Looking at the Gulf region, 5 (Bahrain, Oman, Qatar, Saudi Arabia and United Arab Emirates) out of the 6 countries comprising the Gulf Cooperative Council (GCC) have enacted independent Personal Data Protection Laws (PDPL). Kuwait is only gulf country that does not have an independent Personal Data Protection Law yet.
Below is a quick guide into the current status of these 5 countries, listed in chronological order of enacting its own PDPL:
Jurisdiction |
Law |
Year |
Enact Date |
Enforce Date |
Overview |
Qatar |
Law No. 13 of 2016 |
2016 |
03 Nov 2016 |
29 Dec 2016 |
- The first GCC State to introduce an independent Personal Data Protection Law.
- The provisions of the law apply to personal data, whether it was processed electronically and/or through traditional processing methods.
|
Bahrain |
Law No. 30 of 2018 |
2018 |
12 Jul 2018 |
1 Aug 2019 |
- The second GCC State to introduce an independent Personal Data Protection Law.
- The law applies to very individual and business living and operating in the Kingdom of Bahrain.
- The law imposes strict obligations in relation to how, when and why personal data is collected, stored and used.
- The key principles the law founded for the processing of Personal data data are:
- Legitimate and fair processing.
- Legitimate, specific and clear purposes.
- Sufficient, relevant and not excessive.
- Correct, accurate and updated.
- Retention is for limited periods.
- Security and confidentiality.
- Authorization.
|
Saudi Arabia |
Royal Decree No. M/19 of 1443H |
2021 |
16 Sep 2021 |
24 Mar 2022 |
- The law applies to all entities, whether inside or outside the Kingdom, that process Personal Data - wholly or partially - related to individuals residing in the Kingdom using any means.
- Data Controllers or processors are required comply with the provisions of the Law within 1 year from enforcement date. The timeframe may be extended by the government if needed.
|
United Arab Emirates |
Decree-Law No. 45 of 2021 |
2021 |
20 Sep 2021 |
02 Jan 2022 |
- The law adopts well-known data protection regimes, including the GDPR.
- The law introduces rights for individuals to access, rectify, correct, delete, restrict processing, request cessation of processing or transfer of data, and object to automated processing.
- Certain businesses may need to adjust certain rules or procedures to comply with the provisions of the law and avoid any breach.
Additional resources for data privacy in UAE:
|
Oman |
Royal Decree No. 6 of 2022 |
2022 |
09 Feb 2022 |
09 Feb 2023 |
- The most recent Law enacted, in the region, concerning the protection of personal data.
- The law urges businesses and entities to process personal data within the framework of transparency, honesty, and respect for human dignity.
- The law requires explicit and documented consent of data subjects to any processing of their personal data, unlike most international data protection laws that allows a flexibility in processing certain data types without prior consent or authorization.
- The enforcement date will be in February 2023.
|