Law / Qatar

Personal Data Privacy Protection Law, enforcement and penalties

Law No. 13 of 2016, Arts. 23-26

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2017.

An enforcement supervision rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app processing the personal data of an individual in Qatar, including a voiceprint or faceprint, must answer to the Competent Department's complaint-and-rectification process rather than a private civil suit from the individual; a violation of the special-nature-data permission requirement or the children's-website provisions carries the higher QAR 5,000,000 fine tier, and these violations are framed as criminal offenses reaching a responsible legal person.

If you get it wrong

Private right of actionNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 23 sets fines up to QAR 1,000,000 for violations of Arts. 4, 8, 9, 10, 11, 12, 14, 15, and 22. Art. 24 sets fines up to QAR 5,000,000 for violations of Art. 13, Art. 16(3) (special-nature data processing without permission), and Art. 17 (children's websites). Art. 25 extends liability to a legal person committing these "crimes" in its name, confirming these are framed as criminal offenses rather than purely civil or administrative fines.

Art. 26 gives an Individual a complaint route to the Competent Department, which can issue a binding rectification order for a proven serious complaint, with a grievance route to the Minister (60-day windows both ways, silence treated as implicit rejection); no private civil right of action was found.

The PDPPL's own text names "the Competent Department" (within the Ministry of Transport and Communications) as enforcer; current secondary sources refer to a National Data Privacy Office (NDPO) operating within the National Cyber Security Agency, but whether NDPO has formally assumed the Competent Department's statutory role was not confirmed at primary source.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official statute text, National Cyber Security Agency document library

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app