What Is Law No. 30 of 2018 on Personal Data Protection?
Bahrain’s principal statute remains Law No. 30 of 2018 on Personal Data Protection, published in Official Gazette No. 3375 on 19 July 2018 and effective from 1 August 2019. The current Legislation and Legal Opinion Commission listing continues to publish the law and a consolidated version. No amendment located, not confirmed proof that none exists. The framework is supplemented by Decree No. 78 of 2019, which assigns the Authority’s functions to the Ministry of Justice pending the Authority’s institutional conditions, and by 2022 implementing orders including Orders Nos. 42, 49, 50 and 51. These instruments supply procedures for rights, complaints, transfers, and public information. The Act provides detailed rights and deadlines, including access within 15 working days, rectification, blocking and erasure within 10 working days, direct-marketing objection within 10 working days, and a complaint route for a person with legitimate interest or capacity. It also establishes adequacy and authorization requirements for transfers outside Bahrain.
At a glance
- Full name
- Law No. 30 of 2018 on Personal Data Protection
- Short code
- Law No. 30 of 2018
- Jurisdiction
- Bahrain
- Enacted
- 2018
- Last major update
- Effective 1 August 2019; supplemented by Decree No. 78 of 2019 and 2022 implementing orders; no amendment located, not confirmed proof that none exists
- Regulator
- Personal Data Protection Authority, with functions assigned to the Ministry of Justice under Decree No. 78 of 2019 pending the Authority’s institutional conditions
- Private right of action
- Yes
- Statutory citation
- Law No. 30 of 2018 on Personal Data Protection
Scope, who Law No. 30 of 2018 covers
Protected data
Data subject rights
Right to notice and transparency concerning the controller, purposes, recipients or recipient categories, rights, direct-marketing use, and other necessary information
Right to processing confirmation and access, generally within 15 working days
Right to object free of charge to direct marketing, including where data is legally public; the controller must stop or not begin the marketing processing within no more than 10 working days
Right to require cessation or limitation of processing causing or reasonably likely to cause substantial and unjustified material or moral harm, subject to statutory exceptions
Right to request a non-solely-automated process for specified automated assessments of work performance, financial standing, creditworthiness, reliability, or conduct
Right to rectification, completion, updating, blocking, or erasure for unlawful, inaccurate, incomplete, or outdated processing, generally within 10 working days
Right to withdraw consent at any time through an easy and free process without liability
Right to submit a written complaint to the Authority where the complainant has legitimate interest or capacity
Notable features
The framework combines short controller-response periods with a formal cross-border authorization and adequacy regime. Access generally takes 15 working days, rectification, blocking and erasure 10 working days, and direct-marketing objections no more than 10 working days. Public-register correction, blocking, and erasure are deferred to the establishing law, so the general rights framework does not create a universal public-record deletion route.
Enforcement & penalties
Penalties: Administrative daily threatening fine: up to BD 1,000 per day for a first violation and BD 2,000 per day for another violation within three years. Administrative fine: up to BD 20,000. Criminal violations including unlawful sensitive-data processing, unauthorized international transfers, failure to notify or obtain authorization, misleading information, obstruction, and unlawful disclosure may carry imprisonment up to 1 year and/or a fine from BD 1,000 to BD 20,000. Breach of Article 32(1) or (2) carries a fine from BD 3,000 to BD 20,000, with possible confiscation of proceeds. A legal person may face fines at double the lower and upper limits where statutory corporate-liability conditions apply.
Private right of action: Civil compensation is available for damage caused by unlawful processing or a guardian’s violation. An interested person may also challenge an Authority decision before the Appeal Tribunal within 30 days of becoming aware of it, subject to the prescribed fee, with a final Tribunal decision appealable before the Court of Cassation.
Relevance to data brokers
No dedicated Bahrain data-broker registry, broker-specific complaint form, or broker-specific deletion mechanism was located. This does not establish that such a route is nonexistent. A general PDPA complaint route remains available for a suspected statutory violation, subject to scope exclusions. Public registers must be limited to necessary data and purposes and may provide amendment or deletion free of charge in cases permitted by law, but there is no verified universal public-record deletion route.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What rights does Bahrain’s Personal Data Protection Law provide?+
The law provides notice and transparency, access, rectification, blocking, erasure, direct-marketing objection, protection against specified harmful processing, human review of certain solely automated decisions, consent withdrawal, and a complaint route to the Authority.
How long does a Bahrain controller have to answer a data request?+
Access requests generally require a response within 15 working days. Rectification, blocking, and erasure requests generally require a response within 10 working days, while direct-marketing objections must be stopped or not begun within no more than 10 working days.
Can I request deletion from a data broker or public register in Bahrain?+
No data-broker-specific deletion mechanism was located, and this does not establish that such a route is nonexistent. Public-register amendment or deletion depends on what the establishing law permits; there is no verified universal public-record deletion route.
Official sources & citations
Other international privacy regimes
Law No. 30 of 2018 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
