Personal Data Protection Law, comprehensive regime and lawful basis
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 August 2019.
A comprehensive regime rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Bahrain must obtain the Data Subject's consent or rely on a listed alternative lawful basis under the Personal Data Protection Law.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Personal Data Protection Law is Bahrain's comprehensive, consent-centric statute with enumerated grounds. Processing generally requires the Data Subject's consent or a listed alternative basis. A Controller/Processor structure is present, alongside a "Data Protection Guardian" role, Bahrain's DPO-equivalent. The Personal Data Protection Authority (PDPA), established by Art. 27, supervises compliance.
Roughly ten Ministerial Resolutions (Orders No. 42-51 of 2022) supply substantial operative detail; their content is not described here.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official statute text, Personal Data Protection Authority
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.