Skip to content
Intellectual Property & Technology

Data Protection and Privacy in Qatar: What Businesses Should Know

Published Last reviewed 12 min readPrepared by Almarshed Law Firm

What Qatar's personal data framework asks of businesses, which authorities oversee it, and what to review in internal policies.

Personal data processing in Qatar is governed by Law No. 13 of 2016 on Personal Data Privacy Protection, published in the Official Gazette, issue 15, on 29 December 2016. It runs to thirty-two articles and has its own terminology and structure. The most common error in approaching it is reading it through the vocabulary of foreign frameworks and assuming requirements it does not impose.

The terms the Law actually uses

A Controller is a natural or legal person who, acting alone or jointly with others, determines how personal data may be processed and the purposes of that processing. A Processor is a natural or legal person who processes personal data for the Controller. An Individual is the natural person whose data are processed. Personal data are data of an individual whose identity is defined, or can reasonably be defined, whether through those data or by combining them with other data (Article 1).

Article 1 also defines the Ministry as the Ministry of Transport and Communications, the Minister as the Minister of Transport and Communications, the Competent Department as the competent administrative unit at the Ministry, and the Competent Authority as any government entity legally competent to regulate and supervise acts or procedures pertinent to personal data processing. Those are the names as enacted. The institutional arrangements for supervision in practice have developed since the Law was issued, so the body currently exercising that function and the channels for dealing with it should be confirmed before corresponding with it or relying on its procedures.

What the Law applies to

The Law applies to personal data processed electronically, or obtained, gathered or extracted in any other way in preparation for electronic processing, or processed through a combination of electronic and traditional processing. It does not apply to personal data processed by individuals within a private or family scope, nor to data processed for the purpose of obtaining official statistics under Law No. 2 of 2011 (Article 2).

Every individual has the right to the privacy of their personal data, and such data may be processed only within a framework of transparency, honesty, respect for human dignity and acceptable practices, in accordance with the Law (Article 3).

Consent, and the lawful purpose

A controller may not process personal data without obtaining the individual's consent, unless the processing is necessary to achieve a lawful purpose of the controller or of the third party to whom the data are sent (Article 4). The structure is not a list of processing bases: it is a consent rule with an exception for necessity in pursuit of a lawful purpose. Lawful purpose is a defined term in the Law and is not to be read as any commercial interest.

Individual rights

An individual may at any time withdraw prior consent to processing; object to processing where it is not necessary for the purposes for which the data were collected, or is beyond those requirements, or is discriminatory, unfair or unlawful; request omission or erasure of the data in those cases, or where the purpose of processing has ended, or where there is no justification for the controller retaining them; and request correction of the data, accompanied by proof supporting the request (Article 5).

An individual may at any time access their personal data and apply to review them against any controller, and has in particular the right to be notified of the processing of their data and its purposes, to be notified of any disclosure of inaccurate personal data about them, and to obtain a copy of their data on payment of an amount not exceeding the service charge (Article 6). The controls and procedures for exercising these rights are set by a decision of the Minister (Article 7).

Controller and processor obligations

A controller must process data honestly and legitimately; observe the controls relating to designing, changing or developing products, systems and services pertinent to personal data processing; take appropriate administrative, technical and physical precautions to protect the data as determined by the Competent Department; and comply with the privacy protection policies developed by the Competent Department and issued by decision of the Minister (Article 8).

Before beginning any processing, the controller must inform the individual of the controller's details or those of any other party processing on its behalf or for its use, the lawful purposes of the processing, a comprehensive and accurate description of the processing activities and the degrees of disclosure for lawful purposes — or, where that is not possible, a general description — and any other information necessary to satisfy the conditions of processing (Article 9).

The controller must verify that the data it collects, or that are collected on its behalf, are relevant to the lawful purposes and sufficient to achieve them, and that they are accurate, complete and up to date for those purposes, and must not retain them longer than is necessary to achieve them (Article 10).

Article 11 sets out organisational steps the controller must take: reviewing privacy protection procedures before introducing new processing; designating the processors responsible for protecting personal data; training and raising their awareness; establishing internal systems for receiving and considering complaints and requests for access, correction or erasure, and making these available to individuals; establishing internal systems for effective data management and for reporting any breach of protective procedures; using appropriate technological means to let individuals access, review and correct their data directly; conducting comprehensive audits of compliance; and verifying the processor's compliance with its instructions and its adoption of appropriate precautions, monitoring this continuously.

When disclosing data or transferring them to a processor, the controller must ensure they conform to the lawful purposes and are processed in accordance with the Law (Article 12). That is the textual basis for reviewing supplier and service-provider contracts, addressed in the contractual framework.

Security, and breaches of precautions

Both controller and processor must take the necessary precautions to protect personal data from loss, damage, modification, disclosure, access or accidental or unlawful use, and those precautions must be proportionate to the nature and importance of the data. The processor must notify the controller of any breach of those precautions, or of any risk threatening individuals' personal data in any way, immediately upon becoming aware of it (Article 13).

The controller must inform the individual and the Competent Department of any breach of those precautions where it would cause serious harm to the personal data or to the individual's privacy (Article 14). The test is the seriousness of the harm, and the Law fixes no notification deadline. Anyone planning incident response should not assume a period drawn from another framework, and should check the guidance issued by the competent body.

Cross-border data flows

The drafting here deserves attention because it runs opposite to many expectations: a controller is prohibited from taking any decision or action that would restrict the cross-border flow of personal data, unless processing those data would contravene the Law or would cause serious harm to the personal data or to the individual's privacy (Article 15). The provision restrains impeding the flow, not the flow itself.

Special-nature data, and children

Data relating to ethnic origin, children, health or physical or psychological condition, religious beliefs, marital relationship and criminal offences are special-nature personal data. The Minister may add further categories where their misuse or disclosure would cause serious harm to the individual. Such data may be processed only after obtaining a permit from the Competent Department, in accordance with procedures and controls set by decision of the Minister, and the Minister may impose additional precautions to protect them (Article 16).

That prior-permit requirement is the point businesses most need to notice: processing these categories is not a matter of internal risk assessment — it requires a permit.

The Law sets a distinct regime for websites directed at children: the owner or operator must post a notice on the site about what children's data are collected, how they are used and its disclosure policies; obtain the explicit consent of the child's guardian by electronic communication or another suitable means; provide the guardian, on request and after verifying identity, with a description of the type of data processed, the purpose and a copy of the data; delete, erase or stop processing any data collected from or about the child if the guardian so requests; and not condition a child's participation in a game, prize offer or other activity on providing personal data beyond what is necessary to participate (Article 17).

Exemptions

A Competent Authority may decide to process certain personal data without being bound by Articles 4, 9, 15 and 17, in order to protect national security and public safety; protect the State's international relations; protect the State's economic or financial interests; or prevent, gather information about, or investigate a criminal offence. The Competent Authority keeps a dedicated register of such data (Article 18).

A controller is exempted from Articles 4, 5 (items 1, 2 and 3) and 6 where it is executing a task related to the public interest under the law; implementing a legal obligation or an order of a competent court; protecting the vital interests of the individual; pursuing the purposes of scientific research conducted in the public interest; or gathering information necessary to investigate a criminal offence on the official request of investigative bodies (Article 19).

A controller is exempted from disclosing its reasons for refusing to comply with the individual's rights under Article 6 where disclosure would prevent achieving the purposes stipulated in Article 18 (Article 20). It is also exempted from Article 6 where disclosure would harm another person's commercial interests, or where compliance would disclose personal data relating to another individual who has not consented and disclosure may cause that or any other individual physical or moral damage (Article 21).

Direct marketing

Sending any electronic communication for the purpose of direct marketing to an individual is prohibited without their prior consent. The communication must identify its sender, indicate that it is sent for direct marketing purposes, and include a valid and easily accessible address through which the individual can ask the sender to stop such communications or withdraw consent to receiving them (Article 22).

Penalties and complaints

Without prejudice to any severer penalty in another law, a fine of up to one million riyals applies to breaches of Articles 4, 8, 9, 10, 11, 12, 14, 15 and 22, and a fine of up to five million riyals to breaches of Articles 13, 16 (third paragraph) and 17. A legal person is fined up to one million riyals where one of the offences under the Law is committed in its name and for its account, without prejudice to the criminal liability of the natural person associated with it (Articles 23 to 25).

An individual may complain to the Competent Department where the Law or the decisions issued under it are breached. After investigating and establishing that the complaint is serious, the Competent Department may issue a reasoned decision requiring the controller or processor to remedy the breach within a period it sets. That decision may be appealed to the Minister within sixty days of notification; the Minister decides within sixty days of submission, expiry of that period without a reply counts as implicit rejection, and the Minister's decision is final (Article 26).

In applying the Law, the Competent Department may take all necessary measures, and in particular: coordinate with any professional group or association representing controllers or website operators to encourage self-regulation, raise awareness and develop training programmes; work with organisations and associations concerned with family affairs to promote children's online safety; and conduct research, monitor technological developments and prepare reports and recommendations (Article 27).

One provision carries particular commercial weight: any contract or agreement made in breach of the Law is void (Article 28). Ministry employees designated by a decision of the Attorney-General in agreement with the Minister have the status of judicial enforcement officers for detecting and establishing offences under the Law (Article 29). Article 30 required those subject to the Law to bring their positions into conformity within six months of its commencement, with the Council of Ministers able to extend that period.

The QFC is a separate regime

All of the above concerns State law. The Qatar Financial Centre has its own legal and regulatory framework, including its own data protection rules. This article does not address those rules, and it should not be assumed that Law No. 13 of 2016 applies to an entity licensed in the QFC, or the reverse. A business licensed there should confirm the framework applicable to it from that regime's own official sources.

What businesses should review

  • Establish whether the business is a controller, a processor, or both depending on the activity — the obligations differ.
  • The basis for each processing activity: consent, or necessity for a lawful purpose? And record it.
  • The prior information Article 9 requires, and whether existing privacy notices match it.
  • Whether the business processes special-nature data, which requires a permit from the Competent Department.
  • Websites and services directed at children, which attract the distinct regime in Article 17.
  • Supplier and processor contracts: instructions, precautions, continuous monitoring, and immediate notification of any breach.
  • Retention periods, since Article 10 prohibits keeping data longer than necessary.
  • Direct marketing communications: prior consent, sender identity, and a means to stop them.

The Minister issues the decisions necessary to implement the Law (Article 31), and the Competent Department develops the privacy protection policies and the controls governing precautions. The decisions and controls in force, and the body currently exercising supervision, should therefore be confirmed before a compliance programme is built on them. In particular, the channel for the notifications required under Article 14 and for complaints under Article 26 should be confirmed with the authority currently exercising supervision before a business relies on any filing or notification process. Our technology law practice and corporate and commercial team advise on reviewing data processing policies and related contracts.

Key takeaways

  • Law No. 13 of 2016 governs personal data privacy in Qatar and uses its own terms — Controller and Processor — rather than the vocabulary of foreign frameworks.
  • A controller may not process personal data without the individual's consent, unless processing is necessary to achieve a lawful purpose of the controller or of the recipient (Article 4).
  • Special-nature data — including data on children, health, religious belief and criminal offences — may be processed only with a permit from the Competent Department (Article 16).
  • The Law sets no fixed breach-notification deadline: it requires informing the individual and the Competent Department where the breach would cause serious harm (Article 14).
  • Electronic communications for direct marketing are prohibited without prior consent, and must identify the sender and provide a means to stop them (Article 22).
  • Fines reach one million riyals, and five million for breaches of Articles 13, 16(3) and 17 (Articles 23 and 24).
  • Any contract or agreement made in breach of the Law is void (Article 28).
  1. Law No. 13 of 2016 on Personal Data Privacy Protection — Articles 1 to 32

    Al Meezan — Qatary Legal Portal (Arabic text); Official Gazette issue 15, 29 December 2016

Need legal guidance?

Speak with our legal team.

+974 5122 2353