Skip to content
AuditGRC

Qatar PDPPL (Law No. 13 of 2016)

National Cyber Governance and Assurance Affairs · Qatar · Updated July 30, 2026

Law No. 13 of 2016 sets obligations for organisations processing personal data in Qatar: lawful-basis processing, transparent privacy notices, explicit prior consent where relied upon, individual rights, security measures proportionate to sensitivity, written processor contracts, and notification of the competent authority within 72 hours of a breach.

The legal analysis — determining lawful bases and drafting notices — is work for counsel. What software helps with is the recurring, evidence-heavy operational layer underneath it.

Structure at a glance

Instrument
Law No. 13 of 2016
Supervisory body
NCGAA
Breach notification
Within 72 hours
Consent
Explicit and prior, where relied upon
Impact assessment
Expected before new processing

Obligations compiled from the law and published regulatory guidance. Less directly primary-sourced than the ECC and SAMA entries — treat the detail as orientation, not legal advice.

Who is in scope

  • Organisations processing personal data in Qatar
  • Controllers determining the purpose and means of processing
  • Processors acting on a controller’s behalf, via written contract

How compliance is assessed

Supervised by the National Cyber Governance and Assurance Affairs. Accountability is evidenced through processing records, consent records, impact assessments and breach documentation rather than a certification.

Go deeper on PDPPL

Other frameworks