Personal Data Protection Law, cross-border transfer
Law No. 30 of 2018, Arts. 12-13
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 August 2019.
A cross border transfer rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of an individual in Bahrain to a recipient outside Bahrain must confirm the destination is on the PDPA's published adequacy whitelist or has case-by-case PDPA authorisation, or must rely on one of Art. 13's listed exemptions such as the Data Subject's consent.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 12 prohibits transfer of personal data outside Bahrain except to a country on a PDPA-published adequacy whitelist (published in the Official Gazette), or under a case-by-case PDPA authorisation based on an adequacy assessment considering the data's nature, origin and destination, and relevant international agreements.
Art. 13 lists exemptions allowing transfer to a non-adequate destination without going through Art. 12: data-subject consent, a public-register transfer, contract necessity, vital-interest protection, legal obligation or court or prosecution order, and legal-claim preparation. This is a prohibition-with-listed-exceptions structure, the strictest transfer posture across this batch.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
official statute text, Personal Data Protection Authority
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.