العربية

Market · Kingdom of Bahrain

Meet the CBB module that governs your licence

Bahrain is easy to overlook and awkward to get wrong. It holds the most prescriptive external-assessor requirement anywhere in the Gulf, and the only statutory register of accredited data protection officers in the region.

The rule nobody else in the Gulf has written

Under the Central Bank of Bahrain Rulebook, a licensee must have penetration testing performed by internal and external independent third parties — and the external party must be changed at least every two years.

No other Gulf regulator mandates rotation of the assessor. It is a small clause with large consequences: it means your tester is a recurring procurement decision rather than a standing relationship, and it quietly rules out the arrangement where the firm that built your controls keeps testing them.

What binds you

Bahrain embeds cyber security per volume of the CBB Rulebook rather than in a single framework document, so the applicable text depends on your licence category.

CBB

Rulebook cyber security modules

e.g. Vol. 4, Module RM-9

Requires a qualified CISO with authority to implement the cyber security strategy, and testing using grey box and black box approaches aligned to NIST or OWASP. The incident clock is the tightest in the Gulf: the CBB notified within one hour by telephone, an initial report within two hours, a detailed root-cause report within ten calendar days, then weekly updates until resolution. Conventional banks, Islamic banks, insurance, investment business and specialised licensees each have their own module.

Who signsInternal and external independent testers, the external one rotated at least every two years. Tested each June, reported to the CBB by 30 September.
PDPA

Personal Data Protection Law

Law 30/2018

In force since August 2019, with ten supplementary ministerial resolutions issued in 2022. Written, explicit consent is required before processing, and specifically for international transfers. Transfers are permitted to 83 whitelisted countries, or case by case with authority approval or data subject consent. Penalties are criminal rather than administrative — up to a year's imprisonment and fines from BHD 1,000 to 20,000.

Who signsNotification to the authority of processing that requires prior authorisation.
PDPA

The accredited DPO register

Data protection guardian

The clearest statutory basis in the Gulf for an external data protection officer. The role is mandatory for all licensed financial institutions and optional elsewhere — but officers must be accredited and appear on the authority's register. Internal appointees need permanent Bahraini residency and employment in the organisation or group; external individuals need a relevant degree or a professional certification in a related cyber security field, with good standing and no disciplinary history.

Who signsThe authority accredits the officer. The register is the gate.
iGA

General Policy for the Use of Artificial Intelligence

v1.0 · July 2025

Adopted alongside the GCC Guiding Manual on the Ethics of Artificial Intelligence Use — the only supranational Gulf AI instrument identified, issued by the Cooperation Council's Ministerial Committee for eGovernment and framed explicitly around shared Gulf values. Both are voluntary policy instruments.

Who signsSelf-assessed. No certification attaches.

The draft AI law is not law

A draft AI regulation bill of 38 articles was approved by the Shura Council in April 2024. It proposes mandatory licensing from a new Artificial Intelligence Unit for all AI development and deployment, a prohibition on fully automated decisions affecting human life, freedom or bodily integrity, and penalties up to permanent business closure. It has not been enacted. If it passes it would be the first standalone AI law in the region — which is exactly why it is worth watching and exactly why it must never be presented to a client as a current obligation.

The authority is still an interim arrangement

The PDPL envisages an independent Personal Data Protection Authority. Royal Decree 78 of 2019 designated the Ministry of Justice, Islamic Affairs and Waqf to perform its duties in the interim, and as of this review the permanent independent authority has still not been established. We also found no published Bahraini enforcement decisions in the last two years. Treat the regime as binding and the enforcement posture as untested — both are true at once.

Where we are useful here

What we do

  • Readiness against the CBB module that applies to your licence category, ahead of the June testing window.
  • Incident response playbooks written to the one-hour, two-hour and ten-day clock rather than to a generic template.
  • Outsourced data protection officer, where the register's external-appointee criteria are met.
  • Gap assessment before the external tester arrives, so their report is short.

What we do not do

  • The penetration test itself. The rotation rule means that engagement is a separate procurement, and we would be the wrong supplier for it in any case.
  • Anything that would place us on both sides of an assessment.
  • Advise that the draft AI law creates present obligations.

Start with a scoping call

Tell us your CBB licence category, or whether the DPO obligation is what brought you here. Twenty minutes usually settles it.