Bahrain
Bahrain Data Privacy Laws: PDPL Law No. 30 of 2018 Complete Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 12 primary sources cited on this page. How we verify our legal content

Bahrain's Personal Data Protection Law (PDPL), Law No. 30 of 2018, came into force on 1 August 2019. It made Bahrain the second Gulf Cooperation Council (GCC) state, after Qatar's Law No. 13 of 2016 on Protecting Personal Data Privacy, to enact a general data protection statute. The Personal Data Protection Authority (PDPA) supervises compliance, with its functions entrusted to the Ministry of Justice, Islamic Affairs and Waqf under Royal Decree No. 78 of 2019.
Information last verified on 2026-05-19. This article has not yet been reviewed by a licensed lawyer.
Jurisdictional scope: This article addresses data protection law in the Kingdom of Bahrain under Law No. 30 of 2018 (PDPL) and its implementing Orders. It does not address recording consent law in Bahrain; for that, see Bahrain Recording Laws.
Quick Answer: Is Bahrain's Data Protection Law GDPR-Equivalent?
Bahrain's PDPL shares the GDPR's general architecture: lawful bases for processing, data subject rights, breach notification, supervisory authority oversight, and restrictions on cross-border transfers. The core differences are enforcement scale (Bahrain's maximum fines are far lower than the GDPR's EUR 20 million / 4% of global turnover), the absence of a formal adequacy mechanism flowing from the EU to Bahrain, and the PDPL's structure as a single statute supplemented by ten Ministry of Justice Orders rather than a directly applicable regulation. Organizations subject to both should not assume that GDPR compliance carries across. Bahrain adds a prior-notification duty to the PDPA under Article 14, a prior-authorization regime under Article 15 that covers CCTV surveillance and biometric processing, Data Protection Guardian registration and fees, and its own adequacy record under Order No. 42 of 2022.

The PDPL: History and Legislative Context
Bahrain enacted Law No. 30 of 2018 with respect to Personal Data Protection on 12 July 2018. The law came into force on 1 August 2019 after a one-year implementation period. The Law contains no repeal or supersession clause. Its Second Article provides that it does not derogate from rights granted by international treaties and conventions in force in Bahrain, and Article 58 opens by preserving any stricter penalty imposed by another law.
The law draws from the architecture of the EU's General Data Protection Regulation (GDPR) while reflecting Bahrain's legal context as a civil-law-influenced Gulf monarchy. The PDPL does not transplant the GDPR wholesale: it omits the concept of a lead supervisory authority for cross-border processing, sets lower financial penalties, and structures the supervisory authority as a board-based governmental body rather than an independent administrative authority.
On 17 March 2022, the Minister of Justice, Islamic Affairs and Waqf issued ten Orders, Nos. 42 to 51 of 2022. Each was published in Official Gazette No. 3593 of 17 March 2022 and took effect the next day, 18 March 2022. These Orders fill in the operational detail that the PDPL left to secondary legislation. There is no Order No. 41 of 2022.
Article 2(2) sets the territorial test. The Law applies to every natural person habitually resident in Bahrain or maintaining a place of business there, every legal person with a place of business in Bahrain, and every person outside Bahrain that processes data using means situated in Bahrain, unless those means are used only to route data across Bahraini territory. The trigger for the last category is equipment located in Bahrain, not the location of the individual, so this is not the GDPR targeting test. Under Article 2(3), a person caught by that limb must appoint a representative in Bahrain and notify the PDPA of the appointment immediately.

The Supervisory Authority: PDPA Structure and Powers
Establishment Under Royal Decree No. 78 of 2019
The PDPL established the Personal Data Protection Authority (PDPA) as the supervisory body under Articles 27-39. Because the independent Authority Board had not yet been constituted when the law came into force, Royal Decree No. 78 of 2019 entrusted the functions and competencies of the PDPA to the Ministry of Justice, Islamic Affairs and Waqf. This arrangement means that in practice the Ministry acts as the supervisory authority, operating through an internal PDPA unit.
Article 39 provides for a Board of seven members including the Chairman, constituted by Decree, with one member nominated by each of:
- The Council of Ministers
- The University of Bahrain, from its academic faculty at the rank of associate professor or above
- The Telecommunications Regulatory Authority (TRA), a senior employee
- The Central Bank of Bahrain (CBB), a senior employee
- The Bahrain Chamber of Commerce and Industry (BCCI)
- The most representative body of stakeholders in the financial institutions sector
- The most representative body of IT specialists
No such Decree has been issued, so no Board exists. Royal Decree No. 78 of 2019 remains the operative arrangement.
Mandate and Enforcement Powers
The PDPA's mandate under the PDPL includes:
- Monitoring compliance with the law and its implementing resolutions
- Receiving and investigating complaints under Article 25 (procedures set by Order No. 49 of 2022)
- Conducting audits and inspections of data controllers and processors
- Issuing guidance, recommendations, and binding administrative decisions
- Maintaining the official Notifications and Authorizations Register under Article 16
- Referring cases for criminal prosecution where the PDPL provides criminal penalties
- Issuing stop orders halting the collection, processing, or transfer of personal data
The PDPA website (pdp.gov.bh) publishes the full text of the PDPL, Royal Decree No. 78 of 2019, all ten Orders in Arabic and English, and the prescribed forms. It does not publish a separate library of guidance notes.

Scope and Key Definitions
Who and What Is Covered
Article 2(1) applies the Law to processing by wholly or partly automatic means, and to non-automatic processing of data that forms part of a filing system or is intended to. Within that, it reaches any natural or legal person, including public entities, and there is no "small business" threshold.
Article 2(4) carves out two categories. Processing undertaken by an individual solely for personal or family affairs is outside the Law, and so are processing operations concerning public security handled by the Ministry of Defense, the Ministry of Interior, the National Guard, the National Security Service or another security body. Article 2(5) preserves confidentiality duties relating to Bahrain Defence Force matters.
Processing means any operation performed on personal data, including: collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure, and destruction.
A data controller is the natural or legal person who determines the purposes and means of processing. A data processor is a person who processes data on behalf of and under the instructions of a controller.
Personal Data and Sensitive Personal Data
Personal data means any data relating to a natural person who is identified or identifiable, directly or indirectly. This includes names, identification numbers, addresses, telephone numbers, email addresses, IP addresses, and any other information that can be used to identify an individual.
Sensitive personal data is defined in Article 1 as any personal information revealing, directly or indirectly:
- Race or ethnic origin
- Political or philosophical opinions
- Religious beliefs
- Affiliation to a union
- Personal criminal record
- Any information in relation to health or sexual status
Family origins is not one of the categories, despite appearing in some other Gulf laws. Order No. 45 of 2022 sets out the rules and procedures for processing sensitive personal data, including how to seek the prior authorization the PDPA must give under Article 15 where the processing is automatic.
Data Quality Principles
Article 3 of the PDPL sets out five data quality requirements that govern all processing. Personal data must be:
- Processed fairly and lawfully
- Collected for a specific, explicit and legitimate purpose, and not further processed in a way incompatible with that purpose. Further processing for historical, statistical or scientific purposes is compatible, provided the data is not used to support a decision or measure about a particular individual
- Adequate, relevant and not excessive in relation to the purpose of collection or further processing
- Correct, accurate and, where relevant, kept up to date
- Not kept in a form permitting identification once the purpose has been achieved. Data held longer for historical, statistical or scientific use must be anonymised, or, where that is not possible, the data subjects' identity must be encrypted
Security is a separate duty under Article 8, not one of the Article 3 requirements. Article 6 disapplies Articles 3, 4 and 5 altogether to processing carried out exclusively for press, arts or literature, provided the data is correct and up to date, safeguards prevent its use for other purposes, and the processing complies with the press, printing and publishing laws.
Lawful Bases for Processing
Consent as Primary Basis
Consent is the default lawful basis under the PDPL. Article 4 prohibits processing without the data subject's consent unless one of five necessities applies. Article 4 of Order No. 48 of 2022 requires that, where data is obtained directly from the data subject, the controller obtain explicit consent in writing, including by electronic means, meeting the Article 24 standard. Article 6 of the same Order gives the data subject the right to withdraw consent easily, at any time, free of charge, and requires the controller to publish clear procedures for doing so. Withdrawal does not affect the lawfulness of processing carried out before it.
Article 5 prohibits processing sensitive personal data without the data subject's consent, subject to the exemptions below. The quality standard for consent is set once, in Article 24, and applies to all consent: it must be given by a person of full legal capacity, be written, explicit, clear and specific to the processing of certain data, and be freely given after the data subject has been advised of the intended purposes and, where the circumstances require, of the consequences of refusing. Under Article 5 of Order No. 48 of 2022, consent obtained through a cookie wall that forces a user to consent before accessing a website does not count as consent at all.
Article 4 Exemptions from Consent
Article 4 lists five necessities, and no others. Processing without consent is lawful where it is necessary for:
- Performance of a contract to which the data subject is a party
- Taking steps at the data subject's request with the purpose of entering into a contract
- Compliance with a legal obligation other than one imposed by contract, or with orders issued by a competent court or the Public Prosecution
- Protecting the vital interests of the data subject
- Pursuing the legitimate interests of the controller or any third party to whom the data has been disclosed, provided this does not conflict with the fundamental rights and freedoms of the data subject
Bahrain has no public-interest basis and no legal-claims basis for ordinary personal data, and Article 4 contains no children's-data carve-out. Legal claims appear only in Article 5, for sensitive data, and in Article 13, for transfers abroad.
Article 5 Exemptions for Sensitive Data
Sensitive personal data may be processed without consent where processing:
- Is necessary to carry out the controller's obligations and rights as laid down by law with respect to those working under his authority in the course of employment
- Is necessary to protect an individual where the data subject or his custodian, legal guardian or conservator is legally incapable of giving consent. This limb is conditional on obtaining the PDPA's prior approval under Article 15, following the procedure in Article 3 of Order No. 45 of 2022
- Relates to data the data subject has made available to the public
- Is necessary for pursuing legal claims or defenses, including preparing them
- Is necessary for preventive medicine, medical diagnosis, provision of healthcare or treatment, or management of healthcare services, carried out by a licensed medical professional or another person bound by a legal duty of confidentiality
- Is carried out in the course of the activities of associations, unions and other non-profit bodies, on the conditions set in Article 5(6)
- Is carried out by a competent public body to the extent necessary for its legitimate statutory duties
- Concerns racial, ethnic or religious origins and is necessary to identify the existence or absence of equality of opportunity or treatment, with appropriate safeguards
Data Subject Rights
The Rights Granted
The PDPL grants data subjects the following enforceable rights:
- Right to be informed (Article 17): at the point of registration the controller must give the data subject its full name, field of activity or profession and address, the purposes of processing, and any further information needed for fair processing, including the names or categories of recipients, whether answering particular questions is mandatory or optional and what happens if the data subject does not answer, the right to be notified of the data held and to have it rectified, and whether the data will be used for direct marketing. Where the data was not obtained from the data subject, that information must be provided within five days of registration, along with the categories and origin of the data.
- Right of access (Article 18): the data subject may ask whether data concerning him is being processed and receive the data, its source, the purposes, the recipients, and, where the data is the sole basis of a decision affecting his interests, how it will be used.
- Right to rectification, blocking and erasure (Article 23): available where processing breaches the Law, in particular where the data is inaccurate, incomplete, outdated or unlawfully processed.
- Right to object to direct marketing (Articles 19 and 20): the controller must tell the data subject of this right, and must stop or not start direct marketing on request.
- Right to object to damaging processing (Article 21): available where processing is causing, or is likely to cause, unwarranted substantial material or moral damage to the data subject or others.
- Right to object to solely automated decisions (Article 22): where a decision is based solely on automated processing to assess performance at work, financial standing, credit-worthiness, reliability or conduct, the data subject may require a decision that is not solely automated, and reconsideration is obligatory and free. Article 3 of Order No. 48 of 2022 requires the controller to tell the data subject about the automated decision and to publish a procedure for objecting.
- Right to withdraw consent (Article 24(3) and Article 6 of Order No. 48 of 2022): available at any time where consent is the basis of processing.
Response Deadlines
There is no single deadline. Under Article 18, an access request supported by proof of identity must be answered free of charge within 15 working days. The controller may, within 10 days of receiving the request, ask the applicant to cure a deficiency, and must notify the applicant of a reasoned decision to accept or reject within the 15 working days.
Requests to rectify, block or erase data under Article 23, and objections under Articles 20 and 21, carry a shorter deadline of 10 working days, and a refusal must come with a legally acceptable justification.
Where a controller rectifies, erases or blocks personal data following an Article 23 request, it must notify any third party to whom the data was previously disclosed of that action within 15 days of responding to the data subject, unless that proves impossible or unachievable.
Data subjects who consider that their rights have been violated may lodge a complaint with the PDPA under Article 25, following the procedures in Order No. 49 of 2022.
Data Breach Notification
72-Hour Notification to the PDPA
Article 4 of Order No. 43 of 2022 establishes the breach framework. Order No. 44 of 2022 is a different instrument and says nothing about breaches. The controller must document breaches, recording their causes, effects and the rectification measures taken, and must establish procedures to inform the PDPA of any breach or violation within 72 hours of discovering it, unless the breach would not affect data subjects' rights. Where notification is not made within 72 hours, it must be accompanied by justifications for the delay. The controller must also give data subjects a channel for reporting breaches and suspected violations to it.
The notification to the PDPA must describe:
- The nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned
- The name and contact details of the data protection guardian or other contact point
- The likely consequences of the breach
- The measures taken or proposed to address the breach, including where appropriate measures to mitigate its adverse effects
- The measures taken to address the main cause of the breach and prevent its recurrence
Where the information cannot all be given at once, Article 4(5) allows it to be provided in phases without undue delay.
Notification to Data Subjects
Bahrain does not run the GDPR's self-executing duty here. Under Article 4(2) of Order No. 43 of 2022, if the controller has not communicated the breach to the data subject, the PDPA, having considered the likelihood of a high risk, may require it to do so. The trigger is the Authority's assessment, not the controller's.
A controller is not obliged to notify the data subject where the breached data is unintelligible to anyone not authorized to access it, for example because it is encrypted; where the controller has since taken measures ensuring the high risk is no longer likely to materialise; or where notification would involve disproportionate effort, in which case there must be a public communication instead.
What must be told to affected data subjects, when they are told, is the type of breach, details of the data breached, and recommendations to mitigate its effects.
Data Processor Obligations
Neither the PDPL nor Orders Nos. 42 to 51 of 2022 imposes a freestanding duty on a processor to report a breach to the controller. What Article 8(3) does require is that the controller choose a processor giving sufficient safeguards, take reasonable steps to check compliance, and put the processing under a written contract that binds the processor to act only on the controller's instructions and to meet obligations equivalent to the controller's on security and confidentiality. In practice the breach-reporting duty has to be written into that contract.
Data Protection Guardian (DPG)
The Role
Bahrain's PDPL uses the term "Data Protection Guardian" (DPG), which is functionally equivalent to the GDPR's "Data Protection Officer" (DPO). Under Article 10 of the PDPL and Order No. 46 of 2022, the DPG:
- Assists the controller in complying with the PDPL
- Acts as the primary liaison with the PDPA
- Keeps the register of processing that the controller must notify to the PDPA under Article 14, and files an updated copy with the PDPA once every month
- Reports violations to the controller and, where violations are not corrected within 10 days, reports directly to the PDPA
- Performs duties independently and impartially
The DPG may be an employee of the controller (internal DPG) or an external natural or legal person (external DPG). Both must be enrolled in the Data Protection Guardians Register, and both must meet the Article 5 conditions of Order No. 46 of 2022: full legal competence; a bachelor's degree in information technology at a minimum, or a professional certificate in information security, information security audit or cyber security, or at least two years' practical experience in one of those fields; good reputation with no final conviction for breach of trust or an offence affecting honour or integrity and no conviction involving breach of professional ethics unless reinstated; and no dismissal by disciplinary ruling and no revoked or suspended professional licence.
Article 9 adds two conditions for an internal DPG: the person must be among the employees of the controller, a subsidiary, a branch or a company in the same regional or international group under common ownership, and must have permanent residence in Bahrain. An external DPG that is a legal person must be licensed in Bahrain, work in legal, audit, IT, management consulting, accounting or risk management services, and employ at least three people who meet the natural-person conditions.
When a DPG Is Mandatory
Appointment is optional under Article 10(4), which lets the controller appoint a DPG and lets the Board oblige certain categories of controller to do so. Article 2 of Order No. 46 of 2022 puts that power in the hands of the Chairman of the Board, who may require categories of controllers to appoint an internal or external Guardian where the type of work, the nature of the activity, the volume of processing or the manner of processing calls for extra monitoring. No such resolution appears among the executive decisions published on pdp.gov.bh, which still lists exactly the ten 2022 Orders.
There is a practical incentive to appoint one anyway. Article 14(1) exempts a controller from the prior-notification duty entirely where a Data Protection Guardian is appointed.
Sectoral regulators are widely reported to have imposed their own requirements: a Central Bank of Bahrain circular said to require CBB licensees that are data controllers to appoint a Guardian, and a National Health Regulatory Authority requirement said to cover private healthcare facilities. Neither text is published on the regulator's own website, and the CBB Rulebook's circular list and site search return nothing on the subject, so organizations in those sectors should confirm the position directly with their regulator rather than rely on secondary reporting.
In telecommunications, what the TRA has actually published is a Final Direction of 21 January 2024 (reference LAD/0124/001) issuing Guidelines on the Privacy of Individuals and Data Protection in the Telecommunications Sector, following a consultation that closed in October 2023. Those Guidelines sit alongside the PDPL and do not themselves require the appointment of a Data Protection Guardian.
Registration and Fees
All appointed DPGs must be enrolled in the PDPA's Data Protection Guardians Register, which has one section for external Guardians and one for internal Guardians and is published on the PDPA website. Controllers must notify the PDPA of any DPG appointment within 3 working days. The PDPA decides on an enrolment application within thirty days and notifies the applicant within seven days of the decision; silence past that period counts as an implied rejection, appealable to the Appeals Committee within thirty days.
Order No. 47 of 2022 sets the fees:
| Category | Enrolment | Annual renewal |
|---|---|---|
| External Guardian, natural person | BD 300 | BD 100 |
| External Guardian, legal person | BD 500 | BD 150 |
| Internal Guardian | BD 100 | BD 30 |
Enrolment runs for one year and is renewed on a request made at least thirty days before it expires, with the renewal fee paid. An entity obliged to appoint an internal Guardian may apply for a fee waiver, supported by a three-month bank statement and the last audited annual report, and the PDPA decides within five working days; Article 4 sets out when fees are refunded. Under Article 13 of Order No. 46 of 2022, a Guardian must disclose any conflict of interest at the outset and disclose again immediately whenever anything changes.
The Ten Ministerial Orders (2022)
The Minister of Justice, Islamic Affairs and Waqf issued ten Orders on 17 March 2022, published in Official Gazette No. 3593 of that date and effective from 18 March 2022. Each carries its own number and subject:
| Order | Subject |
|---|---|
| No. 42 of 2022 | Transfer of personal data outside the Kingdom, with the attached record of countries and territories providing adequate protection |
| No. 43 of 2022 | Conditions to be met in technical and organizational measures, including privacy by design, data protection impact assessments, breach notification, internal investigation, joint controllers and training |
| No. 44 of 2022 | Rules and procedures for submitting notifications and prior authorization requests to the PDPA and deciding on them |
| No. 45 of 2022 | Rules and procedures for processing sensitive personal data |
| No. 46 of 2022 | Data Protection Guardians: appointment, enrolment conditions, duties and supervision |
| No. 47 of 2022 | Fees for enrolment and renewal in the Data Protection Guardians register, and waiver and refund |
| No. 48 of 2022 | The data subject's rights: automated decisions, consent, cookie walls, withdrawal and objections |
| No. 49 of 2022 | Rules and procedures for submitting complaints about violations of the PDPL |
| No. 50 of 2022 | Controls and safeguards for the confidentiality of data concerning criminal proceedings and related judgments |
| No. 51 of 2022 | Conditions to be met when creating registers accessible to the public |
Cross-Border Data Transfers
The Restriction
The PDPL restricts transfers of personal data outside Bahrain in Articles 12 and 13. Article 12 prohibits a controller from transferring personal data abroad except to a country or territory on a record compiled and updated by the PDPA and published in the Official Gazette, or under a case-by-case PDPA authorization granted after the Authority assesses the nature, purpose and duration of the processing, the destination and the protections available there, and the relevant international agreements in force. Article 13 then lists the exemptions. Article 28 of the PDPL is a different provision entirely, dealing with the Minister's oversight of the Authority.
Order No. 42 of 2022: The Adequacy Record
Order No. 42 of 2022, made under Article 12 of the PDPL, attaches a record of 83 countries and territories that the PDPA has determined provide adequate legislative and regulatory protection. Transfers to a country on that record may proceed without prior PDPA authorization.
The record includes all EU member states, the European Economic Area states (Iceland, Liechtenstein, Norway), the United Kingdom, the United States, Switzerland, Canada, Australia, Japan, and four of the five other GCC states: Saudi Arabia, Kuwait, Oman and the United Arab Emirates.
Qatar is not on the record. The list is alphabetical and runs straight from Portugal to Romania. A transfer of personal data from Bahrain to Qatar therefore needs case-by-case PDPA authorization under Article 12(2) or an Article 13 exemption; sending it on the assumption that Qatar is covered exposes the controller to the Article 58(1)(b) offence. The full record in English is published on the PDPA website at pdp.gov.bh.
Transfers to Non-Listed Countries
Transfers to countries not on the record require prior PDPA authorization under Article 12(2), or one of the Article 13(1) exemptions:
- Consent of the data subject to the transfer. The Bahraini text asks only for consent; it does not add the GDPR's requirement that the data subject first be warned of the risks of transferring to a country without an adequacy finding.
- Public registers: the data comes from a register compiled under law to provide information to the public, and access follows that register's own conditions.
- Contract with the data subject: the transfer is necessary to perform a contract between the data subject and the controller, or to take steps at the data subject's request towards entering one.
- Contract with a third party concluded or performed in the data subject's interest.
- Vital interests of the data subject.
- Legal obligation other than a contractual one, or an order from a competent court, the Public Prosecution, the investigation judge or the Military Prosecution.
- Legal claims: preparing or pursuing a legal claim or defense.
Separately, Article 13(2) lets the PDPA authorize a transfer to a country without adequate protection where the controller adduces adequate safeguards, in particular by contract. That is the statutory hook for the model contract clauses in Article 5 of Order No. 42 of 2022; where authorization is sought on that basis, a copy of the agreement must be provided.
Penalties and Enforcement
Criminal Penalties
Article 58 of the PDPL establishes the criminal penalties, and it does so for nine specific acts rather than for any breach of the Law. Processing ordinary personal data without consent contrary to Article 4 is not among them. Article 54 deals with something else, the Board's disposition of an investigation.
Article 58(1) makes a person liable to imprisonment of up to one year and, or, a fine of BD 1,000 to BD 20,000 (approximately USD 2,650 to USD 53,000) for:
- Processing personal data in contravention of Article 5, which governs sensitive personal data
- Transferring personal data to another country or territory in contravention of Articles 12 and 13
- Processing personal data without notifying the PDPA in breach of Article 14(1)
- Failing to notify the PDPA of a change to notified data, contrary to Article 14(6)
- Processing without the prior authorization required by Article 15
- Providing the PDPA or a data subject with incorrect or misleading data, or data contrary to the records in the person's possession
- Withholding from the PDPA data, information, records or documents it should have access to
- Preventing or delaying the PDPA's inspectors or an ongoing investigation
- Disclosing or unlawfully using, for personal benefit or the benefit of others, data or information accessible by virtue of the person's post
Article 58(2) adds a fine of BD 3,000 to BD 20,000 for a breach of the Board conflict-of-interest rules in Article 32(1) and (2), with possible confiscation on conviction, and Article 58(3) a fine of BD 100 to BD 500 and up to one month's imprisonment for misuse of the PDPA's logo. Under Article 60, the Board may agree to conciliation on three of the offences, except in cases of recidivism, if the minimum fine is paid within seven days.
Corporate Liability
Under Article 59, where an Article 58 offence is committed in a legal person's name, on its behalf or for its benefit, and results from the action, omission, approval, cover-up or gross negligence of a board member, a delegated official or someone acting in that capacity, the lower and upper fine limits are doubled. That puts the corporate maximum at BD 40,000 (approximately USD 106,000). The corporate penalty does not replace individual liability: officers and employees personally responsible remain subject to imprisonment and individual fines.
Civil Compensation
Article 57 of the PDPL provides that a party who suffers damage from the processing of his personal data by a data controller, or from a Data Protection Guardian's breach of the Law, may claim compensation from the controller or the Guardian, without prejudice to the Civil Law. This creates a civil cause of action parallel to criminal enforcement, distinct from PDPA administrative action.
Administrative Enforcement
Administrative enforcement is not fine-free, and this is the route a controller is most likely to meet. Under Article 55, once a violation is proven the Board orders the offender to stop and to remove the causes and effects, immediately or within a set period. If the offender does not comply within that period, the Board may issue reasoned decisions:
- Withdrawing an authorization granted under Article 15, where the violation concerns that authorization
- Imposing a daily penalty of up to BD 1,000 per day for a first violation, and BD 2,000 per day for a second violation within three years of the decision on the first
- Imposing an administrative penalty of up to BD 20,000
Article 55(2) requires the gravity of the violation, the offender's intransigence, the benefit gained and the damage suffered by data subjects to be weighed in setting the amount. Article 55(5) lets the PDPA publish a statement naming a controller or Data Protection Guardian for proven violations, but only after the appeal period has expired or a final ruling has issued. Article 56 adds urgent-case powers to suspend processing or block data temporarily, enforceable by a writ on petition from the Civil High Court, with the controller able to object within eight days. Where the investigation identifies a criminal offence, the Board refers it to the Public Prosecution.
Security Requirements and Privacy by Design
Technical and Organizational Measures
Article 8 of the PDPL requires data controllers to implement technical and organizational measures appropriate to the risk, taking account of the state of security technology, cost, the nature of the data and the potential risks, and to record those measures so they are accessible to the PDPA, the controller and the processor. Article 2 of Order No. 43 of 2022 then lists what the controller must implement, all or some of it depending on the scope, context, purposes or risks of the processing:
- A Privacy by Design programme when preparing, designing, selecting and using applications, services and products used to process data
- Privacy frameworks covering structure, practice and instructions for protecting personal data
- Effective measures against breaches and attempted breaches, for example regulating access to stored data, password protection, anti-virus software and firewalls, complying with software licences, regulating retention and disposal periods, backup measures, and access-control and security protocols for data held physically and virtually
- Periodic Vulnerability Assessment and Penetration Testing (VAPT) to measure and rectify weaknesses
- A plan for sudden breaches in processing systems that allows processing to continue without interruption
- A determination of each employee's competence for the task entrusted to him, with a duty to inform employees of these measures
Encryption is not itself mandated by the Order; it appears as an example of data being unintelligible for the purposes of the breach-notification exemption. Order No. 43 of 2022 also requires written internal-investigation rules and the retention of evidence for the PDPA or the judicial authorities (Article 5), a written agreement, disclosure and a contact point where two or more controllers process jointly (Article 7), and periodic training for staff who process personal data (Article 8).
Privacy by Design and by Default
Order No. 43 of 2022 defines Privacy by Design as a method of processing that seeks to provide the maximum extent of privacy by protecting personal data in a technological system or business practice by default, applying security measures at every stage in a way that anticipates and prevents privacy implications before they occur, and Article 2(1) requires a Privacy by Design programme when applications, services and products are prepared, designed, selected and used. The Order does not add the GDPR's separate data-protection-by-default obligation.
Data Protection Impact Assessments (DPIAs)
Article 3 of Order No. 43 of 2022 is permissive at the outset: the controller may conduct a Data Protection Impact Assessment, taking account of the nature, scope, context and purposes of the processing and the high risks to individuals, and a single assessment may cover a set of similar operations. Where a Data Protection Guardian is designated, the controller must seek the Guardian's advice when carrying one out.
Article 3(3) then makes a DPIA mandatory in three cases only:
- Processing within Article 22 of the Law, or systematic and extensive automated evaluation of personal aspects, including profiling, on which decisions producing legal or similarly significant effects are based
- Large-scale processing of special categories of data, or of the criminal-proceedings data covered by Article 7 of the Law
- Systematic monitoring of a publicly accessible area on a large scale
Article 6 of Order No. 44 of 2022 adds a fourth trigger: a DPIA must accompany a prior-authorization request for automatic processing of biometric data or for processing by visual recording used for surveillance.
A DPIA must describe the envisaged processing and its purposes, assess necessity and proportionality, assess the risks to data subjects, and set out the measures envisaged to address them, and where appropriate the controller must seek the views of data subjects or their representatives. Bahrain has no prior-consultation duty of the kind in GDPR Article 36: a high residual risk does not oblige the controller to go to the PDPA before proceeding.
Registration and Notification Obligations
Notification Register
The Notifications and Authorisations Register is kept by the PDPA, not by controllers: Article 16 requires the Authority to maintain it and to keep it updated, and lets any person inspect it free of charge on a prescribed form during working hours.
What controllers owe is prior notification. Under Article 14(1), a controller must give the PDPA prior notice of any wholly or partly automated processing operation intended to serve a single purpose or several related purposes. The notification must contain:
- The controller's and processor's names and addresses
- The purposes for which data is being processed
- A description of the data, the categories of data subjects, and the recipients or categories of recipient
- Any proposed transfers outside Bahrain
- A general description allowing the PDPA to assess the appropriateness of the security measures under Article 8
Article 14(1) exempts four situations: processing whose sole purpose is keeping a register intended to inform the public; processing in the course of the activities of associations of all types, unions and non-profit bodies; an employer processing employee data as far as necessary for his duties and to protect employees' rights; and, importantly, any situation where a Data Protection Guardian is appointed. Article 14(3) allows a simplified notification where the nature of the data means no infringement of rights will occur.
Under Article 14(4), the PDPA has ten working days to ask the controller to cure a deficient notification, which must be cured within fifteen days, and processing must stop until the notification is complete. Article 14(6) requires any change to notified information to be reported within thirty days, and Article 7 of Order No. 44 of 2022 sets the form for doing so.
Processing Register
The internal register duty comes from Article 10(1)(e) of the PDPL, not from any 2022 Order. The Data Protection Guardian keeps a register of the processing the controller must notify to the PDPA, and the controller keeps it where no Guardian is appointed. It must contain at least the Article 14 notification information, and where a Guardian is appointed he must give the PDPA an updated version once every month.
A separate regime applies to registers the public can consult. Article 11 of the PDPL and Order No. 51 of 2022 require such a register to hold only what is necessary for its purpose, to be genuinely accessible, to record the type of data, the purpose of collection and the date of the last update, and to let a data subject amend or delete his entry free of charge in the cases the Law permits. Consent under Article 24 is needed before including a person's data, unless the entry executes a legal or contractual obligation or a judicial order.
GCC Context: Bahrain's Regional Position
Bahrain's PDPL came into force in August 2019, roughly two years after Qatar's, making Bahrain the second GCC state with a general data protection statute rather than the first. The regional picture has changed further since:
| Country | Law | Status (2026) |
|---|---|---|
| Bahrain | PDPL, Law No. 30 of 2018 | In force since August 2019 |
| Qatar | Law No. 13 of 2016 on Protecting Personal Data Privacy | Issued 3 November 2016; general scope covering personal data processed electronically, with carve-outs only for private or family processing and official statistics |
| Saudi Arabia | PDPL (amended 2023) | Full enforcement from September 2024 |
| UAE | Federal Decree-Law No. 45 of 2021 | In force; executive regulations pending |
| Kuwait | CITRA Resolution No. 42 of 2021, Data Privacy Protection Regulation | In force from publication in 2021; applies to the public and private sectors |
| Oman | PDPL 2022 | Full enforcement from February 2026 |
The record attached to Order No. 42 of 2022 covers four of the five other GCC states, so transfers to Saudi Arabia, the United Arab Emirates, Kuwait and Oman proceed without prior PDPA authorization. Qatar is not on the record, so a transfer to Qatar needs case-by-case authorization or an Article 13 exemption.
Sector-Specific Considerations
Financial Services
Bahrain's role as a GCC financial hub means the PDPL has its deepest practical impact in financial services. Banks, insurance companies, investment firms, and other CBB licensees must comply with both the PDPL and the CBB's sector-specific data requirements.
A CBB circular is widely reported to require CBB licensees that are data controllers to appoint a Data Protection Guardian, with the PDPA notified within three working days as Article 10(4) of the PDPL requires in any event. The circular is not published on the CBB's website or in the public Rulebook circular list, so licensees should confirm its terms with the CBB directly rather than rely on secondary summaries.
Healthcare
An NHRA requirement for private healthcare facilities to appoint a Data Protection Guardian is reported by law firms but is not published on the NHRA's website, so it should be confirmed with the regulator. What is certain is that health data is sensitive personal data, so Article 5 of the PDPL requires the data subject's consent unless one of its exemptions applies, and automatic processing of it needs the PDPA's prior authorization under Article 15, following the procedure in Article 3 of Order No. 45 of 2022.
Telecommunications
The TRA issued a Final Direction on 21 January 2024 (LAD/0124/001) adopting Guidelines on the Privacy of Individuals and Data Protection in the Telecommunications Sector, after a consultation that closed in October 2023. The Guidelines sit alongside the PDPL, which prevails in any inconsistency, and they do not impose a Data Protection Guardian requirement of their own. The sector processes large volumes of personal data (subscriber data, call records and location data), so the PDPL's data quality, security and prior-authorization rules bite hard on it regardless.
Technology and Fintech
Bahrain's growing fintech and technology sector operates under the PDPL's general framework. The Bahrain FinTech Bay and other innovation sandbox initiatives exist alongside PDPL compliance obligations; entities operating in innovation sandboxes are not exempt from PDPL requirements.
Recent Developments (2024-2026)
AI Regulation
Bahrain has no artificial intelligence statute in force. Members of the Shura Council have put forward a legislative proposal to regulate AI technologies, which under Bahrain's process goes to the Government to be drafted into a bill before either chamber can pass it. No enacted text exists, and reported figures for the number of articles and the licensing scheme it would create are not confirmed by any published record, so they are not repeated here.
What governs AI systems that touch personal data today is the PDPL. Article 22 gives a data subject the right to demand a decision that is not solely automated where automated processing assesses his performance at work, financial standing, credit-worthiness, reliability or conduct, and Article 3 of Order No. 48 of 2022 requires the controller to inform him of the automated decision and to publish an objection procedure. Article 15 makes automatic processing of biometric or genetic data, and processing by visual recording used for surveillance, licensed activities requiring the PDPA's prior written authorization. Article 57 allows compensation for damage caused by unlawful processing.
In July 2025, the Information and eGovernment Authority (iGA) published the Kingdom's General Policy for the Use of Artificial Intelligence (Version 1.0), which applies to government entities. Its first of four pillars is Commitment to Policies and Legislations, and PDPL compliance is one of the named legal obligations within that pillar (section 6.1.2.1), alongside Law No. 16 of 2014 on state documents, Law No. 60 of 2014 on cybercrime, Decree-Law No. 56 of 2018 on cloud computing services, the electronic transactions law, the Open Data Policy, and the GCC Artificial Intelligence Ethics Guideline issued by the GCC General Secretariat.
Sector Mandate Expansion
Reported sectoral requirements in finance and private healthcare, and the TRA's 2024 telecoms guidelines, point to regulators taking data protection into their own supervisory frameworks. That is separate from the PDPL's own mechanism: only the Authority can oblige a category of controllers to appoint a Data Protection Guardian, under Article 10(4) of the Law and Article 2 of Order No. 46 of 2022, and no such resolution has been published on pdp.gov.bh.
Overlap With the Cybercrime Law
Law No. 60 of 2014 on Cybercrime sits alongside the PDPL and criminalises unauthorized access to systems, damage to data, electronic fraud and the dissemination of unlawful content. The two regimes are meant to stack rather than compete: Article 58 of the PDPL opens by preserving any stricter penalty imposed by another law, so conduct that breaches both can be prosecuted under whichever carries the heavier penalty. Proposals to amend the cybercrime law to deal further with data privacy in digital communications have been reported, but no amending text has been published in the Official Gazette.
GCC Harmonization
With all six GCC states now having data protection frameworks in force or imminent (Oman from February 2026), regional discussion has shifted to interoperability. Bahrain's inclusion of four other GCC states in the Order No. 42 of 2022 record is one step, and Qatar's absence from it shows how uneven that step still is; formal mutual recognition of adequacy determinations or a GCC-level transfer framework has been discussed but not yet formalized.
Compliance Checklist for Organizations
Organizations processing personal data in Bahrain should work through the following steps, referenced to the specific PDPL provisions and resolutions:
| Step | Requirement | Source |
|---|---|---|
| 1. Map processing | Identify all data flows, purposes, legal bases and categories; keep the internal processing register | Art. 3 PDPL; Art. 10(1)(e) PDPL |
| 2. Notify the PDPA | Give prior notice of automated processing unless an Art. 14(1) exemption applies; stop processing if asked to cure a deficiency | Art. 14 PDPL; Order 44/2022 |
| 3. Lawful basis | Identify consent or one of the five Article 4 necessities for each processing activity | Arts. 4-5 PDPL |
| 4. Consent mechanisms | Written or electronic, explicit, clear and specific, from a person of full legal capacity; no cookie walls | Art. 24 PDPL; Order 48/2022 |
| 5. Sensitive data | Obtain consent or identify an Art. 5 exemption; obtain prior PDPA authorization for automatic processing | Art. 5 PDPL; Art. 15 PDPL; Order 45/2022 |
| 6. Privacy notice | Give the Article 17 information at registration, or within five days where the data was not obtained from the data subject | Art. 17 PDPL |
| 7. Data subject requests | Answer access requests within 15 working days; answer rectification, blocking, erasure and objections within 10 working days; notify third parties within 15 days | Arts. 18, 20, 21, 23 PDPL |
| 8. Security measures | Implement the Order 43 measures including VAPT and a continuity plan; train staff; record the measures | Art. 8 PDPL; Order 43/2022 |
| 9. Breach notification | Document breaches and inform the PDPA within 72 hours of discovery unless data subjects' rights are unaffected; tell individuals if the PDPA requires it | Order 43/2022, Art. 4 |
| 10. Cross-border transfers | Check the Order 42 adequacy record; obtain PDPA authorization or rely on an Art. 13 exemption for other countries; remember Qatar is not listed | Arts. 12-13 PDPL; Order 42/2022 |
| 11. Prior authorization | Obtain written PDPA authorization before CCTV surveillance, biometric or genetic processing, automatic processing of Art. 5(2) sensitive data, or linking files of two or more controllers | Art. 15 PDPL; Order 44/2022 |
| 12. DPG | Appoint and enrol a Guardian where required or chosen; notify the PDPA within 3 working days; appointment removes the Art. 14 notification duty | Art. 10 PDPL; Orders 46-47/2022 |
| 13. DPIA | Mandatory for the three Order 43 Art. 3(3) cases and for biometric or CCTV authorization requests; optional otherwise | Order 43/2022, Art. 3; Order 44/2022, Art. 6 |
Disclaimer
This article provides general legal information about data protection law in the Kingdom of Bahrain as of 19 May 2026. It does not constitute legal advice and should not be relied upon as such. Data protection laws are subject to amendment, and the implementing resolutions issued by the Personal Data Protection Authority may be updated. Organizations and individuals should consult a lawyer licensed in Bahrain for advice specific to their circumstances.
Authorities Cited
- Law No. 30 of 2018 with Respect to Personal Data Protection (PDPL). Official text: https://www.pdp.gov.bh/en/assets/pdf/regulations.pdf
- Royal Decree No. 78 of 2019, determining the administrative entity assuming the PDPA's duties. Official text: https://www.pdp.gov.bh/en/royal-decree.html
- Ministry of Justice Order No. 42 of 2022 (transfer of personal data outside the Kingdom, with the adequacy record). Official English text: https://www.pdp.gov.bh/assets/pdf/executive-decisions/eng/trans-order-countries-and-territories-with-adequate-protection-en.pdf
- Ministry of Justice Order No. 43 of 2022 (technical and organizational measures, DPIA, breach notification). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/the_be_met_in_the_technical.pdf
- Ministry of Justice Order No. 44 of 2022 (notifications and prior authorization requests). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-submission-of-notifications-en.pdf
- Ministry of Justice Order No. 45 of 2022 (sensitive personal data). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-sensitive-data-processing-procedures-en.pdf
- Ministry of Justice Order No. 46 of 2022 (Data Protection Guardians). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-auditor-tasks-en.pdf
- Ministry of Justice Order No. 47 of 2022 (Data Protection Guardians register fees, waiver and refund). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/auditor-fees-en.pdf
- Ministry of Justice Order No. 48 of 2022 (the data subject's rights). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/Data-Subjects-Rights-REVIEWED.pdf
- Ministry of Justice Order No. 49 of 2022 (complaints). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-complaints-en.pdf
- Ministry of Justice Order No. 50 of 2022 (confidentiality of criminal-proceedings data). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-criminal-cases-en.pdf
- Ministry of Justice Order No. 51 of 2022 (registers accessible to the public). Official English text: https://www.pdp.gov.bh/en/assets/pdf/executive-decisions/eng/trans-order-public-info-en.pdf
- Personal Data Protection Authority, Executive Decisions and Orders index: https://www.pdp.gov.bh/en/executive-decisions.html
- Personal Data Protection Authority, Kingdom of Bahrain: https://www.pdp.gov.bh/en/index.html
- Ministry of Justice announcement, 20 March 2022, on the ten Orders implementing the PDPL: https://www.moj.gov.bh/ar/news-archived-274
- Telecommunications Regulatory Authority, Final Direction of 21 January 2024 and Guidelines on the Privacy of Individuals and Data Protection in the Telecommunications Sector: https://www.tra.org.bh/en/article/consultation-on-guidelines-for-privacy-protection-and-data-protection-in-the-telecommunications-sector
- Information and eGovernment Authority, General Policy for the Use of Artificial Intelligence, 30 July 2025: https://www.iga.gov.bh/Media/Publications/National%20Digital%20Policies/General%20Policy%20for%20the%20Use%20of%20AI%20-%20%20Final%2030%20Jul%202025.pdf
- Qatar Law No. 13 of 2016 on Protecting Personal Data Privacy (Al Meezan official English text): https://www.almeezan.qa/EnglishLaws//132016.pdf
- Kuwait CITRA Resolution No. 42 of 2021 on the Data Privacy Protection Regulation: https://www.citra.gov.kw/sites/en/LegalReferences/Resolution-No-42-On-Data-Privacy-Protection-Regulation.pdf
- DLA Piper: Data Protection Laws of the World, Bahrain: https://www.dlapiperdataprotection.com/index.html?t=law&c=BH
- ASAR Legal: DPOs now required across Finance, Telecom and Health (secondary reporting on the CBB and NHRA requirements, which are not published by those regulators): https://www.asarlegal.com/data-protection-officers-now-required-across-finance-telecom-and-health-sectors-in-bahrain/
Frequently Asked Questions
What is Bahrain's main data protection law?
Law No. 30 of 2018 on Personal Data Protection (PDPL) is Bahrain's general data protection statute. It came into force on 1 August 2019 and is supplemented by ten Ministry of Justice Orders, Nos. 42 to 51 of 2022, issued on 17 March 2022 and published in Official Gazette No. 3593 of that date. There is no Order No. 41 of 2022. The PDPA's functions are currently exercised by the Ministry of Justice, Islamic Affairs and Waqf under Royal Decree No. 78 of 2019.
What are the penalties for data protection violations in Bahrain?
Article 58 of the PDPL punishes nine specific acts, including processing sensitive data contrary to Article 5, transferring data abroad contrary to Articles 12 and 13, and processing without the required notification or prior authorization, with imprisonment of up to one year and, or, a fine of BD 1,000 to BD 20,000 (approximately USD 2,650 to USD 53,000). Article 59 doubles those limits for a legal person, to BD 40,000 (approximately USD 106,000). Not every breach of the PDPL is a crime. Separately, Article 55 lets the Board order a violator to stop and, on non-compliance, impose a daily penalty of up to BD 1,000 (BD 2,000 for a repeat within three years) and an administrative penalty of up to BD 20,000, and Article 57 gives affected individuals a right to seek civil compensation.
How quickly must a data breach be reported in Bahrain?
Article 4 of Order No. 43 of 2022 requires a controller to document breaches and to have procedures to inform the PDPA within 72 hours of discovering one, unless the breach would not affect data subjects' rights. Where notification is delayed beyond 72 hours, it must be accompanied by justifications for the delay. Bahrain does not make the controller decide whether to warn individuals: if the controller has not told them, the PDPA, having considered the likelihood of a high risk, may require it to do so. Order No. 44 of 2022 deals with notifications and prior authorization requests, not breaches.
Can personal data be transferred outside Bahrain?
Transfers are permitted without prior PDPA authorization to the 83 countries and territories on the record attached to Order No. 42 of 2022, which includes all EU member states, the UK, the US, Saudi Arabia, Kuwait, Oman and the United Arab Emirates. Qatar is not on it. Transfers to countries not on the record require case-by-case PDPA authorization under Article 12(2), or one of the Article 13 exemptions: the data subject's consent, a public register, a contract with or in the interest of the data subject, vital interests, a legal obligation or judicial order, or a legal claim. The PDPA may also authorize a transfer where the controller adduces adequate safeguards by contract under Article 13(2).
Does Bahrain require organizations to appoint a Data Protection Guardian?
Under Article 10(4) of the PDPL, appointing a Data Protection Guardian (Bahrain's term for a DPO) is optional unless the Authority obliges a category of controllers to appoint one, a power Article 2 of Order No. 46 of 2022 gives the Chairman of the Board. No such resolution is published on pdp.gov.bh. Sectoral requirements in banking and private healthcare are reported by law firms but are not published by the regulators themselves, so entities in those sectors should confirm the position with their regulator. Any appointment must be notified to the PDPA within 3 working days, and the Guardian must be enrolled in the Data Protection Guardians Register. Appointing one has a practical benefit: it removes the Article 14 prior-notification duty.
What countries are on Bahrain's data protection adequacy list?
The record attached to Order No. 42 of 2022 lists 83 countries and territories, including all EU member states, Iceland, Liechtenstein, Norway, the UK, Switzerland, the US, Canada, Australia, Japan, and four of the five other GCC states: Saudi Arabia, the UAE, Kuwait and Oman. Qatar is not listed, and the alphabetical record runs straight from Portugal to Romania. The full record in English is published at pdp.gov.bh. Transfers to listed countries do not require prior PDPA authorization; a transfer to Qatar does.
How does Bahrain's PDPL compare to the GDPR?
The PDPL and GDPR share the same architectural principles: lawful bases, data quality, data subject rights, security obligations, breach notification, supervisory authority oversight, and cross-border transfer restrictions. The differences matter in practice. Bahrain's financial penalties are far lower (a corporate maximum of BD 40,000 under Article 59, against the GDPR's EUR 20 million or 4% of global turnover). Access requests carry a 15-working-day deadline under Article 18, while objections and rectification carry 10 working days, rather than the GDPR's one month. Bahrain keeps a prior-notification duty to the regulator (Article 14) and a prior-authorization regime (Article 15) covering CCTV surveillance and biometric processing, neither of which the GDPR has. It uses the term 'Data Protection Guardian' rather than 'Data Protection Officer'. And it is a statute supplemented by Ministerial Orders rather than a directly applicable regulation.
What are Bahrain's lawful bases for processing personal data?
Article 4 of the PDPL makes consent the default and allows processing without it only where it is necessary for one of five things: performance of a contract to which the data subject is a party; taking steps at the data subject's request towards entering a contract; compliance with a legal obligation other than a contractual one, or with an order of a competent court or the Public Prosecution; protecting the data subject's vital interests; or pursuing the legitimate interests of the controller or a third party to whom the data has been disclosed, provided this does not conflict with the data subject's fundamental rights and freedoms. Bahrain has no public-interest basis, no legal-claims basis for ordinary data, and no children's-data carve-out in Article 4. For sensitive personal data, Article 5 requires consent unless one of its eight exemptions applies.
How long does a data controller have to respond to a data subject request?
It depends on the request. Under Article 18, an access request supported by proof of identity must be answered free of charge within 15 working days, with a reasoned decision to accept or reject; the controller may ask within 10 days for a deficient request to be completed. Requests to rectify, block or erase data under Article 23, and objections under Articles 20 and 21, must be answered within 10 working days. Where the controller has rectified, erased or blocked data, it must notify any third party to whom the data was disclosed within 15 days of responding. Article 14 of the PDPL is not about data subject requests at all; it is the controller's prior-notification duty to the PDPA. Data subjects may complain to the PDPA under Article 25 and Order No. 49 of 2022.
What is the relationship between Bahrain's PDPL and the proposed AI regulation law?
Bahrain has no AI statute in force. Members of the Shura Council have put forward a legislative proposal to regulate AI technologies, which under Bahrain's process must go to the Government to be drafted into a bill before it can be passed, and no enacted text has been published. Until then the PDPL governs AI systems that process personal data: Article 22 gives a right to demand a decision that is not solely automated where automated processing assesses performance at work, financial standing, credit-worthiness, reliability or conduct; Article 15 makes biometric and genetic processing and CCTV surveillance subject to prior PDPA authorization; and Article 57 allows compensation for damage. The iGA's General Policy for the Use of AI (July 2025) applies to government entities and names PDPL compliance as one of the legal obligations under its first pillar, Commitment to Policies and Legislations.
Updates
Corrected the citations throughout this guide against the official texts: the implementing instruments are Ministry of Justice Orders Nos. 42 to 51 of 2022 (there is no Order 41), the 72-hour breach rule is in Order 43 rather than Order 44, and the article numbers for penalties, cross-border transfers, data subject deadlines, the Data Protection Guardian and the data quality rules were wrong. We also removed Qatar from the list of countries Bahrain treats as providing adequate protection, because it is not on the official record, removed several GDPR duties that Bahraini law does not impose, added the Article 55 administrative penalties and the Article 15 prior-authorization regime, and replaced unsourced claims about an AI bill, a cybercrime amendment and sector regulators with what the published record supports.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded from about 2,380 to about 5,200 words with sections on the implementing orders, breach notification, the supervisory structure, the adequacy list, data subject request deadlines, the compensation right and GCC context. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.
Reviewed and approved by an editor
Sources and References
- Personal Data Protection Authority, Kingdom of Bahrain (Official)(pdp.gov.bh).gov
- PDPL Full Text (PDF), pdp.gov.bh(pdp.gov.bh).gov
- Resolution No. 42/2022: Adequacy List (English PDF)(pdp.gov.bh).gov
- Royal Decree No. 78 of 2019 (full text), Personal Data Protection Authority(pdp.gov.bh).gov
- Executive Decisions and Orders (Nos. 42 to 51 of 2022), pdp.gov.bh(pdp.gov.bh).gov
- Clyde & Co: Bahrain issues new privacy guidelines (2022)(clydeco.com)
- Trowers & Hamlins: Bahrain enhances its data protection regime (2022)(trowers.com)
- DLA Piper: Data Protection Laws of the World, Bahrain(dlapiperdataprotection.com)
- Order No. 46 of 2022 on Data Protection Guardians (English PDF), pdp.gov.bh(pdp.gov.bh).gov
- ASAR Legal: DPOs now required across Finance, Telecom and Health(asarlegal.com)
- Ministry of Justice announcement, 20 March 2022: ten Orders implementing the PDPL(moj.gov.bh).gov
- Bahrain Recording Laws, RecordingLaw.com
- Order No. 43 of 2022: technical and organizational measures, DPIA and breach notification (English PDF)(pdp.gov.bh).gov
- Order No. 48 of 2022: the Data Subject's rights (English PDF)(pdp.gov.bh).gov
- iGA General Policy for the Use of Artificial Intelligence, 30 July 2025 (official PDF)(iga.gov.bh).gov
- TRA Final Direction of 21 January 2024 and telecoms privacy Guidelines(tra.org.bh).gov
- Qatar Law No. 13 of 2016 on Protecting Personal Data Privacy (official English text)(almeezan.qa).gov