Guide

Bahrain PDPL and AI: transfers, authorisation and prior notice for automated processing

Bahrain’s Personal Data Protection Law, Law No. 30 of 2018, has no AI chapter, but three of its duties decide how an AI system can go live. Article 14 requires a data controller to notify the Personal Data Protection Authority before any wholly or partially automated processing, unless it has appointed a Data Protection Guardian, who then keeps the register of that processing and sends the Authority an updated copy every month. Article 15 requires the Authority’s prior written authorisation for five kinds of processing, including automatic processing of biometric data to verify identity, automatic linking of the personal data files of two or more controllers held for different purposes, and visual recording used for surveillance. Article 12 allows transfers outside Bahrain only to countries on the Authority’s record or with its case-by-case authorisation, unless an Article 13 exemption such as the person’s consent applies. Ministry of Justice Order No. 42 of 2022 lists 83 countries and territories, including the UAE, Saudi Arabia, the UK and the US. Qatar is not on it. Processing without the notice or the authorisation, or transferring in breach of Articles 12 and 13, is a criminal offence under Article 58.

Bahrain PDPL. Bahrain’s Personal Data Protection Law, issued by Law No. 30 of 2018 and in force since 1 August 2019, read with the orders issued under it by the Minister of Justice, Islamic Affairs and Waqf, whose ministry performs the duties of the Personal Data Protection Authority under Decree No. 78 of 2019.

Checked . Law No. 30 of 2018 and Orders No. 42, 43, 44, 45, 46 and 48 of 2022 were read in the Authority’s English texts on pdp.gov.bh, Order No. 42 also in its Arabic Official Gazette text, together with the Authority’s pages on its orders, its forms and Decree No. 78 of 2019, and Google Cloud’s regions page, on this date. The Authority can update its list of countries, so check the current record before you rely on it. This page is not legal advice.

A 2018 data law that hears about every automated system first

Bahrain’s Personal Data Protection Law, قانون حماية البيانات الشخصية, is Law No. 30 of 2018, and it has been in force since 1 August 2019 [1, 10]. It never mentions artificial intelligence, and it does not need to. Article 2 applies it to any processing by wholly or partly automatic means, and Article 14 makes the controller tell the regulator before that kind of processing starts [1]. An AI system is automatic processing from its first call to a model.

The Law applies to any individual habitually resident in Bahrain and anyone with a place of business there who processes personal data, and to anyone else who processes data using means situated in the Kingdom other than for transit; a company in that last group must appoint a representative in Bahrain and tell the Authority [1]. On its text the hook is where the controller is or where its equipment sits, not where the people in the data live. That is a narrower reach than Saudi Arabia’s law, which also covers companies abroad processing data about people in the Kingdom, as the duty-by-duty reading of the Saudi PDPL sets out. Public-security processing by the security bodies is excluded, but the Law defines a person to include any public entity, so ministries and government-owned companies are controllers like everyone else [1].

The regulator is the Personal Data Protection Authority (PDPA). Under Decree No. 78 of 2019 the Ministry of Justice, Islamic Affairs and Waqf performs its duties, with the Minister acting as its board and the Undersecretary as its chief executive until the Authority has a board of its own [11]. Most of the detail an AI team needs sits in orders the Minister issued on 17 March 2022 [2, 4, 5, 6, 7, 8, 9].

The filing duties carry criminal penalties. Processing without the Article 14 notice, failing to notify a change, processing without an Article 15 authorisation and transferring data in breach of Articles 12 and 13 are all offences under Article 58, punishable by up to a year in prison, a fine of 1,000 to 20,000 Bahraini dinars, or both [1]. Article 59 doubles the fine limits for a company where the offence results from the conduct or gross negligence of its board or a delegated official. Where a controller ignores an order to stop a violation, the Authority can also impose a daily penalty of up to 1,000 dinars (2,000 for a repeat within three years), an administrative penalty of up to 20,000 dinars, or withdraw an authorisation, and anyone harmed can claim compensation [1].

What an AI use case can trigger, and what each duty leaves on file

Here is the Law and its orders read the way an AI team has to read them. The first column is where each duty sits. The second is my reading of when an AI system triggers it. The third is what you file or keep, which is what the Authority or an inspector will ask to see.

Seven duties an AI system can trigger under Bahrain’s PDPL, where each one sits and what it leaves on file
DimensionWhere it sitsWhen an AI system triggers itWhat you file or keep
Prior noticeLaw Article 14; Order No. 44 of 2022Before any wholly or partly automated processing for a purpose, unless an exemption applies or a Data Protection Guardian is appointed, and again within 30 days of any changeA notification on the Authority’s form, or the guardian’s register entry
Prior authorisationLaw Article 15; Order No. 44 of 2022, Articles 3, 4 and 6Biometric identity checks, linking two or more controllers’ files held for different purposes, camera surveillance, genetic data, and sensitive data where the person cannot consentA written authorisation, with an impact assessment in the request for biometric and camera uses
Transfer outside BahrainLaw Articles 12 and 13; Order No. 42 of 2022Any model, hosting, logging or support endpoint that receives personal data outside BahrainAn endpoint list checked against the Authority’s record, and an authorisation or exemption for each unlisted country
Impact assessmentOrder No. 43 of 2022, Article 3Solely automated decisions on work, finances, credit, reliability or conduct; profiling with legal or similar effects; large-scale sensitive or criminal data; large-scale monitoring of public placesA written assessment with at least the four parts the order lists
Automated decisionsLaw Article 22; Order No. 48 of 2022, Article 3A decision based solely on automated processing that assesses those same five things about a personA notice of the decision, and an electronic route to object and get a human reconsideration
Processor termsLaw Article 8; Order No. 43 of 2022, Article 6Every model or hosting provider acting for youA written contract that keeps the provider to your instructions and to equivalent security duties
Breach noticeOrder No. 43 of 2022, Article 4A breach that affects the rights of the people in the dataThe Authority told within 72 hours of discovery, and a breach log with causes, effects and fixes

The first column is from the Law [1] and the orders [2, 4, 5, 7]. The middle column is my reading, not the Authority’s, and this page is not legal advice.

Article 14 asks you to file before you build, or to appoint a guardian

This is the duty that catches teams out, because it bites before the system exists. Article 14 requires the controller to give the Authority prior notice of any wholly or partially automated processing operation, or set of operations, serving one purpose or several related ones [1]. The notice names the controller and any processor, the purpose, the data, the categories of people and recipients, any proposed transfer outside the Kingdom, and enough about security for the Authority to make a preliminary assessment, and it goes in on the Authority’s own form [1, 5, 12].

The Authority has ten working days to ask for anything missing, the controller then has up to fifteen days to supply it, and processing stops until the notification is complete [1, 5]. A change to anything notified goes to the Authority within thirty days [1, 5]. On my reading, a new model provider or a new country receiving the data is exactly that kind of change. Notification does not replace consent where the Law requires consent [5].

Four cases need no notice: a register kept by law to inform the public, processing by associations, unions and non-profit bodies, an employer’s processing of its employees’ data as far as necessary, and any controller that has appointed a Data Protection Guardian [1]. The employee exemption is narrower than it looks for AI. It covers employees, so on my reading a model that screens job applicants sits outside it.

The guardian route is the one I would look at first for any organisation planning more than one AI use case. A guardian keeps the register of the processing the controller would otherwise notify and sends the Authority an updated version every month [1]. Guardians must be enrolled in the Authority’s register: internal guardians are employees of the controller or its group with permanent residence in Bahrain, and external guardians are qualified individuals or licensed firms with at least three qualifying staff. Enrolment lasts a year, and the controller tells the Authority of an appointment within three working days [1, 6]. That swaps a filing per use case for a register that has to stay current, which suits a team shipping changes every month.

Five kinds of processing need written permission, and silence means no

Article 15 prohibits five kinds of processing without the Authority’s prior written authorisation: automatic processing of sensitive data where the person is legally unable to consent, automatic processing of biometric data to verify identity, automatic processing of genetic data outside licensed medical care, automatic processing that links the personal data files of two or more controllers processed for different purposes, and visual recording used for surveillance [1]. Appointing a guardian does not lift any of them.

Three of the five map straight onto common AI projects. Face matching at onboarding is biometric processing to verify identity. Video analytics on camera feeds is visual recording used for surveillance. Enriching your customer data with a partner’s dataset to train or run a scoring model is, on my reading, linkage between two controllers’ files held for different purposes. None of these is unusual in a bank, a telecoms operator or a government service.

The request carries the same information as a notification [1, 5]. For biometric and camera uses it must also come with a data protection impact assessment and a statement on transparency, proportionality, who can reach the images, videos and biometric data, and how people can see recordings of themselves [5]. The Authority decides within thirty days of submission, and no answer in that time counts as a refusal [1, 5]. Put those thirty days in the project plan before anyone books a launch date.

The transfer whitelist lists 83 countries, and Qatar is not one of them

Article 12 prohibits transferring personal data outside Bahrain except to a country or territory on a record the Authority compiles, or with the Authority’s authorisation case by case where the data will have adequate protection [1]. Ministry of Justice Order No. 42 of 2022, issued on 17 March 2022, carries that record: 83 countries and territories, including the United Arab Emirates, Saudi Arabia, Kuwait, Oman, Jordan, Egypt, India, the United Kingdom and the United States [2, 3]. Qatar is not on it, in the English text or in the Arabic text published in the Official Gazette [2, 3]. Check the record itself rather than a summary of it. The Authority’s list of its orders, read on 30 September 2026, shows no later order replacing it [9].

For a country off the record, Order No. 42 sets the route. The controller asks for prior authorisation on the Authority’s form, giving the controller and processor, the data, the purpose and duration, the origin and destination with the protections there, the relevant agreements and laws, and a statement on whether protection will be adequate [2]. A transfer within a group to an unlisted country needs the same authorisation, and the group’s binding corporate rules apply where it has them. A transfer under contract to a controller or third party in an unlisted country needs the authorisation and a copy of the contract, which must keep processing to its stated purposes, limit retention, keep the data accurate, apply technical and organisational measures, inform the people concerned and let them see, correct, block or erase their data [2]. The authorisation can be conditional or time-limited [1, 2].

Article 13 allows a transfer to a country without adequate protection in listed cases, including the person’s consent, necessity for a contract with them or in their interest, their vital interests, a legal obligation and legal claims [1]. Consent under the Law has to be written, explicit, clear and specific to the processing [1], which is hard to collect for every prompt a support assistant sends.

For an AI team the practical result is a country list, not a vendor list. The UAE, Saudi Arabia, the UK and the US are on the record, so a model endpoint in any of them needs no authorisation, although the transfer still belongs in the Article 14 notification [1, 2]. Google Cloud’s Doha region, me-central1, is in Qatar, while its Dammam region, me-central2, is in Saudi Arabia [13]: the first needs an authorisation or an exemption for Bahraini personal data and the second does not. A cloud region in Bahrain does not settle the question either, because a region can host the platform while the model runs somewhere else, which is the gap between a live region in the country and a model running in it. Ask each provider for every country that can receive a prompt, a log or a support ticket, and check each one against the record.

Solely automated decisions carry a reconsideration right and an assessment

Article 22 gives a person the right to ask for a decision to be taken again in a way that is not solely automated, where it is based solely on automated processing of their data and assesses their performance at work, financial standing, creditworthiness, reliability or conduct [1]. The reconsideration is obligatory and free. It does not apply where the decision is taken in entering into or performing a contract with the person and suitable safeguards, such as hearing their view, are in place [1].

Order No. 48 of 2022 turns that into two things to build: telling the person about the automated decision, and an electronic or similar procedure for raising an objection, deciding it and telling them the outcome within a reasonable period [7]. Article 18 adds that when data is the sole basis for a decision directly affecting someone, a request for their data must be answered with how it is used, in terms an average person can follow [1].

Order No. 43 of 2022 then makes a data protection impact assessment compulsory in the Article 22 cases, for systematic and extensive evaluation based on automated processing, including profiling, that produces legal or similarly significant effects, for large-scale processing of sensitive or criminal data, and for systematic monitoring of a public area on a large scale [4]. The assessment needs at least a systematic description of the processing and its purposes, a necessity and proportionality test, the risks to people’s rights and the measures to address them, and the controller takes the guardian’s advice where there is one [4]. A credit model, a fraud score that blocks payments or an HR model that flags staff will usually meet one of the first two triggers. Before writing any of these, rank your AI use cases by risk so the assessments go where they matter.

One more line matters for training data. Order No. 45 of 2022 keeps sensitive data to the scope of the consent or authorisation it is processed under, and rules out any other purpose [8]. On my reading, health records collected for care cannot be reused to train a model on the strength of the original purpose alone, so settle the basis with counsel first.

An AI intake that files before it builds

This is the order I would run for each AI use case, from idea to launch. It is built from the Law and the orders, not a process the Authority publishes.

Choose the notice route once
Decide whether the organisation notifies the Authority per processing operation or appoints a Data Protection Guardian who keeps the register. Every later step depends on that choice.
Map the use case
Write down the purpose, the personal data, the people it concerns, the recipients, and every model, embedding, hosting, logging and support endpoint with the country each one runs in.
Check the countries
Compare each country with the Order No. 42 record. For anything off it, rely on an Article 13 exemption only where it genuinely applies, or start the authorisation request, with the six contract terms where the transfer is under contract.
Screen for Article 15
Biometric identity checks, camera surveillance, linking another controller’s files, genetic data and sensitive data without consent all need written authorisation, and its thirty-day clock, before launch.
Assess where the orders require it
Write the impact assessment for automated decisions, profiling with significant effects, large-scale sensitive data and large-scale public monitoring, and build the objection route for Article 22 decisions.
File, then keep it current
Submit the notification, or add the guardian’s register entry, before go-live. Notify changes within thirty days and rehearse the 72-hour breach notice to the Authority.

It moves quickly when the data owner can make decisions and the authorisations are started early. When nobody can say which systems hold personal data, the map is the project.

Where 1AYM fits

The work on this page is what we sell as AI governance implementation: the endpoint map, the transfer checks, the impact assessments and the decision logs built into the system they describe, so the notification or the guardian’s register is drawn from the system rather than written beside it. We work with clients across the UK, the US and the Gulf, and we have built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR, which matters in Bahrain because much of the personal data an AI system reads there is in Arabic.

Our closest published work in the region is the production estate of a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements. For a Bahraini controller that same region is in Qatar and off the transfer record, which is exactly the kind of fact the endpoint map exists to catch. Once a scope is signed, a fixed-scope build can start within a day, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. The filings with the Authority and the legal view stay with your guardian and your counsel. The call is booked from the end of this page.

For engineers: endpoint countries, change triggers and decision records

The duties above in engineering terms. Each item is something a guardian or an inspector can check in configuration, code or logs rather than by asking someone.

Endpoint country register
Keep every model, embedding, vector store, logging and support endpoint in configuration with its provider and the country that receives data. Load the Order No. 42 record as data and fail a deployment when an endpoint’s country is off the record and no authorisation or exemption reference is recorded.
Change triggers
A new provider, region, data category or recipient changes what was notified. Open the ticket to the guardian or the notification owner from the same pull request, because the thirty-day clock in Article 14 runs from the change, not from the next audit.
Where inference runs
Pin inference to named regions where the provider allows it, and log the region that served each call. A cross-region or global routing option can send a prompt to a country the notification does not name.
Prompt and output logs
Logs of prompts, retrieved passages and outputs are personal data. Keep them in a country on the record, state their retention, and give them enough structure (subject identifiers, data categories, counts) to scope a breach inside 72 hours.
Decision records
For each decision about work, finances, credit, reliability or conduct, log whether it was solely automated, what the reviewer saw and whether they changed it. That record answers an Article 22 objection and feeds the impact assessment.
Biometric and video pipelines
Run face matching and camera analytics as their own services with their own access controls, so each Article 15 authorisation and its conditions map to one deployable unit that can be switched off.
Linkage guard
Tag each dataset with the controller that supplied it and the purpose it was collected for, and block joins across controllers in feature and retrieval pipelines unless an authorisation reference is attached.
Erasure and blocking
Build erase and block by person across source systems, caches, vector index entries and evaluation sets. Article 23 gives ten working days to respond to a request and fifteen days after that to tell third parties the data went to.

Sources

  1. [1]Personal Data Protection Authority, Law No. (30) of 2018 with Respect to Personal Data Protection Law, English text, read 30 September 2026
  2. [2]Ministry of Justice, Islamic Affairs and Waqf, Order No. (42) of 2022 regarding the transfer of personal data outside the Kingdom of Bahrain, with the record of countries and territories, English text, read 30 September 2026
  3. [3]وزارة العدل والشئون الإسلامية والأوقاف, قرار رقم (42) لسنة 2022 بشأن نقل البيانات الشخصية إلى خارج مملكة البحرين, Order No. 42 in Arabic, Official Gazette issue 3593 (17 March 2022), read 30 September 2026
  4. [4]Ministry of Justice, Islamic Affairs and Waqf, Order No. (43) of 2022 regarding the technical and organisational measures that guarantee protection of personal data, English text, read 30 September 2026
  5. [5]Ministry of Justice, Islamic Affairs and Waqf, Order No. (44) of 2022 regarding notifications and prior authorisation requests, English text, read 30 September 2026
  6. [6]Ministry of Justice, Islamic Affairs and Waqf, Order No. (46) of 2022 regarding Data Protection Guardians, English text, read 30 September 2026
  7. [7]Ministry of Justice, Islamic Affairs and Waqf, Order No. (48) of 2022 regarding the data subject’s rights, English text, read 30 September 2026
  8. [8]Ministry of Justice, Islamic Affairs and Waqf, Order No. (45) of 2022 regarding the processing of sensitive personal data, English text, read 30 September 2026
  9. [9]Personal Data Protection Authority, Executive Decisions/Orders, the list of orders issued under the Law, read 30 September 2026
  10. [10]Personal Data Protection Authority, overview: issue and entry into force of the Law, read 30 September 2026
  11. [11]Personal Data Protection Authority, Decree No. (78) of 2019 on the administrative entity performing the Authority’s duties, read 30 September 2026
  12. [12]Personal Data Protection Authority, Forms: notification of automated processing, prior authorisation, breach notification and guardian registration, read 30 September 2026
  13. [13]Google Cloud, Regions and zones: me-central1 in Doha, Qatar and me-central2 in Dammam, Saudi Arabia, read 30 September 2026

Questions DPOs and AI leads ask

Does Bahrain’s PDPL apply to AI?

Yes, whenever an AI system processes personal data, because it always does so by automatic means. The Law does not mention AI, but Article 14 requires prior notice to the Personal Data Protection Authority of any wholly or partially automated processing unless a Data Protection Guardian is appointed, Article 15 requires written authorisation for uses such as biometric identity checks and camera surveillance, and Article 22 gives people a right to have solely automated decisions about their work, finances, credit, reliability or conduct reconsidered. This is not legal advice.

Is Qatar on Bahrain’s list of countries with adequate protection?

No. The record attached to Ministry of Justice Order No. 42 of 2022 lists 83 countries and territories in both its English and Arabic texts. It includes the UAE, Saudi Arabia, Kuwait and Oman but not Qatar. A transfer of personal data from Bahrain to Qatar needs the Authority’s authorisation or an Article 13 exemption such as the person’s consent. The Authority’s list of orders, read on 30 September 2026, shows no later order replacing the record.

Can we send personal data from Bahrain to an AI model hosted in the US or the UK?

Under Article 12, yes, without prior authorisation, because both are on the Order No. 42 record. The transfer still belongs in the Article 14 notification or the guardian’s register, and the provider still needs a written processor contract under Article 8. Check every country the provider can route data to, not only the one on the order form.

Do we have to notify the Authority before launching an AI system?

Unless an exemption applies or you have appointed a Data Protection Guardian, yes. Article 14 requires notice on the Authority’s form before any wholly or partially automated processing, and if the Authority asks for missing details, processing stops until the notification is complete. Changes to what you notified go to the Authority within thirty days.

What is a Data Protection Guardian in Bahrain?

A person or firm enrolled in the Authority’s register who helps the controller comply, liaises with the Authority and keeps the register of processing, sending the Authority an updated copy every month. Appointing one removes the Article 14 prior-notice duty, though not the Article 15 authorisations. Internal guardians must be employees with permanent residence in Bahrain; external guardians can be qualified individuals or licensed firms with at least three qualifying staff.

Who regulates personal data protection in Bahrain?

The Personal Data Protection Authority, whose duties and powers the Ministry of Justice, Islamic Affairs and Waqf performs under Decree No. 78 of 2019, with the Minister acting as the board and the Undersecretary as chief executive until the Authority has a board of its own. The Minister issued the implementing orders, including the transfer record, on 17 March 2022.

What are the penalties under Bahrain’s PDPL?

Processing without the Article 14 notice or an Article 15 authorisation, or transferring data in breach of Articles 12 and 13, can bring up to a year in prison, a fine of 1,000 to 20,000 Bahraini dinars, or both, under Article 58, and Article 59 doubles the fine limits for a company where its board or a delegated official is responsible. The Authority can also impose daily penalties of up to 1,000 dinars and administrative penalties of up to 20,000 dinars, and people harmed can claim compensation. This is not legal advice.

More in this topic

  • The UAE free-zone regime that adds AI-specific duties on top of its data law, from a first-use notice to certification for high risk use.

  • Getting reliable text out of Arabic scans and forms, which is where much of the personal data in a Bahraini AI system starts.

Further

  • AI governance implementation · The engagement that builds the endpoint map, the assessments and the decision logs into the system itself.
  • Engagement file D-02 · A government-accredited EdTech in the Middle East, with its database in Google Cloud’s Doha region.

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM