Qatar PDPPL compliance checklist
Work through the 35 practical obligations under Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016), mark where you stand, and export your gap list with owners and target dates. No signup — everything stays in your browser.
—
Readiness
0
Gaps to address
0
of 35 answered
Governance and accountability
The foundations the rest of the obligations depend on.
- We know which of our processing activities fall within scope of the PDPPL
- A named individual or function is accountable for personal data protection
- We maintain a record of our processing activities What data, why, on what basis, who it is shared with, how long it is kept
- We have an internal personal data protection policy that staff are aware of
- Staff handling personal data receive periodic training
- We have an internal system for managing personal data, breaches and individual rights
Lawful basis, notices and consent
Why you are allowed to process, and what you told people about it.
- Every processing activity has an identified lawful basis
- Privacy notices are provided to individuals and describe our actual processing Notices that no longer match reality are a common finding
- Where we rely on consent, it is obtained explicitly and in advance
- We keep a record of how and when consent was obtained
- Individuals are given a valid address through which they can withdraw consent
- Withdrawal of consent is honoured and stops the relevant processing
- Direct electronic marketing is only sent with prior consent
- Processing of data of children or data of a special nature receives additional safeguards
Individual rights
Whether you can actually answer a request within a reasonable time.
- We can receive, verify and log requests from individuals
- We can retrieve all personal data we hold about a given individual
- We can correct inaccurate personal data on request
- We can erase personal data on request where the obligation applies
- We can act on objections to processing, including direct marketing
- Requests are tracked to a deadline with escalation if they age
Security and data minimisation
Technical and organisational measures proportionate to the data.
- Technical and organisational security measures are in place and proportionate to sensitivity
- Access to personal data is restricted on a need-to-know basis and reviewed periodically
- We collect only the personal data necessary for the stated purpose
- Retention periods are defined and personal data is deleted when no longer needed
- We assess privacy impact before starting new or significantly changed processing A data protection impact assessment
Processors and transfers
Everyone else who touches the data on your behalf.
- We know which third parties process personal data on our behalf
- A written data processing contract is in place with each processor Covering type, duration and purpose of processing, individual rights and security measures
- We check our processors' compliance rather than assuming it
- Cross-border transfers are assessed before data leaves Qatar
Breach response
The obligation with a clock attached.
- We can detect a personal data breach and escalate it internally without delay
- We have a documented breach assessment and notification procedure
- We can notify the competent authority within 72 hours of a breach Notification to the NCGAA is required within 72 hours
- We can notify affected individuals where the breach causes serious damage to their privacy or data
- Processors are contractually required to notify us of breaches immediately
- Breaches and our response decisions are documented for accountability
About this checklist
Qatar's Law No. 13 of 2016 Concerning Personal Data Privacy Protection sets obligations for organisations processing personal data in Qatar: processing on a lawful basis, transparent privacy notices, explicit prior consent where relied upon, honouring individual rights, proportionate security measures, written contracts with processors, impact assessment before new processing, and notification of the competent authority within 72 hours of a breach.
This is a readiness checklist, not legal advice. It is written to help you find operational gaps quickly. The authoritative sources are the law itself and the guidance issued by the National Cyber Governance and Assurance Affairs — and the lawful-basis analysis behind several of these questions is legal work you should do with counsel, not a tick box.
Where to start if most answers are "no"
Build the processing record first — every other obligation depends on knowing what personal data you hold and why. Then stand up the breach and individual-request workflows, because those carry deadlines with legal consequences. Security measures, processor contracts and impact assessments follow. Buying tooling before the processing record exists is the most reliable way to end up with expensive shelfware.
For more depth, read our PDPPL software buyer's guide, or compare platforms that ship PDPPL control content in the compliance software category.