Qatar’s data privacy law, the Personal Data Privacy Protection Law (Law No. 13 of 2016), directly shapes how you are allowed to market, and the core rule is simple: you need a person’s explicit, opt-in consent before sending them direct marketing. That means no pre-ticked boxes and no assuming consent because someone bought from you; they have to actively agree, be clearly told what they are agreeing to, and be able to withdraw at any time. Every marketing message must identify you, state plainly that it is marketing, and offer a working way to opt out, and you must keep a record of how and when each consent was obtained. With fines that can reach one million riyals, treating consent as a genuine, documented opt-in is not just compliant, it is cheaper than the alternative. This is a practical overview rather than legal advice, so check the law itself and a qualified adviser for your specifics.

Most marketing teams here collect and use customer data in ways that predate the rules they now have to follow, and privacy is the kind of thing nobody thinks about until it becomes expensive. Qatar’s law is clearer than many assume, so let me translate the parts that actually affect your day-to-day marketing into plain language.

What the law covers

The Personal Data Privacy Protection Law of 2016 is Qatar’s main data protection statute, and it governs how personal data that is processed electronically is collected, stored, used and shared, including for marketing. It is overseen by the National Cyber Security Agency, and it gives individuals real rights over their data, including the right to be informed, to access it, and to withdraw consent. If your marketing touches customer names, emails, phone numbers or behaviour, and almost all marketing does, you are handling personal data that this law protects. Understanding that framing is the starting point for everything else.

Network of connected nodes around a central hub – Qatar's Data Privacy Law and Your Marketing

The consent rule that changes your marketing

The single rule that reshapes most marketing here is that direct marketing requires explicit, prior consent. It has to be a positive, active opt-in, freely given by someone who has been clearly told what they are agreeing to, and it cannot be inferred from silence, a pre-ticked box, or the fact that they once made a purchase. The table below is the quickest way to see where common practices fall.

PracticeCompliant?Why
Pre-ticked opt-in boxNoConsent must be a positive, active opt-in
Assuming consent from a purchaseNoConsent must be explicit and specific to marketing
A clear, unticked opt-in with a noticeYesExplicit, informed and unambiguous
No opt-out link in your emailsNoA valid way to opt out is required in every message
Logging how and when consent was givenYesControllers must keep a record of consent

What every marketing message must include

When you use electronic channels for direct marketing, each message has to carry a few specific things. It must clearly identify you as the sender, with your identity and contact details, so the recipient knows exactly who is contacting them. It must make plain that the communication is marketing, rather than disguising a promotion as something else. And it must give a valid, working way to opt out or revoke consent, so leaving off the unsubscribe link is not a minor oversight but a breach. These requirements apply across electronic marketing, so treat email, SMS and other channels to the same standard.

Consent records and the right to withdraw

Two obligations tend to catch marketers out. The first is record-keeping: you are expected to keep a record of how and when each person’s consent was obtained, which means your opt-in process has to capture and store that, not just collect the address. The second is that withdrawing consent must be as straightforward as giving it, and you have to honour a withdrawal promptly. Both of these happen to align with good marketing anyway, because a list of people who genuinely chose to hear from you, and can easily leave, outperforms a larger list that never opted in.

The penalties, and why compliance is cheaper

The law has teeth. Organisations that breach it can face fines reaching up to one million riyals, alongside potential criminal liability for the individuals responsible, and that is before you count the reputational damage of being known for mishandling customer data. Set against that, the cost of doing consent properly is small: cleaner forms, a working unsubscribe, and a record of permissions. And because permission-based marketing simply performs better than blasting people who never asked to hear from you, compliance and results point in the same direction rather than pulling against each other.

The smallest first step

Start by auditing where your marketing data actually came from and whether you have genuine, recorded consent for it, because that one exercise usually reveals most of your exposure. Then fix the basics: turn your opt-in into a clear, unticked, informed choice, add a proper opt-out to every marketing message, and begin logging how and when consent is given. That clean-up is the smallest first step that produces the biggest result, because it removes the bulk of the risk while quietly improving the quality of your marketing list.

Frequently asked questions

Do I need consent to email my existing customers?

For direct marketing, yes, you need explicit opt-in consent, and a past purchase on its own does not count as consent to market to them. The safe approach is to ask existing customers to actively opt in and to record when they do. This is a practical summary rather than legal advice, so confirm your specific situation with a qualified adviser.

Are pre-ticked opt-in boxes allowed?

No, consent has to be a positive, active opt-in that the person deliberately gives, so a box that is already ticked does not meet the standard. The same applies to burying consent in terms and conditions. Use a clear, unticked opt-in with a short notice explaining what they are agreeing to.

What must a marketing email or SMS include?

It must identify you as the sender with contact details, make clear that it is a marketing message, and provide a valid, working way to opt out or withdraw consent. Missing any of these, particularly the opt-out, puts the message offside. Apply the same standard across every electronic channel you use.

What are the penalties for getting it wrong?

Organisations can be fined up to one million riyals, with possible criminal liability for the responsible individuals on top of that. Beyond the fine, there is the reputational cost of being seen to misuse customer data. Given how modest proper compliance is, the risk is rarely worth taking.

Does this apply to WhatsApp and SMS marketing too?

The requirements for consent and opt-out apply to electronic direct marketing generally, so it is safest to treat WhatsApp, SMS and email to the same standard rather than assuming one channel is exempt. Get explicit consent, identify yourself, and offer a way out. Consistency across channels is both simpler to manage and safer.

Performance gauge dial with glowing indicator – Qatar's Data Privacy Law and Your Marketing

Make consent your default, not your afterthought

Qatar’s privacy law rewards the same thing good marketing does: a genuine, permission-based relationship with people who chose to hear from you. It touches how you track and measure, so sensible marketing attribution and clean data capture in your conversion process both need to be built on real consent. Getting this right is part of running marketing properly, which sits across my services and is exactly the kind of standard a fractional CMO is there to hold. Book a free 30-minute call through the contact page and we will review your marketing against the basics, though for legal certainty you should also consult a qualified adviser.

Book a Call
HomeAboutServicesPortfolioTestimonialsInsightsContactBook a Call

Want results like these? Let’s talk.

Every case study starts with a free 30-minute conversation.

Book a Free Call →

See the case studies

Book a Free Call