Qatar Central Bank Data Handling and Protection Regulation compliance software
QCB's data handling and protection regulation for its Financial Institutions — 126 controls across 10 domains, the DPO and retention obligations tracked alongside the breach-notification chain to QCB, NCSA and the Ministry of Interior.
- RegulatorQatar Central Bank (QCB)
- InstrumentData Handling and Protection Regulation
- Structure10 domains, 126 controls, each citing its section
- RetentionPersonal Data / SFI: 10-year floor · Technical Information: 1 year
What QCB Data Handling & Protection requires
Who it applies to
- Banks and insurance companies licensed by Qatar Central Bank — exempted from none of the regulation
- Exchange houses, fintechs, finance and investment companies, and insurance brokers with defined exemptions under Appendix 1
- Organisations appointing or reporting a Data Protection Officer to QCB
- Institutions using fully autonomous decision-making systems requiring prior QCB approval
Qatar Central Bank's Data Handling and Protection Regulation governs how every QCB-regulated Financial Institution collects, stores, processes and protects data, and sits alongside the Cloud Computing Regulation and QCB's AI Guideline as one of the Bank's data-facing secondary regulations. It requires data handling to align with QCB Law, the regulation itself and Qatar's Personal Data Privacy Protection Law together, not any one in isolation.
126 controls run across ten domains — organisational governance, policy and classification and the Record of Processing Activities, data handling and processing, data security, third-party access, assessments and reporting, retention and disaster recovery and continuity, privacy and customer data protection, cross-border transfer and data breaches, and exemptions and secondary regulations. A Data Protection Officer appointment needs QCB notification and a Fit and Proper form, must sit outside operations, and reports directly to the CEO, who escalates privacy risk to the board.
Retention carries an explicit floor — Sensitive Financial Information and Personal Data at ten years, Technical Information at one, extended wherever another legal or regulatory mandate requires more — and the primary storage and processing environment for personal and sensitive data must sit inside Qatar. A breach is reported to QCB, the National Cyber Security Agency and the Ministry of Interior together; Appendix 1 grants a defined set of exemptions to non-bank, non-insurance Financial Institutions, with banks and insurers exempted from none of it.
How GRCLens supports QCB Data Handling & Protection
QCB Data Handling & Protection runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
DPO governance as tracked controls
QCB notification, the Fit and Proper form, the outside-operations requirement and the direct-to-CEO reporting line are each their own control, not one line in a policy.
Appendix 1 exemptions applied by subsector
The regulation's own exemption table is built in — banks and insurers see every control as mandatory, while exchange houses, fintechs and finance and investment companies see the specific sections QCB exempted them from.
Retention floor and DR/backup matrix
The 10-year and 1-year retention floors, and the local-versus-foreign disaster-recovery and backup requirements by institution type, are assessed as their own controls rather than left to a data-lifecycle policy nobody checks against them.
Three-way breach notification
QCB, NCSA and the Ministry of Interior are each tracked as a required recipient on a data breach record, so the notification chain is complete before the regulator asks.
QCB Data Handling & Protection frequently asked questions
Who must comply with the QCB Data Handling and Protection Regulation?
Every Financial Institution licensed by Qatar Central Bank. Banks and insurance companies carry every requirement; exchange houses, fintechs, finance and investment companies and insurance brokers are granted specific exemptions under Appendix 1.
Where must personal and financial data be stored?
The primary storage and processing environment for Personal Data, Sensitive Personal Information and Sensitive Financial Information must sit within Qatar; local disaster recovery and local backup are mandatory for every Financial Institution type.
Who is a data breach reported to?
QCB, the National Cyber Security Agency and the Ministry of Interior, together. The regulation does not state a fixed numeric deadline, deferring instead to QCB's separate incident-reporting guidelines.
One platform, many obligations

Talk to us about QCB Data Handling & Protection
Security Solution Consultants provides Qatar QCB data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.