Oman
Full enforcement has begun
From February 2026
Action: Confirm permits, processing records, officer designation, breach contacts and transfer assessments.

Data protection in the Middle East is no longer a collection of isolated privacy provisions. By 2026, much of the region has moved toward dedicated laws, active regulators, detailed implementing rules and formal controls for international transfers, sensitive data, breach response and accountability.
The difficult part is fragmentation. There is no single “Middle East privacy law”, no regional equivalent of the GDPR and no universal compliance deadline. A company may face a national law, sector rules and a special financial-zone regime at the same time. The applicable rules can change depending on where the entity is established, whose data it processes, whether it targets local users, the sector in which it operates and where its vendors can access the data.
For international SaaS providers, e-commerce businesses, employers, healthcare platforms, financial services firms and regional groups, the right objective is therefore not to create one generic MENA privacy policy. It is to build one defensible privacy operating model with carefully documented local variations.
The short answer: most active Middle Eastern regimes now expect lawful and transparent processing, defined purposes, proportionate collection, security, retention controls, data-subject request handling and governance over processors. The main differences lie in consent, registrations and permits, local representatives or data protection officers, breach deadlines, cross-border transfer mechanisms, sensitive-data controls and regulatory maturity.
This guide explains those differences and identifies the developments that matter most in 2026.
Scope note: “Middle East” has no single legal definition. This guide focuses on the six GCC states, Türkiye, Egypt, Jordan, Israel, Lebanon and Syria, with a shorter note on Iraq, Iran, Yemen and the Palestinian territories. It is a regional operational guide, not a substitute for jurisdiction-specific legal advice. Sector rules for banking, insurance, telecoms, healthcare, government data, cybersecurity and digital platforms may add separate duties.
The major theme is not the sudden arrival of one regional law. It is the transition from high-level legislation to operational compliance.
The same processing activity can produce different legal answers across the region. Before comparing obligations, a company should resolve five threshold questions.
The country is not always the final answer. A UAE entity in the Dubai International Financial Centre may be subject to the DIFC Data Protection Law rather than the federal private-sector framework for the relevant activity. An Abu Dhabi Global Market entity operates under the ADGM Data Protection Regulations. A Qatar Financial Centre firm uses the QFC regime, which is distinct from Qatar’s national law.
Corporate registration, licensing status and the place where the relevant processing occurs should therefore be checked before selecting a compliance framework.
Some regimes expressly reach foreign processing connected with people in the jurisdiction. The connecting factor may refer to residents, citizens, people located in the country, offering goods or services, or monitoring behaviour. These concepts are not interchangeable.
A foreign website being technically accessible from a country does not automatically settle applicability. Language, local pricing, delivery, sales activity, contracts, marketing, user volume, behavioural monitoring and the presence of local staff or partners can all matter.
The difference between controller and processor affects contracts, direct legal duties, breach escalation and data-subject requests. A cloud provider can be a processor for hosted customer data, a controller for billing and account security, and a joint or independent controller for another feature. The label in the contract is useful but does not override the facts.
Health, biometric, genetic, financial, criminal-record, religious, political and children’s data commonly receive additional protection. Marketing, surveillance, employee monitoring, profiling, AI training and large-scale tracking may also trigger special conditions, permits, DPO duties or impact assessments.
International transfer analysis should include more than the primary hosting location. Remote administrator access, customer-support tools, global identity systems, security monitoring, backups, analytics, subprocessors and disaster-recovery environments can create separate data flows.
The UAE must be analyzed as several privacy environments rather than one.
Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data establishes the core federal framework. It addresses lawful processing, transparency, data-subject rights, security, breach management, DPO appointments in specified circumstances and transfers outside the UAE.
However, important operating detail is delegated to Executive Regulations, including procedural deadlines, aspects of breach notification, transfer mechanisms, DPO thresholds and penalties. As of the date of this guide, the general Executive Regulations were not identifiable in the official UAE legislation database. This does not make the federal law irrelevant. It means organizations must comply with the law’s operative principles while avoiding invented deadlines or mechanisms and maintaining a readiness plan for the regulations.
When the Executive Regulations are issued, Article 29 provides a six-month period for organizations to regularize their position, subject to any extension. That window should be treated as a final implementation period, not the point at which privacy work begins.
Federal Decree-Law No. 26 of 2025 Regarding Child Digital Safety entered into force on 1 January 2026. It applies to a broad range of digital platforms operating in the UAE or directed at users there. Among other duties, it restricts the collection, processing, publication and sharing of personal data of children under 13 unless specified conditions—including explicit, documented and verifiable caregiver consent—are satisfied. It also requires age-appropriate controls and privacy protections.
Digital platforms should map this law separately from the general PDPL. The affected product teams may include identity, age assurance, advertising, recommender systems, gaming, content moderation, trust and safety, and parental-control functions.
DIFC Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 are separate, detailed regimes with their own regulators, accountability requirements, breach rules and transfer mechanisms. ADGM added Substantial Public Interest Conditions Rules in 2025. DIFC also contains specific rules addressing autonomous and semi-autonomous systems.
An organization should not copy its federal UAE analysis into a DIFC or ADGM compliance register. The applicable entity, processing context, regulator, registration or notification duties, DPO analysis and transfer tool must be determined under the relevant regime.
2026 priority: maintain a federal-regulation watch, review child-facing or child-accessible services, and keep DIFC/ADGM records separate from mainland compliance documentation.
Saudi Arabia’s Personal Data Protection Law, as amended, is supported by Implementing Regulations and separate transfer rules. It applies to processing in the Kingdom and can also reach processing by a party outside the Kingdom involving personal data related to individuals residing there, subject to the law’s scope and exceptions.
The regime requires controllers to identify a lawful basis, provide required information, respect data-subject rights, control retention, implement appropriate security and govern processors. Consent remains important, but it is not the only possible legal basis. Sensitive data, credit data, health data, direct marketing and scientific or research activity require additional care.
For many international businesses, transfers are the most demanding part. Saudi rules distinguish transfers to destinations with an appropriate level of protection from other transfers. Official mechanisms now include binding common rules and Saudi standard contractual clauses, supported by transfer risk-assessment guidance. The correct mechanism depends on the data flow and the conditions in the law and transfer regulation; attaching EU clauses by habit is not a Saudi transfer assessment.
The DPO requirement is also conditional rather than universal. The official rules cover public entities processing at scale, regular and systematic monitoring as a core activity and core activities involving sensitive personal data. The role may be internal or external but must be documented, supported and free from conflicting duties.
2026 priority: reconcile privacy notices, records of processing, DPO analysis, processor terms and transfer documentation with current SDAIA tools—not merely the original statutory text.
Oman’s Personal Data Protection Law was issued under Royal Decree No. 6/2022 and supplemented by Ministerial Decision No. 34/2024. The Ministry has stated that full enforcement of the Executive Regulation began in February 2026.
The operational requirements include a published privacy policy, records of processing, controls for children’s data, a designated personal data protection officer, documented security and breach procedures, and conditions for international transfers. Processing the categories specified in Article 5 of the Law requires a permit from the Ministry. Organizations should check the category against the official text rather than assume that their internal GDPR “special category” list is identical.
The Executive Regulation requires notification to the Ministry within 72 hours of awareness where a breach threatens data-subject rights. Notification to affected individuals is also required within the same period where the incident causes serious harm or high risk.
International transfers require careful review of consent, national-security restrictions, the recipient’s protection and the assessment expected under the regulation. A cloud contract alone is not the assessment.
2026 priority: move from policy drafting to evidence. Confirm permits, processing records, officer designation, breach contacts, transfer assessments and proof that notices and consent mechanisms work in the live product.
Bahrain’s Law No. 30 of 2018 Regarding Personal Data Protection is supplemented by executive decisions issued in 2022. The framework covers processing principles, individual rights, security, sensitive data, automated processing and cross-border transfers.
Bahrain retains formal notification and authorization concepts that can be missed by organizations working only from a GDPR template. For example, the law provides for prior notification of certain automated processing, subject to exemptions. Transfers may proceed to destinations on the approved list, while transfers to other destinations can require another legal route or prior authorization. Order No. 42 of 2022 addresses international transfers and the use of safeguards, including group arrangements.
2026 priority: verify whether the planned processing, sensitive-data use or transfer requires a notification or authorization before launch. Keep the decision and supporting evidence with the relevant project record.
Qatar’s national Law No. 13 of 2016 Concerning Personal Data Privacy Protection applies to electronically processed personal data and data collected in preparation for electronic processing, subject to exemptions. It establishes individual rights and controller and processor duties, addresses privacy by design, sensitive data and direct marketing, and authorizes significant fines for specified violations.
The National Cyber Security Agency and National Data Privacy Office have published practical guidance, including principles for regulated entities and guidance on processing personal data of a special nature. Organizations should use the current regulator materials alongside the statute.
The Qatar Financial Centre is separate. QFC Data Protection Regulations 2021 and the supporting Rules apply within that framework and include international-style accountability, data-subject rights, breach notification and transfer tools. QFC guidance expressly recognizes an extraterritorial element in its scope. Its Data Protection Office has also demonstrated that delayed breach notification and weak security can attract enforcement.
2026 priority: establish whether the entity and activity are under Qatar national law, QFC rules or both through different group entities. Use the correct regulator, breach process and transfer mechanism.
Kuwait does not currently have one GDPR-style data protection statute applying across the entire private sector. Data and privacy obligations arise through the Electronic Transactions Law, cybercrime rules, sector requirements and contractual or confidentiality duties.
CITRA Decision No. 26 of 2024 issued the current Data Privacy Protection Regulation and repealed the earlier Decision No. 42 of 2021 and its amendments. Its scope is tied to telecommunications and information-technology service providers licensed by CITRA. It should not be presented as a general law covering every company in Kuwait.
This distinction matters for gap assessments. A telecom licensee, cloud provider, bank, healthcare organization and ordinary retailer may face different primary instruments and regulators.
2026 priority: begin with licence and sector mapping. Do not apply CITRA obligations to an entity without first establishing scope, and do not assume that being outside CITRA scope means no privacy or security duties exist.
Egypt’s Personal Data Protection Law No. 151 of 2020 regulates electronically processed personal data. Executive Regulations No. 816 of 2025 made the framework substantially more operational, and the Personal Data Protection Center is now providing guidance and services.
The current framework includes lawful-basis requirements, transparency, data-subject rights, processor governance, security, breach handling, DPO appointment and registration, licences and permits, international transfers and electronic direct marketing. The PDPC states that juridical persons acting as data users must appoint a DPO, and its guidance describes registration and independence requirements.
The one-year statutory regularisation period following the Executive Regulations is generally calculated as ending on 1 November 2026. Because licensing, registration and platform availability can affect the practical sequence, organizations should not leave formal applications until the final weeks.
Foreign companies should not treat Egypt as a purely subsidiary-level exercise. The law and regulations can reach processing involving Egyptian citizens, including citizens outside Egypt, and non-Egyptian citizens residing in Egypt, within the scope described by the official framework.
2026 priority: complete the data inventory and local applicability analysis; appoint and prepare the DPO; identify licences and permits; map international transfers and direct marketing; and prepare a filing pack before the end of the regularisation window.
Jordan’s Personal Data Protection Law No. 24 of 2023 entered into force on 17 March 2024. The official general adjustment period ended on 16 March 2025, while newly collected data and new companies did not benefit from the same delay in the way existing processing did.
The law applies to processing personal data of citizens and residents within Jordan, according to the Ministry’s published guidance. It provides individual rights, consent and other compliance requirements, controller and processor duties, DPO appointment in specified cases, registration, security, breach reporting and controls for transfers. The Personal Data Protection Directorate and Council now perform regulatory functions, while further instructions and operational materials continue to develop.
2026 priority: treat compliance as current, not prospective. Record the lawful basis and consent position, confirm whether a DPO is mandatory, prepare register information, operationalize requests and complaints, and verify the latest transfer and licensing procedures before submission.
Israel’s framework is built around the Protection of Privacy Law, 5741-1981, the Privacy Protection Regulations (Data Security), 5777-2017, transfer regulations and sector-specific rules.
Amendment 13, effective from 14 August 2025, is the most substantial modernization of the law in decades. It broadened and updated key definitions, narrowed traditional database-registration duties while introducing notification duties for some large sensitive databases, created mandatory DPO obligations for defined categories of organizations, and materially strengthened the Privacy Protection Authority’s investigative and financial enforcement powers.
The DPO analysis requires more than copying the GDPR threshold. Public bodies and organizations whose core activities involve data trading, large-scale regular monitoring or large-scale processing of particularly sensitive information are among the categories requiring careful assessment. In July 2026 the Authority published its final position explaining the scope, competence, independence and organizational status of the DPO.
2026 priority: revisit old registration assumptions, document the Amendment 13 DPO assessment, update definitions and notices, test security-regulation compliance and ensure management understands the expanded enforcement exposure.
Türkiye’s Law No. 6698 on the Protection of Personal Data—the KVKK—covers processing principles, lawful conditions, special categories, transparency, individual rights, security, deletion and the Data Controllers’ Registry, known as VERBİS.
Amendments effective in 2024 changed the rules for special-category processing and international transfers. Article 9 now uses an adequacy, appropriate-safeguards and limited-derogations structure. Available safeguards include binding corporate rules, Board-approved undertakings and the standard contracts published by the Turkish Authority. A signed standard contract must be notified to the Authority within five business days.
Foreign-established controllers require a careful two-stage analysis. First determine whether the KVKK applies to the processing. Then determine whether VERBİS registration is required, taking current exemptions and Board criteria into account. A foreign controller that is required to register uses the representative route in the Registry. This should not be reduced to the incorrect claim that every foreign company with any Turkish user must automatically appoint a representative.
2026 priority: map foreign cloud and support access, replace legacy consent-only transfer logic, file standard contracts correctly, align the data inventory with notices and VERBİS, and document the applicability and representative assessment.
Lebanon regulates personal data principally through Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data. The law contains processing rules, rights, security concepts and notification or authorization mechanisms. The Ministry of Economy and Trade publishes information connected with personal-data processing under the law.
The framework is not equivalent to a modern independent-authority model. Official reform materials and recent public assessments continue to identify incomplete implementation, limited independent oversight and gaps in the law. Businesses should neither ignore Law No. 81 nor claim that a GDPR programme automatically satisfies it.
2026 priority: identify the declarations or authorizations relevant to the processing, apply strong baseline privacy and security controls, and obtain current local advice for sensitive, government-connected or cross-border projects.
Syria enacted Law No. 12 of 2024 concerning electronic personal data, with a stated effective date of 1 January 2025. The text covers consent, processing principles, sensitive data, rights, security, licensing, transfers and a personal data protection authority. Government communications in 2025 also imposed controls over electronic data-collection forms.
The legal and institutional environment has continued to change. Organizations should confirm the current status of the implementing instructions, authority, licensing process and any government-data or hosting restrictions with qualified Syrian counsel before relying on the original statutory architecture.
2026 priority: use the statute as a risk signal, but do not represent unverified implementing procedures as settled or operational.
These markets require a different research method. As of the date of this guide, Iraq and Iran do not have a fully operational, cross-sector data protection statute comparable to the detailed regimes described above. Privacy, confidentiality, cybersecurity, electronic-transactions, telecoms, health, banking, consumer and constitutional rules can still apply. Iraq has discussed a proposed personal data protection framework, but a proposal should not be treated as enacted law.
Yemen’s framework remains fragmented, and work toward developing a personal data protection law has been reported in 2026. The Palestinian territories require territory-, authority- and sector-specific analysis, including the interaction of local instruments and the practical control of the relevant area.
The absence of one comprehensive statute is not permission to process without limits. Contracts, sector rules, criminal law, confidentiality duties, cybersecurity requirements and foreign laws such as the GDPR may still shape the activity.
Regional programmes become manageable when teams separate the shared control from the local legal rule. A processing register, for example, can use one global data model. The fields, filing format, regulator and legal basis must then be localized.
Consent is prominent across several Middle Eastern laws, particularly for sensitive data, marketing, children or transfers. But “get consent for everything” is usually a weak compliance strategy.
Consent may be invalid when it is bundled, unclear, non-specific or not genuinely optional. It can also create operational problems when a business cannot stop processing after withdrawal because another legal obligation applies. Each purpose should be matched to the conditions available under the relevant law, with consent reserved for activities that actually require and can support it.
Health and biometric data commonly receive special protection, but regional definitions differ. Financial information, criminal records, political or religious views, children’s data and location data may be classified or controlled differently. A single global “sensitive” flag is useful for security, but the legal rules engine should support multiple local classifications.
Many failures occur because the policy team completes notices and contracts but does not identify a formal filing. Examples include Egyptian licences and DPO registration, Omani permits for specified data, Bahraini notifications or authorizations, Saudi controller-registration rules, Israeli database notifications and Turkish VERBİS obligations.
Maintain a formalities register with the legal trigger, responsible entity, filing owner, regulator, due date, renewal date and supporting evidence.
Middle Eastern companies and foreign SaaS providers depend on global cloud infrastructure, support teams and subprocessors. The transfer analysis therefore needs to follow real system architecture.
A defensible process has six parts:
Do not assume that EU Standard Contractual Clauses automatically satisfy Saudi, Turkish, Bahraini, QFC or other local mechanisms. Similar names do not make the instruments interchangeable.
Consider an EU-based B2B SaaS company with customers in Saudi Arabia, the UAE, Qatar, Türkiye and Egypt. It hosts production data in Frankfurt, uses a US analytics provider, has support staff in Europe and sells through a UAE entity.
One generic privacy notice and an EU data processing agreement will not resolve the regional position.
The efficient solution is one verified data map and security baseline, followed by local modules for legal basis, notices, transfer mechanisms, formalities and incident response.
GDPR work provides useful foundations, but it does not complete local permits, registrations, representative appointments, transfer instruments or regulator-specific notifications.
A high-level global notice may be helpful, but the identity of the controller, legal bases, rights, regulator, representative, transfer disclosures and complaint routes may need local layers.
Core principles, security duties and sector obligations may already apply. This is especially important in the federal UAE: uncertainty about implementing detail is a reason to maintain a documented readiness position, not to ignore the law.
Support, security monitoring, subprocessors and backups often create additional access countries. Architecture diagrams and vendor evidence should support the legal transfer register.
Several regimes use 72-hour rules, but triggers, recipients, calculation methods and affected-person duties vary. Other frameworks use different or less precisely specified timing. The incident plan should use a jurisdiction matrix rather than one global sentence.
A DPO or equivalent privacy officer needs independence, access, competence, resources and a workable conflict-of-interest model. Some regimes also require registration or impose specific appointment thresholds.
No. Each country has its own legal system, and the UAE and Qatar also contain special-zone regimes that may replace or sit alongside national rules for relevant entities.
No. It can provide a strong control baseline, but local laws may require different consent rules, filings, DPOs, representatives, permits, breach procedures and transfer tools.
Not as a universal rule. Many regimes allow international transfers if legal conditions and safeguards are met. Sectoral localization rules, government-data controls or permit conditions may still apply.
No. The answer depends on the law’s territorial scope and the specific representative or registration trigger. In Türkiye, for example, the representative route is tied to foreign controllers that are required to register with VERBİS; the underlying applicability and registration questions must be assessed first.
No. Oman and QFC are examples of regimes with a 72-hour rule in defined circumstances, but regional requirements are not uniform. A breach matrix should identify the regulator, deadline, risk threshold, content and individual-notification rule for each applicable regime.
An organization may centralize expertise, but it must still check local qualification, independence, accessibility, registration, location and conflict rules. A regional lead may need local support or formally separate appointments.
That is rarely the useful question. A regime with high penalties may have limited sector scope; another may impose permits or transfer approvals that create more operational friction. Risk depends on the activity, data, regulator, enforcement maturity and evidence of compliance.
The direction of travel is clear: data protection across the Middle East is becoming more formal, more operational and more closely connected with cybersecurity, digital-platform and AI governance.
The practical response is not to maintain disconnected country documents. Build a shared control environment for data mapping, security, vendor oversight, retention, requests and incident response. Add local legal modules for applicability, lawful basis, notices, sensitive data, transfers, formalities and regulator engagement. Review those modules whenever a law, implementing regulation or official guidance changes.
Kooch Cybersecurity & Compliance helps international and regional teams turn privacy requirements into workable inventories, notices, vendor controls, transfer documentation, security evidence and prioritized remediation plans. Where a matter requires a local legal opinion, filing or representation outside Kooch’s scope, we can structure the compliance work so qualified local counsel can review the right facts efficiently.
CTA: Need to understand which Middle Eastern privacy regimes apply to your product or group? Request a scoped multi-jurisdiction privacy gap assessment from Kooch.
Legal position and official-source availability checked on 28 August 2026. English translations may be unofficial; the authoritative local-language text should be used for legal interpretation.