Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › PDPPL (Law 13/2016) + National AI Strategy
AI governance law · Qatar

๐Ÿ‡ถ๐Ÿ‡ฆ PDPPL (Law 13/2016) + National AI Strategy

Qatar sets its AI direction through a National AI Strategy and NCSA guidance, both soft law, while the binding duties come from the Personal Data Privacy Protection Law (Law 13 of 2016). The PDPPL supplies a near-mandatory impact assessment, a 72-hour breach duty where serious damage arises, and a permit regime for special-nature data. Financial institutions also face binding QCB AI guidance issued in September 2024.

Cited to primary sources
PDPPL (Law 13/2016)
Governing framework
National Cyber Security Agency (NCSA); QCB for financial institutions
Supervisory authority
2
Controls this market requires
5
Required or strongly expected
Good to know: Qatar's National AI Strategy and NCSA AI guidance are soft law, so most AI-specific items sit at prudent or expected rather than required. The firm duties come from the PDPPL - impact assessment and breach notification - and, for banks and insurers, from QCB AI guidance which is binding on financial institutions.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What Qatar expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI DataRequired

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. PDPPL lawful-processing and special-nature-data rules govern AI data.

Closes with: AI data-governance standard
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. PDPPL 72-hour breach notification where serious damage arises.

Closes with: AI incident-response plan + reporting templates
AI RiskExpected

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). PDPPL Articles 11 and 13 impact assessment - near-mandatory.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI TransparencyExpected

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. Transparency expected under PDPPL and NCSA guidance.

Closes with: AI transparency + disclosure notices
AI SecurityExpected

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. Security of processing expected under the PDPPL.

Closes with: AI security controls statement
AI GovernancePrudent

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI governance prudent; the National AI Strategy is soft law.

Closes with: AI policy + governance charter
AI InventoryPrudent

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor. AI inventory prudent to support impact-assessment duties.

Closes with: AI system register
AI OversightPrudent

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. Human oversight prudent; no binding automated-decision right.

Closes with: Human-oversight + automated-decision safeguards note
AI AssurancePrudent

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.

Closes with: Model monitoring + drift-review plan
AI Supply ChainPrudent

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments.

Closes with: Vendor AI due-diligence + model cards
AI UsePrudent

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Staff generative-AI policy is prudent under NCSA guidance.

Closes with: Acceptable-use policy for generative AI
AI AssurancePrudent

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. Record-keeping prudent to evidence PDPPL compliance.

Closes with: AI logging + technical-documentation pack

Get Qatar-ready against the PDPPL and NCSA guidance

PrivMatrix maps the PDPPL duties and NCSA AI guidance onto your systems - and the QCB rules if you are a financial institution - then generates the assessments, notices and policies that close each gap.

Other markets

See all AI laws →
๐Ÿ‡ช๐Ÿ‡บ EU๐Ÿ‡ฌ๐Ÿ‡ง UK๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฎ๐Ÿ‡ณ India