Skip to content

Cold Email Laws in Qatar: Two Regimes, Opposite Defaults

September 10, 2026. Qatar is one of the few countries where the same cold email, sent to the same person, can be lawful or unlawful depending on which side of a registry line their employer sits. On the mainland, Law No. 13 of 2016 makes prior consent a precondition for any marketing email. Inside the Qatar Financial Centre, a separate rulebook lets a firm send on legitimate interests and stop only when the recipient objects. Almost no English language guide states this, and it is the first thing a sender targeting Doha needs to know.

What the law actually says

The controlling provision is Article 22 of Law No. 13 of 2016 on Protecting Personal Data Privacy, in the chapter headed Electronic Communication for the Purpose of Direct Marketing. In the regulator's own English translation it reads: "The transmission of any Electronic Communication to an Individual, for the purpose of Direct Marketing, shall be forbidden, except after obtaining the prior consent thereof."

That is opt-in, with no soft opt-in and no B2B carve-out anywhere in the statute's 32 articles. The next question is usually whether email is covered at all, since several Gulf spam rules reach only calls and text messages. In Qatar it is covered, and the chain is definitional rather than a matter of interpretation. Article 1 defines Direct Marketing as advertising or marketing material sent "in whatsoever means", defines Electronic Communication by reference to Wire and Wireless Communications, and defines that term as sending "signals, images, shapes, sound, data, texts or information, of whatsoever kind or nature" by wire, wireless or "other electromagnetic communication means". There is no medium carve-out to argue about.

Whether a work address counts follows the same route. The law protects an "Individual", defined as a natural person, and Personal Data is data of an individual "whose identity is defined or can be reasonably defined". A named mailbox at a Qatari company identifies a natural person. A pure role address that identifies nobody is the only genuinely arguable case.

The five rules that decide a Qatar send

  1. Prior consent is mandatory on the mainland. Article 22 admits no alternative lawful basis, and no exemption article reaches it.
  2. Three content duties travel with every message. The same article requires the sender's identity, a clear statement that the message is direct marketing, and a valid address through which the recipient can ask you to stop or withdraw consent.
  3. A separate telecom rulebook adds four more. The Communications Regulatory Authority's Spam Regulation, amended 6 August 2017, binds "any person or organization providing, sending, or using Electronic Communications", not only carriers. It bars direct marketing between 21:00 and 09:00, requires opt-outs to be actioned "without delay, and at a maximum within two (2) business days", requires sender contact details in both Arabic and English, and requires that contact route to stay valid for at least 30 days after the message goes out.
  4. Qatar has an express B2B consent provision. That same regulation says an individual with the authority to do so may consent on behalf of an organisation, and that it is the organisation's responsibility to decide who holds that authority. Nothing in the data protection statute says this.
  5. The mainland ceiling for a marketing breach is QAR 1,000,000. Article 23 lists Article 22 among the provisions it covers, and Article 25 caps a legal person at the same figure for any offence under the law.

Article 22 has no exemption

Here is the finding that changes how a list is built rather than how a message is worded. The statute contains four exemption articles and Article 22 appears in none of them. Article 18 exempts Articles 4, 9, 15 and 17. Article 19 exempts Articles 4, 5 and 6. Articles 20 and 21 exempt Article 6. Article 22 is absent from all four.

The practical effect is a split most compliance summaries miss. Article 4 permits processing without consent where it serves a lawful purpose, so building and enriching a Qatari contact list can rest on that basis. Sending to it cannot. Collection and transmission sit under different rules, and the transmission rule has no escape hatch. If your process assumes that a lawful basis for holding a record implies a lawful basis for emailing it, Qatar breaks that assumption. It is also why sending infrastructure never settles a compliance question on its own: the deliverability stack has no idea what basis a record was collected on.

A second statute still has a soft opt-in

Qatar also has an older e-commerce statute that was never repealed. Decree-Law No. 16 of 2010, Article 54(b), presumes consent where an existing relationship with the service provider "meets the apparent expectation of the consumer to receive the electronic communication", provided the content is relevant to that relationship and an opt-out is offered. That is the soft opt-in familiar from European rules. The 2016 law contains no such presumption and did not repeal it, so Qatar carries a hard opt-in and a soft opt-in on its books at once. We read that article as reproduced inside the regulator's own Spam Regulation rather than in the gazette, so treat it as a tension to raise with counsel, not a defence to lean on.

The QFC runs the opposite default

The Qatar Financial Centre is not a tax wrapper over the same law. Article 2 of the QFC Data Protection Regulations 2021 states that the laws of the State of Qatar "concerning the matters dealt with by or under these Regulations do not apply in the QFC". Direct marketing there lives in Article 19(3), a right to object: a data subject "has the right to object at any time to the Processing of their Personal Data for direct marketing purposes", and once they do, processing for that purpose must stop.

The QFC Data Protection Office's own guidance makes the consequence explicit, stating that "regardless of the lawful basis chosen by the firm for marketing purposes", an objection ends the processing. Regardless of the lawful basis is the load bearing phrase: consent is one option rather than a precondition, and the regulations list legitimate interests among the available bases. Across that entire guidance document the word "unsolicited" does not appear once, and there is no standalone electronic marketing consent rule at all. So a firm inside the QFC and a trading company on the mainland, both in Doha, are governed by opposite defaults on the same email.

Who can actually fine you

The enforcement picture inverts the rules. On the mainland, Article 26 gives the competent department one power, to order rectification. The money in Articles 23 to 25 is criminal, reached through the Public Prosecutor rather than by regulatory decision. The published record matches that design. The National Data Privacy Office has issued a handful of binding decisions since December 2024, most recently Binding Decision No. 3 of 2025 announced on 2 February 2026 against a sports sector company, and they order remediation rather than impose fines.

We could not find a single published Qatari enforcement action under Article 22. Not one, in a decade of the statute. Every published mainland decision we located concerns security, consent to process, accuracy or breach notification instead.

The QFC is the reverse. Its Data Protection Office imposed a reprimand and a financial penalty of US$150,000 on a QFC licensed firm on 2 September 2024, using its own powers under Article 33 of the QFC regulations, and it was reported at the time as the first penalty of its kind in Qatar. The zone with the lighter marketing rule carries the heavier enforcement stick.

The rulebook that may already be gone

One caveat every Qatar guide should carry and none does. The Spam Regulation quoted above, the instrument holding the night curfew, the two business day opt-out deadline, the bilingual contact duty and the only express B2B consent provision, is on a published repeal path. The Communications Regulatory Authority announced on 20 October 2024 that previous consumer related instruments, naming the decision that issued the Spam Regulation, will be repealed after the transition period set out in its new Communications Consumer Protection Regulation dated 2 October 2024. We could not confirm whether that period has expired, or whether the replacement binds every sender or only licensed service providers. Treat the Spam Regulation as the best available statement of Qatari practice and verify its status before relying on the B2B consent provision, which has no equivalent anywhere in the statute.

What it means for operators

If you sell into Qatar, segment the list by regime before you segment it by persona. QFC registration is public record, so the check is cheap, and it decides whether your basis is consent or legitimate interests. Treat mainland records as consent only, and treat the empty enforcement record as a timing observation rather than a safety margin, because Article 26 lets the regulator order you to fix a list at any point and the ceiling above that order is criminal.

The Gulf reads as one market to a sales team and three rulebooks to a compliance officer. Qatar's mainland opt-in sits beside the UAE and Saudi regimes we have covered separately, and a sequence built for one will not clear the others. Capture the consent record at collection rather than reconstructing it afterwards, keep the Arabic and English sender block, honour stops inside two business days, and hold sends to daytime hours. If you would rather have the segmentation and the consent trail designed once and run properly, that is exactly what our cold email programs and lead generation work are built around.

Want a compliant outbound program built for the Gulf?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

On the Qatari mainland it is legal only with the recipient's prior consent. Article 22 of Law No. 13 of 2016 forbids sending an electronic communication for direct marketing except after obtaining prior consent, and there is no soft opt-in and no business to business carve-out in the statute. Firms registered in the Qatar Financial Centre follow a different rulebook, where marketing may rest on legitimate interests and the recipient has a right to object.

Yes, where the address identifies a person. The law protects an Individual, defined as a natural person, and Personal Data is data of an individual whose identity is defined or can reasonably be defined. A named mailbox at a Qatari company identifies a natural person, so it is covered. A generic role address that identifies nobody is the only genuinely arguable case.

Article 23 of Law No. 13 of 2016 sets a ceiling of QAR 1,000,000 for breaches of the listed provisions, and Article 22 on direct marketing is one of them. Article 25 caps a legal person at the same QAR 1,000,000 for any offence committed in its name or interest. These are criminal penalties reached through the Public Prosecutor, not administrative fines the regulator issues directly.

No. Article 2 of the QFC Data Protection Regulations 2021 states that the laws of the State of Qatar concerning matters dealt with by those regulations do not apply in the QFC. Direct marketing there sits under Article 19(3), a right to object, and the QFC Data Protection Office's guidance says an objection ends the processing regardless of the lawful basis the firm chose. In practice that is an opt-out regime, the reverse of the mainland default.

The Communications Regulatory Authority's Spam Regulation bars direct marketing between 21:00 and 09:00, requires opt-outs to be actioned within two business days at most, and requires sender contact details in both Arabic and English that stay valid for at least 30 days. The authority announced in October 2024 that this instrument would be repealed after a transition period, and we could not confirm its current status, so verify before relying on it.

We found no published enforcement action under Article 22 in the decade since the law was passed. The binding decisions the National Data Privacy Office has published since December 2024 concern security, consent to process, accuracy and breach notification, and they order remediation rather than impose fines. The one published financial penalty in Qatar came from the QFC Data Protection Office, which fined a licensed firm US$150,000 in September 2024 on grounds unrelated to marketing.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us