Regulatory Framework

    The laws that govern how your business uses AI - wherever you operate in the GCC.

    Every Arcus audit maps your AI operations against the specific instruments that apply to your jurisdiction, your sector, and your data flows. No generic checklists. Every finding is cited to the exact article and the exact penalty that applies to you.

    Select your jurisdiction

    Qatar

    Personal Data Privacy Protection Law (PDPPL)

    Law No. 13 of 2016 · QFC Data Protection Regulations 2021

    Authority

    National Data Privacy Office (NDPO) / NCSA · QFC Data Protection Office (QFC entities)

    Applies to

    All entities processing personal data in Qatar · QFC-registered entities under the parallel QFC DPR regime

    Qatar was the first GCC jurisdiction to enact a comprehensive data protection statute. The PDPPL requires documented lawful basis for every processing activity, privacy notices, data subject rights including access, rectification and erasure, breach notification within 72 hours, and Data Protection Impact Assessments for high-risk processing. The NDPO has been in active enforcement since 2024 - issuing binding compliance orders against an ICT company in December 2024, an e-commerce company in March 2025, and a contracting firm in April 2025. A QFC-registered firm was separately fined following a data breach in 2025. QFC-registered entities operate under the QFC DPR - a GDPR-aligned parallel regime with its own enforcement authority and a higher maximum fine.

    Where AI exposes you

    Every AI tool that processes personal data of Qatar residents or clients - including ChatGPT, Microsoft Copilot, Google Gemini, and Notion AI - requires documented lawful basis and a signed Data Processing Agreement with the vendor. Transferring personal data to overseas AI servers in the US or EU without NCSA authorisation is a direct violation. Employees using personal AI accounts for work involving client or company data creates immediate individual and organisational liability.

    Penalty

    • PDPPL: QAR 1,000,000 - 5,000,000 per violation.
    • QFC DPR: up to QAR 7,000,000 for serious violations.
    • Cybercrime Law: up to 3 years imprisonment + QAR 500,000 fine + deportation for expatriates.
    • Law No. 11/2025: up to 1 year imprisonment + QAR 100,000 for AI-generated images of identifiable individuals without consent.

    Delivered within 48 hours.

    These summaries are general information, not legal advice. Arcus provides strategic management advisory and framework-aligned risk mapping - not legal representation or certification. Penalty figures are indicative statutory maximums drawn from publicly available sources. Actual exposure depends on the specific facts and the determination of the relevant authority. For binding legal opinions, consult qualified legal counsel admitted in the relevant jurisdiction.

    The next move is yours

    Most businesses using AI are not compliant. Most never know until it's too late.

    Free - receive your personalised risk feedback in under 48 hours. The cost of finding out later: everything.

    Not sure which you need?