Data Protection in Bahrain

Data protection officers in Bahrain

Data controllers may voluntarily appoint a data protection officer, however all licensed financial institutions are required to appoint a data protection officer. 

The data controller may appoint an external or internal data protection officer. 
The conditions for registering an internal data protection officer: 

  • The individual must be an employee of the data controller or of one of its subsidiaries or branches or be part of a regional or international group under the same ownership.
  • The individual must have permanent residency in Bahrain.

The conditions for registering an external data protection officer: 

For Natural Persons

  • Must be fully legally competent.
  • Must hold at least a Bachelor’s degree in Information Technology or possess a professional certification in information security, information security audit or cybersecurity. Alternatively, must have a minimum of two years of practical experience in any of the foregoing fields.
  • Must be of good standing and must not have been finally convicted of any offence involving breach of trust, honour or integrity, nor of any crime involving breach of professional ethics, unless reinstated.
  • Must not have been dismissed from employment pursuant to a disciplinary decision, nor had their professional license revoked or suspended under a disciplinary ruling.

For Legal Persons 

  • Must be licensed to operate in Bahrain.
  • Must be engaged in providing legal, audit, information technology, management consulting, accounting or risk management services.
  • Must employ at least three individuals who meet the eligibility requirements applicable to natural persons.
  • Must satisfy any additional conditions set by the Board of Directors.

A data protection officer must help the data controller in exercising its rights and fulfilling its obligations prescribed under the PDPL. The data protection officer also has a number of other roles, including liaising with the Authority, verifying that personal data is processed in accordance with the PDPL, notifying the Authority of any violations of the PDPL that the data protection officer becomes aware of and maintaining a register of processing operations that the data controller must notify the Authority about.

Continue reading

  • no results

Previous topic
Back to top