Markets

B2B website visitor identification in Qatar

Qatar was the first country in the Gulf region to pass a comprehensive data protection law, and international suppliers selling into its energy, construction and infrastructure sector are increasingly asked where visitor data goes and under which regime. Two frameworks can apply depending on where the buying entity sits: the onshore PDPPL, or the separate regime run inside the Qatar Financial Centre.

  • FrameworkPDPPL — Law No. 13 of 2016 (onshore), plus the separate QFC data protection regime
  • SupervisionThe competent data protection authority within the relevant ministry (NCGAA), for onshore matters
  • Usual legal basisLegitimate interest at company level, documented, with transparency in the privacy notice
  • Processing locationISO-certified EU data centres

This page sets out both, describes what lead.box does at company level, and is explicit about where the assessment remains with you as the controller rather than something a vendor can settle on your behalf.

At a glance

Framework
PDPPL — Law No. 13 of 2016 (onshore), plus the separate QFC data protection regime
Supervision
The competent data protection authority within the relevant ministry (NCGAA), for onshore matters
Usual legal basis
Legitimate interest at company level, documented, with transparency in the privacy notice
Processing location
ISO-certified EU data centres

Two regimes: onshore PDPPL and the QFC

Regulation at a glance

  • FrameworkPDPPL — Law No. 13 of 2016 (onshore), plus the separate QFC data protection regime
  • SupervisionThe competent data protection authority within the relevant ministry (NCGAA), for onshore matters
  • Usual legal basisLegitimate interest at company level, documented, with transparency in the privacy notice
  • Processing locationISO-certified EU data centres

Qatar's Law No. 13 of 2016 concerning Personal Data Privacy Protection — the PDPPL — was the first comprehensive data protection statute in the Gulf, and it applies onshore to the processing of personal data by electronic means. It sets principles familiar from other modern data protection laws: a lawful basis for processing, purpose limitation, data subject notice and consent requirements, and obligations around data security and cross-border transfer. Responsibility for enforcement and guidance onshore sits with the competent data protection authority within the relevant ministry, referred to as the National Cyber Governance and Assurance Affairs (NCGAA); as with any newer regulatory structure, the precise procedural detail of how reviews and complaints are handled has not been something we would presume to describe in more depth than that.

Separately, the Qatar Financial Centre — the QFC, a financial free zone with its own legal system — operates its own data protection regulations and its own regulator, independent of the onshore PDPPL. This mirrors the pattern seen in the UAE, where the DIFC and ADGM free zones run their own data protection law alongside the federal one. If your Qatari counterparty's contracting entity is registered in the QFC, its data protection regulations are the ones that apply to that entity's processing, not the onshore PDPPL.

For an international vendor, the practical consequence is to establish, before writing any compliance documentation, which entity you are actually dealing with: an onshore Qatari company under the PDPPL, or a QFC-registered entity under the QFC's own regime. The two are not interchangeable, and a data processing agreement drafted for one may need a different framing for the other. Cross-border transfer of data collected in either regime is generally handled through contractual safeguards and a description of the processing location — the same approach that a GDPR-based framework already requires, which is one reason ISO-certified EU data centres tend to satisfy the underlying question either way.

What Qatari and project buyers expect

Much of Qatar's B2B buying activity runs through energy majors, construction contractors and infrastructure operators procuring from international suppliers — often multi-year projects where a handful of specific companies research a supplier's site over months before an RFP is issued. Procurement and legal teams on these projects increasingly ask a standard set of questions: which law governs the processing, where the data physically sits, and whether transfer outside Qatar is involved.

Because Qatar sits between an onshore civil-law framework and a common-law-influenced QFC regime, buyers are used to vendors clarifying which one applies to a given relationship rather than assuming one size fits all. A vendor that states plainly which regime it is addressing, and backs that with a documented processing location and a processor agreement, moves through review faster than one that offers a generic global privacy statement.

English is workable as the documentation language for most international project procurement in Qatar, particularly within QFC-registered structures and multinational contractors, though onshore Arabic-language requirements can apply depending on the counterparty and contract.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

Energy, LNG and petrochemical suppliers, construction and infrastructure contractors, and engineering and procurement firms bidding into large Qatari projects all share a pattern: long pre-RFP research phases where several people from the same contractor or operator visit a supplier's site before any formal contact. Seeing that company name early lets a supplier's business development team reach out while the shortlist is still being formed.

It also suits professional services and industrial equipment suppliers working with QFC-registered financial and holding entities, where a single identified visit from a known project sponsor is worth escalating internally well before an inquiry is submitted.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

Company-level identification is workable under Law No. 13 of 2016 on Personal Data Privacy Protection when a Qatari energy, construction or infrastructure buyer's site visit is resolved to the visiting organisation rather than to a named engineer or procurement officer. The PDPPL requires a lawful basis, purpose limitation and a privacy notice that a visitor can reasonably consult, and lead.box's model supports that because no individual profile, contact record or device fingerprint is ever created from the traffic. Where the visiting entity is registered onshore, the PDPPL governs the relationship; where it sits inside the Qatar Financial Centre, the QFC's separate data protection regulations apply instead, so the first practical step is establishing which of the two frameworks the counterparty's contracting entity actually falls under before drafting any notice language. The controller retains the final call on whether a given deployment is appropriate for its own site and audience; lead.box supplies the technical description and documentation that supports that call rather than substituting for it.

Onshore processing questions under the PDPPL fall to the competent authority operating within the relevant ministry structure, commonly referenced as the National Cyber Security Agency's data protection function together with a Compliance and Data Protection department that handles guidance and complaints; QFC-registered entities instead answer to the QFC's own regulator, which operates independently of the onshore authority. Because Qatar's project-driven procurement often routes through legal teams attached to energy majors and EPC contractors rather than a single national data office, a supplier is more likely to face an internal Qatari counsel's checklist than a formal regulatory filing at this stage of a deal. That internal review typically wants the same three things a regulator would: a named lawful basis, a description of where processing occurs, and a processor agreement. We do not attempt to characterise the authority's internal procedures beyond that, since the operative guidance is published by the authority itself and should be read directly rather than summarised by a vendor with an interest in the answer.

Most B2B site owners in Qatar rely on legitimate interest as the operative basis for resolving visiting organisations, paired with a short internal note explaining why the interest in identifying a prospective supplier or contractor's research activity is proportionate to the limited, company-level nature of the data involved. That written assessment, together with a privacy notice disclosure naming the practice, is the documentation a Qatari legal reviewer or project procurement officer typically asks to see, and it is far more persuasive than a bare assertion of compliance. lead.box does not perform this assessment on a customer's behalf because it depends on the specific site, audience and sector; what we provide instead is a factual account of the processing — company-level resolution, no cookies, no device identifiers — that a Qatari counsel can weigh directly against the PDPPL's or the QFC regulations' own tests, whichever applies to the entity in question.

No. The system resolves the organisation behind a site visit from network-level signals tied to the requesting infrastructure, not from a login, a form fill or a device identifier, and it never stores or infers a visitor's name, title, email address or any other personal contact detail. No cookie or local device storage is used to build the match, which matters in Qatar because both the onshore PDPPL and the QFC's regulations attach heightened scrutiny to tracking technologies that persist on a user's device across sessions. What a Qatari sales or business development team sees in the dashboard is limited to the visiting company's name, its industry and size band, and the pages a member of that organisation viewed — enough to prioritise a call to the right project contractor or operator, but nothing that resembles a personal data record requiring the individual rights machinery either regime provides for.

Yes, and the transfer is handled the same way whether the visiting entity sits onshore under the PDPPL or is registered within the Qatar Financial Centre: through contractual safeguards and a documented description of the destination rather than through an assumption that no transfer is taking place. lead.box processes all identification activity, including matches tied to Qatari IP ranges, in ISO-certified data centres located in the European Union, and it backs that with a data processing agreement and a versioned sub-processor list that a Qatari legal team can cite directly in its own transfer assessment. Because Qatar sits between a civil-law onshore tradition and a QFC regime with different transfer mechanics, we recommend naming both the physical location and the contractual basis explicitly in any documentation prepared for a Qatari counterparty, rather than relying on a general statement that would need separate justification under each framework.

The data processing agreement sets out lead.box's role as processor, the categories of company-level data involved, the security measures applied, and the obligations around breach notification and deletion, structured so that a Qatari legal team reviewing an EPC contractor's vendor list or a QFC-registered fund's onboarding checklist can map each clause to the tests their own framework applies. The sub-processor list is published and versioned, naming the infrastructure and monitoring providers involved in delivering the service, and it is updated whenever a sub-processor changes so a customer's own register stays current without a manual request each time. Neither document claims regulatory pre-approval in Qatar, since no such approval mechanism exists for a service of this kind; both are drafted to give a Qatari reviewer, whether working from the onshore PDPPL or the QFC's own regulations, the factual basis to complete its own internal sign-off.

Once the snippet is live, a resolved match — company name, sector, size band and the pages viewed — typically appears in the dashboard within a day, and from there it can route automatically into a CRM record or a webhook aimed at the business development desk tracking a specific EPC contractor or operator. Given how much of Qatar's project pipeline runs through long pre-tender research phases, several matches from the same contractor over consecutive weeks is often the clearer signal than any single visit, so most teams set up an alert or a weekly export rather than checking the dashboard manually. Seats can be added for colleagues covering Doha-based project offices or regional hubs without a separate contract negotiation, and lists can be exported to spreadsheet formats that a project bid team already uses for tracking active opportunities alongside other supplier-intelligence sources.

Resolution accuracy depends on how a visiting organisation's network infrastructure is structured: a project office or contractor with its own registered IP ranges typically resolves cleanly to that specific entity, while traffic routed through a shared corporate VPN, a mobile carrier network or a public co-working connection may resolve to a broader entity, a carrier, or not at all. Because Qatari project bidding often involves consortium partners sharing infrastructure or visiting from a joint venture office, a supplier should treat a match as a strong signal to prioritise outreach rather than definitive proof that a specific department authorised the research, and cross-check unusually valuable matches manually before treating them as qualified. lead.box does not claim, and a Qatari buyer should not expect, resolution of every visit, nor identification of the specific individual who browsed a page — the mechanism is built to surface company-level signal, not to close that gap.

See which Qatari and project companies are on your site

Install a first-party snippet, see named companies from onshore Qatar and the QFC, and document the processing location before a project procurement team asks.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links