Qatar sets its AI direction through a National AI Strategy and NCSA guidance, both soft law, while the binding duties come from the Personal Data Privacy Protection Law (Law 13 of 2016). The PDPPL supplies a near-mandatory impact assessment, a 72-hour breach duty where serious damage arises, and a permit regime for special-nature data. Financial institutions also face binding QCB AI guidance issued in September 2024.
All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.
Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. PDPPL lawful-processing and special-nature-data rules govern AI data.
Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. PDPPL 72-hour breach notification where serious damage arises.
Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). PDPPL Articles 11 and 13 impact assessment - near-mandatory.
Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. Transparency expected under PDPPL and NCSA guidance.
AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. Security of processing expected under the PDPPL.
A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI governance prudent; the National AI Strategy is soft law.
A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor. AI inventory prudent to support impact-assessment duties.
Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. Human oversight prudent; no binding automated-decision right.
Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.
Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments.
An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Staff generative-AI policy is prudent under NCSA guidance.
Keeping the logs, technical documentation and conformity evidence regulators expect. Record-keeping prudent to evidence PDPPL compliance.
PrivMatrix maps the PDPPL duties and NCSA AI guidance onto your systems - and the QCB rules if you are a financial institution - then generates the assessments, notices and policies that close each gap.