{
  "node_id": "bh-pdpl-2018",
  "title": "Bahrain Personal Data Protection Law 2018 - PDPA",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Bahrain's Personal Data Protection Law (PDPL) - Legislative Decree No. 30 of 2018, issued by His Majesty King Hamad bin Isa Al Khalifa on 12 July 2018 and published in the Official Gazette - is Bahrain's comprehensive personal data protection legislation, making Bahrain the first Gulf Cooperation Council (GCC) member state to enact a standalone, comprehensive personal data protection law. The PDPL came into full force following the issuance of the Executive Regulations (Resolution No. 1 of 2019), and full compliance was required from 1 August 2019. The PDPL is broadly aligned with international data protection standards, particularly the European Union GDPR (Regulation (EU) 2016/679), and reflects Bahrain's position as a regional financial and technology hub seeking to align its regulatory framework with global best practice. The enforcement authority is the Personal Data Protection Authority (PDPA) - an independent statutory body established under the PDPL to regulate, supervise, and enforce personal data protection in Bahrain. Key features of the Bahrain PDPL: (1) Applies to any person (natural or legal) who controls the processing of personal data in Bahrain or where personal data of persons in Bahrain is processed, regardless of whether the controller is located in Bahrain; (2) Lawful processing conditions - personal data may be processed only where one of the following applies: the data subject's consent; contractual necessity; legal obligation; vital interests; public interest; or the legitimate interests of the controller (where not overridden by the data subject's interests); (3) Sensitive personal data - the PDPL designates categories of sensitive personal data requiring additional safeguards: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health or medical data; sexual life or orientation; biometric and genetic data; financial data; and data relating to criminal offences and convictions; (4) Data subject rights - right of access; right to rectification; right to erasure; right to restriction of processing; right to data portability; right to object; right not to be subject to automated decision-making with significant effects; (5) Data Controller obligations - maintain a record of processing activities; implement data protection by design and by default; designate a Data Protection Officer (DPO) where required; conduct Data Protection Impact Assessments (DPIAs) for high-risk processing; notify the PDPA and data subjects of personal data breaches; (6) Data Protection Officer - required for controllers: processing large volumes of personal data; processing sensitive personal data; or conducting systematic monitoring of individuals; (7) Breach notification - controllers must notify the PDPA of personal data breaches within a reasonable time (the PDPA has issued guidance on notification timelines); data subjects must be notified where the breach is likely to harm them; (8) Cross-border data transfer - personal data may only be transferred to a country or territory providing adequate protection for personal data; where adequacy is not established, transfers require PDPA approval or one of the specified safeguards (consent, contractual necessity, vital interests, or binding corporate rules); (9) Penalties - administrative sanctions including fines; criminal penalties for wilful violations including imprisonment; the PDPA may impose corrective orders, warnings, and temporary or permanent prohibitions on processing. Bahrain's PDPL was a pioneering instrument in the Gulf region and has influenced subsequent data protection law developments in other GCC states.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 7
}