HomeFrameworksBahrain PDPL
Personal Data Protection Authority (Kingdom of Bahrain) · Bahrain

Personal Data Protection Law (Law No. 30 of 2018) compliance software

Bahrain's data protection law, with its ten Ministerial Orders, transcribed as 82 controls across 12 domains — the Data Protection Guardian regime and the 72-hour breach clock tracked as their own indicators.

At a glance
  • RegulatorPersonal Data Protection Authority (PDPA), Kingdom of Bahrain
  • InstrumentsLaw No. 30 of 2018 · ten Ministerial Orders (42–51), all dated 17 March 2022
  • Structure12 duty-based domains, 82 controls, each citing its article or Order
  • Breach window72 hours from discovery, to the Authority (Order 43)
Bahrain PDPLAvailable
Overview

What Bahrain PDPL requires

Who it applies to

  • Any controller or processor processing personal data in the Kingdom of Bahrain
  • Organisations appointing a Data Protection Guardian under Article 10
  • Controllers relying on the 83-country transfer whitelist or seeking case-by-case authorisation
  • Organisations processing sensitive or criminal data requiring prior Article 15 approval

Law No. 30 of 2018 is Bahrain's Personal Data Protection Law, in force since 1 August 2019. It applies to any processing of personal data by automated means and to manual filing systems alike, and it was extended by ten Ministerial Orders — all issued 17 March 2022 — covering cross-border transfer, technical and organisational measures, notifications and prior authorisation, sensitive-data rules, Data Protection Guardians, data subject rights, complaints, criminal-data confidentiality and public registers.

Order 43 sets the technical and organisational measures: a mandatory Data Protection Impact Assessment for large-scale sensitive or criminal data, large-scale public monitoring or profiling-based decisions, and a 72-hour breach notification window to the Authority measured from discovery. The Data Protection Guardian — a role every relevant controller must appoint and notify to the Authority within three working days — is Bahrain's closest equivalent to a Data Protection Officer, and escalates an unremedied violation after ten days.

GRCLens carries the Law and its ten Orders as 82 controls in twelve duty-based domains, each citing its article or Order. Penalties reach a daily fine of BD 2,000 for repeat non-compliance, an administrative penalty up to BD 20,000, and criminal penalties up to one year's imprisonment and a BD 1,000–20,000 fine, doubled for legal persons — so the record the Guardian keeps is the record examined first.

In the platform

How GRCLens supports Bahrain PDPL

Bahrain PDPL runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

The Guardian's clocks

Appointment notified within 3 working days, unremedied violations escalated after 10 days — the Data Protection Guardian regime is tracked as its own readiness indicator.

DPIA triggers, not a blanket requirement

Order 43's mandatory DPIA triggers — large-scale sensitive or criminal data, large-scale monitoring, profiling-based decisions — are individually assessable controls, so a DPIA is flagged only where the Order actually requires one.

Transfer whitelist tracked

The 83-country whitelist and the case-by-case authorisation route for every other destination are carried as separate controls, so a transfer decision cites which route it actually used.

Arabic and English

Every article and Order-level control carries Arabic alongside the English, matching the Authority's own bilingual publication.

Questions

Bahrain PDPL frequently asked questions

What is a Data Protection Guardian?

Bahrain's closest equivalent to a Data Protection Officer: a role every relevant controller must appoint and notify to the Authority within three working days, and which escalates an unremedied violation after ten days. Order 46 sets its duties.

How quickly must a data breach be notified?

Order 43 sets a 72-hour window from discovery for notifying the Authority — a shorter, discovery-anchored clock rather than one counted from confirmation.

Can personal data be transferred outside Bahrain?

Yes, by default to any of 83 whitelisted countries and territories under Order 42; a transfer to any other destination needs case-by-case authorisation from the Authority.

Talk to us about Bahrain PDPL

Security Solution Consultants provides Bahrain data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.