Personal Data Privacy Protection Law, cross-border data flow
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2017.
A cross border transfer rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of an individual in Qatar out of the country, including a voiceprint or faceprint, is not itself restricted by the Controller absent an underlying breach of the PDPPL or a risk of serious damage to the data or the individual's privacy; Qatar's PDPPL, read plainly, does not impose an adequacy or whitelist gate on outbound transfer the way the UAE's or Saudi Arabia's do.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.
Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
official statute text, National Cyber Security Agency document library
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.