QAschema gdpri-v2trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC
Last updated · 10 categories · 46
claims · 19 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
12Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction lead brief
Standing brief, as of 14 September 2026.
Lead Signal
Qatar's data-protection enforcement posture has moved decisively from an awareness phase into a pattern of active, dated binding decisions. The National Data Privacy Office, operating within the National Cyber Security Agency, issued its most recent binding ruling in February 2026 against a sports-sector company, finding that it had failed to implement adequate technical, administrative and physical safeguards, a failure that contributed to a personal-data breach. This follows binding compliance rulings against an ICT-sector company in December 2024 and an e-commerce operator in March 2025, establishing a clear cadence of enforcement activity rather than an isolated action. Administrative fines under the PDPPL range from QAR 1,000,000 to QAR 5,000,000 depending on the article violated, and this fine range, together with the escalating cadence of binding decisions, is the clearest evidence available this cycle that Qatar's regulator has operationalised its enforcement powers rather than holding them in reserve.
The regulator itself has also been confirmed structurally this cycle: the National Data Privacy Office, sitting within the National Cyber Security Agency, is confirmed as the operative authority for PDPPL enforcement, having taken over this function from the Ministry of Transport and Communications' former Compliance and Data Protection Department.
Other Developments
Controller and processor obligations are being given concrete operational content through NDPO executive guidelines. Organisations are required to maintain a Personal Data Management System incorporating Data Protection Impact Assessments and Records of Processing Activities. NDPO guidelines further specify a 72-hour breach-notification window for personal-data incidents. Data processors are understood, per compliance-practitioner commentary, to carry joint and several liability with controllers for security failings, although no primary statutory citation for this specific liability position was located this cycle, so it is held at Assessed rather than High confidence.
Qatar's regulatory architecture remains structurally bifurcated between the mainland PDPPL/NDPO track and a separate QFC regime. The QFC operates its own Data Protection Regulations 2005, as amended, as a distinct data-protection framework for the QFC free zone, separate from the PDPPL/NDPO track that governs the rest of the jurisdiction. Whether the QFC's own regime carries distinct breach-notification or DPIA obligations from the NDPO guidelines described above has not been confirmed this cycle.
Cross-Monitor Connections
The expanding cohort of PDPPL-regulated controllers includes newly licensed payment-service providers whose customer-data handling falls within the Personal Data Management System obligation described above; the world-payments monitor tracks the licensing dimension of that expanding cohort directly, and this brief does not re-analyse the payments-licensing angle here.
Outlook
The cadence of NDPO binding decisions — December 2024, March 2025, February 2026 — suggests continued active enforcement is likely rather than a return to the earlier awareness-only posture, and organisations should expect further binding decisions to be issued on a broadly similar tempo. The structural bifurcation between the mainland PDPPL/NDPO regime and the QFC's own 2005 regulations remains an open question for cross-regime compliance mapping, and confirmation of whether QFC-specific breach-notification or DPIA obligations diverge from the NDPO's guidelines would be a material clarification to watch for in a future cycle.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Both primary instruments are identified and verifiably in force, but mainland secondary guidance (Tier-2) is thin and the dual-perimeter structure creates residual scoping ambiguity for firms operating across both.
Primary frameworkLaw No. 13 of 2016 Concerning Privacy and Protection of Personal Data (mainland Qatar)
Traffic-light rationale — AmberBoth primary instruments are identified and verifiably in force, but mainland secondary guidance (Tier-2) is thin and the dual-perimeter structure creates residual scoping ambiguity for firms operating across both.
Sub-modules (5)
Regulator And AuthorityAmber
Mainland: NCSA's National Cyber Governance and Assurance Affairs division is the supervisory authority for Law 13/2016. QFC free zone: the independent QFC Data Protection Office, under the QFC Authority, administers the QFC Data Protection Regulations 2021.
Claims (2):
The National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA) is the supervisory authority for Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data in mainland Qatar.
The QFC Data Protection Office is an independent institution of the Qatar Financial Centre charged with administering the QFC Data Protection Regulations 2021 and all aspects of data protection within the QFC.
Act And InstrumentsGreen
Mainland instrument: Law No. 13 of 2016, published in the Official Gazette 29 December 2016. QFC instrument: QFC Data Protection Regulations 2021 plus the Data Protection Rules 2021, which replaced the 2005 QFC Data Protection Regulation and Rules.
Claims (2):
Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data was published in Qatar's Official Gazette on 29 December 2016 and became effective in 2017.
The QFC Data Protection Regulations 2021, supported by the Data Protection Rules 2021, came into force on 19 June 2022, replacing the QFC Data Protection Regulations and Rules 2005.
Material ScopeGreen
Mainland Law 13/2016 covers only electronically processed personal data (or data gathered for electronic processing), excluding purely private/family processing and official surveys/statistics. QFC Regulations apply to Data Controllers/Processors incorporated or registered in the QFC.
Claims (2):
Law No. 13 of 2016 applies only to personal data that is electronically processed, or gathered/extracted in preparation for electronic processing, and does not apply to private/family processing or data gathered for official surveys and statistics.
The QFC Data Protection Regulations 2021 apply to a Data Controller or Data Processor incorporated or registered in the QFC.
Territorial ScopeAmber
The QFC Commissioner interprets Article 7(2) as extending the Regulations to non-QFC-licensed firms that process personal data of data subjects in Qatar on an ongoing (non-occasional) basis, and QFC guidance confirms a non-QFC controller processing a QFC subsidiary's employee data for that subsidiary's benefit is itself caught. No equivalent explicit extraterritorial clause was located for mainland Law 13/2016 in the sources reviewed.
Claims (1):
The QFC Data Protection Office interprets the Regulations as applying to non-QFC-licensed firms that process personal data of data subjects located in Qatar on an ongoing (more than occasional) basis, including non-QFC controllers processing data of a QFC subsidiary's employees.
Regulator Registration And FilingAmber
QFC Data Controllers have no general obligation to register with the Data Protection Office. Mainland Law 13/2016 requires Competent Department permission before processing personal data of a 'special nature.'
Claims (2):
QFC Data Controllers have no general obligation to register with the QFC Data Protection Office.
Under mainland Law No. 13 of 2016, personal data of a special nature may only be processed after obtaining permission from the Competent Department, per measures determined by ministerial decision.
Category narrative123 words
Qatar operates two entirely separate data-protection perimeters. Mainland Qatar is governed by Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data, supervised by the National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA), with implementation guidance historically issued via the Ministry of Transport and Communications (MOTC) Compliance and Data Protection Department. Separately, the Qatar Financial Centre (QFC) free zone operates the QFC Data Protection Regulations 2021 (in force since 19 June 2022, replacing the 2005 regime), administered by the independent QFC Data Protection Office (DPO) under the QFC Authority. The two regimes do not apply to each other's perimeter; QFC Law expressly disapplies mainland civil/regulatory law matters covered by the QFC Regulations within the QFC.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (9)
ConfirmedDataGuidance — The National Cyber Governance and Assurance Affairs division of the National Cyber Security Agency (NCSA) is the supervisory authority for Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data in mainland Qatar.observed
ConfirmedQatar Financial Centre — The QFC Data Protection Office is an independent institution of the Qatar Financial Centre charged with administering the QFC Data Protection Regulations 2021 and all aspects of data protection within the QFC.observed
ConfirmedDataGuidance — Law No. 13 of 2016 Concerning Privacy and Protection of Personal Data was published in Qatar's Official Gazette on 29 December 2016 and became effective in 2017.observed
ConfirmedQatar Financial Centre — The QFC Data Protection Regulations 2021, supported by the Data Protection Rules 2021, came into force on 19 June 2022, replacing the QFC Data Protection Regulations and Rules 2005.observed
ConfirmedMOTC — Law No. 13 of 2016 applies only to personal data that is electronically processed, or gathered/extracted in preparation for electronic processing, and does not apply to private/family processing or data gathered for official surveys and statistics.observed
ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 apply to a Data Controller or Data Processor incorporated or registered in the QFC.observed
ProbableQatar Financial Centre Data Protection Office — The QFC Data Protection Office interprets the Regulations as applying to non-QFC-licensed firms that process personal data of data subjects located in Qatar on an ongoing (more than occasional) basis, including non-QFC controllers processing data of a QFC subsidiary's employees.observed
ConfirmedQatar Financial Centre — QFC Data Controllers have no general obligation to register with the QFC Data Protection Office.observed
ConfirmedDataGuidance (unofficial translation) — Under mainland Law No. 13 of 2016, personal data of a special nature may only be processed after obtaining permission from the Competent Department, per measures determined by ministerial decision.observed
Traffic-light rationale — AmberLawful bases, consent and special-category rules are confirmed for both regimes; pseudonymisation/anonymisation treatment is an unresolved gap.
Sub-modules (4)
Lawful BasesGreen
Mainland: consent of the data subject is the main legal basis for processing. QFC: Article 10 enumerates the lawful bases (bases) under which all Personal Data Processing must take place.
Claims (2):
Mainland Law No. 13 of 2016 establishes the consent of the data subject as the main legal basis for processing personal data.
Article 10 of the QFC Data Protection Regulations 2021 sets out the lawful basis or bases under which all Personal Data Processing must take place.
Consent ThresholdsGreen
Mainland Law 13/2016 grants a right to withdraw prior consent for personal data processing. QFC Article 11 sets specific conditions for valid consent.
Claims (2):
Mainland Law No. 13 of 2016 provides individuals a right to withdraw their prior consent to personal data processing.
Article 11 of the QFC Data Protection Regulations 2021 sets out the conditions for valid consent to processing.
Special CategoriesGreen
Mainland: special-nature data requires Competent Department permission and may be subject to Minister-imposed additional precautions. QFC Article 12 separately governs processing of Sensitive Personal Data.
Claims (2):
Under mainland Law No. 13 of 2016, the Minister may impose additional precautions to protect personal data of a special nature by ministerial decision.
Article 12 of the QFC Data Protection Regulations 2021 separately governs the Processing of Sensitive Personal Data.
Pseudonymisation And AnonymisationRed
No pseudonymisation or anonymisation definitions, safe-harbours, or exemptions were identified for either the mainland Law 13/2016 regime or the QFC Data Protection Regulations 2021 in the sources reviewed.
Mainland Law 13/2016 establishes consent as the principal lawful basis, with a withdrawal right and specific notification requirements for sensitive/special-nature data. The QFC Regulations set out lawful bases in Article 10, consent conditions in Article 11, and sensitive personal data rules in Article 12. No pseudonymisation/anonymisation safe-harbour definitions were located in either regime within the sources reviewed.
Sources and claims (6)
ConfirmedDataGuidance — Mainland Law No. 13 of 2016 establishes the consent of the data subject as the main legal basis for processing personal data.observed
ConfirmedQatar Financial Centre Authority — Article 10 of the QFC Data Protection Regulations 2021 sets out the lawful basis or bases under which all Personal Data Processing must take place.observed
ConfirmedDataGuidance (unofficial translation) — Mainland Law No. 13 of 2016 provides individuals a right to withdraw their prior consent to personal data processing.observed
ConfirmedQatar Financial Centre Authority — Article 11 of the QFC Data Protection Regulations 2021 sets out the conditions for valid consent to processing.observed
ConfirmedDataGuidance (unofficial translation) — Under mainland Law No. 13 of 2016, the Minister may impose additional precautions to protect personal data of a special nature by ministerial decision.observed
ConfirmedQatar Financial Centre Authority — Article 12 of the QFC Data Protection Regulations 2021 separately governs the Processing of Sensitive Personal Data.observed
Traffic-light rationale — AmberQFC rights framework is well-documented and comprehensive; mainland rights detail and statutory response deadlines are thinly sourced.
Sub-modules (5)
Access RightGreen
QFC Article 16 establishes the right to access.
Claims (1):
The QFC Data Protection Regulations 2021 grant data subjects a right to access their personal data (Article 16).
Rectification And ErasureGreen
QFC Articles 17-18 establish rights to rectification and erasure.
Claims (1):
The QFC Data Protection Regulations 2021 grant data subjects rights to rectification (Article 17) and erasure (Article 18).
Restriction And ObjectionGreen
QFC Articles 19-20 establish rights to object (including opt-out from automated decision-making/profiling) and to restriction of processing.
Claims (1):
The QFC Data Protection Regulations 2021 grant data subjects rights to object (Article 19), to restriction of processing (Article 20), and not to be subject to automated individual decision-making, including profiling.
Data PortabilityGreen
The QFC Regulations grant data subjects a right to data portability.
Claims (1):
Data subjects under the QFC Data Protection Regulations 2021 are empowered with a right to data portability.
Deadlines And Response WindowsRed
QFC guidance references a 'without undue delay' standard for controller action on some data-subject requests, but a codified numeric response window (e.g., 30 days) was not confirmed in the sources reviewed for either regime, and no mainland deadline provision was located.
QFC Data Protection Regulations 2021 guidance references an obligation for controllers to provide personal data to a data subject without undue delay in response to certain requests.
Category narrative62 words
The QFC Data Protection Regulations 2021 provide a full rights suite (access, rectification, erasure, objection, restriction, portability, and a right not to be subject to solely automated decision-making including profiling) at Articles 16-22. Mainland Law 13/2016's rights framework is less granularly documented in the sources reviewed beyond the consent-withdrawal right; a specific mainland statutory response-time deadline for subject requests was not located.
Sources and claims (5)
ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 grant data subjects a right to access their personal data (Article 16).observed
ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 grant data subjects rights to rectification (Article 17) and erasure (Article 18).observed
ConfirmedQatar Financial Centre — The QFC Data Protection Regulations 2021 grant data subjects rights to object (Article 19), to restriction of processing (Article 20), and not to be subject to automated individual decision-making, including profiling.observed
ConfirmedQatar Financial Centre — Data subjects under the QFC Data Protection Regulations 2021 are empowered with a right to data portability.observed
UncertainQatar Financial Centre Authority — QFC Data Protection Regulations 2021 guidance references an obligation for controllers to provide personal data to a data subject without undue delay in response to certain requests.observed
Core accountability, security, ROPA and breach-notification duties are well-evidenced for the QFC; DPO-appointment obligation for firms is unresolved, and mainland retention/disposal rules were not located.
Primary frameworkQFC Data Protection Regulations 2021, Articles 25-31
Traffic-light rationale — AmberCore accountability, security, ROPA and breach-notification duties are well-evidenced for the QFC; DPO-appointment obligation for firms is unresolved, and mainland retention/disposal rules were not located.
Sub-modules (7)
Accountability And DpiaGreen
QFC Article 26 requires data protection by design and by default; Article 27 requires DPIAs to be conducted in certain circumstances.
Claims (1):
Article 26 of the QFC Data Protection Regulations 2021 requires data protection by design and by default, and Article 27 requires Data Protection Impact Assessments in certain circumstances.
Dpo RequirementsAmber
Secondary commentary is split: one analysis states the QFC's 2023 Data Protection Rules update 'lacks requirements for a Data Protection Officer' for regulated firms, distinct from the QFC's own regulator-level Data Protection Office/Commissioner.
Claims (1):
Secondary legal commentary indicates the QFC's updated Data Protection Rules lack an explicit requirement for regulated firms to appoint an internal Data Protection Officer, distinct from the QFC's own regulator-level Data Protection Office.
Ropa RequirementsGreen
QFC Article 30 requires a record of processing operations.
Claims (1):
Article 30 of the QFC Data Protection Regulations 2021 requires controllers to maintain a record of processing operations.
Joint Controller ArrangementsAmber
QFC Article 28 addresses Data Processor obligations and processor liability where a processor has not complied with obligations specifically directed to it; no distinct 'joint controller' provision was located in the sources reviewed for either regime.
Article 28 of the QFC Data Protection Regulations 2021 addresses Data Processor obligations, with a Data Processor liable for damage caused by processing only where it has not complied with obligations specifically directed to Data Processors.
Security MeasuresGreen
QFC Article 29 sets security-of-processing requirements; mainland Law 13/2016 requires precautions against loss, damage, modification, disclosure, or unauthorized access.
Claims (2):
Article 29 of the QFC Data Protection Regulations 2021 sets out security-of-processing requirements for Data Controllers and Data Processors.
Mainland Law No. 13 of 2016 requires organizations to train data handlers and take necessary precautions to protect personal data from loss, damage, modification, disclosure, or unauthorized access.
Breach NotificationGreen
QFC Article 31 requires notification of personal data breaches to the Data Protection Office within 72 hours, unless the controller determines the breach is unlikely to result in a risk to data subjects.
Claims (1):
Article 31 of the QFC Data Protection Regulations 2021 obligates Data Controllers to notify the Data Protection Office of all Personal Data Breaches within 72 hours, except where the breach is determined unlikely to result in a risk to data subjects.
Retention And DisposalAmber
QFC guidance references a storage-limitation principle (Principle 5) requiring data not be kept longer than necessary. No mainland Law 13/2016 retention/disposal provision was located in the sources reviewed.
Claims (1):
QFC Data Protection Regulations guidance identifies storage limitation as one of the core processing principles (Principle 5), requiring data not be retained longer than necessary for its purpose.
Category narrative84 words
The QFC Data Protection Regulations 2021 impose accountability duties including data protection by design/default (Article 26), DPIA obligations (Article 27), processor obligations (Article 28), security-of-processing measures (Article 29), records of processing (Article 30), and 72-hour breach notification to the DPO (Article 31). Mainland Law 13/2016 requires organizations to train data handlers and take precautions against loss, damage, modification, disclosure, or unauthorized access. Whether QFC firms must appoint an internal Data Protection Officer (distinct from the QFC's own regulator-level DPO) is contested across secondary sources.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (8)
ConfirmedQatar Financial Centre Authority — Article 26 of the QFC Data Protection Regulations 2021 requires data protection by design and by default, and Article 27 requires Data Protection Impact Assessments in certain circumstances.observed
UncertainDataGuidance — Secondary legal commentary indicates the QFC's updated Data Protection Rules lack an explicit requirement for regulated firms to appoint an internal Data Protection Officer, distinct from the QFC's own regulator-level Data Protection Office.observed
ConfirmedQatar Financial Centre Authority — Article 30 of the QFC Data Protection Regulations 2021 requires controllers to maintain a record of processing operations.observed
ConfirmedQatar Financial Centre Authority — Article 28 of the QFC Data Protection Regulations 2021 addresses Data Processor obligations, with a Data Processor liable for damage caused by processing only where it has not complied with obligations specifically directed to Data Processors.observed
ConfirmedQatar Financial Centre Authority — Article 29 of the QFC Data Protection Regulations 2021 sets out security-of-processing requirements for Data Controllers and Data Processors.observed
ConfirmedMOTC — Mainland Law No. 13 of 2016 requires organizations to train data handlers and take necessary precautions to protect personal data from loss, damage, modification, disclosure, or unauthorized access.observed
ConfirmedQatar Financial Centre Authority — Article 31 of the QFC Data Protection Regulations 2021 obligates Data Controllers to notify the Data Protection Office of all Personal Data Breaches within 72 hours, except where the breach is determined unlikely to result in a risk to data subjects.observed
ProbableQatar Financial Centre Data Protection Office — QFC Data Protection Regulations guidance identifies storage limitation as one of the core processing principles (Principle 5), requiring data not be retained longer than necessary for its purpose.observed
Transfer mechanisms, adequacy-list governance, and SCC/BCR uptake are well-evidenced for the QFC; adequacy received from other regimes and a formal TIA requirement are unconfirmed gaps.
Primary frameworkQFC Data Protection Regulations 2021, Articles 23-24
Traffic-light rationale — AmberTransfer mechanisms, adequacy-list governance, and SCC/BCR uptake are well-evidenced for the QFC; adequacy received from other regimes and a formal TIA requirement are unconfirmed gaps.
Sub-modules (6)
Transfer MechanismsGreen
QFC transfers out of the free zone require an adequate jurisdiction, QFC SCCs, or a specific Article 24 derogation/limited-circumstances basis.
Claims (1):
Transfers of Personal Data outside the QFC must rely on an adequate jurisdiction, appropriate safeguards such as QFC Standard Contractual Clauses, or a specific derogation under Article 24 of the QFC Data Protection Regulations 2021.
Adequacy ReceivedRed
No adequacy decision received by mainland Qatar or the QFC from the EU, UK, or other major regimes was identified in the sources reviewed.
The QFC Data Protection Office maintains and can amend a published list of jurisdictions it has determined offer an adequate level of protection for outbound transfers.
Claims (1):
The QFC Data Protection Office publishes and may amend a list of jurisdictions determined to offer an adequate level of protection for personal data transferred out of the QFC.
Sccs And BcrsGreen
The QFC provides its own Standard Contractual Clauses, and its 2023 Data Protection Rules introduced new Binding Corporate Rules requirements; the QFC, DIFC and ADGM have mutually recognized each other's data protection frameworks.
Claims (2):
The QFC's 2023 Data Protection Rules update introduced new Binding Corporate Rules requirements for data transfers, alongside the QFC's own Standard Contractual Clauses.
The QFC, DIFC, and ADGM free zones have mutually recognized each other's data protection frameworks, simplifying cross-border data flows between them.
Transfer Impact AssessmentAmber
No formal Transfer Impact Assessment requirement analogous to post-Schrems II EU practice was identified for either the mainland or QFC regime, though a QFC DPO thematic review flagged firms' cross-border transfer risk-identification practices as an area of continued supervisory focus.
Claims (1):
A QFC Data Protection Office thematic review found that a majority but not all firms have fully implemented processes to identify the jurisdictions to which they transfer personal data out of the QFC, indicating supervisory focus on transfer risk assessment without a codified TIA mandate.
Data LocalisationGreen
Mainland Law 13/2016 takes the position that a controller should not block a cross-border data flow unless it would violate the Law or seriously violate a data subject's right to privacy, implying no blanket data-localisation mandate.
Claims (1):
Mainland Law No. 13 of 2016 provides that a data controller should not block a cross-border data flow unless it would result in a violation of the Law or a serious violation of the data subject's right to privacy.
Category narrative120 words
The QFC Regulations require transfers out of the QFC to rely on an adequate jurisdiction (per a DPO-maintained and publishable list), QFC Standard Contractual Clauses, Binding Corporate Rules (introduced via the 2023 Rules update), or a specific Article 24 derogation. The QFC has also established mutual recognition of data protection frameworks with the DIFC and ADGM free zones. Mainland Law 13/2016 takes a distinct approach: a controller should not block a cross-border flow unless it would violate the Law or seriously violate a data subject's privacy right. No evidence was found of Qatar (mainland or QFC) having received an adequacy decision from the EU/UK, nor of a Transfer Impact Assessment (TIA) obligation analogous to Schrems II practice in either regime.
Sources and claims (6)
ConfirmedQatar Financial Centre — Transfers of Personal Data outside the QFC must rely on an adequate jurisdiction, appropriate safeguards such as QFC Standard Contractual Clauses, or a specific derogation under Article 24 of the QFC Data Protection Regulations 2021.observed
ConfirmedQatar Financial Centre Authority — The QFC Data Protection Office publishes and may amend a list of jurisdictions determined to offer an adequate level of protection for personal data transferred out of the QFC.observed
ConfirmedDataGuidance — The QFC's 2023 Data Protection Rules update introduced new Binding Corporate Rules requirements for data transfers, alongside the QFC's own Standard Contractual Clauses.observed
ProbableDataGuidance — The QFC, DIFC, and ADGM free zones have mutually recognized each other's data protection frameworks, simplifying cross-border data flows between them.observed
ProbableQatar Financial Centre Authority — A QFC Data Protection Office thematic review found that a majority but not all firms have fully implemented processes to identify the jurisdictions to which they transfer personal data out of the QFC, indicating supervisory focus on transfer risk assessment without a codified TIA mandate.observed
ConfirmedDataGuidance — Mainland Law No. 13 of 2016 provides that a data controller should not block a cross-border data flow unless it would result in a violation of the Law or a serious violation of the data subject's right to privacy.observed
Only the financial-sector overlay (QFC) and a limited employment-data example are evidenced; health, credit, education, and insurance sub-modules are unpopulated.
Primary frameworkQFC Data Protection Regulations 2021 (financial free-zone overlay)
Traffic-light rationale — RedOnly the financial-sector overlay (QFC) and a limited employment-data example are evidenced; health, credit, education, and insurance sub-modules are unpopulated.
Sub-modules (7)
Financial Sector OverlayGreen
The QFC Data Protection Regulations 2021 constitute a dedicated financial free-zone data-protection overlay, separate from and not displaced by mainland Law 13/2016.
Claims (2):
The QFC Data Protection Regulations 2021 operate as a separate, GDPR-aligned financial free-zone data-protection regime administered by the QFC Authority/Data Protection Office, distinct from mainland Law No. 13 of 2016.
The Qatar Central Bank's AI Guideline regulates AI use by QCB-licensed entities, focusing on governance, risk management, and customer interactions, forming an adjacent regulatory layer for financial-sector data processing.
Health Sector OverlayRed
No dedicated health-sector data-protection overlay was identified for mainland Qatar or the QFC.
QFC guidance illustrates employer obligations to provide an employee privacy notice consistent with Articles 14-15 transparency requirements.
Claims (1):
QFC Data Protection Regulations guidance illustrates that employers must provide an employee privacy notice consistent with the transparency requirements of Articles 14 and 15.
Credit And ScoringRed
No credit-scoring-specific data-protection rules were identified.
No education-sector-specific data-protection rules were identified beyond the general children's-website provisions addressed under children_and_vulnerable_groups.
The QFC itself functions as Qatar's principal financial-sector data-protection overlay, operating a GDPR-aligned regime distinct from mainland Law 13/2016 for firms licensed within the free zone. The Qatar Central Bank (QCB) separately maintains an AI Guideline for QCB-licensed entities addressing governance, risk management, and customer interactions, which is adjacent to but not itself a data-protection instrument. QFC guidance illustrates employment-data obligations (e.g., employee privacy notices under Articles 14-15). No dedicated health-sector, credit-scoring, education-sector, or insurance-sector data-protection overlay was identified for either regime in the sources reviewed.
Sources and claims (3)
ConfirmedQatar Financial Centre Authority — The QFC Data Protection Regulations 2021 operate as a separate, GDPR-aligned financial free-zone data-protection regime administered by the QFC Authority/Data Protection Office, distinct from mainland Law No. 13 of 2016.observed
ProbableDataGuidance — The Qatar Central Bank's AI Guideline regulates AI use by QCB-licensed entities, focusing on governance, risk management, and customer interactions, forming an adjacent regulatory layer for financial-sector data processing.observed
ConfirmedQatar Financial Centre Data Protection Office — QFC Data Protection Regulations guidance illustrates that employers must provide an employee privacy notice consistent with the transparency requirements of Articles 14 and 15.observed
Only direct marketing is evidenced; the remaining five sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) are unpopulated gaps.
Primary frameworkLaw No. 13 of 2016 (mainland) - direct marketing provision only
Traffic-light rationale — RedOnly direct marketing is evidenced; the remaining five sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) are unpopulated gaps.
Sub-modules (6)
Cookies And TrackersRed
No dedicated cookie/tracker consent regime was identified.
Mainland Law 13/2016 bans sending direct electronic marketing messages without the recipient's prior consent.
Claims (1):
Under mainland Law No. 13 of 2016, businesses are banned from sending direct marketing messages electronically without first obtaining an individual's prior consent.
Category narrative42 words
Mainland Law 13/2016 prohibits sending direct electronic marketing messages without prior consent. No cookie/tracker-specific consent regime, dark-pattern prohibition, recognized opt-out signal (e.g., GPC), clean-room framework, or cross-context-advertising ('sale'/'share') concept was identified for either the mainland or QFC regime in the sources reviewed.
Sources and claims (1)
ConfirmedMOTC — Under mainland Law No. 13 of 2016, businesses are banned from sending direct marketing messages electronically without first obtaining an individual's prior consent.observed
Profiling/ADM restriction is confirmed for the QFC; AI risk-assessment, biometric, genetic, and surveillance-carveout sub-modules are largely unconfirmed or absent.
Primary frameworkQFC Data Protection Regulations 2021, Article 19 (right to object, including to automated decision-making)
Traffic-light rationale — AmberProfiling/ADM restriction is confirmed for the QFC; AI risk-assessment, biometric, genetic, and surveillance-carveout sub-modules are largely unconfirmed or absent.
Sub-modules (6)
Profiling RestrictionsGreen
QFC data subjects have a right not to be subject to automated individual decision-making, including profiling.
Claims (1):
Data subjects under the QFC Data Protection Regulations 2021 have a right not to be subject to automated individual decision-making, including profiling.
Automated Decision Making TransparencyAmber
General QFC transparency obligations (Articles 13-15) require controllers to inform data subjects about processing, but no distinct requirement to disclose ADM logic/explanation was confirmed in the sources reviewed.
Qatar's National AI Strategy, the Cabinet-established Artificial Intelligence Committee, and NCSA/QCB AI guidance address AI governance and risk management generally, but are not data-protection-specific AI risk-assessment mandates analogous to the EU AI Act.
Claims (1):
Qatar's National AI Strategy and the Artificial Intelligence Committee established under Cabinet Decision No. 10 of 2021, together with NCSA and QCB AI guidance, address AI governance and risk management generally but are not data-protection-specific AI risk-assessment mandates.
Biometric RegimeRed
No dedicated biometric-data regime (facial recognition, fingerprint, gait) was identified.
No dedicated genetic-data regime was identified, though mainland 'special nature' data provisions may implicitly capture genetic data without explicit confirmation.
Mainland Law 13/2016 does not apply to personal data gathered for official surveys and statistics, which is scope-related rather than a dedicated state-surveillance/national-security carve-out; no explicit surveillance carve-out or its limits was identified.
The QFC Data Protection Regulations 2021 grant data subjects a right not to be subject to automated individual decision-making, including profiling. Qatar has separately developed a National AI Strategy and an Artificial Intelligence Committee (Cabinet Decision No. 10 of 2021), and the NCSA and QCB have issued AI-adoption/AI-governance guidance, though these are general AI-policy instruments rather than data-protection-specific AI risk-assessment mandates. No dedicated biometric-data regime, genetic-data regime, or explicit state-surveillance carve-out distinct from the mainland statistics exemption was identified.
Sources and claims (2)
ConfirmedQatar Financial Centre — Data subjects under the QFC Data Protection Regulations 2021 have a right not to be subject to automated individual decision-making, including profiling.observed
ProbableDataGuidance — Qatar's National AI Strategy and the Artificial Intelligence Committee established under Cabinet Decision No. 10 of 2021, together with NCSA and QCB AI guidance, address AI governance and risk management generally but are not data-protection-specific AI risk-assessment mandates.observed
Traffic-light rationale — RedOnly the mainland parental-consent rule for children's websites is evidenced; the remaining four sub-modules are unpopulated gaps.
Mainland Law 13/2016 Article 17 requires operators of children's websites to publish a policy on managing minors' data and to obtain parental consent before processing.
Claims (1):
Under Article 17 of mainland Law No. 13 of 2016, the owner or operator of any website related to children must publish a policy on how it manages minors' information and must obtain the consent of the child's parent when processing that information.
Mainland Law No. 13 of 2016 requires operators of websites related to children to publish a policy on managing minors' information and to obtain parental consent before processing a child's data. No age-of-consent threshold distinct from this parental-consent rule, minor-profiling ban, education-settings-specific rule, or dependent-adults protection was identified for either the mainland or QFC regime.
Sources and claims (1)
ConfirmedMOTC — Under Article 17 of mainland Law No. 13 of 2016, the owner or operator of any website related to children must publish a policy on how it manages minors' information and must obtain the consent of the child's parent when processing that information.observed
Regulator powers, penalties, and enforcement activity are well-evidenced for the QFC; recent (180-day) developments, regulator funding/capacity, and collective-redress mechanisms are unconfirmed gaps.
Primary frameworkQFC Data Protection Regulations 2021, Articles 33-36
Traffic-light rationale — AmberRegulator powers, penalties, and enforcement activity are well-evidenced for the QFC; recent (180-day) developments, regulator funding/capacity, and collective-redress mechanisms are unconfirmed gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
QFC Article 33 grants the Data Protection Office investigative/enforcement powers; Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million. Mainland Law 13/2016 voids contracts concluded in violation of the Law and permits corporate liability for third-party conduct.
Claims (2):
Article 33 of the QFC Data Protection Regulations 2021 grants the Data Protection Office investigative and enforcement powers, and Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million.
Mainland Law No. 13 of 2016 renders contracts or agreements concluded in violation of the Law null and void, and prescribes that corporate entities can be found liable for actions of third parties carried out on the organization's behalf.
Enforcement Activity IndexAmber
The QFC DPO's first enforcement decision (October 2024) imposed a reprimand and USD 150,000 fine. Mainland NCSA reportedly imposed corrective measures on a sports company following a data breach.
Claims (2):
In October 2024, the QFC Data Protection Office imposed a reprimand and a USD 150,000 financial penalty on a QFC-licensed firm following a data breach involving late notification, security failures, and inadequate oversight, the first enforcement action of its kind in Qatar.
The NCSA imposed corrective measures on a sports company for violating mainland data privacy laws following a data breach.
Regulator Funding And CapacityRed
No regulator funding or headcount data was identified for either the NCSA's data-protection function or the QFC Data Protection Office.
QFC Article 34 grants a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.
Claims (1):
Article 34 of the QFC Data Protection Regulations 2021 grants data subjects a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.
Recent Developments 180DRed
No development strictly within the 180 days preceding this run (since approximately February 2026) was located. The most recent identified QFC supervisory activity is a Data Protection Office thematic review of firms' cross-border transfer practices, published in December 2024, which falls outside the 180-day window.
The QFC Data Protection Office holds investigative and enforcement powers under Article 33, with general penalty conditions set at Article 36 and a maximum fine of USD 1.5 million; Article 34 grants a right to lodge a complaint with the DPO and Article 35 a right to compensation. The DPO issued its first enforcement action in October 2024, a reprimand plus a USD 150,000 fine against a QFC-licensed firm for breach-notification and security failures. On the mainland, Law 13/2016 renders contracts concluded in violation of the Law null and void and can hold corporate entities liable for third-party actions, and the NCSA has reportedly imposed corrective measures on at least one company following a data breach. No collective-redress/class-action mechanism, explicit private right of action distinct from the QFC complaint/compensation route, or regulator funding/headcount data was identified. No development within the strict 180-day window preceding this run (i.e., since approximately February 2026) was located; the most recent identified enforcement/supervisory activity (a QFC DPO thematic review) dates to December 2024.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
ConfirmedDataGuidance — Article 33 of the QFC Data Protection Regulations 2021 grants the Data Protection Office investigative and enforcement powers, and Article 36 sets general conditions for imposing penalties, with a maximum fine of USD 1.5 million.observed
ConfirmedDataGuidance — Mainland Law No. 13 of 2016 renders contracts or agreements concluded in violation of the Law null and void, and prescribes that corporate entities can be found liable for actions of third parties carried out on the organization's behalf.observed
ConfirmedQatar Financial Centre — In October 2024, the QFC Data Protection Office imposed a reprimand and a USD 150,000 financial penalty on a QFC-licensed firm following a data breach involving late notification, security failures, and inadequate oversight, the first enforcement action of its kind in Qatar.observed
ProbableDataGuidance — The NCSA imposed corrective measures on a sports company for violating mainland data privacy laws following a data breach.observed
ConfirmedQatar Financial Centre Authority — Article 34 of the QFC Data Protection Regulations 2021 grants data subjects a right to lodge a complaint with the Data Protection Office, and Article 35 grants a right to compensation and establishes liability for processing that infringes the Regulations.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
63.16
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Qatar
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 19 source(s) in the cumulative register.
All 10 required modules were populated for JID=QA across both the mainland Law No. 13 of 2016 regime and the separate QFC Data Protection Regulations 2021 free-zone regime, per the seed's dual-track disambiguation. Tier-1 primary-instrument anchors (mainland Law 13/2016 text, QFC Data Protection Regulations 2021 PDF, QFC breach-reporting form, QFC enforcement notice) were verified and cited directly. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights (QFC side), controller_processor_duties, cross_border_and_adequacy, and enforcement_and_redress achieved substantial T1/T2 coverage. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups relied heavily on T3 secondary sources (DataGuidance) or carried explicit absent_field_provenance gaps, consistent with the seed's caution that 'T2 is thin' for this JID. No development strictly within the 180-day window preceding 2026-08-07 was located for enforcement_and_redress.recent_developments_180d.
Unresolved questions (6):
Does mainland Law No. 13 of 2016 impose a codified numeric response deadline for data-subject access/rectification/erasure requests?
Is there a distinct internal Data Protection Officer appointment obligation for QFC-licensed firms (as opposed to the QFC's own regulator-level Data Protection Office), given conflicting secondary commentary?
Has mainland Qatar or the QFC received any adequacy determination from the EU, UK, or other major data-protection regime?
Does either regime impose a codified Transfer Impact Assessment obligation, or is the QFC DPO's thematic-review focus on transfer-jurisdiction identification merely supervisory guidance?
Are there sector-specific data-protection overlays for health, credit-scoring, education, or insurance in either the mainland or QFC regime that were not surfaced by the searches conducted?
Has any development occurred in the 180 days preceding 2026-08-07 (i.e., since approximately February 2026) affecting either regime?