Bahrain · Privacy & Technology

Personal data:
flow map to privacy notice

First, we define people, data, goals, systems, vendors and countries - then we select a lawful basis, contracts, transfer route and security controls.

Controllergoals and means
Processorprocessing on behalf of
Guardianregistered function
Transferlegal route

01

What is considered personal data

The law covers information in any form about an identified or identifiable individual. Processing includes collection, recording, organizing, storing, modifying, retrieving, using, disclosing, transmitting, combining, blocking, deleting, and destroying.

Customers
KYC, payments, communications and behavior
Employees
HR, payroll, health and performance
Website
Forms, cookies, devices and analytics
Vendors
Contacts, due diligence and access logs
CCTV / biometrics
Identification and sensitive context
AI profiling
Input, output, inference and decisions

02

Controller and processor are determined by facts

Controller decides why and how data is processed; processor acts on its behalf. One vendor can be a processor for hosting and an independent controller for its own compliance obligations. The contractual name does not replace functional analysis.

Vendor contract

Instructions, confidentiality, security, subprocessors, location, assistance, incidents, return/deletion and audit rights are recorded.

03

Lawful basis for each goal

Consent is only one of the reasons. For each operation, purpose, data set, subject, basis, retention and recipient are recorded separately. The new target should not automatically inherit the old consent.

Contract
Necessary processing for the contract
Legal obligation
KYC, employment, tax or regulation
Legitimate interests
After necessity and balancing test
Consent
Informed, specific and manageable
Vital / public grounds
Only within the limits of the law
Marketing
Separate notice and objection

04

Sensitive data requires enhanced analysis

This is information about race, ethnic origin, political/philosophical opinions, religious beliefs, union affiliation, criminal record, health or sexual status. Special reason or permission, minimization, access and encryption are checked.

05

Rights turn into workflow

Notice

Controller, purposes, basis, recipients and rights.

Access

Identity check, systems search and redactions.

Correction

Correction of source and downstream copies.

Objection / deletion

Basis, retention and exceptions.

06

Privacy by design and technical measures

Executive order specifies privacy by design, access control, passwords, antivirus/firewalls, retention and disposal, backups, VAPT, continuity plan and delimitation of powers. The choice of measures depends on scope, context, purpose and risk.

Inventory
Systems, fields, owners and locations
Access
Least privilege, MFA and review
Lifecycle
Retention schedule and deletion
Testing
Vulnerability assessment and penetration test
Resilience
Backup, recovery and continuity
DPIA
High-risk processing before launch

07

Transfer outside Bahrain

Order 42/2022 allows direct transfer to listed adequate countries without prior authorization. For another country, the statutory route is analyzed; case-by-case authorization may be required. An intra-group transfer to a non-listed country may be subject to Binding Corporate Rules.

  1. 01
    Map

    Exporter, recipient, country, data and purpose.

  2. 02
    Adequacy

    Check the current official list.

  3. 03
    Route

    Authorization, exemption or BCR.

  4. 04
    Contract

    Security, onward transfer and deletion.

  5. 05
    Record

    Decision, evidence and review.

08

Data Protection Guardian

In established cases, the controller assigns an internal or external Guardian and notifies the Authority. Guardian must be included in the register, maintain independence and confidentiality, monitor compliance and interact with the Authority.

09

Incident response before leak

Detect
Channels SOC, staff and vendors
Contain
Accounts, keys, systems and evidence
Assess
Data, persons, consequences and jurisdiction
Escalate
Legal, security, management and regulator
Notify
Authority/individuals as applicable
Remediate
Root cause, controls and record

10

Privacy programme

  1. 01

    Create a data inventory and processing record.

  2. 02

    Assign role, purpose, basis and retention.

  3. 03

    Check notices, consent and rights workflow.

  4. 04

    Conduct vendor, security and transfer reviews.

  5. 05

    Define Guardian, DPIA and authorization.

Official base

PDPL and executive orders

01

PDPL — Law 30/2018

Official English text of Personal Data Protection Law.

Open source
02

Order 42/2022 — Transfers

Adequate countries, prior authorization and Binding Corporate Rules.

Open source
03

Technical and Organisational Measures

Privacy by design, security, VAPT, continuity and DPIA.

Open source
04

Data Protection Guardian Order

Purpose, register, qualification and responsibilities of Guardian.

Open source
05

Decree 78/2019

Powers of the Personal Data Protection Authority.

Open source

Privacy programme

We will build processing and international transmissions

Data map, notices, contracts, DPIA, Guardian, transfer and incident response.

Discuss data
WAWhatsAppTGTelegram