Qatar was the first country in the GCC to adopt a comprehensive data protection law: Law No. 13 of 2016 on the Protection of Personal Data Privacy, usually called the PDPPL. Regulatory guidelines issued in 2020 clarified how it applies in practice. If your website, app or internal system processes personal data about people in Qatar, the law affects how it should be designed.
This checklist is written from an engineering perspective: what to build, configure and document. It is not legal advice, and for a formal compliance opinion you should involve legal counsel. It is, however, the list we work through when we design software and apps for Qatar clients.
1. Know what personal data you collect and why
- Create a data inventory: every form, API and integration that collects personal data, what fields it collects, where the data is stored and who can access it.
- Record the purpose of each processing activity. Collecting data "in case it is useful later" is hard to justify.
- Remove fields you do not need. The cheapest data to protect is data you never collected.
2. Be transparent before you collect
- Publish a clear privacy notice in Arabic and English that explains what you collect, why, who it is shared with and how people can exercise their rights.
- Show the notice at the point of collection, for example next to sign-up and contact forms, not only in the footer.
- Where you rely on consent, record it: what the person agreed to, when, and which version of the notice they saw.
3. Treat "special nature" data differently
The PDPPL defines categories of personal data of a special nature, including data relating to health, religion, ethnic origin, criminal records, marital relationships and children. Processing these categories requires additional conditions and, under the regulatory guidelines, authorisation from the regulator.
- Flag special-nature fields in your data model so they can be handled, encrypted and audited separately.
- Restrict access to them to the smallest possible group of staff and services.
- If your website or app is directed at children, plan for parental consent and child-appropriate notices from the start.
Healthcare, education and HR systems almost always fall into this category, so plan for it during discovery rather than at launch.
4. Build in individuals' rights
The law gives individuals rights including withdrawing consent, objecting to processing, and requesting correction or erasure of their data. The guidelines set a 30-day window to respond to such requests.
- Build an admin workflow to find all data about one person across your systems, correct it and export or delete it.
- Make sure deletion actually reaches backups, analytics tools and third-party systems where practical, or document why it cannot.
- Log each request and response so you can show what was done and when.
5. Security by design
- Encrypt personal data in transit (HTTPS everywhere) and at rest.
- Use role-based access control and log access to personal data.
- Patch frameworks, libraries and servers on a regular schedule; most breaches use known vulnerabilities.
- Separate production data from development and testing; developers should not need real customer data to do their work.
- Run a data privacy impact assessment before launching new processing that is high-risk, involves special-nature data or sends data outside Qatar.
6. Plan for breaches before they happen
The regulatory guidelines require notification of personal data breaches to the regulator, and in certain cases to affected individuals, within 72 hours. That is only achievable if detection and response are prepared in advance.
- Set up monitoring and alerting that would actually notice unusual access.
- Write an incident response plan: who decides, who investigates, who notifies.
- Keep enough logs to establish what data was affected.
7. Check your processors and cross-border transfers
- List every third-party service that receives personal data: hosting, email, analytics, CRM, payment and messaging providers.
- Have written agreements with them covering security and data handling.
- Know where each one stores data. For sensitive systems, hosting in a Qatar cloud region simplifies the picture considerably.
8. AI features need the same discipline
If you add AI chatbots or document processing, personal data may flow to model providers. Minimise what is sent, choose providers and regions deliberately, and log what the system does. Our AI governance work covers this in detail.
Why this matters
Beyond the regulatory exposure, which includes substantial fines, privacy problems damage trust quickly in a market as connected as Qatar. Building these controls in from the start costs far less than retrofitting them after an incident.
If you are planning a new system or want a privacy-focused review of an existing one, talk to our team in Doha. We design data handling with the PDPPL in mind from the first architecture review.