Qatar DPL
Individual Rights

Qatar DPL QATAR-3: Data Subject Rights

Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: data subject rights. Requirements include (a) Access + Rectification + Erasure + Object + Portability + (b) automated decision protections + (c) mechanism + (d) records of requests.

What else in your programme already covers this

This control maps to 143 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.20 Right to data portability
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data

Bahrain PDPL · 4 controls

  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • CA-10 Selects and Develops Control Activities
  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

South Korea ISMS-P · 3 controls

  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality

Turkey KVKK · 2 controls

  • P3-S3 Cooperative Arrangements/Procedures
  • DS-2 Ensure software supply chain security
  • DIQ-1 Data Integration and Interoperability

ISO/IEC 23894:2023 · 1 control

  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • SAPAIA-4 Information Regulator Cooperation and Appeals
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 143 it maps to, and the evidence behind each claim, over MCP and REST.