Guide

Qatar’s data privacy law and AI: what Law 13 of 2016 asks before you deploy

Qatar’s Law No. 13 of 2016 on Protecting Personal Data Privacy (the PDPPL) never mentions artificial intelligence, but it applies to any AI system that processes personal data electronically. Article 11(1) requires the controller to review its privacy protection measures before any new processing operation, which the National Cyber Security Agency’s guidelines turn into a data privacy impact assessment, with new technology, automated decisions and transfers outside Qatar among the signs that one is needed. Article 16 makes data on ethnic origin, children, health, physical or psychological condition, religious belief, marital relations and criminal offences special-nature data, processed only with the competent department’s permission. Article 13 requires precautions proportionate to the data, and Article 14 requires notice of a serious breach, within 72 hours on NCSA’s guidelines. Article 15 runs the other way from most residency talk: it forbids the controller from restricting cross-border data flows unless the processing breaches the law or may seriously damage privacy. Fines reach QR5 million.

Qatar PDPPL. Qatar’s Law No. (13) of 2016 on Protecting Personal Data Privacy, issued on 3 November 2016 and published in the Official Gazette, Issue No. 15 of 2016, administered by the National Cyber Security Agency as the competent department.

Checked . Law No. 13 of 2016 was read in its English translation and its Arabic text on Al Meezan, Qatar’s legal portal, which lists it as in force; NCSA’s PDPPL guidelines on impact assessments, controllers and processors, breach notification and privacy by design, and a presentation in NCSA’s document library, were read on ncsa.gov.qa; the Qatar Central Bank’s Cloud Computing Regulation on qcb.gov.qa and the QFC’s data protection page on qfc.qa, all on this date. NCSA revises its guidelines, so check the current text before you rely on it. This page is not legal advice.

A 2016 law with no AI chapter that still shapes how you build one

Qatar’s data privacy law, القانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية, was issued in November 2016 and published in the Official Gazette at the end of that year [1, 2]. Al Meezan, the state’s legal portal, lists it as in force [2]. It was written before anyone put a language model in front of customer records, and it never uses the words artificial intelligence.

It does not need to. The law applies to personal data processed electronically, or gathered in preparation for electronic processing [1], which describes every AI system I have seen in production. Its definition of personal data covers data from which a person can be reasonably identified, directly or “through the combination of such data with any other data” [1]. Combining data is what retrieval and inference do all day.

The law gives enforcement to a competent department inside the ministry. NCSA’s own guidelines state that under Amiri Decree No. 1 of 2021 that role belongs to the National Cyber Governance and Assurance Affairs at the National Cyber Security Agency, which publishes the guidelines quoted on this page [3]. The Arabic text calls the controller المراقب and the competent department الإدارة المختصة [2], which is worth knowing when your DPO and your counsel are reading different versions.

The penalties are in the law. Breaching the articles on consent, design and precautions, notice, data quality, the review and processor duties, disclosure to processors, breach notice, cross-border flow or direct marketing (Articles 4, 8 to 12, 14, 15 and 22) carries a fine of up to QR1 million. Breaching the security precautions in Article 13, processing special-nature data without a permit, or the rules for websites aimed at children carries up to QR5 million, a company can be fined up to QR1 million for an offence committed in its name, and any contract that breaches the law is void [1]. Firms in the Qatar Financial Centre have their own Data Protection Regulations 2021 and Data Protection Office [4]; this page covers the national law.

Article 15 protects the flow of data, and that changes the hosting question

Here is Article 15 in full, in the official English translation: “Taking into account the liabilities provided for hereto, the Controller shall be forbidden from taking any decision or measure that may limit the Cross-Border Data Flow, unless the processing of such data is in breach of this Law, or where such processing may cause serious damage to the Personal Data or to the Individual’s privacy” [1]. The Arabic opens the operative clause with يُحظر على المراقب, the controller is prohibited [2].

Read that twice. A lot of Gulf residency conversations assume the law wants data kept at home. Qatar’s data privacy statute starts from the other end: the party it restrains is the controller that blocks the flow, and a breach of Article 15 sits in the same QR1 million band as a missed breach notice [1].

The flow is not unconditional. The opening words keep every other duty in play, and NCSA’s impact assessment guidelines treat a transfer of personal data outside Qatar as one of two kinds of processing the law itself marks as able to cause serious damage [3]. So a model endpoint in another country is allowed, and it is something you assess before you use it. NCSA’s controller and processor guidelines add that the contract with a processor must say it processes personal data only on your written instructions, including on any transfer outside Qatar [5].

In practice the statute will rarely be the reason an AI system has to run in Doha. Sector rules can be. The Qatar Central Bank’s Cloud Computing Regulation, in force since 15 April 2024, requires every entity it regulates to ensure that personally identifiable and financial information is processed within Qatar only, and to get QCB approval before entering a cloud arrangement [6]. Whether the model you want runs in the Doha region at all is a separate question, and the guide to where Gulf AI workloads actually run sets out what to ask a cloud or model vendor.

The duties an AI system triggers, and the evidence each one leaves

Here is the law read the way an AI team has to read it. The first column is where each duty sits and the most it can cost. The second is my reading of what it asks of an AI system. The third is the artefact that shows the duty was met, which is what a DPO, an auditor or NCSA will ask to see.

Ten PDPPL duties an AI system triggers, where each sits and the artefact each one leaves
DimensionWhere it sitsWhat it asks of an AI systemThe artefact
Design controlsArticle 8(2); up to QR1 millionThe controls on processing personal data are considered when a product, system or service is designed, changed or developed, so each model or prompt change countsDesign records showing the privacy decisions for each release
NoticeArticle 9; up to QR1 millionBefore processing starts, people are told who the controller is and who processes for it, the lawful purposes, and a full and accurate description of the processing and how far the data is disclosedNotice text for each channel, naming the AI processing and the providers that receive the data
Relevance, accuracy and retentionArticle 10; up to QR1 millionOnly data relevant and adequate for the purpose reaches the system, it is kept accurate and current, and nothing is kept longer than the purpose needsA retention rule for prompts, outputs, logs and indexes
Review before new processingArticle 11(1); up to QR1 millionPrivacy protection measures are reviewed before any new processing operation, which NCSA’s guidelines implement as an impact assessmentAn impact assessment, or a signed record of why none was needed
ProcessorsArticles 11(2), 11(8) and 12; up to QR1 millionThe processors responsible for the data are named, checked for following your instructions and keeping precautions, and checked again over timeA processor contract for each model or hosting provider, and a review record
Rights and complaintsArticles 5, 6, 11(4) and 11(6); up to QR1 million under Article 11People can access, correct and ask for erasure of their data, and complain, through systems the controller providesAccess, correction and erasure that reach the index and the logs
Security precautionsArticle 13; up to QR5 millionPrecautions against loss, damage, change, disclosure, access or misuse, proportionate to the data, and a processor that reports a breach or a risk at onceAccess controls, encryption, and a breach clause in each processor contract
Breach noticeArticle 14; up to QR1 millionThe person and the competent department are told of a breach that may cause serious damage, within 72 hours of becoming aware on NCSA’s guidelinesA breach runbook, and logs that can say whose data was exposed
Special-nature dataArticle 16; up to QR5 millionA permit from the competent department before processing data on ethnic origin, children, health, physical or psychological condition, religious belief, marital relations or criminal offencesThe permit, and a register of special-nature fields and inferences
Direct marketingArticle 22; up to QR1 millionPrior consent before any electronic message sent for direct marketing, including AI-written and AI-targeted campaigns, with a way to opt outConsent records checked before each send

The first column is from the law [1]. The 72 hours come from NCSA’s breach guidelines, not the statute, which asks for notice without setting hours [7], and NCSA grounds privacy by design and by default in Articles 3, 8 and 13 [8]. The middle column is my reading, not NCSA’s, and this page is not legal advice.

Article 11(1) asks for a review before every new processing operation

Article 11(1) is one line: the controller reviews its privacy protection measures before proceeding with new processing operations [1]. The Arabic says the same thing, قبل إدراج عمليات معالجة جديدة, before introducing new processing operations [2]. NCSA’s guidelines turn that line into a data privacy impact assessment and are firmer than its brevity suggests. An assessment should be done before any new processing activity, it must be done where the processing may cause serious damage, and where you decide one is not needed you record that decision and the reasons for it [3].

NCSA gives a screening list for that judgement [3], and an AI system usually meets several items on it at once.

New technology
“Using a new innovative technology or an existing technology in a new way” [3]. A language model reading customer records meets this on day one.
Automated decisions
Automated decision-making that leads to a decision limiting a person’s access to a product, service, opportunity or benefit, which NCSA glosses as decisions made by a computer without human involvement [3].
Data from third parties
Collecting personal data through third parties instead of directly from the person [3], which covers a model enriching a record from outside sources.
Transfers and employees
A transfer of personal data outside Qatar, and processing employees’ personal data [3]. A model hosted abroad trips the first, and an internal assistant over HR files trips the second.

The appendix matters most to an AI team. Its examples of changes that may trigger an assessment include using a new third-party system provider, processing personal data for a new use case and using existing personal data to improve a product [3]. On that reading, switching model provider, pointing an existing assistant at a new data source or fine-tuning on customer history each start a new review, so the assessment is not a one-off at launch.

The assessment has a set shape in NCSA’s guidelines: who owns the processing, the decision on whether to assess, what is processed, whose data, how and where and why, necessity and proportionality, risks and mitigations, residual risk, how each data privacy principle is met, and sign-off by the data protection lead, the head of the owning function and the people who contributed [3]. If a high risk of serious damage remains after the mitigations, you consult NCSA before going ahead, and NCSA reads a failure to assess where one was clearly required as open to the QR1 million fine in Article 23 [3].

Saudi Arabia’s regulation works the other way round: it names the situations that require an assessment. Qatar’s law asks for the review before every new processing operation and leaves the depth to the controller. If one system serves both countries, write one assessment that answers both, starting from Saudi Arabia’s impact assessment triggers and NCSA’s screening list.

Special-nature data, and the AI that creates it without collecting it

Article 16 treats data on ethnic origin, children, health, physical or psychological condition, religious creeds, marital relations and criminal offences as personal data of a special nature, and allows it to be processed only after the competent department grants permission, under procedures a ministerial decision sets [1]. The Arabic word is تصريح, a permit [2], and processing without one is in the QR5 million band [1].

Children are on that list as a category in their own right. Any AI system that processes data about children, a tutoring product, a school platform, a paediatric triage tool, is processing special-nature data before anyone asks what the model does with it. A website aimed at children carries extra duties under Article 17 as well, including explicit consent from a guardian [1].

The harder case is data the system produces. The law’s definition of personal data turns on whether a person can be identified through the data or its combination with other data [1], and on my reading a model that infers a health condition or a religious practice from ordinary records has created special-nature data about an identifiable person. A presentation published in NCSA’s document library in February 2026, given by a Qatar University law professor, makes the same argument: inference is processing, and an inferred special-nature attribute calls for permission and heightened safeguards [9]. That is a lecture rather than NCSA guidance, but I would design as if it were right.

In practice that means deciding which inferences the system is allowed to make, blocking the rest at the prompt and at the output, and never writing an inferred special-nature attribute into a profile or a vector index that no permit covers.

Ministries and public bodies: the exemptions stop short of the review

Nothing in the law takes government entities out of the definition of a controller, and two articles give them room. Article 18 lets the competent authority process some personal data without Articles 4, 9, 15 and 17 (consent, notice, the cross-border rule and the rules for children’s websites) to protect national and public security, the state’s international relations or its economic and financial interests, or to prevent and investigate crime, and it keeps a special record of that data [1]. Article 19 exempts a controller from consent, from the rights to withdraw, object and seek erasure, and from the access rights in Article 6, where it is carrying out a public-interest task under law, meeting a legal obligation or court order, protecting a person’s vital interests, doing public-interest research or gathering information for a criminal investigation [1].

Neither article touches Articles 8, 11, 13, 14 or 16. A ministry that needs no consent for an assistant over case files still reviews its privacy measures before the new processing starts, still keeps precautions proportionate to the data, still reports a serious breach and still needs a permit for health or children’s data. For a public-sector programme, the Article 11(1) review is the document that shows the exemption was considered rather than assumed.

A review-before-launch checklist for one AI use case

This is the order I would work in. It is built from the law and NCSA’s guidelines rather than a procedure NCSA publishes, and it assumes someone can make decisions about the system.

Map the processing
What personal data the system reads, writes and infers, whose it is, where each store and model endpoint runs, and the lawful purpose for each. Mark special-nature fields, children’s data included.
Decide on the assessment
Screen against NCSA’s list, record the decision either way, and write the assessment where it is needed, with each processor’s input.
Apply for permits
If special-nature data is in scope, get the permit before processing. If inference could create it, decide on paper what the system may infer.
Notices and consent
Update the notice for each channel before processing starts, naming the parties that process for you, and check marketing consent before any AI-targeted campaign.
Processor contracts
For each model and hosting provider: documented instructions, including on transfers outside Qatar, security measures, sub-processors only with your authorisation and notice of changes you can object to, help with rights requests, audit rights and deletion at the end [5]. A QCB-regulated entity adds QCB approval before the cloud arrangement [6].
Rights and retention
Access, correction and erasure that reach logs, caches and the vector index, and a retention period for each of them.
Breach readiness
Logs that can say whose data was exposed, a processor clause that brings you the news at once, and a rehearsed notice to NCSA and to the people affected within 72 hours [7].
Sign-off
Signed by the data protection lead, the head of the owning function and the contributors, and reopened when the model, the provider or the data changes [3].

Where nobody can say which systems hold personal data, start with the map, because the other seven steps all depend on it.

Where 1AYM fits

This is the work we sell as AI governance implementation: the impact assessment, the processor register and the logging built into the system they describe, so the evidence NCSA may ask for comes out of the system rather than from a document written beside it. We work with clients across the UK, the US and the Gulf, and we have built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR, which matters in Qatar because the records an assessment has to map are often in Arabic.

Our closest published work in the region is the production estate of a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements, with every store placed in a named region and the reasons written down. Once a scope is signed, a fixed-scope build can start within a day, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. Whether the result satisfies NCSA stays with your data protection lead and your counsel. The call is booked from the end of this page.

For engineers: endpoint registers, assessment gates, inference controls and the 72-hour clock

The duties above in engineering terms. Each item is something a data protection lead or NCSA could check in configuration, code or logs rather than by asking someone.

Endpoint register
Record every model, embedding and hosting endpoint with its provider, region, processor contract and the written instruction that covers transfers outside Qatar. For a QCB-regulated entity, add the QCB approval reference and fail any deployment that sends personal or financial information to an endpoint outside Qatar.
Assessment gate in the pipeline
Treat a new model provider, a new data source or a new use of existing data as a change that needs an assessment reference. A deployment check that refuses the change without one turns Article 11(1) into something the pipeline enforces.
Field map at context assembly
Map each personal data field to the purpose that justifies it (Article 10) and enforce the map where the prompt is assembled, so a field with no purpose for this use case never reaches the model.
Inference controls
List the attributes the system may infer. Screen outputs and memory writes for special-nature attributes (health, religion, ethnic origin, marital status, criminal matters, and whether the person is a child) and block storage of any that no permit covers.
Logs are personal data
Prompts, retrieved passages and outputs carry personal data. Restrict who can read them, set their retention, and keep enough structure (subject identifiers, data categories, counts) to scope a breach inside 72 hours.
Erasure that reaches copies
Article 5 lets a person ask for erasure once the purpose has ended. Delete by subject across source systems, caches, vector index entries, evaluation sets and any fine-tuning data, and test that it works.
Processor alerts
Article 13 obliges a processor to tell you of a breach or a risk forthwith. Route each provider’s security notices into your incident process, pin sub-processors in configuration and alert when a provider’s list changes.
Decision records
Where an output limits someone’s access to a product, service or benefit, log whether a person reviewed it, what they saw and whether they changed it. NCSA’s screening list treats decisions without human involvement as a reason to assess, so that log shows which side of the line a system sits on.

Sources

  1. [1]Al Meezan, Law No. (13) of 2016 on Protecting Personal Data Privacy, official English translation, read 30 September 2026
  2. [2]Al Meezan, قانون رقم (13) لسنة 2016 بشأن حماية خصوصية البيانات الشخصية, the Arabic text and its legislation card (in force, 32 articles), read 30 September 2026
  3. [3]NCSA, Data Privacy Impact Assessment (DPIA) Guidelines for Regulated Entities, PDPPL-02050206E, version 2.0 (September 2022), read 30 September 2026
  4. [4]Qatar Financial Centre, Data Protection: the QFC Data Protection Regulations 2021 and the Data Protection Office, read 30 September 2026
  5. [5]NCSA, Controller and Processor Guidelines for Regulated Entities, PDPPL-02050209E, version 2.0 (September 2022), read 30 September 2026
  6. [6]Qatar Central Bank, Cloud Computing Regulation for QCB-licensed entities, in force 15 April 2024, read 30 September 2026
  7. [7]NCSA, Personal Data Breach Notifications Guidelines for Regulated Entities, PDPPL-02050217E, version 2.0 (September 2022), read 30 September 2026
  8. [8]NCSA, Data Privacy by Design and by Default Guidelines for Regulated Entities, PDPPL-02050208E, version 2.0 (September 2022), read 30 September 2026
  9. [9]NCSA document library, “Implementing Responsible and Compliant AI System: AI Inference and Data Protection”, a presentation by a Qatar University law professor (February 2026), read 30 September 2026

Questions DPOs and AI leads in Qatar ask

Does Qatar’s data protection law apply to AI?

Yes, whenever an AI system processes personal data electronically. Law No. 13 of 2016 never mentions artificial intelligence, but Article 11(1) requires a review of privacy protection measures before any new processing operation, which NCSA’s guidelines implement as a data privacy impact assessment, and Article 16 requires a permit for special-nature data such as health or children’s data. This is not legal advice.

Does the PDPPL require personal data to stay in Qatar?

No. Article 15 forbids the controller from taking any decision or measure that may limit cross-border data flows, unless the processing breaches the law or may cause serious damage to the data or the person’s privacy. NCSA’s guidelines still treat a transfer outside Qatar as a reason to carry out an impact assessment. Sector rules can require local processing: the Qatar Central Bank’s Cloud Computing Regulation requires the entities it regulates to process personally identifiable and financial information within Qatar only.

Is a DPIA mandatory under Qatar’s PDPPL?

NCSA’s guidelines say a controller must carry out a data privacy impact assessment for any processing that may cause serious damage, should carry one out before any new processing, and must record its reasons where it decides one is not needed. They list new technology, automated decisions that limit access to a service, transfers outside Qatar, special-nature data and employees’ data among the screening factors, and read a failure to assess where one was clearly required as open to a fine of up to QR1 million under Article 23.

What is the breach notification deadline under the PDPPL?

Article 14 requires the controller to tell the person and the competent department of a breach that may cause serious damage to the data or the person’s privacy, without setting hours. NCSA’s breach guidelines ask for notice within 72 hours of becoming aware of the breach, through the breach notification form on its website, and require a processor to tell the controller at once.

Who enforces Qatar’s PDPPL?

The law gives the role to a competent department. NCSA’s guidelines state that under Amiri Decree No. 1 of 2021 the National Cyber Governance and Assurance Affairs at the National Cyber Security Agency is the competent department for administering and enforcing it. People can complain to it, and after investigating it can order a controller or processor to fix a breach within a set period (Article 26).

What are the penalties under Qatar’s PDPPL?

Fines of up to QR1 million for breaching Articles 4, 8, 9, 10, 11, 12, 14, 15 and 22, and up to QR5 million for breaching Article 13 (security precautions), processing special-nature data without a permit, or the rules for websites aimed at children. A company can be fined up to QR1 million for an offence committed in its name, and any contract that breaches the law is void. This is not legal advice.

What about firms in the Qatar Financial Centre?

QFC firms have their own Data Protection Regulations 2021, administered by the QFC’s Data Protection Office. Check with counsel which regime governs a given processing activity; this page covers the national law.

More in this topic

  • Dubai’s financial centre wrote duties for AI systems into its data protection rules, where Qatar’s law has none.

  • Getting reliable text out of Arabic scans and forms, which the data map for a Qatari system usually depends on.

Further

  • AI governance implementation · The engagement that builds the impact assessment, the processor register and the logging into the system itself.
  • Engagement file D-02 · A government-accredited EdTech in the Middle East, with its database replatformed into Google Cloud’s Doha region.

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM