Bahrain flag

Bahrain

Bahrain Data Privacy Laws: PDPL Law No. 30 of 2018 Complete Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 12 primary sources cited on this page. How we verify our legal content

Bahrain Data Privacy Laws: PDPL Law No. 30 of 2018 Complete Guide (2026)

Frequently Asked Questions

What is Bahrain's main data protection law?

Law No. 30 of 2018 on Personal Data Protection (PDPL) is Bahrain's general data protection statute. It came into force on 1 August 2019 and is supplemented by ten Ministry of Justice Orders, Nos. 42 to 51 of 2022, issued on 17 March 2022 and published in Official Gazette No. 3593 of that date. There is no Order No. 41 of 2022. The PDPA's functions are currently exercised by the Ministry of Justice, Islamic Affairs and Waqf under Royal Decree No. 78 of 2019.

What are the penalties for data protection violations in Bahrain?

Article 58 of the PDPL punishes nine specific acts, including processing sensitive data contrary to Article 5, transferring data abroad contrary to Articles 12 and 13, and processing without the required notification or prior authorization, with imprisonment of up to one year and, or, a fine of BD 1,000 to BD 20,000 (approximately USD 2,650 to USD 53,000). Article 59 doubles those limits for a legal person, to BD 40,000 (approximately USD 106,000). Not every breach of the PDPL is a crime. Separately, Article 55 lets the Board order a violator to stop and, on non-compliance, impose a daily penalty of up to BD 1,000 (BD 2,000 for a repeat within three years) and an administrative penalty of up to BD 20,000, and Article 57 gives affected individuals a right to seek civil compensation.

How quickly must a data breach be reported in Bahrain?

Article 4 of Order No. 43 of 2022 requires a controller to document breaches and to have procedures to inform the PDPA within 72 hours of discovering one, unless the breach would not affect data subjects' rights. Where notification is delayed beyond 72 hours, it must be accompanied by justifications for the delay. Bahrain does not make the controller decide whether to warn individuals: if the controller has not told them, the PDPA, having considered the likelihood of a high risk, may require it to do so. Order No. 44 of 2022 deals with notifications and prior authorization requests, not breaches.

Can personal data be transferred outside Bahrain?

Transfers are permitted without prior PDPA authorization to the 83 countries and territories on the record attached to Order No. 42 of 2022, which includes all EU member states, the UK, the US, Saudi Arabia, Kuwait, Oman and the United Arab Emirates. Qatar is not on it. Transfers to countries not on the record require case-by-case PDPA authorization under Article 12(2), or one of the Article 13 exemptions: the data subject's consent, a public register, a contract with or in the interest of the data subject, vital interests, a legal obligation or judicial order, or a legal claim. The PDPA may also authorize a transfer where the controller adduces adequate safeguards by contract under Article 13(2).

Does Bahrain require organizations to appoint a Data Protection Guardian?

Under Article 10(4) of the PDPL, appointing a Data Protection Guardian (Bahrain's term for a DPO) is optional unless the Authority obliges a category of controllers to appoint one, a power Article 2 of Order No. 46 of 2022 gives the Chairman of the Board. No such resolution is published on pdp.gov.bh. Sectoral requirements in banking and private healthcare are reported by law firms but are not published by the regulators themselves, so entities in those sectors should confirm the position with their regulator. Any appointment must be notified to the PDPA within 3 working days, and the Guardian must be enrolled in the Data Protection Guardians Register. Appointing one has a practical benefit: it removes the Article 14 prior-notification duty.

What countries are on Bahrain's data protection adequacy list?

The record attached to Order No. 42 of 2022 lists 83 countries and territories, including all EU member states, Iceland, Liechtenstein, Norway, the UK, Switzerland, the US, Canada, Australia, Japan, and four of the five other GCC states: Saudi Arabia, the UAE, Kuwait and Oman. Qatar is not listed, and the alphabetical record runs straight from Portugal to Romania. The full record in English is published at pdp.gov.bh. Transfers to listed countries do not require prior PDPA authorization; a transfer to Qatar does.

How does Bahrain's PDPL compare to the GDPR?

The PDPL and GDPR share the same architectural principles: lawful bases, data quality, data subject rights, security obligations, breach notification, supervisory authority oversight, and cross-border transfer restrictions. The differences matter in practice. Bahrain's financial penalties are far lower (a corporate maximum of BD 40,000 under Article 59, against the GDPR's EUR 20 million or 4% of global turnover). Access requests carry a 15-working-day deadline under Article 18, while objections and rectification carry 10 working days, rather than the GDPR's one month. Bahrain keeps a prior-notification duty to the regulator (Article 14) and a prior-authorization regime (Article 15) covering CCTV surveillance and biometric processing, neither of which the GDPR has. It uses the term 'Data Protection Guardian' rather than 'Data Protection Officer'. And it is a statute supplemented by Ministerial Orders rather than a directly applicable regulation.

What are Bahrain's lawful bases for processing personal data?

Article 4 of the PDPL makes consent the default and allows processing without it only where it is necessary for one of five things: performance of a contract to which the data subject is a party; taking steps at the data subject's request towards entering a contract; compliance with a legal obligation other than a contractual one, or with an order of a competent court or the Public Prosecution; protecting the data subject's vital interests; or pursuing the legitimate interests of the controller or a third party to whom the data has been disclosed, provided this does not conflict with the data subject's fundamental rights and freedoms. Bahrain has no public-interest basis, no legal-claims basis for ordinary data, and no children's-data carve-out in Article 4. For sensitive personal data, Article 5 requires consent unless one of its eight exemptions applies.

How long does a data controller have to respond to a data subject request?

It depends on the request. Under Article 18, an access request supported by proof of identity must be answered free of charge within 15 working days, with a reasoned decision to accept or reject; the controller may ask within 10 days for a deficient request to be completed. Requests to rectify, block or erase data under Article 23, and objections under Articles 20 and 21, must be answered within 10 working days. Where the controller has rectified, erased or blocked data, it must notify any third party to whom the data was disclosed within 15 days of responding. Article 14 of the PDPL is not about data subject requests at all; it is the controller's prior-notification duty to the PDPA. Data subjects may complain to the PDPA under Article 25 and Order No. 49 of 2022.

What is the relationship between Bahrain's PDPL and the proposed AI regulation law?

Bahrain has no AI statute in force. Members of the Shura Council have put forward a legislative proposal to regulate AI technologies, which under Bahrain's process must go to the Government to be drafted into a bill before it can be passed, and no enacted text has been published. Until then the PDPL governs AI systems that process personal data: Article 22 gives a right to demand a decision that is not solely automated where automated processing assesses performance at work, financial standing, credit-worthiness, reliability or conduct; Article 15 makes biometric and genetic processing and CCTV surveillance subject to prior PDPA authorization; and Article 57 allows compensation for damage. The iGA's General Policy for the Use of AI (July 2025) applies to government entities and names PDPL compliance as one of the legal obligations under its first pillar, Commitment to Policies and Legislations.

Updates

Corrected the citations throughout this guide against the official texts: the implementing instruments are Ministry of Justice Orders Nos. 42 to 51 of 2022 (there is no Order 41), the 72-hour breach rule is in Order 43 rather than Order 44, and the article numbers for penalties, cross-border transfers, data subject deadlines, the Data Protection Guardian and the data quality rules were wrong. We also removed Qatar from the list of countries Bahrain treats as providing adequate protection, because it is not on the official record, removed several GDPR duties that Bahraini law does not impose, added the Article 55 administrative penalties and the Article 15 prior-authorization regime, and replaced unsourced claims about an AI bill, a cybercrime amendment and sector regulators with what the published record supports.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded from about 2,380 to about 5,200 words with sections on the implementing orders, breach notification, the supervisory structure, the adequacy list, data subject request deadlines, the compensation right and GCC context. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.

Reviewed and approved by an editor

Sources and References

  1. Personal Data Protection Authority, Kingdom of Bahrain (Official)(pdp.gov.bh).gov
  2. PDPL Full Text (PDF), pdp.gov.bh(pdp.gov.bh).gov
  3. Resolution No. 42/2022: Adequacy List (English PDF)(pdp.gov.bh).gov
  4. Royal Decree No. 78 of 2019 (full text), Personal Data Protection Authority(pdp.gov.bh).gov
  5. Executive Decisions and Orders (Nos. 42 to 51 of 2022), pdp.gov.bh(pdp.gov.bh).gov
  6. Clyde & Co: Bahrain issues new privacy guidelines (2022)(clydeco.com)
  7. Trowers & Hamlins: Bahrain enhances its data protection regime (2022)(trowers.com)
  8. DLA Piper: Data Protection Laws of the World, Bahrain(dlapiperdataprotection.com)
  9. Order No. 46 of 2022 on Data Protection Guardians (English PDF), pdp.gov.bh(pdp.gov.bh).gov
  10. ASAR Legal: DPOs now required across Finance, Telecom and Health(asarlegal.com)
  11. Ministry of Justice announcement, 20 March 2022: ten Orders implementing the PDPL(moj.gov.bh).gov
  12. Bahrain Recording Laws, RecordingLaw.com
  13. Order No. 43 of 2022: technical and organizational measures, DPIA and breach notification (English PDF)(pdp.gov.bh).gov
  14. Order No. 48 of 2022: the Data Subject's rights (English PDF)(pdp.gov.bh).gov
  15. iGA General Policy for the Use of Artificial Intelligence, 30 July 2025 (official PDF)(iga.gov.bh).gov
  16. TRA Final Direction of 21 January 2024 and telecoms privacy Guidelines(tra.org.bh).gov
  17. Qatar Law No. 13 of 2016 on Protecting Personal Data Privacy (official English text)(almeezan.qa).gov
Share: