01
What is considered personal data
The law covers information in any form about an identified or identifiable individual. Processing includes collection, recording, organizing, storing, modifying, retrieving, using, disclosing, transmitting, combining, blocking, deleting, and destroying.
- Customers
- KYC, payments, communications and behavior
- Employees
- HR, payroll, health and performance
- Website
- Forms, cookies, devices and analytics
- Vendors
- Contacts, due diligence and access logs
- CCTV / biometrics
- Identification and sensitive context
- AI profiling
- Input, output, inference and decisions
02
Controller and processor are determined by facts
Controller decides why and how data is processed; processor acts on its behalf. One vendor can be a processor for hosting and an independent controller for its own compliance obligations. The contractual name does not replace functional analysis.
Instructions, confidentiality, security, subprocessors, location, assistance, incidents, return/deletion and audit rights are recorded.
03
Lawful basis for each goal
Consent is only one of the reasons. For each operation, purpose, data set, subject, basis, retention and recipient are recorded separately. The new target should not automatically inherit the old consent.
- Contract
- Necessary processing for the contract
- Legal obligation
- KYC, employment, tax or regulation
- Legitimate interests
- After necessity and balancing test
- Consent
- Informed, specific and manageable
- Vital / public grounds
- Only within the limits of the law
- Marketing
- Separate notice and objection
04
Sensitive data requires enhanced analysis
This is information about race, ethnic origin, political/philosophical opinions, religious beliefs, union affiliation, criminal record, health or sexual status. Special reason or permission, minimization, access and encryption are checked.
05
Rights turn into workflow
Controller, purposes, basis, recipients and rights.
Identity check, systems search and redactions.
Correction of source and downstream copies.
Basis, retention and exceptions.
06
Privacy by design and technical measures
Executive order specifies privacy by design, access control, passwords, antivirus/firewalls, retention and disposal, backups, VAPT, continuity plan and delimitation of powers. The choice of measures depends on scope, context, purpose and risk.
- Inventory
- Systems, fields, owners and locations
- Access
- Least privilege, MFA and review
- Lifecycle
- Retention schedule and deletion
- Testing
- Vulnerability assessment and penetration test
- Resilience
- Backup, recovery and continuity
- DPIA
- High-risk processing before launch
07
Transfer outside Bahrain
Order 42/2022 allows direct transfer to listed adequate countries without prior authorization. For another country, the statutory route is analyzed; case-by-case authorization may be required. An intra-group transfer to a non-listed country may be subject to Binding Corporate Rules.
- 01Map
Exporter, recipient, country, data and purpose.
- 02Adequacy
Check the current official list.
- 03Route
Authorization, exemption or BCR.
- 04Contract
Security, onward transfer and deletion.
- 05Record
Decision, evidence and review.
08
Data Protection Guardian
In established cases, the controller assigns an internal or external Guardian and notifies the Authority. Guardian must be included in the register, maintain independence and confidentiality, monitor compliance and interact with the Authority.
09
Incident response before leak
- Detect
- Channels SOC, staff and vendors
- Contain
- Accounts, keys, systems and evidence
- Assess
- Data, persons, consequences and jurisdiction
- Escalate
- Legal, security, management and regulator
- Notify
- Authority/individuals as applicable
- Remediate
- Root cause, controls and record
10
Privacy programme
- 01
Create a data inventory and processing record.
- 02
Assign role, purpose, basis and retention.
- 03
Check notices, consent and rights workflow.
- 04
Conduct vendor, security and transfer reviews.
- 05
Define Guardian, DPIA and authorization.
+7 (495) 221 31 46