Qatar PDPPL (Law No. 13 of 2016)
National Cyber Governance and Assurance Affairs · Qatar · Updated July 30, 2026
Law No. 13 of 2016 sets obligations for organisations processing personal data in Qatar: lawful-basis processing, transparent privacy notices, explicit prior consent where relied upon, individual rights, security measures proportionate to sensitivity, written processor contracts, and notification of the competent authority within 72 hours of a breach.
The legal analysis — determining lawful bases and drafting notices — is work for counsel. What software helps with is the recurring, evidence-heavy operational layer underneath it.
Structure at a glance
- Instrument
- Law No. 13 of 2016
- Supervisory body
- NCGAA
- Breach notification
- Within 72 hours
- Consent
- Explicit and prior, where relied upon
- Impact assessment
- Expected before new processing
Obligations compiled from the law and published regulatory guidance. Less directly primary-sourced than the ECC and SAMA entries — treat the detail as orientation, not legal advice.
Who is in scope
- Organisations processing personal data in Qatar
- Controllers determining the purpose and means of processing
- Processors acting on a controller’s behalf, via written contract
How compliance is assessed
Supervised by the National Cyber Governance and Assurance Affairs. Accountability is evidenced through processing records, consent records, impact assessments and breach documentation rather than a certification.
Go deeper on PDPPL
Free PDPPL compliance checklist
35 controller obligations across governance, consent, rights, security, processors and breach response.
PDPPL software buyer’s view
Where software genuinely helps, where it does not, and how to sequence a first-time programme.
Compare compliance platforms
Which platforms ship PDPPL content, and which expect you to build it.