Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
Middle EastMEDIUM coverage

Qatar Personal Data Protection Law (PDPL): AI Compliance Requirements

Qatar Law No. 13 of 2016 (Personal Data Privacy Protection Law, "PDPL"/"PDPPL"), promulgated 13 November 2016 and in force from 2017, is enforced by the National Cyber Security Agency (NCSA). Any organization using AI systems to process Qatar resident data must comply with lawful basis, data subject rights, and cross-border transfer requirements. Administrative fines are TIERED: up to QAR 1,000,000 for general violations, up to QAR 5,000,000 for more serious breaches (e.g. sensitive data or children's data) — verified this cycle. The PDPL itself has NO imprisonment provision (a prior "up to 3 years imprisonment" claim was fabricated/conflated with Qatar's separate Cybercrime Law No. 14 of 2014, a different statute, and has been removed).

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

November 14, 2016

Enforcement Begins

November 14, 2017

Maximum Penalty

QAR 1,000,000 (~$275,000 USD) for general violations; up to QAR 5,000,000 (~$1.37M USD) for serious violations (sensitive data, children's data). No imprisonment under the PDPL itself (a distinct statute, the Cybercrime Law, carries separate criminal penalties).

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Lawful Basis for AI Data Processing (Qatar)

High Priority

Qatar PDPL requires documented consent or legitimate interest justification for processing Qatar resident personal data through AI systems. Document the legal basis for each AI use case.

Deadline: November 14, 2017

Qatar PDPL (Law No. 13 of 2016) Art. 4

Disclose AI-Driven Automated Decisions (Qatar)

High Priority

Qatar PDPL Art. 10 requires informing data subjects about AI automated decisions that significantly affect them. Implement disclosure mechanisms for Qatar residents.

Qatar PDPL (Law No. 13 of 2016) Art. 10

Cross-Border AI Data Transfer Authorization (Qatar)

Medium Priority

Transferring Qatar resident data to AI vendors outside Qatar requires NCSA authorization. Review AI vendor data residency for Qatar data.

Qatar PDPL (Law No. 13 of 2016) Art. 14

Recent Regulatory Guidance

guidance2023-11

Qatar NCSA — AI Data Governance Guidance under PDPL (2023)

Qatar's National Cyber Security Agency published guidance on PDPL application to AI systems: all automated processing of personal data requires NCSA authorization; AI systems making decisions with significant effects on Qatari residents must provide PDPL Article 10 objection rights; cross-border transfers of Qatari personal data to AI cloud providers require NCSA adequacy determination or authorization; organizations using new technologies must conduct privacy impact assessments before deployment.

Frequently Asked Questions

Does Qatar Personal Data Protection Law (PDPL) apply to my business?

Qatar Law No. 13 of 2016 (Personal Data Privacy Protection Law, "PDPL"/"PDPPL"), promulgated 13 November 2016 and in force from 2017, is enforced by the National Cyber Security Agency (NCSA). Any organization using AI systems to process Qatar… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Qatar Personal Data Protection Law (PDPL) is: QAR 1,000,000 (~$275,000 USD) for general violations; up to QAR 5,000,000 (~$1.37M USD) for serious violations (sensitive data, children's data). No imprisonment under the PDPL itself (a distinct statute, the Cybercrime Law, carries separate criminal penalties).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Qatar Personal Data Protection Law (PDPL)?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.motc.gov.qa/en/page/pdpl

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan