Qatar DPL
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach and Enforcement
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: breach + enforcement. Requirements include (a) breach notification to NDPC (Qatar Cyber Security Office) + affected subjects + (b) incident response + (c) regulator cooperation + (d) penalties awareness + (e) breach log + tabletops.
- Qatar Law 13/2016 evidence for QATAR-8
- NDPC notification + transfer + DPO partial
Consent and Notice
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: consent + notice + sensitive data. Requirements include (a) obtain valid consent + (b) provide privacy notice + (c) implement sensitive data safeguards + (d) maintain records of consent + (e) change management.
- Qatar Law 13/2016 evidence for QATAR-2
- NDPC notification + transfer + DPO partial
Governance
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: governance. Requirements include (a) DPO designation + (b) records of processing + (c) retention + (d) marketing safeguards + (e) training + (f) accountability framework.
- Qatar Law 13/2016 evidence for QATAR-7
- NDPC notification + transfer + DPO partial
High-Risk Processing
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: heightened safeguards. Requirements include (a) children's data protections + (b) DPIA for high-risk + (c) privacy by design + (d) documented safeguards.
- Qatar Law 13/2016 evidence for QATAR-4
- NDPC notification + transfer + DPO partial
Individual Rights
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: data subject rights. Requirements include (a) Access + Rectification + Erasure + Object + Portability + (b) automated decision protections + (c) mechanism + (d) records of requests.
- Qatar Law 13/2016 evidence for QATAR-3
- NDPC notification + transfer + DPO partial
Scope and Lawful Basis
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: scope + lawful basis + purpose. Requirements include (a) determine applicability + (b) establish lawful basis for processing + (c) apply purpose limitation + (d) document applicability + lawful basis + (e) align with NDPC (Qatar Cyber Security Office) guidance.
- Qatar Law 13/2016 evidence for QATAR-1
- NDPC notification + transfer + DPO partial
Security
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: security. Requirements include (a) appropriate technical + organisational measures + (b) encryption + pseudonymisation + (c) access control + (d) regular testing + (e) integrate with broader InfoSec.
- Qatar Law 13/2016 evidence for QATAR-5
- NDPC notification + transfer + DPO partial
Transfer and Processor
Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: cross-border + processor. Requirements include (a) transfer restrictions + (b) processor agreements + (c) cross-border safeguards + (d) inventory + (e) supplier due diligence.
- Qatar Law 13/2016 evidence for QATAR-6
- NDPC notification + transfer + DPO partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Qatar DPL framework page.