Personal Data Protection Law, sensitive personal data
Law No. 30 of 2018, Arts. 1, 5
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 August 2019.
A sensitive categories rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app processing an individual's race, ethnic origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, or health or sexual status in Bahrain must obtain the Data Subject's consent unless the Art. 5 public-availability exception applies; biometric data is not part of this Sensitive Personal Data category, so it is governed instead by the Art. 15 prior-authorisation rule.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 1's Sensitive Personal Data definition covers race, ethnical origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, and health or sexual status. Biometric data is absent from this list, the same gap found in Qatar's PDPPL; it is instead regulated separately under Art. 15 (see the biometric_privacy instrument).
Art. 5(3) exempts data the Data Subject has made publicly available from the Sensitive Personal Data consent rule, but because biometric data is not itself Sensitive Personal Data, this exemption does not textually reach Art. 15's separate biometric prior-authorisation gate.
When LexLint raises it
crawls_web
Read the law
official statute text, Personal Data Protection Authority
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.