What is PDPPL?
Qatar's Personal Data Privacy Protection Law (PDPPL) is Law No. 13 of 2016. It was promulgated by HH the Emir on 13 November 2016 and entered into force in 2017, making Qatar the first GCC state with a comprehensive data protection statute. It is supervised by the National Data Privacy Office (NDPO) within NCSA, applies to anyone processing personal data in Qatar, requires breach notification within 72 hours, and carries fines of QAR 1,000,000 to QAR 5,000,000 per violation.
The Personal Data Privacy Protection Law (PDPPL) is Qatar's primary personal data protection statute, promulgated by His Highness the Emir on 13 November 2016 as Law No. 13 of 2016 and entering into force in 2017. It established Qatar as one of the first GCC jurisdictions with a comprehensive data protection regime, predating Saudi Arabia's PDPL by several years.
PDPPL applies to any natural or legal person processing personal data within the State of Qatar — both public and private sector. It establishes core data subject rights (access, correction, withdrawal of consent, the right to be informed of processing purposes), defines obligations for data controllers and processors, and mandates appropriate organisational and technical security measures calibrated to the nature and sensitivity of the data being processed.
Supervision is performed by the National Data Privacy Office (NDPO), which sits within the National Cyber Governance and Assurance Affairs (NCGAA) division of NCSA. The NDPO has issued a series of executive guidelines clarifying breach notification timelines (72 hours), the requirement for a Personal Data Management System (incorporating DPIAs and Records of Processing Activities), and the calculation of penalties — which range from QAR 1 million to QAR 5 million per violation. Active enforcement began in earnest in 2024-2025 with public compliance orders against ICT and e-commerce operators.
Who must comply with PDPPL?
- 01Any natural or legal person processing personal data within the State of Qatar
- 02All Qatar-based public sector entities (ministries, agencies, statutory bodies)
- 03All private sector organisations operating in Qatar — irrespective of size
- 04Foreign organisations processing personal data of individuals located in Qatar
- 05Data processors acting on behalf of controllers (joint and several liability for security failings)
PDPPL structure at a glance
The PDPPL framework is organised into the following control areas. Vantage GRC pre-maps each one so evidence collected once contributes to your compliance picture across overlapping frameworks.
Data Subject Rights
Controller & Processor Obligations
Special Categories & Cross-Border
What PDPPL requires you to do
- 1Establish and maintain a Personal Data Management System (PDMS) covering processing activities, breach notification procedures, and data subject rights fulfilment.
- 2Maintain Records of Processing Activities (RoPA) for all personal data processing operations.
- 3Conduct Data Protection Impact Assessments (DPIAs) for processing likely to result in high risk to data subjects.
- 4Implement organisational and technical security measures commensurate with the nature, volume, and risk of the data processed.
- 5Notify NDPO of personal data breaches within 72 hours of becoming aware, with notification to affected data subjects where their rights are at material risk.
- 6Honour data subject rights requests within statutory timelines and provide a clear redress mechanism.
Score your PDPPL readiness in under 5 minutes
Answer 17 questions across all PDPPL control domains, get an instant maturity score, a scored gap analysis, and a downloadable PDF report with prioritised remediation guidance.
Achieve PDPPL compliance with Vantage
PDPPL Compliance Assessment
Structured gap assessment against PDPPL and the NDPO executive guidelines, with a RoPA baseline and prioritised remediation roadmap on a fixed fee.
GRC Consulting Qatar
Senior advisory to build and run your PDPPL data-protection compliance programme.
IT Audit & Cybersecurity Audit in Qatar
Independent audit of the technical and access controls that underpin PDPPL security obligations, by CISA-certified auditors.
Information Security Risk Assessment
Risk assessment feeding the DPIAs that PDPPL requires for high-risk processing activities.
PDPPL questions
What is the effective date of Qatar's data privacy law?
Law No. 13 of 2016 on the Protection of Personal Data Privacy was promulgated by HH the Emir on 13 November 2016 and entered into force in 2017, six months after publication in the Official Gazette. The NDPO's executive guidelines — which set the 72-hour breach notification window and the Personal Data Management System requirement — were issued subsequently and are what most organisations are actually assessed against today.
Where can I find the official text of Qatar Law No. 13 of 2016?
The authoritative Arabic text is published in Qatar's Official Gazette and hosted on Al-Meezan, the Qatar Legal Portal (almeezan.qa), which is the government's official legislation repository. The National Cyber Security Agency (NCSA) publishes the National Data Privacy Office guidelines that sit underneath the law. Vantage does not republish the statute — for any compliance decision you should work from the official Al-Meezan text or a certified translation, since unofficial English versions circulating online differ in places that matter.
Is there an official English version of the Qatar PDPPL?
Arabic is the authoritative legal language for Qatari legislation, and the Arabic text on Al-Meezan governs in any dispute. English translations are available through Al-Meezan and various law firms, but they are reference aids rather than binding instruments. Where an obligation is ambiguous in translation — particularly around consent, special-category data, and cross-border transfer — we recommend validating against the Arabic text before designing a control.
Who must comply with Qatar PDPPL?
PDPPL applies to any natural or legal person processing personal data within the State of Qatar — covering both public and private sector, of any size, and including foreign organisations processing the personal data of individuals located in Qatar.
What are the maximum penalties under PDPPL?
Penalties range from QAR 1 million to QAR 5 million (~USD 275,000 to ~USD 1.4 million) per violation. Failure to put in place appropriate security precautions carries fines up to QAR 5 million per violation, applied equally to controllers and processors. PDPPL does not include imprisonment provisions — it is a purely financial penalty regime.
How quickly must data breaches be notified?
The NDPO's executive guidelines require notification within 72 hours of the breach occurring or being detected. Notifications must include details of the nature of the breach, the data affected, the number of data subjects involved, and the measures taken to address and mitigate the breach.
How does PDPPL differ from GDPR?
PDPPL is consent-centric and lacks GDPR's broader range of lawful bases (legitimate interest, contract performance, etc.). It applies a fixed financial penalty range rather than GDPR's percentage-of-turnover model. However, it shares core principles — purpose limitation, data minimisation, security by design, and data subject rights. Organisations operating across both regimes typically build a unified privacy programme that satisfies the stricter requirement on each dimension.
Is PDPPL actively enforced?
Yes. Public enforcement actions began in earnest in 2024-2025. In December 2024, the NDPO issued a compliance ruling against an ICT sector company; in March 2025, an e-commerce operator received an order to enhance its administrative, technical, and financial procedures for personal data protection. Active enforcement is now the operating reality.
Ready to operationalise PDPPL compliance?
Talk to a Vantage GRC consultant about your PDPPL programme — pre-mapped controls, evidence management, and audit-ready dashboards. Doha-based.