Law / Qatar

Qatar

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 10 in force. As of 16 September 2026.

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (148 words)

Qatar has no general AI statute; the national AI strategy published by the Ministry of Communications and Information Technology (MCIT) is a government-facing policy document rather than a law binding third parties.

The one binding, sector-specific AI rule found at primary source is the Qatar Central Bank's Artificial Intelligence Guideline, issued for 2024 under the Qatar Central Bank Law, which imposes mandatory AI-governance, approval, and human-oversight duties on QCB-regulated financial entities.

Other Qatari regulators, including MCIT and the National Cyber Security Agency, have issued non-binding AI ethics and security guidance; because such guidance carries no statutory force, it is not authored here as an instrument.

A Qatar International Court and Dispute Resolution Centre practice direction on verifying AI-generated material in court filings governs litigation conduct before that court alone and does not impose a duty on an app or service generally, so it is likewise not authored here.

AI sector rules

Qatar Central Bank Artificial Intelligence Guideline

Qatar Central Bank Artificial Intelligence Guideline (2024)Qatar Central Bank, official guideline text

In force. Binds private bodies.

What this law does

The Guideline covers the use of AI by a QCB-regulated entity and imposes mandatory duties, using 'must' throughout, rather than voluntary recommendations. An entity must receive QCB approval before launching a new AI system as a provider, before a material modification to one, and before signing a High-Risk AI purchase, licensing, or outsourcing agreement.

A regulated entity must maintain an AI system register and a defined AI strategy, adopt an AI governance policy, conduct risk assessments including bias testing for High-Risk AI, and provide human oversight of AI-driven decisions. A regulated entity must give a customer a mechanism to raise inquiries about an AI-driven decision and request a review of it, and must handle any resulting complaint through standard customer-complaint processes.

The Guideline states that, alongside the Qatar Central Bank Law, an entity must also comply with named secondary regulations, including the Personal Data Privacy Protection Law (Law No. 13 of 2016) where personal data is involved. The Guideline's own commencement clause names it 'the Artificial Intelligence Guideline for 2024' without a further stated calendar day for its entry into force.

What it requires

Privacy law5 instruments, 5 in force

Research summary (281 words)

Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, PDPPL) is the Gulf's first data-protection statute and, read at primary source, is markedly shorter and more high-level than the UAE or Saudi PDPLs. It is a comprehensive regime: Art. 1's broad, technology-neutral Personal Data definition reaches a voiceprint or faceprint like any other identifying data, so an app deriving one from an individual in Qatar is bound by the PDPPL's ordinary duties.

A real gap relative to its Gulf peers remains: Article 16's "Personal Data with Special Nature" list, the closest thing the PDPPL has to a sensitive-category provision, does not name biometric data at all, unlike the newer UAE, Saudi, Omani, and Jordanian statutes, so a biometric identifier does not trigger the Art. 16(3) heightened Competent Department permission requirement the way it does in those regimes, though the Minister may add categories by decision and no evidence such a decision has added biometric data was found.

Cross-border data flow is governed by Article 15, whose plain text bars the Controller from restricting flow except where the underlying processing already breaches the Law or risks serious damage, a permissive default rather than an adequacy gate, arguably lighter than the carried moderate seed.

A 2025 Cybercrime Law amendment (Law No. 11 of 2025, reportedly adding Art. 8 bis to Law No. 14 of 2014) is referenced by secondary trackers; its Official Gazette text has not been located, so its content is not described here. Qatar also runs a separate Qatar Financial Centre (QFC) Data Protection Regulations free-zone regime; only the superseded 2005 QFC text could be located, not the reported 2021 General Data Protection Regulation (GDPR)-aligned replacement, so it is likewise not authored here.

Breach notification

Personal Data Privacy Protection Law, breach notification

Law No. 13 of 2016, Arts. 13-14official statute text, National Cyber Security Agency document library

In force since 1 January 2017. Binds public and private bodies.

What this law does

Art. 14 requires the Controller to inform the Individual and the Competent Department of a breach of the Art. 13 security precautions, but only if the breach may cause serious damage to Personal Data or individual privacy, a materiality-gated duty with no fixed notification timeline (no hours or days figure) in the text read.

Art. 13 separately requires the Processor to "forthwith notify the Controller" of any breach or risk, an internal Processor-to-Controller duty distinct from the Controller's own duty to the Individual and Department. These duties apply to any Personal Data breach, including one involving a biometric identifier, since Arts. 13-14 are not limited to Art. 16's special-nature categories.

What it requires

Comprehensive regime

Personal Data Privacy Protection Law, comprehensive regime

Law No. 13 of 2016, Chapter Oneofficial statute text, National Cyber Security Agency document library

In force since 1 January 2017. Binds public and private bodies.

What this law does

The Personal Data Privacy Protection Law (PDPPL), 27 articles, is Qatar's comprehensive personal-data statute, defining Controller, Processor, Individual, Personal Data, Cross-Border Data Flows, and other core terms in Chapter One.

Art. 1's Personal Data definition ("data of an individual whose identity is defined or can be reasonably defined") is broad and technology-neutral and plainly reaches a voiceprint or faceprint, so a biometric identifier is ordinary Personal Data bound by the PDPPL's ordinary duties even though it is absent from the Art. 16 special-nature list (see the sensitive_categories instrument): the absence changes which heightened permission duty applies, not whether the PDPPL applies at all.

Its structure is consent-and-purpose based rather than the multi-basis structure seen in the UAE and Saudi statutes; a full enumeration of lawful-basis grounds was not individually extracted.

What it requires

Cross border transfer

Personal Data Privacy Protection Law, cross-border data flow

Law No. 13 of 2016, Art. 15official statute text, National Cyber Security Agency document library

In force since 1 January 2017. Binds public and private bodies.

What this law does

Art. 15 bars the Controller from restricting cross-border data flow, unless the underlying processing already breaches the Law or would cause serious damage to the Personal Data or the Individual's privacy. Read plainly, this is a permissive default favoring cross-border flow, notably lighter than the adequacy-gated regimes in the UAE and Saudi Arabia read in this batch, and arguably lighter than the carried moderate seed suggests. No data-localization requirement was found.

Art. 15 applies to Personal Data generally, biometric identifiers included, since Art. 16's special-nature list narrows only which processing needs Competent Department permission, not what counts as Personal Data for this provision.

What it requires

Enforcement supervision

Personal Data Privacy Protection Law, enforcement and penalties

Law No. 13 of 2016, Arts. 23-26official statute text, National Cyber Security Agency document library

In force since 1 January 2017. Binds public and private bodies.

What this law does

Art. 23 sets fines up to QAR 1,000,000 for violations of Arts. 4, 8, 9, 10, 11, 12, 14, 15, and 22. Art. 24 sets fines up to QAR 5,000,000 for violations of Art. 13, Art. 16(3) (special-nature data processing without permission), and Art. 17 (children's websites). Art. 25 extends liability to a legal person committing these "crimes" in its name, confirming these are framed as criminal offenses rather than purely civil or administrative fines.

Art. 26 gives an Individual a complaint route to the Competent Department, which can issue a binding rectification order for a proven serious complaint, with a grievance route to the Minister (60-day windows both ways, silence treated as implicit rejection); no private civil right of action was found.

The PDPPL's own text names "the Competent Department" (within the Ministry of Transport and Communications) as enforcer; current secondary sources refer to a National Data Privacy Office (NDPO) operating within the National Cyber Security Agency, but whether NDPO has formally assumed the Competent Department's statutory role was not confirmed at primary source.

What it requires

Sensitive categories

Personal Data Privacy Protection Law, special-nature personal data

Law No. 13 of 2016, Art. 16official statute text, National Cyber Security Agency document library

In force since 1 January 2017. Binds public and private bodies.

What this law does

Art. 16 lists ethnic origin, children's data, health, physical or psychological condition, religious creeds, marital relations, and criminal offenses as "Personal Data with Special Nature."

Biometric data is not named, unlike the UAE, Saudi, Oman, and Jordan statutes researched in this batch, a real gap rather than a research omission: the Minister may add other categories by decision where misuse could cause serious damage (Art. 16, para. 2), but no evidence that this power has been exercised for biometric data was found.

Processing special-nature data requires "permission from the Competent Department, as per the measures and controls determined by a decision issued by the Minister" (Art. 16, para. 3), and a violation carries the higher QAR 5,000,000 penalty tier under Art. 24. A voiceprint or faceprint might be captured under "physical... condition" by a stretched reading, but that fit is not textually confirmed, so Qatar's PDPPL is not coded here as reaching biometric identifiers as a heightened category.

What it requires

Scraping law3 instruments, 3 in force

Research summary (275 words)

Qatar has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrime Prevention Law (Law No. 14 of 2014) criminalises intentionally and illegally accessing a website, information system, or information network, exceeding authorised access, or knowingly continuing access once it is known to be unauthorised (art. 3), with a doubled penalty where the target belongs to a state authority or affiliated corporation (art. 2); no reported case addresses whether reading a public, unauthenticated page without defeating an access control fits this offence.

No Qatari court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Protection Law (Law No. 7 of 2002) permits reproduction for personal use, non-profit teaching illustration, and brief quotation for criticism (art. 18), and lets the lawful holder of a computer program copy adapt it to the extent justified by the original purpose (art. 20), but Qatar has not enacted a text-and-data-mining exception, so bulk reproduction of copyrighted text to train a model does not fit these narrow categories.

A database or compilation is protected only if creative in the selection or arrangement of its contents (art. 3(3)); Qatar confers no separate sui generis database right, and laws, official documents, ideas, procedures, and daily news of a mere informatory nature are excluded from protection altogether (art. 4).

Personal-data reach over scraped public personal data is governed by the Personal Data Privacy Protection Law (Law No. 13 of 2016), already researched under this jurisdiction's privacy topic. No Qatari statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrime Prevention Law, unauthorised access

Law No. 14 of 2014 (Cybercrime Prevention Law), arts. 2-4official unofficial-translation text published by the Communications Regulatory Authority (CRA)

In force. Binds public and private bodies.

What this law does

Article 3 punishes any person who intentionally and illegally accesses a website, information system, information network, or information technology technique, exceeds authorised access, or knowingly continues to visit or access it once aware the access is unauthorised, with imprisonment of up to three years and a fine of up to QAR 500,000, doubled where the access results in acquiring, disclosing, destroying, or republishing data.

Article 2 imposes the same base penalty, doubled on the same grounds, for unlawful access specifically to a website or information system belonging to a state authority, body, entity, or affiliated corporation. Article 4 separately punishes unlawfully capturing, intercepting, or spying on traffic data or data in transit through an information network or technology technique, with a lower ceiling of two years and QAR 100,000. The Law does not define 'unauthorised' by reference to a technical access control.

What it requires

Copyright and text and data mining (TDM)

Copyright Protection Law, exceptions to copyright

Law No. 7 of 2002, arts. 18, 20-21official English translation of Law No. 7 of 2002, WIPO Lex

In force since 3 August 2002. Binds public and private bodies.

What this law does

Article 18 permits using a protected work without the author's authorisation for exclusively personal use (reproduction, translation, or quotation among other means), and for non-profit teaching illustration with source and author attribution. Article 20 lets the rightful owner of a copy of a computer program reproduce or adapt it, in a single copy, to the extent justified by the original purpose or for preservation, a right that lapses once possession of the program ceases to be lawful.

Article 21 permits reproduction of articles, short works, or extracts for teaching in non-commercial educational institutions, subject to conditions. Article 58 ties the Law's entry into force to the date of its publication in the Official Gazette, reported by WIPO Lex's bibliographic record for this version as 3 August 2002. Exceeding these exceptions is an ordinary infringement, punishable under article 48.

What it requires

Database right

Copyright Protection Law, database and excluded subject matter

Law No. 7 of 2002, arts. 3(3), 4official English translation of Law No. 7 of 2002, WIPO Lex

In force since 3 August 2002. Binds public and private bodies.

What this law does

Article 3(3), read against article 2's list of originally protected works, protects a database as a derived work only 'if creative in the arrangement of selection of their subject matter', the same originality-in-selection standard the article applies to encyclopedia collections and folklore compilations; Qatar confers no separate sui generis database right beyond this compilation standard.

Article 4 excludes laws, legal provisions, administrative decisions, international treaties, and official documents from protection (though a creative compilation of such material is still protected), along with daily news and other news of a mere informatory nature, and ideas, procedures, operational methods, mathematical concepts, principles, and mere data, while any derivative expression of the latter category remains protectable.

A scraper copying data from a non-creatively-arranged database, or copying facts, ideas, or bare daily news, does not infringe a copyright interest in that material under this Law.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (184 words)

Qatar has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; neighbouring rights under the Copyright Protection Law (Law No. 7 of 2002) protect performers, sound-recording producers, and broadcasting organisations, not a print or online news publisher's own reporting. The Law's general framework is the only regime reaching an aggregator's reproduction.

Its press-article provision permits reproducing, broadcasting, or otherwise communicating to the public an article on current political, economic, social, cultural, or religious topics published in a newspaper or periodical, subject to source and author attribution, unless the publisher has explicitly reserved the reproduction right (art. 19); it also excludes daily news of a mere informatory nature from copyright protection altogether (art. 4(2)).

No statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from this copyright framework exists. The Law carries no machine-readable text-and-data-mining opt-out; article 19's reservation is a general publication right a publisher can invoke against a reproducer, not a technical opt-out mechanism aimed at automated indexing or training.

Snippet reproduction

Copyright Protection Law, press-article reproduction exception

Law No. 7 of 2002, art. 19official English translation of Law No. 7 of 2002, WIPO Lex

In force since 3 August 2002. Binds public and private bodies.

What this law does

Article 19 permits reproducing an article in a newspaper or periodical, or broadcasting or otherwise communicating to the public an article published in a newspaper or periodical on current political, economic, social, cultural, or religious topics (or a broadcast work of the same character), subject to clearly indicating the source and the author's name where known.

The permission does not apply where the author has explicitly reserved the right of reproduction or communication to the public, so a publisher can withdraw the exception for its own content by express reservation. Article 4(2) separately excludes daily news and other news of a mere informatory nature from copyright protection altogether, so a bare factual news item carries no copyright interest to begin with, independent of article 19's conditional permission for full articles.

Neighbouring rights under article 1's definitions protect performers, sound-recording producers, and broadcasting organisations, not a print or online news publisher as such, so no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates exists in Qatar. A reproduction that does not meet article 19's conditions, or that a publisher has reserved, is an ordinary infringement under article 48.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.