Law / Bahrain

Personal Data Protection Law, enforcement and penalties

Law No. 30 of 2018, Arts. 55, 57-60

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 August 2019.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • An app processing the personal data of an individual in Bahrain without the required lawful basis, prior authorisation, or transfer safeguard risks both criminal penalties (imprisonment and fines up to BD 20,000) and administrative penalties (up to BD 20,000, plus a daily compliance penalty on repeat violation) from the Personal Data Protection Authority, and a data subject who suffers damage from unlawful processing may separately claim compensation directly from the app under Art. 57.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Art. 58(1) criminalizes nine categories of Data Controller misconduct: unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14(1)), failure to notify a change to a notified processing operation (Art. 14(6)), processing without the Art. 15 prior authorization, giving the Authority or a data subject false or misleading data, withholding data from the Authority, obstructing inspectors or an investigation, and an insider's unlawful disclosure or use of data. Each is punishable by imprisonment for a term not exceeding one year, and/or a fine of not less than BD 1,000 and not exceeding BD 20,000. Art. 59 doubles both fine limits, BD 2,000 to BD 40,000, where the offense is committed in a legal person's name or for its benefit, attributable to a board member's, delegated official's or agent's act, omission, approval, cover-up, or gross negligence. A narrower Art. 58(2) fine of BD 3,000 to BD 20,000 applies only to a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not to a Data Controller's data-handling violation, so it is not counted as this instrument's criminal exposure to a regulated app. Art. 60 lets the Board offer conciliation, which ends the criminal proceeding on payment of the minimum fine within 7 days, for the Art. 58(1) notification, updated-notification, and unauthorized-processing offenses (paragraphs 1/c-1/e).

Penalty structure

Art. 55(1) empowers the PDPA Board, once a violation is established and the offender fails to comply with the Board's stop order, to issue reasoned resolutions choosing among: withdrawing an Art. 15 authorization; imposing a daily compliance penalty of BD 1,000 per day for a first violation, escalating to BD 2,000 per day for a second violation within three years of the first decision, uncapped in total and running until the violation is stopped; or imposing a separate, one-off administrative penalty not exceeding BD 20,000. The BD 20,000 figure is that separate administrative penalty's own ceiling, not an aggregate cap on the daily compliance penalty, which the statute leaves open-ended. This administrative track is independent of the criminal fines under Arts. 58-59 (see criminal_exposure_note) and of the Art. 57 private compensation claim.

Rule
Per violation only
As of
2 September 2026
Currency
BHD
Per violation unit
Day
Per violation amount
1,000

Over one month of continuous breach, BHD 30,440.

Who enforces it

Enforcement body

Personal Data Protection Authority (PDPA)

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Protection Authority (PDPA), established by Art. 27, enforces the Law.

Penalties are dual-track: under Art. 58, imprisonment up to one year and/or a fine of BD 1,000 to BD 20,000 for a list of violations including unlawful sensitive-data processing (Art. 5), unlawful cross-border transfer (Arts. 12-13), failure to notify the Authority of processing (Art. 14), processing without Art. 15 prior authorisation, and providing false information or obstructing inspectors; Art. 58(2)'s separate BD 3,000 to BD 20,000 fine is for a PDPA Board member's or employee's own breach of the Art. 32 conflict-of-interest duty, not a Data Controller's data-handling violation.

Art. 59 doubles these fines for a legal person committing the offense in its name or for its benefit. Art. 55 supplies a separate administrative track: a daily compliance penalty (BD 1,000 per day on a first violation, BD 2,000 per day on a repeat violation within three years) and an administrative penalty up to BD 20,000, plus withdrawal of an Art. 15 authorisation.

Art. 57 gives a Data Subject a private right of action: a party who suffers damage from a Data Controller's or Data Protection Guardian's processing of their personal data, or from a Data Protection Guardian's violation of the Law, is entitled to claim compensation from the Data Controller or Data Protection Guardian, without prejudice to the Civil Law.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute text, Personal Data Protection Authority

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app