Law / Qatar

Personal Data Privacy Protection Law, comprehensive regime

Law No. 13 of 2016, Chapter One

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2017.

A comprehensive regime rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that collects, uses, or discloses the personal data of an individual in Qatar, including a voiceprint, faceprint, or other biometric identifier, must have a lawful, consent-and-purpose-based basis for processing under the PDPPL; Qatar's special-nature-data list does not name biometric data as its own heightened category, but ordinary personal data duties still apply to it.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.

Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.

Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official statute text, National Cyber Security Agency document library

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app