What Bahrain Personal Data Protection Law 2018 - PDPA requires
Bahrain's Personal Data Protection Law (PDPL) - Legislative Decree No. 30 of 2018, issued by His Majesty King Hamad bin Isa Al Khalifa on 12 July 2018 and published in the Official Gazette - is Bahrain's comprehensive personal data protection legislation, making Bahrain the first Gulf Cooperation Council (GCC) member state to enact a standalone, comprehensive personal data protection law. The PDPL came into full force following the issuance of the Executive Regulations (Resolution No. 1 of 2019), and full compliance was required from 1 August 2019. The PDPL is broadly aligned with international data protection standards, particularly the European Union GDPR (Regulation (EU) 2016/679), and reflects Bahrain's position as a regional financial and technology hub seeking to align its regulatory framework with global best practice. The enforcement authority is the Personal Data Protection Authority (PDPA) - an independent statutory body established under the PDPL to regulate, supervise, and enforce personal data protection in Bahrain. Key features of the Bahrain PDPL: (1) Applies to any person (natural or legal) who controls the processing of personal data in Bahrain or where personal data of persons in Bahrain is processed, regardless of whether the controller is located in Bahrain; (2) Lawful processing conditions - personal data may be processed only where one of the following applies: the data subject's consent; contractual necessity; legal obligation; vital interests; public interest; or the legitimate interests of the controller (where not overridden by the data subject's interests); (3) Sensitive personal data - the PDPL designates categories of sensitive personal data requiring additional safeguards: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health or medical data; sexual life or orientation; biometric and genetic data; financial data; and data relating to criminal offences and convictions; (4) Data subject rights - right of access; right to rectification; right to erasure; right to restriction of processing; right to data portability; right to object; right not to be subject to automated decision-making with significant effects; (5) Data Controller obligations - maintain a record of processing activities; implement data protection by design and by default; designate a Data Protection Officer (DPO) where required; conduct Data Protection Impact Assessments (DPIAs) for high-risk processing; notify the PDPA and data subjects of personal data breaches; (6) Data Protection Officer - required for controllers: processing large volumes of personal data; processing sensitive personal data; or conducting systematic monitoring of individuals; (7) Breach notification - controllers must notify the PDPA of personal data breaches within a reasonable time (the PDPA has issued guidance on notification timelines); data subjects must be notified where the breach is likely to harm them; (8) Cross-border data transfer - personal data may only be transferred to a country or territory providing adequate protection for personal data; where adequacy is not established, transfers require PDPA approval or one of the specified safeguards (consent, contractual necessity, vital interests, or binding corporate rules); (9) Penalties - administrative sanctions including fines; criminal penalties for wilful violations including imprisonment; the PDPA may impose corrective orders, warnings, and temporary or permanent prohibitions on processing. Bahrain's PDPL was a pioneering instrument in the Gulf region and has influenced subsequent data protection law developments in other GCC states.
Pillar: Cybersecurity · Authority: Personal Data Protection Authority (PDPA, Bahrain) · Version: 1.0.0 · Last updated:
Primary source: https://www.pdpa.gov.bh/
SHA-256 integrity: 2327ce0b4b2eba77f0aeeac4eff78062156261bfb20db5b7359ee85d28fc3372
Primary Citations — 7 traced to source
- Personal Data Protection Law (PDPL, Legislative Decree No. 30 of 2018, Kingdom of Bahrain) - issued by His Majesty King Hamad bin Isa Al Khalifa 12 July 2018; published in Official Gazette; Executive Regulations (Resolution No. 1 of 2019); full compliance required from 1 August 2019; first comprehensive standalone personal data protection law in the GCC; applies to controllers processing personal data in Bahrain or processing data of persons in Bahrain; lawful processing conditions: consent, contract, legal obligation, vital interests, public interest, legitimate interests; sensitive personal data: racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual life, biometric, genetic, financial, criminal; data subject rights: access, rectification, erasure, restriction, portability, objection, automated decision-making
- Personal Data Protection Authority (PDPA, Bahrain) - independent statutory supervisory authority established under the PDPL; issues enforcement orders, warnings, and administrative sanctions; conducts investigations; receives breach notifications; approves cross-border data transfers; issues guidance on data protection compliance including consent, DPO designation, DPIA methodology, and sensitive data processing; pdpa.gov.bh is the official portal for registration, breach notification, and PDPA guidance
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/bh-pdpl-2018.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/bh-pdpl-2018.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/bh-pdpl-2018
- Back to registry: Browse all 10,090 compliance nodes