations 2021 (version 3, December 2023), Articles 2, 3, 12, 23, 24, 27, 31-36; QFC Data Protection Rules, DATA 2, DATA 5, DATA 9 · Directly binding regulation
Companies registered in the Qatar Financial Centre sit outside the national privacy law. They follow European-style rules instead. Those include a list of approved countries, standard contract clauses, group-wide rules and a seventy-two hour deadline for reporting breaches.
Enforced by Qatar Financial Centre Data Protection Office — not yet operational
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hoursA notification made later than seventy-two hours after becoming aware must explain the delay.
- Assess high-risk projects
- Keep records of how you use data
- Written vendor contract
- Let people take their data elsewhere
- Limit automated decisions
- Register or notifyYou need a permit from the Data Protection Office to handle sensitive personal data.
What it costs if you get it wrong
- Fixed maximum finePenalties must be effective, proportionate and dissuasive; they may be imposed instead of or in addition to orders of the Data Protection Office
- Claims by individualsIndividuals have a right to compensation for damage
- Order to stopOrders of the Data Protection Office
Sources
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations 2021 (version 3, December 2023) — Articles 2, 3, 23, 24 and 36
qfcra-en.thomsonreuters.com
“To the fullest extent permitted by the QFC Law, the laws, rules and regulations of the State of Qatar concerning the matters dealt with, by or under these Regulations do not apply in the QFC.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 23 — Transfers Out of the QFC: Adequate Level of Protection
qfcra-en.thomsonreuters.com
“Any Processing of Personal Data which involves the transfer of Personal Data to a Recipient located in a jurisdiction outside the QFC may take place if the Data Protection Office has decided that the jurisdiction has an adequate level of protection.”
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Regulations, Article 24 — Transfers Out of the QFC in the Absence of an Adequate Level of Protection
qfcra-en.thomsonreuters.com
Link checked 18 August 2026
- Secondary sourceQatar Financial Centre Regulatory Authority RulebookQFC Data Protection Rules, DATA 9 — Notification of Personal Data Breaches
qfcra-en.thomsonreuters.com
“if the notification is not made within 72 hours after becoming aware of the Personal Data Breach, give reasons for the delay”
Link checked 18 August 2026
- Official sourceQatar Financial Centre AuthorityQatar Financial Centre — Laws and Regulations
qfc.qa
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether Law No. 13 of 2016 reaches a foreign company with no establishment in Qatar.
We could not confirm whether this law reaches companies with no office in Qatar. The law has no article about which territory it covers. Article 2 sets only what kinds of data it covers. We found no official interpretation, guidance or court ruling on a Qatari government website, checked 18 August 2026.
The exact date Law No. 13 of 2016 entered into force.
The law does not state when it started. We worked out 29 January 2017 from Cabinet Decision No. 1 of 2018. That decision extends the six-month compliance period in Article 30 'for six months beginning 29/7/2017'. The reasoning is sound, but it is our inference, not a stated date.
Whether the Minister ever issued the implementing decisions the law requires.
We could not confirm that the Minister ever issued the decisions the law calls for. Articles 7, 8(4), 16 and 18 all require them. That includes the procedure for getting a permit to handle sensitive personal data. Searches of the official legal portal on 18 August 2026 found none. That is strong evidence but not proof.
Whether the National Cyber Security Agency has issued any data protection penalty, order or guidance.
We could not read any official Qatari source for the agency's privacy work. Its website serves content from a host we could not reach. The national services portal was showing a maintenance page. Ask the agency directly if you need its current position.
The commencement date of the Qatar Central Bank Data Handling and Protection Regulation.
We could not confirm when this document took effect. Unlike the Cloud Computing Regulation, it has no short-title or start-date clause. It is published on the central bank's own information security page with a file date of February 2025. That is the only date evidence available.
The breach reporting deadline for financial institutions in hours.
We could not confirm the deadline for reporting an incident to the central bank. Clause 16.1 of the Data Handling and Protection Regulation points to 'QCB's incident reporting guidelines'. Those guidelines are not on the central bank's public website. Ask the bank for them.
Whether the Qatar Financial Centre Data Protection Office has published a list of adequate jurisdictions.
We could not confirm that the Qatar Financial Centre has published the countries it treats as safe enough. Article 23(4) requires it to publish those decisions. We found no such list on the Centre's own site. Its rulebook sits on a commercial website, not a government one.
Whether any localisation or data-storage rule exists for health, education, government cloud or mapping data.
We found no such rule in the official gazette or on the regulator sites we could reach, checked 18 August 2026. But we could not confirm this against every government source. The Ministry of Public Health site and the national services portal serve content only to a full browser. We could not obtain the National Information Assurance Policy that the Cloud Policy Framework refers to. If you work in these industries, check before you rely on this.
The primary text of the QFC Data Protection Regulations is cited from a commercial rulebook host.
The Qatar Financial Centre publishes its legislation on a Thomson Reuters rulebook site, not on its own website. We use the Centre's own laws and regulations page as the government link. But the working wording comes from that rulebook.
Whether any Qatari court has decided a case under the personal data privacy law.
We could not search the rulings database on the official legal portal. Draw no conclusion from that either way.
Ordinary commercial, tax and employment record-keeping floors in Qatar.
We only checked the privacy, cybercrime and central bank keeping periods. Company and tax law keeping periods also exist. We did not check them, so confirm those separately.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.