IT business legal support in Qatar
Qatar runs two sets of privacy rules at once. We tell you which one your company falls under, what it demands of the product, and what the money you send abroad is taxed at.
State law ceiling
Потолок по закону
QAR 5,000,000
5 000 000 QAR
In the centre
В финцентре
USD 1.5m per breach
1,5 млн USD за норму
Breach clock there
Часы на утечку там
72 hours
72 часа
Paid abroad
Платёж нерезиденту
5% at source
5% у источника
When an IT business in Qatar needs legal support

The address decides the rules
A company on the mainland and a company inside the Qatar Financial Centre live by different privacy rules. That choice is made before the first user ever signs up.
Your users sit outside Qatar
The state law treats cross-border flow as access and storage without regard to borders, and it stops the controller from limiting that flow on its own initiative.
A breach is found on Friday
Inside the financial centre the clock runs seventy-two hours from the moment you knew. Outside it, the duty is to inform, and the hour count comes from your own policy.
You send marketing to users
Electronic marketing needs consent in advance, has to name who sent it and has to carry a working address where a person can ask you to stop.
The product touches health data
Health, beliefs, marital relations, criminal offences and children's data are of a special nature: processing them waits for permission from the competent department.
You pay developers abroad
Royalties and fees for services performed in the State, paid to a non-resident with no permanent establishment here, are taxed at source when the invoice is settled.
What legal support for an IT business in Qatar covers

Most countries give a software company one privacy law to read. Qatar gives it two, and which one applies is decided by where the company is registered rather than by what the product does.
That makes the address a product decision as much as a corporate one. It sets the wording of your consent, the speed of your incident response and the size of the number at the bottom of an enforcement notice.
Other work we take on in Qatar is gathered on the Qatar page. This service in its general, country-free form lives on the service page.
The plain version for an engineering team: two entities of one group can look identical from the outside and still answer to different regulators under different ceilings.
What you get
- A written answer on which privacy regime you are in
- Consent and notice texts that match that regime
- An incident routine with the right clock inside it
- Marketing wording that survives a complaint
- Cross-border payments quoted with the tax included
Two regimes, one country
On the mainland
The state privacy law of 2016 applies. Special-category data waits for permission from the competent department; a breach is reported to that department and to the person; fines reach one million riyals, and five million for the security, special-data and children's provisions.
Inside the financial centre
The Qatar Financial Centre (QFC) runs its own data protection regulations with its own office. A breach goes to that office within seventy-two hours, and the ceiling is a million and a half dollars for each provision infringed.
What both of them ask
Both want a lawful purpose written down before collection, a description of the processing given to the person, security measured against the data, and a record that shows what you actually did.
What leaves the country as money
Profits are taxed at ten per cent under the income tax law. Separately, royalties, commissions and consideration for services carried out wholly or partly in the State, paid to non-residents outside a permanent establishment, carry a five per cent final deduction at source.
For a software business those two lines usually meet in the same contract: a foreign development team invoicing work done for Qatari users, and a licence fee going the other way.
Sources: Law No. 13 of 2016 on protecting personal data privacy, the QFC data protection regulations and Law No. 24 of 2018 on income tax.
Stages of work
Placing the company in a regime
The first question is not what the product collects but where the entity is registered, because that decides which rulebook, which regulator and which ceiling you are working against.
Writing the purpose down before collection
Both regimes start from a lawful purpose fixed in advance. We write it in the words the product actually works by, so the notice to users matches the database behind it.
Building the incident routine
Who decides that an incident is a breach, who writes the notification, what goes in it and which clock is running are settled while nothing is on fire.
Clearing the marketing channel
Consent capture, sender identity and a working unsubscribe route are checked against the electronic marketing rules, and the record of consent is kept where support can find it.
Reading the cross-border invoices
Development, licence and service agreements are read for the five per cent deduction and for who bears it, before the first invoice rather than after the tax return. A gross-up clause written late costs more than the tax it was meant to cover.
Cover that moves with new markets
New markets and new processors change the answers. Your team sends the change, the updated position comes back written and dated, and the incident routine is adjusted at the same time so the two never drift apart.
Our case studies
FAQ
It follows the registration. A company on the mainland is under the 2016 state law on protecting personal data privacy, supervised by the competent department at the ministry. A company licensed in the financial centre is under that centre's own data protection regulations and its own data protection office. The two overlap in principle and differ in detail, so a group with entities in both places ends up writing two sets of privacy documents rather than one.
Inside the financial centre the regulations name the deadline: notification to the data protection office without undue delay and, where feasible, no later than seventy-two hours after you became aware of it. The state law sets the duty rather than the hour: the controller informs the person and the competent department where the breach may seriously damage the data or the individual's privacy. In practice both regimes need the same thing prepared in advance.
Yes, under the state law. Sending an electronic communication to a person for direct marketing is forbidden without their prior consent. The message itself has to identify who sent it, state plainly that it is marketing, and carry a valid address through which the person can ask for the sending to stop or withdraw the consent they gave. Those three elements are worth building into the template rather than adding after a complaint.
Five per cent of the gross amount, as a final deduction at source. The income tax law applies it to royalties, benefits, commissions and consideration for services rendered wholly or partly in the State when they are paid to non-residents for activity not connected with a permanent establishment here, subject to any tax agreement. Company profits themselves are taxed at ten per cent, so a software business meets both numbers in the same year.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
