Bahrain PDPL: A Practical Compliance Guide for Organisations
If your organisation handles personal data in the Kingdom of Bahrain, the Bahrain PDPL sets the rules you need to follow. Law No. 30 of 2018 with respect to Personal Data Protection came into force on 1 August 2019 and was one of the first GDPR-style laws in the Gulf.
Since then, a set of implementing orders issued in 2022 has added practical detail on security measures, breach notification, international transfers, data protection guardians and more. The result will feel familiar to GDPR practitioners, with important local differences.
This guide covers scope, the regulator, key obligations, individual rights, penalties and a practical checklist.
What the PDPL is and who it applies to
Material scope
Under Article 2, the PDPL applies to the processing of personal data by wholly or partly automated means, and to non-automated processing of data that forms part of a filing system or is intended to.
Territorial scope
The law applies to:
- individuals who normally reside or work in Bahrain, and organisations with a place of business in Bahrain;
- individuals and organisations outside Bahrain that process personal data using means located in the Kingdom, unless those means are used only to pass data through Bahrain.
Exclusions
The law does not apply to processing by an individual for personal or family purposes. It also excludes certain processing by the Ministry of Defence, the Ministry of Interior, the National Guard, the National Security Service and other security bodies.
The regulator
The law establishes the Personal Data Protection Authority (PDPA) as an independent public body. Until the Authority is fully constituted, Royal Decree No. 78 of 2019 designates the Ministry of Justice, Islamic Affairs and Waqf to carry out its duties. The PDPA website publishes the law and the implementing orders.
Key Bahrain PDPL requirements
Lawful bases for processing
Article 4 requires the data subject’s consent unless processing is necessary to:
- perform a contract to which the data subject is a party, or take steps at their request before entering into one;
- comply with a legal obligation to which the controller is subject;
- protect the data subject’s vital interests; or
- pursue the legitimate interests of the controller or a third party, unless these conflict with the data subject’s fundamental rights and freedoms.
Where you rely on consent, it must be explicit, freely given and informed. Data subjects can withdraw consent at any time.
Processing principles
Personal data must be processed fairly and lawfully, collected for specified, explicit and legitimate purposes, adequate, relevant and not excessive, accurate and kept up to date, and retained in identifiable form no longer than necessary.
Sensitive personal data
Sensitive data covers information revealing race, ethnic origin, political or philosophical views, religious beliefs, trade union membership, criminal record, and data concerning health or sex life. Article 5 prohibits processing it without the data subject’s consent, subject to limited exceptions such as employment law obligations, legal claims, healthcare by licensed professionals and data the data subject has made public.
Security and processors
Article 8 requires controllers to implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. Processors must be appointed under a written contract that binds them to equivalent security and confidentiality obligations.
Order No. 43 of 2022 sets out what these measures should include, such as privacy by design, access control, anti-malware and firewalls, periodic vulnerability assessment and penetration testing, business continuity plans and staff training.
Data subject rights
Individuals have the right to:
- be informed about the controller, the purposes of processing and the recipients of their data;
- access their personal data;
- object to processing for direct marketing;
- object to processing that causes, or is likely to cause, unwarranted substantial material or moral damage (Article 21);
- ask for reconsideration of decisions based solely on automated processing that assess matters such as work performance, financial standing, creditworthiness, reliability or conduct (Article 22);
- request rectification, blocking or erasure of data that is inaccurate or processed unlawfully; and
- complain to the Authority.
Several rights come with short response deadlines set in the law, some as short as ten working days. You need a request handling process that can verify identity and respond quickly.
The data protection guardian
One of the law’s most distinctive features is the data protection guardian, a role similar to the GDPR’s data protection officer. Under Article 10, the guardian helps the controller exercise its rights and meet its duties, acts as a link between the controller and the Authority, monitors compliance and keeps a register of processing operations.
Key points to know:
- Guardians must be entered on a register kept by the Authority, and registration fees apply.
- Appointment is generally voluntary, although the Authority’s Board may make it mandatory for certain categories of controller.
- The Authority must be notified within three working days of an appointment.
- The guardian must act independently, and must notify the Authority of violations that the controller has not fixed within ten days of being alerted.
- The 2022 orders set qualification requirements. An internal guardian must be an employee resident in Bahrain, and external guardians must meet qualification or experience criteria.
Notifications and prior authorisation
Notification of processing
Article 14 requires controllers to notify the Authority before carrying out wholly or partly automated processing. There are exceptions, including where a data protection guardian has been appointed, processing of employee data by employers for employment purposes, certain activities of associations and non-profit bodies, and public registers.
Prior authorisation
Article 15 requires prior authorisation from the Authority before certain higher-risk processing, including:
- automated processing of sensitive data in certain cases permitted under Article 5;
- automated processing of biometric data used to verify identity;
- processing of genetic data, except by licensed medical establishments;
- linking data files held by two or more controllers for different purposes; and
- visual recording for surveillance purposes, such as CCTV.
If the Authority does not respond within 30 days, the request is treated as rejected, so plan ahead.
Breach notification
Order No. 43 of 2022 requires controllers to notify the Authority of a personal data breach within 72 hours of discovering it, unless the breach would not affect data subjects’ rights. The notification should describe the breach, who and what is affected, the likely consequences and the corrective measures taken. Affected individuals must also be informed in many cases.
Cross-border data transfers
Under Article 12, personal data may be transferred outside Bahrain to countries that the Authority recognises as providing adequate protection. Order No. 42 of 2022 lists the approved countries.
Transfers to other countries need the Authority’s authorisation on a case-by-case basis, or must fall within an Article 13 exception. These include the data subject’s consent, transfers of data from a public register, and transfers necessary to perform a contract, protect vital interests, or establish, exercise or defend legal claims.
Penalties
The PDPL combines administrative sanctions and criminal penalties.
| Type | Sanction |
|---|---|
| Administrative (Article 55) | Orders to stop the violation, withdrawal of an authorisation, daily penalties of up to BHD 1,000 (up to BHD 2,000 for a repeat violation within three years), and fines of up to BHD 20,000 |
| Criminal (Article 58) | Up to one year’s imprisonment and/or a fine of BHD 1,000 to BHD 20,000 for offences such as unlawful processing of sensitive data, unlawful transfers, processing without notification or authorisation, and obstructing the Authority |
| Legal persons (Article 59) | Double the fines in Article 58 where the offence is committed in the organisation’s name or for its benefit |
Individuals who suffer harm can also claim compensation.
Bahrain PDPL compliance checklist
- Confirm your scope. Identify which entities, systems and activities process personal data in or through Bahrain.
- Map your processing. Build a record of processing activities covering purposes, lawful bases, data categories, systems, recipients, retention and transfers.
- Review lawful bases and consent. Document the basis for each activity and make sure consent is explicit, informed and easy to withdraw.
- Identify sensitive and high-risk processing. Flag sensitive, biometric and genetic data, CCTV and data linking, and apply for prior authorisation where needed.
- Decide on a data protection guardian. Consider appointing a registered guardian, and notify the Authority within three working days if you do.
- Notify the Authority. If no guardian is appointed, confirm whether your automated processing must be notified.
- Update privacy notices. Tell individuals who you are, why you process their data, who receives it and their right to object to direct marketing.
- Apply Order No. 43 security measures. Check your controls, testing, continuity plans and training against the order.
- Put processor contracts in place. Include security and confidentiality obligations in writing.
- Review international transfers. Check destinations against the approved list and obtain authorisation or rely on an exception where needed.
- Prepare for breaches. Define who assesses incidents and how you notify the Authority within 72 hours.
- Handle rights requests. Build a process that meets the law’s short response deadlines.
How Enactia helps
Enactia is an AI-powered governance, risk and compliance (GRC) platform that supports Bahrain’s PDPL alongside the GDPR, the KSA and UAE PDPLs and other frameworks. It gives your team, or your guardian, one place to run and evidence the programme.
- Keep your processing register. Maintain your Record of Processing Activities (ROPA) with purposes, lawful bases, processors and transfers.
- Assess compliance. Run Compliance Assessments against PDPL requirements and use Compliance Universe to cross-map controls you already have for the GDPR or ISO 27701.
- Meet the 72-hour deadline. Incident and data breach management workflows help you assess incidents and track notifications.
- Answer rights requests on time. The Data Subject Requests module helps you log, verify and respond within deadlines.
Frequently asked questions
When did the Bahrain PDPL come into force?
Law No. 30 of 2018 came into force on 1 August 2019. The main implementing orders were issued in 2022.
Who enforces the PDPL in Bahrain?
The Personal Data Protection Authority. Under Royal Decree No. 78 of 2019, the Ministry of Justice, Islamic Affairs and Waqf carries out the Authority’s duties.
Is a data protection guardian mandatory?
Generally not, although the Authority’s Board can require it for certain categories of controller. Appointing a registered guardian can exempt you from the general duty to notify the Authority of automated processing.
Does the PDPL apply to companies outside Bahrain?
It can. The law applies to organisations with a place of business in Bahrain, and to those outside Bahrain that process data using means located in the Kingdom.
What are the penalties for breaching the PDPL?
Administrative fines reach BHD 20,000, with daily penalties for continuing violations. Criminal offences carry up to one year’s imprisonment and fines of up to BHD 20,000, doubled for legal persons.
Conclusion: turn the PDPL into routine practice
The PDPL and its 2022 orders give Bahrain a detailed, GDPR-style framework with its own features, from the data protection guardian to prior authorisation for CCTV and biometrics. Organisations that map their data, plan their notifications and authorisations, and prepare for breaches will find compliance far easier to maintain.
Want to see how Enactia can help you manage PDPL compliance across Bahrain and the wider GCC? Contact us or book a demo with our team.
