0%
SUN-THU: 9:00AM - 06:00PM (AST)
Skip to content
Compliance

Qatar PDPPL and your CRM and ERP: a practical checklist

The Personal Data Privacy Protection Law applies to the data your CRM, ERP and HR systems already hold. This checklist turns the obligations into configuration and process steps a Qatari company can actually complete.

Where personal data lives in your systems

Personal data in a business system is not only the marketing list. It is every customer contact in the CRM, every employee record with national ID, Qatar ID, bank account and medical information in HR, every supplier contact, every visitor log, every WhatsApp conversation logged against a lead, and every attachment: contracts, ID copies, CVs. PDPPL obligations attach to all of it: lawful basis and purpose, transparency, minimisation, accuracy, retention limits, security, individual rights and breach notification.

This checklist is not legal advice; it is the set of system and process changes we configure with clients in Zoho, Odoo and ERPNext as part of a programme run with their legal advisers. The law, its regulations and the regulator's guidance evolve, so confirm current requirements.

1. Inventory

List each system and the personal data it holds, by category and by data subject: customers, employees, suppliers, visitors, candidates. Include attachments and integrations. Tools such as ManageEngine DataSecurity Plus discover personal data in file servers; CRM and ERP inventories are done from the data model.

2. Purpose, lawful basis and consent

Record the purpose for each category and the basis relied on. Where consent is the basis, capture it in the system: a consent field with date, source and scope on the contact, and marketing preferences honoured by campaigns. Web forms and WhatsApp opt-ins should write consent to the record automatically.

3. Access control and audit

Configure roles so people see only the data their job needs: field-level restrictions on national ID and bank details, HR data limited to HR, sensitive attachments restricted. Enable audit logs of views and changes. For file servers and endpoints, ManageEngine ADAudit Plus and Endpoint Central add auditing and device control.

4. Retention and deletion

Define retention per category: candidate data after a decision, ex-employee data after statutory periods, inactive customer data, visitor logs. Configure scheduled anonymisation or deletion, and a process to answer access, correction and deletion requests from the system rather than by searching.

5. Hosting and transfers

Know where each system stores data and whether it leaves Qatar, including backups, integrations and support access. Where policy or the law requires, choose in-country hosting; see ERP data residency. Review vendor and processor terms.

6. Breach readiness

Log and monitor access, define who is notified and how fast, and keep the evidence to notify the regulator and individuals where required. ManageEngine Log360 provides the monitoring layer for larger organisations.

Questions before you book

Yes. HR records are personal data, often sensitive.

Consent is one basis; others apply for contracts and legitimate purposes. Record the basis per category with your advisers.

Yes, with scheduled anonymisation or deletion configured per category.

It depends on the data and the transfer rules; in-country hosting is available on Odoo and ERPNext where required.

No. It is the system and process configuration we implement within a programme run with your legal advisers.

Want this done on your system?

Tell us what you run today and we will say what it takes.

Book a free consultation

A 30-minute call, no obligation. We will tell you if we are not the right fit.

We use your details only to answer this enquiry. No lists, no resale.