IT business legal support in Qatar

Qatar runs two sets of privacy rules at once. We tell you which one your company falls under, what it demands of the product, and what the money you send abroad is taxed at.

 

State law ceiling

Потолок по закону

QAR 5,000,000

5 000 000 QAR

In the centre

В финцентре

USD 1.5m per breach

1,5 млн USD за норму

Breach clock there

Часы на утечку там

72 hours

72 часа

Paid abroad

Платёж нерезиденту

5% at source

5% у источника

When an IT business in Qatar needs legal support

The address decides the rules

A company on the mainland and a company inside the Qatar Financial Centre live by different privacy rules. That choice is made before the first user ever signs up.

Your users sit outside Qatar

The state law treats cross-border flow as access and storage without regard to borders, and it stops the controller from limiting that flow on its own initiative.

A breach is found on Friday

Inside the financial centre the clock runs seventy-two hours from the moment you knew. Outside it, the duty is to inform, and the hour count comes from your own policy.

You send marketing to users

Electronic marketing needs consent in advance, has to name who sent it and has to carry a working address where a person can ask you to stop.

The product touches health data

Health, beliefs, marital relations, criminal offences and children's data are of a special nature: processing them waits for permission from the competent department.

You pay developers abroad

Royalties and fees for services performed in the State, paid to a non-resident with no permanent establishment here, are taxed at source when the invoice is settled.

What legal support for an IT business in Qatar covers

Most countries give a software company one privacy law to read. Qatar gives it two, and which one applies is decided by where the company is registered rather than by what the product does.

That makes the address a product decision as much as a corporate one. It sets the wording of your consent, the speed of your incident response and the size of the number at the bottom of an enforcement notice.

Other work we take on in Qatar is gathered on the Qatar page. This service in its general, country-free form lives on the service page.

The plain version for an engineering team: two entities of one group can look identical from the outside and still answer to different regulators under different ceilings.

What you get

  • A written answer on which privacy regime you are in
  • Consent and notice texts that match that regime
  • An incident routine with the right clock inside it
  • Marketing wording that survives a complaint
  • Cross-border payments quoted with the tax included

Two regimes, one country

On the mainland

The state privacy law of 2016 applies. Special-category data waits for permission from the competent department; a breach is reported to that department and to the person; fines reach one million riyals, and five million for the security, special-data and children's provisions.

Inside the financial centre

The Qatar Financial Centre (QFC) runs its own data protection regulations with its own office. A breach goes to that office within seventy-two hours, and the ceiling is a million and a half dollars for each provision infringed.

What both of them ask

Both want a lawful purpose written down before collection, a description of the processing given to the person, security measured against the data, and a record that shows what you actually did.

What leaves the country as money

Profits are taxed at ten per cent under the income tax law. Separately, royalties, commissions and consideration for services carried out wholly or partly in the State, paid to non-residents outside a permanent establishment, carry a five per cent final deduction at source.

For a software business those two lines usually meet in the same contract: a foreign development team invoicing work done for Qatari users, and a licence fee going the other way.

Sources: Law No. 13 of 2016 on protecting personal data privacy, the QFC data protection regulations and Law No. 24 of 2018 on income tax.

Stages of work

Placing the company in a regime

The first question is not what the product collects but where the entity is registered, because that decides which rulebook, which regulator and which ceiling you are working against.

Writing the purpose down before collection

Both regimes start from a lawful purpose fixed in advance. We write it in the words the product actually works by, so the notice to users matches the database behind it.

Building the incident routine

Who decides that an incident is a breach, who writes the notification, what goes in it and which clock is running are settled while nothing is on fire.

Clearing the marketing channel

Consent capture, sender identity and a working unsubscribe route are checked against the electronic marketing rules, and the record of consent is kept where support can find it.

Reading the cross-border invoices

Development, licence and service agreements are read for the five per cent deduction and for who bears it, before the first invoice rather than after the tax return. A gross-up clause written late costs more than the tax it was meant to cover.

Cover that moves with new markets

New markets and new processors change the answers. Your team sends the change, the updated position comes back written and dated, and the incident routine is adjusted at the same time so the two never drift apart.

Our case studies

No items found.

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward

FAQ

Which privacy law applies to our Qatari company?
add
remove
How fast must we report a data breach?
add
remove
Do we need consent for marketing emails?
add
remove
What is withheld on payments to non-residents?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.