🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
QA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-07

Qatar

QA schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
12Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Standing brief, as of 14 September 2026.

Lead Signal

Qatar's data-protection enforcement posture has moved decisively from an awareness phase into a pattern of active, dated binding decisions. The National Data Privacy Office, operating within the National Cyber Security Agency, issued its most recent binding ruling in February 2026 against a sports-sector company, finding that it had failed to implement adequate technical, administrative and physical safeguards, a failure that contributed to a personal-data breach. This follows binding compliance rulings against an ICT-sector company in December 2024 and an e-commerce operator in March 2025, establishing a clear cadence of enforcement activity rather than an isolated action. Administrative fines under the PDPPL range from QAR 1,000,000 to QAR 5,000,000 depending on the article violated, and this fine range, together with the escalating cadence of binding decisions, is the clearest evidence available this cycle that Qatar's regulator has operationalised its enforcement powers rather than holding them in reserve.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Both primary instruments are identified and verifiably in force, but mainland secondary guidance (Tier-2) is thin and the dual-perimeter structure creates residual scoping ambiguity for firms operating across both.

Primary frameworkLaw No. 13 of 2016 Concerning Privacy and Protection of Personal Data (mainland Qatar)
Traffic-light rationale — AmberBoth primary instruments are identified and verifiably in force, but mainland secondary guidance (Tier-2) is thin and the dual-perimeter structure creates residual scoping ambiguity for firms operating across both.

Sub-modules (5)

Regulator And AuthorityAmber

Mainland: NCSA's National Cyber Governance and Assurance Affairs division is the supervisory authority for Law 13/2016. QFC free zone: the independent QFC Data Protection Office, under the QFC Authority, administers the QFC Data Protection Regulations 2021.

Claims (2):

  • The National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA) is the supervisory authority for Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data in mainland Qatar.
  • The QFC Data Protection Office is an independent institution of the Qatar Financial Centre charged with administering the QFC Data Protection Regulations 2021 and all aspects of data protection within the QFC.

Act And InstrumentsGreen

Mainland instrument: Law No. 13 of 2016, published in the Official Gazette 29 December 2016. QFC instrument: QFC Data Protection Regulations 2021 plus the Data Protection Rules 2021, which replaced the 2005 QFC Data Protection Regulation and Rules.

Claims (2):

  • Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data was published in Qatar's Official Gazette on 29 December 2016 and became effective in 2017.
  • The QFC Data Protection Regulations 2021, supported by the Data Protection Rules 2021, came into force on 19 June 2022, replacing the QFC Data Protection Regulations and Rules 2005.

Material ScopeGreen

Mainland Law 13/2016 covers only electronically processed personal data (or data gathered for electronic processing), excluding purely private/family processing and official surveys/statistics. QFC Regulations apply to Data Controllers/Processors incorporated or registered in the QFC.

Claims (2):

  • Law No. 13 of 2016 applies only to personal data that is electronically processed, or gathered/extracted in preparation for electronic processing, and does not apply to private/family processing or data gathered for official surveys and statistics.
  • The QFC Data Protection Regulations 2021 apply to a Data Controller or Data Processor incorporated or registered in the QFC.

Territorial ScopeAmber

The QFC Commissioner interprets Article 7(2) as extending the Regulations to non-QFC-licensed firms that process personal data of data subjects in Qatar on an ongoing (non-occasional) basis, and QFC guidance confirms a non-QFC controller processing a QFC subsidiary's employee data for that subsidiary's benefit is itself caught. No equivalent explicit extraterritorial clause was located for mainland Law 13/2016 in the sources reviewed.

Claims (1):

  • The QFC Data Protection Office interprets the Regulations as applying to non-QFC-licensed firms that process personal data of data subjects located in Qatar on an ongoing (more than occasional) basis, including non-QFC controllers processing data of a QFC subsidiary's employees.

Regulator Registration And FilingAmber

QFC Data Controllers have no general obligation to register with the Data Protection Office. Mainland Law 13/2016 requires Competent Department permission before processing personal data of a 'special nature.'

Claims (2):

  • QFC Data Controllers have no general obligation to register with the QFC Data Protection Office.
  • Under mainland Law No. 13 of 2016, personal data of a special nature may only be processed after obtaining permission from the Competent Department, per measures determined by ministerial decision.
Category narrative123 words

Qatar operates two entirely separate data-protection perimeters. Mainland Qatar is governed by Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data, supervised by the National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA), with implementation guidance historically issued via the Ministry of Transport and Communications (MOTC) Compliance and Data Protection Department. Separately, the Qatar Financial Centre (QFC) free zone operates the QFC Data Protection Regulations 2021 (in force since 19 June 2022, replacing the 2005 regime), administered by the independent QFC Data Protection Office (DPO) under the QFC Authority. The two regimes do not apply to each other's perimeter; QFC Law expressly disapplies mainland civil/regulatory law matters covered by the QFC Regulations within the QFC.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (9)
  1. ConfirmedDataGuidance — The National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA) is the supervisory authority for Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data in mainland Qatar.observed
  2. ConfirmedQatar Financial Centre — The QFC Data Protection Office is an independent institution of the Qatar Financial Centre charged with administering the QFC Data Protection Regulations 2021 and all aspects of data protection within the QFC.observed
  3. ConfirmedDataGuidance — Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data was published in Qatar's Official Gazette on 29 December 2016 and became effective in 2017.observed
  4. ConfirmedQatar Financial Centre — The QFC Data Protection Regulations 2021, supported by the Data Protection Rules 2021, came into force on 19 June 2022, replacing the QFC Data Protection Regulations and Rules 2005.observed
  5. ConfirmedMOTC — Law No. 13 of 2016 applies only to personal data that is electronically processed, or gathered/extracted in preparation for electronic processing, and does not apply to private/family processing or data gathered for official surveys and statistics.observed
  6. ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 apply to a Data Controller or Data Processor incorporated or registered in the QFC.observed
  7. ProbableQatar Financial Centre Data Protection Office — The QFC Data Protection Office interprets the Regulations as applying to non-QFC-licensed firms that process personal data of data subjects located in Qatar on an ongoing (more than occasional) basis, including non-QFC controllers processing data of a QFC subsidiary's employees.observed
  8. ConfirmedQatar Financial Centre — QFC Data Controllers have no general obligation to register with the QFC Data Protection Office.observed
  9. ConfirmedDataGuidance (unofficial translation) — Under mainland Law No. 13 of 2016, personal data of a special nature may only be processed after obtaining permission from the Competent Department, per measures determined by ministerial decision.observed

#

Lawful bases, consent and special-category rules are confirmed for both regimes; pseudonymisation/anonymisation treatment is an unresolved gap.

Primary frameworkLaw No. 13 of 2016 (mainland); QFC Data Protection Regulations 2021, Articles 10-12 (QFC)
Traffic-light rationale — AmberLawful bases, consent and special-category rules are confirmed for both regimes; pseudonymisation/anonymisation treatment is an unresolved gap.

Sub-modules (4)

Lawful BasesGreen

Mainland: consent of the data subject is the main legal basis for processing. QFC: Article 10 enumerates the lawful bases (bases) under which all Personal Data Processing must take place.

Claims (2):

  • Mainland Law No. 13 of 2016 establishes the consent of the data subject as the main legal basis for processing personal data.
  • Article 10 of the QFC Data Protection Regulations 2021 sets out the lawful basis or bases under which all Personal Data Processing must take place.

Special CategoriesGreen

Mainland: special-nature data requires Competent Department permission and may be subject to Minister-imposed additional precautions. QFC Article 12 separately governs processing of Sensitive Personal Data.

Claims (2):

  • Under mainland Law No. 13 of 2016, the Minister may impose additional precautions to protect personal data of a special nature by ministerial decision.
  • Article 12 of the QFC Data Protection Regulations 2021 separately governs the Processing of Sensitive Personal Data.

Pseudonymisation And AnonymisationRed

No pseudonymisation or anonymisation definitions, safe-harbours, or exemptions were identified for either the mainland Law 13/2016 regime or the QFC Data Protection Regulations 2021 in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative57 words

Mainland Law 13/2016 establishes consent as the principal lawful basis, with a withdrawal right and specific notification requirements for sensitive/special-nature data. The QFC Regulations set out lawful bases in Article 10, consent conditions in Article 11, and sensitive personal data rules in Article 12. No pseudonymisation/anonymisation safe-harbour definitions were located in either regime within the sources reviewed.

Sources and claims (6)
  1. ConfirmedDataGuidance — Mainland Law No. 13 of 2016 establishes the consent of the data subject as the main legal basis for processing personal data.observed
  2. ConfirmedQatar Financial Centre Authority — Article 10 of the QFC Data Protection Regulations 2021 sets out the lawful basis or bases under which all Personal Data Processing must take place.observed
  3. ConfirmedDataGuidance (unofficial translation) — Mainland Law No. 13 of 2016 provides individuals a right to withdraw their prior consent to personal data processing.observed
  4. ConfirmedQatar Financial Centre Authority — Article 11 of the QFC Data Protection Regulations 2021 sets out the conditions for valid consent to processing.observed
  5. ConfirmedDataGuidance (unofficial translation) — Under mainland Law No. 13 of 2016, the Minister may impose additional precautions to protect personal data of a special nature by ministerial decision.observed
  6. ConfirmedQatar Financial Centre Authority — Article 12 of the QFC Data Protection Regulations 2021 separately governs the Processing of Sensitive Personal Data.observed

#

QFC rights framework is well-documented and comprehensive; mainland rights detail and statutory response deadlines are thinly sourced.

Primary frameworkQFC Data Protection Regulations 2021, Articles 16-22
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — AmberQFC rights framework is well-documented and comprehensive; mainland rights detail and statutory response deadlines are thinly sourced.

Sub-modules (5)

Access RightGreen

QFC Article 16 establishes the right to access.

Claims (1):

  • The QFC Data Protection Regulations 2021 grant data subjects a right to access their personal data (Article 16).

Rectification And ErasureGreen

QFC Articles 17-18 establish rights to rectification and erasure.

Claims (1):

  • The QFC Data Protection Regulations 2021 grant data subjects rights to rectification (Article 17) and erasure (Article 18).

Restriction And ObjectionGreen

QFC Articles 19-20 establish rights to object (including opt-out from automated decision-making/profiling) and to restriction of processing.

Claims (1):

  • The QFC Data Protection Regulations 2021 grant data subjects rights to object (Article 19), to restriction of processing (Article 20), and not to be subject to automated individual decision-making, including profiling.

Data PortabilityGreen

The QFC Regulations grant data subjects a right to data portability.

Claims (1):

  • Data subjects under the QFC Data Protection Regulations 2021 are empowered with a right to data portability.

Deadlines And Response WindowsRed

QFC guidance references a 'without undue delay' standard for controller action on some data-subject requests, but a codified numeric response window (e.g., 30 days) was not confirmed in the sources reviewed for either regime, and no mainland deadline provision was located.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • QFC Data Protection Regulations 2021 guidance references an obligation for controllers to provide personal data to a data subject without undue delay in response to certain requests.
Category narrative62 words

The QFC Data Protection Regulations 2021 provide a full rights suite (access, rectification, erasure, objection, restriction, portability, and a right not to be subject to solely automated decision-making including profiling) at Articles 16-22. Mainland Law 13/2016's rights framework is less granularly documented in the sources reviewed beyond the consent-withdrawal right; a specific mainland statutory response-time deadline for subject requests was not located.

Sources and claims (5)
  1. ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 grant data subjects a right to access their personal data (Article 16).observed
  2. ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 grant data subjects rights to rectification (Article 17) and erasure (Article 18).observed
  3. ConfirmedQatar Financial Centre — The QFC Data Protection Regulations 2021 grant data subjects rights to object (Article 19), to restriction of processing (Article 20), and not to be subject to automated individual decision-making, including profiling.observed
  4. ConfirmedQatar Financial Centre — Data subjects under the QFC Data Protection Regulations 2021 are empowered with a right to data portability.observed
  5. UncertainQatar Financial Centre Authority — QFC Data Protection Regulations 2021 guidance references an obligation for controllers to provide personal data to a data subject without undue delay in response to certain requests.observed

#

Core accountability, security, ROPA and breach-notification duties are well-evidenced for the QFC; DPO-appointment obligation for firms is unresolved, and mainland retention/disposal rules were not located.

Primary frameworkQFC Data Protection Regulations 2021, Articles 25-31
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — AmberCore accountability, security, ROPA and breach-notification duties are well-evidenced for the QFC; DPO-appointment obligation for firms is unresolved, and mainland retention/disposal rules were not located.

Sub-modules (7)

Accountability And DpiaGreen

QFC Article 26 requires data protection by design and by default; Article 27 requires DPIAs to be conducted in certain circumstances.

Claims (1):

  • Article 26 of the QFC Data Protection Regulations 2021 requires data protection by design and by default, and Article 27 requires Data Protection Impact Assessments in certain circumstances.

Dpo RequirementsAmber

Secondary commentary is split: one analysis states the QFC's 2023 Data Protection Rules update 'lacks requirements for a Data Protection Officer' for regulated firms, distinct from the QFC's own regulator-level Data Protection Office/Commissioner.

Claims (1):

  • Secondary legal commentary indicates the QFC's updated Data Protection Rules lack an explicit requirement for regulated firms to appoint an internal Data Protection Officer, distinct from the QFC's own regulator-level Data Protection Office.

Ropa RequirementsGreen

QFC Article 30 requires a record of processing operations.

Claims (1):

  • Article 30 of the QFC Data Protection Regulations 2021 requires controllers to maintain a record of processing operations.

Joint Controller ArrangementsAmber

QFC Article 28 addresses Data Processor obligations and processor liability where a processor has not complied with obligations specifically directed to it; no distinct 'joint controller' provision was located in the sources reviewed for either regime.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • Article 28 of the QFC Data Protection Regulations 2021 addresses Data Processor obligations, with a Data Processor liable for damage caused by processing only where it has not complied with obligations specifically directed to Data Processors.

Security MeasuresGreen

QFC Article 29 sets security-of-processing requirements; mainland Law 13/2016 requires precautions against loss, damage, modification, disclosure, or unauthorized access.

Claims (2):

  • Article 29 of the QFC Data Protection Regulations 2021 sets out security-of-processing requirements for Data Controllers and Data Processors.
  • Mainland Law No. 13 of 2016 requires organizations to train data handlers and take necessary precautions to protect personal data from loss, damage, modification, disclosure, or unauthorized access.

Breach NotificationGreen

QFC Article 31 requires notification of personal data breaches to the Data Protection Office within 72 hours, unless the controller determines the breach is unlikely to result in a risk to data subjects.

Claims (1):

  • Article 31 of the QFC Data Protection Regulations 2021 obligates Data Controllers to notify the Data Protection Office of all Personal Data Breaches within 72 hours, except where the breach is determined unlikely to result in a risk to data subjects.

Retention And DisposalAmber

QFC guidance references a storage-limitation principle (Principle 5) requiring data not be kept longer than necessary. No mainland Law 13/2016 retention/disposal provision was located in the sources reviewed.

Claims (1):

  • QFC Data Protection Regulations guidance identifies storage limitation as one of the core processing principles (Principle 5), requiring data not be retained longer than necessary for its purpose.
Category narrative84 words

The QFC Data Protection Regulations 2021 impose accountability duties including data protection by design/default (Article 26), DPIA obligations (Article 27), processor obligations (Article 28), security-of-processing measures (Article 29), records of processing (Article 30), and 72-hour breach notification to the DPO (Article 31). Mainland Law 13/2016 requires organizations to train data handlers and take precautions against loss, damage, modification, disclosure, or unauthorized access. Whether QFC firms must appoint an internal Data Protection Officer (distinct from the QFC's own regulator-level DPO) is contested across secondary sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (8)
  1. ConfirmedQatar Financial Centre Authority — Article 26 of the QFC Data Protection Regulations 2021 requires data protection by design and by default, and Article 27 requires Data Protection Impact Assessments in certain circumstances.observed
  2. UncertainDataGuidance — Secondary legal commentary indicates the QFC's updated Data Protection Rules lack an explicit requirement for regulated firms to appoint an internal Data Protection Officer, distinct from the QFC's own regulator-level Data Protection Office.observed
  3. ConfirmedQatar Financial Centre Authority — Article 30 of the QFC Data Protection Regulations 2021 requires controllers to maintain a record of processing operations.observed
  4. ConfirmedQatar Financial Centre Authority — Article 28 of the QFC Data Protection Regulations 2021 addresses Data Processor obligations, with a Data Processor liable for damage caused by processing only where it has not complied with obligations specifically directed to Data Processors.observed
  5. ConfirmedQatar Financial Centre Authority — Article 29 of the QFC Data Protection Regulations 2021 sets out security-of-processing requirements for Data Controllers and Data Processors.observed
  6. ConfirmedMOTC — Mainland Law No. 13 of 2016 requires organizations to train data handlers and take necessary precautions to protect personal data from loss, damage, modification, disclosure, or unauthorized access.observed
  7. ConfirmedQatar Financial Centre Authority — Article 31 of the QFC Data Protection Regulations 2021 obligates Data Controllers to notify the Data Protection Office of all Personal Data Breaches within 72 hours, except where the breach is determined unlikely to result in a risk to data subjects.observed
  8. ProbableQatar Financial Centre Data Protection Office — QFC Data Protection Regulations guidance identifies storage limitation as one of the core processing principles (Principle 5), requiring data not be retained longer than necessary for its purpose.observed

#

Transfer mechanisms, adequacy-list governance, and SCC/BCR uptake are well-evidenced for the QFC; adequacy received from other regimes and a formal TIA requirement are unconfirmed gaps.

Primary frameworkQFC Data Protection Regulations 2021, Articles 23-24
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — AmberTransfer mechanisms, adequacy-list governance, and SCC/BCR uptake are well-evidenced for the QFC; adequacy received from other regimes and a formal TIA requirement are unconfirmed gaps.

Sub-modules (6)

Transfer MechanismsGreen

QFC transfers out of the free zone require an adequate jurisdiction, QFC SCCs, or a specific Article 24 derogation/limited-circumstances basis.

Claims (1):

  • Transfers of Personal Data outside the QFC must rely on an adequate jurisdiction, appropriate safeguards such as QFC Standard Contractual Clauses, or a specific derogation under Article 24 of the QFC Data Protection Regulations 2021.

Adequacy ReceivedRed

No adequacy decision received by mainland Qatar or the QFC from the EU, UK, or other major regimes was identified in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedGreen

The QFC Data Protection Office maintains and can amend a published list of jurisdictions it has determined offer an adequate level of protection for outbound transfers.

Claims (1):

  • The QFC Data Protection Office publishes and may amend a list of jurisdictions determined to offer an adequate level of protection for personal data transferred out of the QFC.

Sccs And BcrsGreen

The QFC provides its own Standard Contractual Clauses, and its 2023 Data Protection Rules introduced new Binding Corporate Rules requirements; the QFC, DIFC and ADGM have mutually recognized each other's data protection frameworks.

Claims (2):

  • The QFC's 2023 Data Protection Rules update introduced new Binding Corporate Rules requirements for data transfers, alongside the QFC's own Standard Contractual Clauses.
  • The QFC, DIFC, and ADGM free zones have mutually recognized each other's data protection frameworks, simplifying cross-border data flows between them.

Transfer Impact AssessmentAmber

No formal Transfer Impact Assessment requirement analogous to post-Schrems II EU practice was identified for either the mainland or QFC regime, though a QFC DPO thematic review flagged firms' cross-border transfer risk-identification practices as an area of continued supervisory focus.

Claims (1):

  • A QFC Data Protection Office thematic review found that a majority but not all firms have fully implemented processes to identify the jurisdictions to which they transfer personal data out of the QFC, indicating supervisory focus on transfer risk assessment without a codified TIA mandate.

Data LocalisationGreen

Mainland Law 13/2016 takes the position that a controller should not block a cross-border data flow unless it would violate the Law or seriously violate a data subject's right to privacy, implying no blanket data-localisation mandate.

Claims (1):

  • Mainland Law No. 13 of 2016 provides that a data controller should not block a cross-border data flow unless it would result in a violation of the Law or a serious violation of the data subject's right to privacy.
Category narrative120 words

The QFC Regulations require transfers out of the QFC to rely on an adequate jurisdiction (per a DPO-maintained and publishable list), QFC Standard Contractual Clauses, Binding Corporate Rules (introduced via the 2023 Rules update), or a specific Article 24 derogation. The QFC has also established mutual recognition of data protection frameworks with the DIFC and ADGM free zones. Mainland Law 13/2016 takes a distinct approach: a controller should not block a cross-border flow unless it would violate the Law or seriously violate a data subject's privacy right. No evidence was found of Qatar (mainland or QFC) having received an adequacy decision from the EU/UK, nor of a Transfer Impact Assessment (TIA) obligation analogous to Schrems II practice in either regime.

Sources and claims (6)
  1. ConfirmedQatar Financial Centre — Transfers of Personal Data outside the QFC must rely on an adequate jurisdiction, appropriate safeguards such as QFC Standard Contractual Clauses, or a specific derogation under Article 24 of the QFC Data Protection Regulations 2021.observed
  2. ConfirmedQatar Financial Centre Authority — The QFC Data Protection Office publishes and may amend a list of jurisdictions determined to offer an adequate level of protection for personal data transferred out of the QFC.observed
  3. ConfirmedDataGuidance — The QFC's 2023 Data Protection Rules update introduced new Binding Corporate Rules requirements for data transfers, alongside the QFC's own Standard Contractual Clauses.observed
  4. ProbableDataGuidance — The QFC, DIFC, and ADGM free zones have mutually recognized each other's data protection frameworks, simplifying cross-border data flows between them.observed
  5. ProbableQatar Financial Centre Authority — A QFC Data Protection Office thematic review found that a majority but not all firms have fully implemented processes to identify the jurisdictions to which they transfer personal data out of the QFC, indicating supervisory focus on transfer risk assessment without a codified TIA mandate.observed
  6. ConfirmedDataGuidance — Mainland Law No. 13 of 2016 provides that a data controller should not block a cross-border data flow unless it would result in a violation of the Law or a serious violation of the data subject's right to privacy.observed

#

Only the financial-sector overlay (QFC) and a limited employment-data example are evidenced; health, credit, education, and insurance sub-modules are unpopulated.

Primary frameworkQFC Data Protection Regulations 2021 (financial free-zone overlay)
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — RedOnly the financial-sector overlay (QFC) and a limited employment-data example are evidenced; health, credit, education, and insurance sub-modules are unpopulated.

Sub-modules (7)

Financial Sector OverlayGreen

The QFC Data Protection Regulations 2021 constitute a dedicated financial free-zone data-protection overlay, separate from and not displaced by mainland Law 13/2016.

Claims (2):

  • The QFC Data Protection Regulations 2021 operate as a separate, GDPR-aligned financial free-zone data-protection regime administered by the QFC Authority/Data Protection Office, distinct from mainland Law No. 13 of 2016.
  • The Qatar Central Bank's AI Guideline regulates AI use by QCB-licensed entities, focusing on governance, risk management, and customer interactions, forming an adjacent regulatory layer for financial-sector data processing.

Health Sector OverlayRed

No dedicated health-sector data-protection overlay was identified for mainland Qatar or the QFC.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy overlay distinct from Law 13/2016's general direct-marketing consent rule was identified.

Absence provenance: unavailable. Searched: unavailable.

Employment DataAmber

QFC guidance illustrates employer obligations to provide an employee privacy notice consistent with Articles 14-15 transparency requirements.

Claims (1):

  • QFC Data Protection Regulations guidance illustrates that employers must provide an employee privacy notice consistent with the transparency requirements of Articles 14 and 15.

Credit And ScoringRed

No credit-scoring-specific data-protection rules were identified.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No education-sector-specific data-protection rules were identified beyond the general children's-website provisions addressed under children_and_vulnerable_groups.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No insurance-sector-specific data-protection rules were identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative86 words

The QFC itself functions as Qatar's principal financial-sector data-protection overlay, operating a GDPR-aligned regime distinct from mainland Law 13/2016 for firms licensed within the free zone. The Qatar Central Bank (QCB) separately maintains an AI Guideline for QCB-licensed entities addressing governance, risk management, and customer interactions, which is adjacent to but not itself a data-protection instrument. QFC guidance illustrates employment-data obligations (e.g., employee privacy notices under Articles 14-15). No dedicated health-sector, credit-scoring, education-sector, or insurance-sector data-protection overlay was identified for either regime in the sources reviewed.

Sources and claims (3)
  1. ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 operate as a separate, GDPR-aligned financial free-zone data-protection regime administered by the QFC Authority/Data Protection Office, distinct from mainland Law No. 13 of 2016.observed
  2. ProbableDataGuidance — The Qatar Central Bank's AI Guideline regulates AI use by QCB-licensed entities, focusing on governance, risk management, and customer interactions, forming an adjacent regulatory layer for financial-sector data processing.observed
  3. ConfirmedQatar Financial Centre Data Protection Office — QFC Data Protection Regulations guidance illustrates that employers must provide an employee privacy notice consistent with the transparency requirements of Articles 14 and 15.observed

#

Only direct marketing is evidenced; the remaining five sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) are unpopulated gaps.

Primary frameworkLaw No. 13 of 2016 (mainland) - direct marketing provision only
Traffic-light rationale — RedOnly direct marketing is evidenced; the remaining five sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) are unpopulated gaps.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime was identified.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsRed

No dark-pattern prohibition was identified.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

No recognized universal opt-out signal (e.g., Global Privacy Control) mechanism was identified.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room rules were identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

No 'sale'/'share' or cross-context-advertising concept analogous to CPRA was identified.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingGreen

Mainland Law 13/2016 bans sending direct electronic marketing messages without the recipient's prior consent.

Claims (1):

  • Under mainland Law No. 13 of 2016, businesses are banned from sending direct marketing messages electronically without first obtaining an individual's prior consent.
Category narrative42 words

Mainland Law 13/2016 prohibits sending direct electronic marketing messages without prior consent. No cookie/tracker-specific consent regime, dark-pattern prohibition, recognized opt-out signal (e.g., GPC), clean-room framework, or cross-context-advertising ('sale'/'share') concept was identified for either the mainland or QFC regime in the sources reviewed.

Sources and claims (1)
  1. ConfirmedMOTC — Under mainland Law No. 13 of 2016, businesses are banned from sending direct marketing messages electronically without first obtaining an individual's prior consent.observed

#

Profiling/ADM restriction is confirmed for the QFC; AI risk-assessment, biometric, genetic, and surveillance-carveout sub-modules are largely unconfirmed or absent.

Primary frameworkQFC Data Protection Regulations 2021, Article 19 (right to object, including to automated decision-making)
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — AmberProfiling/ADM restriction is confirmed for the QFC; AI risk-assessment, biometric, genetic, and surveillance-carveout sub-modules are largely unconfirmed or absent.

Sub-modules (6)

Profiling RestrictionsGreen

QFC data subjects have a right not to be subject to automated individual decision-making, including profiling.

Claims (1):

  • Data subjects under the QFC Data Protection Regulations 2021 have a right not to be subject to automated individual decision-making, including profiling.

Automated Decision Making TransparencyAmber

General QFC transparency obligations (Articles 13-15) require controllers to inform data subjects about processing, but no distinct requirement to disclose ADM logic/explanation was confirmed in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

Qatar's National AI Strategy, the Cabinet-established Artificial Intelligence Committee, and NCSA/QCB AI guidance address AI governance and risk management generally, but are not data-protection-specific AI risk-assessment mandates analogous to the EU AI Act.

Claims (1):

  • Qatar's National AI Strategy and the Artificial Intelligence Committee established under Cabinet Decision No. 10 of 2021, together with NCSA and QCB AI guidance, address AI governance and risk management generally but are not data-protection-specific AI risk-assessment mandates.

Biometric RegimeRed

No dedicated biometric-data regime (facial recognition, fingerprint, gait) was identified.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataRed

No dedicated genetic-data regime was identified, though mainland 'special nature' data provisions may implicitly capture genetic data without explicit confirmation.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsRed

Mainland Law 13/2016 does not apply to personal data gathered for official surveys and statistics, which is scope-related rather than a dedicated state-surveillance/national-security carve-out; no explicit surveillance carve-out or its limits was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative79 words

The QFC Data Protection Regulations 2021 grant data subjects a right not to be subject to automated individual decision-making, including profiling. Qatar has separately developed a National AI Strategy and an Artificial Intelligence Committee (Cabinet Decision No. 10 of 2021), and the NCSA and QCB have issued AI-adoption/AI-governance guidance, though these are general AI-policy instruments rather than data-protection-specific AI risk-assessment mandates. No dedicated biometric-data regime, genetic-data regime, or explicit state-surveillance carve-out distinct from the mainland statistics exemption was identified.

Sources and claims (2)
  1. ConfirmedQatar Financial Centre — Data subjects under the QFC Data Protection Regulations 2021 have a right not to be subject to automated individual decision-making, including profiling.observed
  2. ProbableDataGuidance — Qatar's National AI Strategy and the Artificial Intelligence Committee established under Cabinet Decision No. 10 of 2021, together with NCSA and QCB AI guidance, address AI governance and risk management generally but are not data-protection-specific AI risk-assessment mandates.observed

#

Only the mainland parental-consent rule for children's websites is evidenced; the remaining four sub-modules are unpopulated gaps.

Primary frameworkLaw No. 13 of 2016, Article 17 (mainland)
Traffic-light rationale — RedOnly the mainland parental-consent rule for children's websites is evidenced; the remaining four sub-modules are unpopulated gaps.

Sub-modules (5)

Age VerificationRed

No age-verification mechanism was identified.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsRed

No education-settings-specific data-protection rule was identified.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No dependent-adults (elderly, mentally incapacitated) data-protection provision was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative55 words

Mainland Law No. 13 of 2016 requires operators of websites related to children to publish a policy on managing minors' information and to obtain parental consent before processing a child's data. No age-of-consent threshold distinct from this parental-consent rule, minor-profiling ban, education-settings-specific rule, or dependent-adults protection was identified for either the mainland or QFC regime.

Sources and claims (1)
  1. ConfirmedMOTC — Under Article 17 of mainland Law No. 13 of 2016, the owner or operator of any website related to children must publish a policy on how it manages minors' information and must obtain the consent of the child's parent when processing that information.observed

#

Regulator powers, penalties, and enforcement activity are well-evidenced for the QFC; recent (180-day) developments, regulator funding/capacity, and collective-redress mechanisms are unconfirmed gaps.

Primary frameworkQFC Data Protection Regulations 2021, Articles 33-36
Supervisory authorityQFC Data Protection Office
Traffic-light rationale — AmberRegulator powers, penalties, and enforcement activity are well-evidenced for the QFC; recent (180-day) developments, regulator funding/capacity, and collective-redress mechanisms are unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

QFC Article 33 grants the Data Protection Office investigative/enforcement powers; Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million. Mainland Law 13/2016 voids contracts concluded in violation of the Law and permits corporate liability for third-party conduct.

Claims (2):

  • Article 33 of the QFC Data Protection Regulations 2021 grants the Data Protection Office investigative and enforcement powers, and Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million.
  • Mainland Law No. 13 of 2016 renders contracts or agreements concluded in violation of the Law null and void, and prescribes that corporate entities can be found liable for actions of third parties carried out on the organization's behalf.

Enforcement Activity IndexAmber

The QFC DPO's first enforcement decision (October 2024) imposed a reprimand and USD 150,000 fine. Mainland NCSA reportedly imposed corrective measures on a sports company following a data breach.

Claims (2):

  • In October 2024, the QFC Data Protection Office imposed a reprimand and a USD 150,000 financial penalty on a QFC-licensed firm following a data breach involving late notification, security failures, and inadequate oversight, the first enforcement action of its kind in Qatar.
  • The NCSA imposed corrective measures on a sports company for violating mainland data privacy laws following a data breach.

Regulator Funding And CapacityRed

No regulator funding or headcount data was identified for either the NCSA's data-protection function or the QFC Data Protection Office.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for data-protection claims was identified in either regime.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionGreen

QFC Article 34 grants a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.

Claims (1):

  • Article 34 of the QFC Data Protection Regulations 2021 grants data subjects a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.

Recent Developments 180DRed

No development strictly within the 180 days preceding this run (since approximately February 2026) was located. The most recent identified QFC supervisory activity is a Data Protection Office thematic review of firms' cross-border transfer practices, published in December 2024, which falls outside the 180-day window.

Absence provenance: unavailable. Searched: unavailable.

Category narrative168 words

The QFC Data Protection Office holds investigative and enforcement powers under Article 33, with general penalty conditions set at Article 36 and a maximum fine of USD 1.5 million; Article 34 grants a right to lodge a complaint with the DPO and Article 35 a right to compensation. The DPO issued its first enforcement action in October 2024, a reprimand plus a USD 150,000 fine against a QFC-licensed firm for breach-notification and security failures. On the mainland, Law 13/2016 renders contracts concluded in violation of the Law null and void and can hold corporate entities liable for third-party actions, and the NCSA has reportedly imposed corrective measures on at least one company following a data breach. No collective-redress/class-action mechanism, explicit private right of action distinct from the QFC complaint/compensation route, or regulator funding/headcount data was identified. No development within the strict 180-day window preceding this run (i.e., since approximately February 2026) was located; the most recent identified enforcement/supervisory activity (a QFC DPO thematic review) dates to December 2024.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedDataGuidance — Article 33 of the QFC Data Protection Regulations 2021 grants the Data Protection Office investigative and enforcement powers, and Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million.observed
  2. ConfirmedDataGuidance — Mainland Law No. 13 of 2016 renders contracts or agreements concluded in violation of the Law null and void, and prescribes that corporate entities can be found liable for actions of third parties carried out on the organization's behalf.observed
  3. ConfirmedQatar Financial Centre — In October 2024, the QFC Data Protection Office imposed a reprimand and a USD 150,000 financial penalty on a QFC-licensed firm following a data breach involving late notification, security failures, and inadequate oversight, the first enforcement action of its kind in Qatar.observed
  4. ProbableDataGuidance — The NCSA imposed corrective measures on a sports company for violating mainland data privacy laws following a data breach.observed
  5. ConfirmedQatar Financial Centre Authority — Article 34 of the QFC Data Protection Regulations 2021 grants data subjects a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct63.16
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Qatar
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 required modules were populated for JID=QA across both the mainland Law No. 13 of 2016 regime and the separate QFC Data Protection Regulations 2021 free-zone regime, per the seed's dual-track disambiguation. Tier-1 primary-instrument anchors (mainland Law 13/2016 text, QFC Data Protection Regulations 2021 PDF, QFC breach-reporting form, QFC enforcement notice) were verified and cited directly. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights (QFC side), controller_processor_duties, cross_border_and_adequacy, and enforcement_and_redress achieved substantial T1/T2 coverage. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups relied heavily on T3 secondary sources (DataGuidance) or carried explicit absent_field_provenance gaps, consistent with the seed's caution that 'T2 is thin' for this JID. No development strictly within the 180-day window preceding 2026-08-07 was located for enforcement_and_redress.recent_developments_180d.

Unresolved questions (6):

  • Does mainland Law No. 13 of 2016 impose a codified numeric response deadline for data-subject access/rectification/erasure requests?
  • Is there a distinct internal Data Protection Officer appointment obligation for QFC-licensed firms (as opposed to the QFC's own regulator-level Data Protection Office), given conflicting secondary commentary?
  • Has mainland Qatar or the QFC received any adequacy determination from the EU, UK, or other major data-protection regime?
  • Does either regime impose a codified Transfer Impact Assessment obligation, or is the QFC DPO's thematic-review focus on transfer-jurisdiction identification merely supervisory guidance?
  • Are there sector-specific data-protection overlays for health, credit-scoring, education, or insurance in either the mainland or QFC regime that were not surfaced by the searches conducted?
  • Has any development occurred in the 180 days preceding 2026-08-07 (i.e., since approximately February 2026) affecting either regime?

Escalate to primary-source review: yes