Personal Data Privacy Protection Law, breach notification
Law No. 13 of 2016, Arts. 13-14
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2017.
A breach notification rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.
Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
official statute text, National Cyber Security Agency document library
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.