Data Protection Atlas

Qatar

Tier 3 Comprehensive law Middle East

Principal framework: Law 13/2016 on Personal Data Privacy Protection (2016). Regulator: NCGAA (+ separate QFC regime). Law 13/2016 was the Gulf’s first comprehensive law; the QFC free zone runs a separate GDPR-style regime with its own Data Protection Office.

At a glance

Principal law
Law 13/2016 on Personal Data Privacy Protection
Regulator
NCGAA (+ separate QFC regime)
Breach notification
Notify the regulator and individuals where serious harm
Maximum penalty
Fines up to QAR 5m
DPO required
Not generally mandatory
Digital consent age
Parental consent for children
Extraterritorial reach
Electronic processing wholly or partly in Qatar

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
QA

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.