The framework
Qatar's framework rests on Law No. 13 of 2016 on Personal Data Privacy Protection, with the National Cyber Governance and Assurance Affairs as the supervisory authority.
That puts Qatar in the global opt-in majority, where permission comes before processing and marketing waits for consent.
Key instruments
Law No. 13 of 2016 on Personal Data Privacy Protection
The first Gulf state with a standalone privacy law (2016); guidelines issued from 2021 gave it operational teeth, and the Qatar Financial Centre runs a separate GDPR-style regime with its own DPO and transfer rules.
Marketing and advertising
Consent-based processing with direct marketing requiring prior consent and opt-out in each message. That single sentence decides most channel plans here.
Cross-border transfers
Permitted with consent or where protection is not undermined; QFC applies GDPR-style rules.
Enforcement and penalties
Fines reach QAR 5M. Read the ceiling together with the authority's track record, which prices the risk.