Personal Data Protection Law, enforcement and penalties
Law No. 30 of 2018, Arts. 55, 57-60
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 August 2019.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- An app processing the personal data of an individual in Bahrain without the required lawful basis, prior authorisation, or transfer safeguard risks both criminal penalties (imprisonment and fines up to BD 20,000) and administrative penalties (up to BD 20,000, plus a daily compliance penalty on repeat violation) from the Personal Data Protection Authority, and a data subject who suffers damage from unlawful processing may separately claim compensation directly from the app under Art. 57.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Art. 58(1) criminalizes nine categories of Data Controller misconduct: unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14(1)), failure to notify a change to a notified processing operation (Art. 14(6)), processing without the Art. 15 prior authorization, giving the Authority or a data subject false or misleading data, withholding data from the Authority, obstructing inspectors or an investigation, and an insider's unlawful disclosure or use of data. Each is punishable by imprisonment for a term not exceeding one year, and/or a fine of not less than BD 1,000 and not exceeding BD 20,000. Art. 59 doubles both fine limits, BD 2,000 to BD 40,000, where the offense is committed in a legal person's name or for its benefit, attributable to a board member's, delegated official's or agent's act, omission, approval, cover-up, or gross negligence. A narrower Art. 58(2) fine of BD 3,000 to BD 20,000 applies only to a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not to a Data Controller's data-handling violation, so it is not counted as this instrument's criminal exposure to a regulated app. Art. 60 lets the Board offer conciliation, which ends the criminal proceeding on payment of the minimum fine within 7 days, for the Art. 58(1) notification, updated-notification, and unauthorized-processing offenses (paragraphs 1/c-1/e).
Penalty structure
Art. 55(1) empowers the PDPA Board, once a violation is established and the offender fails to comply with the Board's stop order, to issue reasoned resolutions choosing among: withdrawing an Art. 15 authorization; imposing a daily compliance penalty of BD 1,000 per day for a first violation, escalating to BD 2,000 per day for a second violation within three years of the first decision, uncapped in total and running until the violation is stopped; or imposing a separate, one-off administrative penalty not exceeding BD 20,000. The BD 20,000 figure is that separate administrative penalty's own ceiling, not an aggregate cap on the daily compliance penalty, which the statute leaves open-ended. This administrative track is independent of the criminal fines under Arts. 58-59 (see criminal_exposure_note) and of the Art. 57 private compensation claim.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- BHD
- Per violation unit
- Day
- Per violation amount
- 1,000
Over one month of continuous breach, BHD 30,440.
Who enforces it
Enforcement body
Personal Data Protection Authority (PDPA)
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Personal Data Protection Authority (PDPA), established by Art. 27, enforces the Law.
Penalties are dual-track: under Art. 58, imprisonment up to one year and/or a fine of BD 1,000 to BD 20,000 for a list of violations including unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14), processing without Art. 15 prior authorisation, and providing false information or obstructing inspectors; Art. 58(2)'s separate BD 3,000 to BD 20,000 fine is for a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not a Data Controller's data-handling violation.
Art. 59 doubles these fines for a legal person committing the offense in its name or for its benefit. Art. 55 supplies a separate administrative track: a daily compliance penalty (BD 1,000 per day on a first violation, BD 2,000 per day on a repeat violation within three years) and an administrative penalty up to BD 20,000, plus withdrawal of an Art. 15 authorisation.
Art. 57 gives a Data Subject a private right of action: a party who suffers damage from a Data Controller's or Data Protection Guardian's processing of their personal data, or from a Data Protection Guardian's violation of the Law, is entitled to claim compensation from the Data Controller or Data Protection Guardian, without prejudice to the Civil Law.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official statute text, Personal Data Protection Authority
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.