Compliance Colleague · Guides

Gulf breach-notification clocks: six countries, one table

By Edward Casteloes, founder of Compliance Colleague · 15 years in GRC · Updated Sep 30, 2026

The short version: if you operate across the Gulf, plan for the shortest clock you are subject to. Four regimes set a 72-hour clock to the regulator (Saudi Arabia, ADGM, Oman and Bahrain), and Qatar’s regulator expects 72 hours in guidance. Kuwait’s is the shortest, 24 hours to CITRA, but it covers only CITRA-licensed telecom and ICT providers. The UAE federal law and the DIFC set no hour count at all.

Where a law gives no fixed, verified figure, the table says Not fixed / see source rather than guessing. Each row links to the official source it was checked against and the date of that check.

JurisdictionLawRegulatorClock to regulatorClock to data subjectsSourceVerified on
Saudi Arabia
PDPL
Personal Data Protection Law (Royal Decree M/19, amended by M/148), Art. 20; Implementing Regulation Art. 24Saudi Data & AI Authority (SDAIA)72 hours from becoming awareNot fixed / see source
Without undue delay (no hour count)
SDAIA: laws and regulations (official English translation)Sep 23, 2026
Official text (SDAIA's English translation; Arabic is binding)
UAE
Onshore (federal PDPL)
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, Art. 9UAE Data Office (a new AI and Data Authority was announced in June 2026; how it will supervise the PDPL is unpublished)Not fixed / see source
On becoming aware, within a period the Executive Regulations will set. They have not been issued, so there is no statutory hour count yet
Not fixed / see source
Within the period the (unissued) Executive Regulations will set
UAE Legislation: Federal Decree-Law 45 of 2021Sep 23, 2026
Official English translation (Arabic is authoritative)
UAE
DIFC
DIFC Data Protection Law, DIFC Law No. 5 of 2020 (consolidated July 2025), Arts. 41 and 42DIFC Commissioner of Data ProtectionNot fixed / see source
As soon as practicable in the circumstances (no hour count)
Not fixed / see source
As soon as practicable; promptly where there is an immediate risk of damage
DIFC: Data Protection Law (consolidated, July 2025)Sep 23, 2026
Official consolidated text
UAE
ADGM
ADGM Data Protection Regulations 2021, s.32ADGM Office of Data Protection (Commissioner of Data Protection)72 hours from becoming aware
Without undue delay and, where feasible, within 72 hours
Not fixed / see source
Without undue delay where the risk is high (no hour count)
ADGM: Personal data breach notificationsSep 23, 2026
ADGM's official web page (the rulebook itself could not be read by our tools)
Kuwait
CITRA DPPR (licensed providers only)
Data Privacy Protection Regulation, issued by CITRA Decision No. 26 of 2024, Art. 6 (and Art. 4(15)). Kuwait has no general data protection lawCommunication and Information Technology Regulatory Authority (CITRA)24 hours from becoming aware
Within no more than 24 hours, through CITRA's official channels
Not fixed / see source
Required, but Art. 6 sets no deadline. Not needed where appropriate technical and organisational measures (e.g. encryption) were applied to the affected data
72 hours in one case: improper disclosure that harms a large number of users: users, CITRA and law enforcement as soon as possible and within 72 hours at most (Art. 4(15))
CITRA: Data Privacy Protection Regulation (Arabic PDF)Sep 30, 2026
Official Arabic text (CITRA PDF, read from the scan; English translation ours)
Oman
PDPL
Personal Data Protection Law (Royal Decree 6/2022), Art. 19; Executive Regulation (Ministerial Decision 34/2024), Arts. 30 and 32Ministry of Transport, Communications and Information Technology (MTCIT)72 hours from becoming aware72 hours
Within 72 hours where the breach causes serious harm or high risk
MTCIT: Executive Regulation of the PDPLSep 23, 2026
Arabic gazette texts (via qanoon.om)
Qatar
PDPPL
Law No. 13 of 2016 on Protecting Personal Data Privacy, Art. 14; NCSA guideline PDPPL-02050217ENational Cyber Security Agency (NCSA)72 hours from becoming aware
Within 72 hours under NCSA's guideline (the Law itself sets no time limit)
72 hours from becoming aware
Within 72 hours under the same guideline (the Law sets no time limit)
NCSA: Personal Data Breach Notifications guidelineSep 29, 2026
Official NCSA domain (search-result text of the guideline)
Bahrain
PDPL
Law No. 30 of 2018 (Personal Data Protection Law); Order No. 43 of 2022, Art. 4. The Law itself has no breach clausePersonal Data Protection Authority (its functions are carried out by the Ministry of Justice, Islamic Affairs and Waqf)72 hours from discoveryNot fixed / see source
Required, but no deadline is stated
PDPA Bahrain: Order No. 43 of 2022Sep 23, 2026
Official English translation (Arabic prevails); reconfirmed 2026-09-28

Working an incident? The breach-notification clock turns your discovery time into dates and times for each jurisdiction.

Conditions and traps, by jurisdiction

How to use this

  1. Work out which regimes apply first. A group with a Riyadh office, a DIFC entity and Qatar customers can be on three different clocks for one incident.
  2. Run your plan from the earliest point. Most of these clocks start when you become aware of the breach; Bahrain’s says discovery. Log that moment in your incident record.
  3. Check sector rules as well. Central-bank, capital-markets and national cyber-security regulators in each country have their own reporting duties, often shorter than the data protection clock.
  4. Confirm against the source before you rely on it. Several Gulf laws changed in 2025 and 2026, and the Arabic text is the binding one.
Compliance Colleague answers questions like “We had a breach affecting customers in Oman and the ADGM. Who do we notify, and by when?” with the article cited, across 30+ security, privacy and AI governance standards. Try it free, no card required →

Not legal advice. This table is a research aid summarising the laws and regulator guidance listed above as checked on the dates shown. Laws change; confirm the current official text, and take local legal advice before making a notification decision.