Data Protection Regulations 2021

Click here to view the earlier versions of Data Protection Regulations.

QFC Reg No 6 – Data Protection Regulations
Enactment Notice
Part 1:
Application, Commencement and Interpretation
Article 1 - Citation
Article 2 - Application
Article 3 - Commencement and Repeal
Article 4 - Language
Article 5 - Purpose of these Regulations
Article 6 - General Application of these Regulations
Article 7 - Scope
Part 2:
General Provisions for the Processing of Personal Data
Article 8 - Principles Relating to the Processing of Personal Data
Article 9 - Responsibility for Compliance with the Principles
Article 10 - Lawfulness of Processing
Article 11 - Conditions for Consent
Article 12 - Processing of Sensitive Personal Data
Article 13 - Transparent Information, Communication and Exercise of the Rights of the Data Subject
Article 14 - Information to be Provided Where Personal Data are Collected from the Data Subject
Article 15 - Information to be Provided Where Personal Data are not Collected from the Data Subject
Part 3:
Data Subjects’ Rights
Article 16 - Right to Access
Article 17 - Right to Rectification
Article 18 - Right to Erasure
Article 19 - Right to Object
Article 20 - Right to Restriction of Processing
Article 21 - Right to Data Portability
Article 22 - Automated Individual Decision-Making, Including Profiling
Part 4:
Transfers of Data Outside the QFC
Article 23 - Transfers Out of the QFC: Adequate Level of Protection
Article 24 - Transfers Out of the QFC in the Absence of an Adequate Level of Protection
Part 5:
Data Controller and Data Processor Obligations
Article 25 - Responsibility of the Data Controller
Article 26 - Data Protection by Design and by Default
Article 27 - Data Protection Impact Assessment
Article 28 - Data Processors
Article 29 - Security of Processing
Article 30 - Record of Processing Operations
Article 31 - Notification of Personal Data Breaches
Part 6:
The Data Protection Office
Article 32 - Establishment of the Data Protection Office and the Data Protection Commissioner
Article 33 - Powers
Part 7:
Remedies
Article 34 - Right to Lodge a Complaint with the Data Protection Office
Article 35 - Right to Compensation and Liability
Article 36 - General Conditions for Imposing Penalties
Part 8:
Final Provisions
Article 37 - General Exemptions
Article 38 - Interpretation
Article 39 - Definitions