Gulf breach-notification clocks: six countries, one table
The short version: if you operate across the Gulf, plan for the shortest clock you are subject to. Four regimes set a 72-hour clock to the regulator (Saudi Arabia, ADGM, Oman and Bahrain), and Qatar’s regulator expects 72 hours in guidance. Kuwait’s is the shortest, 24 hours to CITRA, but it covers only CITRA-licensed telecom and ICT providers. The UAE federal law and the DIFC set no hour count at all.
Where a law gives no fixed, verified figure, the table says Not fixed / see source rather than guessing. Each row links to the official source it was checked against and the date of that check.
| Jurisdiction | Law | Regulator | Clock to regulator | Clock to data subjects | Source | Verified on |
|---|---|---|---|---|---|---|
| Saudi Arabia PDPL | Personal Data Protection Law (Royal Decree M/19, amended by M/148), Art. 20; Implementing Regulation Art. 24 | Saudi Data & AI Authority (SDAIA) | 72 hours from becoming aware | Not fixed / see source Without undue delay (no hour count) | SDAIA: laws and regulations (official English translation) | Sep 23, 2026 Official text (SDAIA's English translation; Arabic is binding) |
| UAE Onshore (federal PDPL) | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, Art. 9 | UAE Data Office (a new AI and Data Authority was announced in June 2026; how it will supervise the PDPL is unpublished) | Not fixed / see source On becoming aware, within a period the Executive Regulations will set. They have not been issued, so there is no statutory hour count yet | Not fixed / see source Within the period the (unissued) Executive Regulations will set | UAE Legislation: Federal Decree-Law 45 of 2021 | Sep 23, 2026 Official English translation (Arabic is authoritative) |
| UAE DIFC | DIFC Data Protection Law, DIFC Law No. 5 of 2020 (consolidated July 2025), Arts. 41 and 42 | DIFC Commissioner of Data Protection | Not fixed / see source As soon as practicable in the circumstances (no hour count) | Not fixed / see source As soon as practicable; promptly where there is an immediate risk of damage | DIFC: Data Protection Law (consolidated, July 2025) | Sep 23, 2026 Official consolidated text |
| UAE ADGM | ADGM Data Protection Regulations 2021, s.32 | ADGM Office of Data Protection (Commissioner of Data Protection) | 72 hours from becoming aware Without undue delay and, where feasible, within 72 hours | Not fixed / see source Without undue delay where the risk is high (no hour count) | ADGM: Personal data breach notifications | Sep 23, 2026 ADGM's official web page (the rulebook itself could not be read by our tools) |
| Kuwait CITRA DPPR (licensed providers only) | Data Privacy Protection Regulation, issued by CITRA Decision No. 26 of 2024, Art. 6 (and Art. 4(15)). Kuwait has no general data protection law | Communication and Information Technology Regulatory Authority (CITRA) | 24 hours from becoming aware Within no more than 24 hours, through CITRA's official channels | Not fixed / see source Required, but Art. 6 sets no deadline. Not needed where appropriate technical and organisational measures (e.g. encryption) were applied to the affected data 72 hours in one case: improper disclosure that harms a large number of users: users, CITRA and law enforcement as soon as possible and within 72 hours at most (Art. 4(15)) | CITRA: Data Privacy Protection Regulation (Arabic PDF) | Sep 30, 2026 Official Arabic text (CITRA PDF, read from the scan; English translation ours) |
| Oman PDPL | Personal Data Protection Law (Royal Decree 6/2022), Art. 19; Executive Regulation (Ministerial Decision 34/2024), Arts. 30 and 32 | Ministry of Transport, Communications and Information Technology (MTCIT) | 72 hours from becoming aware | 72 hours Within 72 hours where the breach causes serious harm or high risk | MTCIT: Executive Regulation of the PDPL | Sep 23, 2026 Arabic gazette texts (via qanoon.om) |
| Qatar PDPPL | Law No. 13 of 2016 on Protecting Personal Data Privacy, Art. 14; NCSA guideline PDPPL-02050217E | National Cyber Security Agency (NCSA) | 72 hours from becoming aware Within 72 hours under NCSA's guideline (the Law itself sets no time limit) | 72 hours from becoming aware Within 72 hours under the same guideline (the Law sets no time limit) | NCSA: Personal Data Breach Notifications guideline | Sep 29, 2026 Official NCSA domain (search-result text of the guideline) |
| Bahrain PDPL | Law No. 30 of 2018 (Personal Data Protection Law); Order No. 43 of 2022, Art. 4. The Law itself has no breach clause | Personal Data Protection Authority (its functions are carried out by the Ministry of Justice, Islamic Affairs and Waqf) | 72 hours from discovery | Not fixed / see source Required, but no deadline is stated | PDPA Bahrain: Order No. 43 of 2022 | Sep 23, 2026 Official English translation (Arabic prevails); reconfirmed 2026-09-28 |
Working an incident? The breach-notification clock turns your discovery time into dates and times for each jurisdiction.
Conditions and traps, by jurisdiction
- Saudi Arabia (PDPL): Only where the incident may cause harm to the data or data subjects, or conflicts with their rights or interests. Late information must be sent as soon as possible, with reasons. NCA and SAMA duties apply on top where relevant.
- UAE (Onshore (federal PDPL)): Breaches that would prejudice the privacy, confidentiality or security of personal data. Processors tell the controller immediately. Health, banking and credit data, government and free zones with their own law are outside this law; sector regulators (CBUAE and others) have their own clocks.
- UAE (DIFC): Where a breach compromises a data subject's confidentiality, security or privacy. Processors tell the controller without undue delay. There is no 72-hour rule in the DIFC Law; DFSA-regulated firms have a separate 72-hour cyber-incident rule (GEN 5.5.19).
- UAE (ADGM): Not required where the breach is unlikely to create a risk. Late notices must give reasons. File through the ADGM Online Registry Solution.
- Kuwait (CITRA DPPR (licensed providers only)): Applies only to CITRA-licensed service providers (telecom and ICT), not every organisation in Kuwait; other organisations have no statutory breach-notification duty. The notice to CITRA must give the nature and extent of the breach, the people affected, the DPO's contact details, likely consequences and the measures taken. Some law-firm guides say 24 hours to users as well; the Arabic text does not. An older draft (v2.0) said 72 hours to CITRA; that is not the current rule.
- Oman (PDPL): To MTCIT where the breach could endanger data subjects' rights; use MTCIT's breach report form. MTCIT may direct how and when data subjects are told (ER Art. 31). Royal Decree 68/2026 amended the Law from 7 September 2026; our sources do not list Art. 19 as changed, and no Executive Regulation update had been found.
- Qatar (PDPPL): Where the breach may cause serious damage to the data or the individual's privacy. Processors tell the controller forthwith. Qatar Financial Centre entities are outside the PDPPL and follow the QFC's own rules.
- Bahrain (PDPL): Not required where the breach does not affect data subjects' rights. Late notices must give reasons. Data subjects need not be told if the data was unintelligible (e.g. encrypted) or later measures removed the high risk; where telling them would take disproportionate effort, a public communication is used instead. CBB licensees have separate, shorter reporting clocks.
How to use this
- Work out which regimes apply first. A group with a Riyadh office, a DIFC entity and Qatar customers can be on three different clocks for one incident.
- Run your plan from the earliest point. Most of these clocks start when you become aware of the breach; Bahrain’s says discovery. Log that moment in your incident record.
- Check sector rules as well. Central-bank, capital-markets and national cyber-security regulators in each country have their own reporting duties, often shorter than the data protection clock.
- Confirm against the source before you rely on it. Several Gulf laws changed in 2025 and 2026, and the Arabic text is the binding one.
Not legal advice. This table is a research aid summarising the laws and regulator guidance listed above as checked on the dates shown. Laws change; confirm the current official text, and take local legal advice before making a notification decision.