2010-01-01

Added · Updated

Law No. (16) of 2010 Issuing the Law on Electronic Transactions and E-Commerce

This law establishes the legal framework for electronic transactions in Qatar, defining key terms such as electronic messages, digital signatures, and data messages. It mandates that electronic communications and digital signatures hold the same legal validity as written documents and physical signatures, provided they meet specific integrity and authentication standards. The law outlines the responsibilities of signatories and certification service providers, while excluding certain matters like family law and real estate taxes from its scope.

Qatar Central Bank logo

Qatar

Qatar Central Bank

Click to view thumbnail

Law No. (16) of 2010 Issuing the Law on Electronic Transactions and E-Commerce

We, Tamim bin Hamad Al Thani, Deputy Emir of the State of Qatar, Having reviewed the Constitution, And the Civil and Commercial Transactions Law issued by Law No. (13) of 1990, and its amendments, And the Civil Law issued by Law No. (32) of 2004, And the Decree-Law No. (36) of 2004 establishing the Supreme Council for Communications and Information Technology, And the Commercial Law issued by Law No. (37) of 2006, amended by Law No. (7) of 2010, And the Communications Law issued by Decree-Law No. (34) of 2006, And Law No. (8) of 2008 concerning Consumer Protection, And upon the proposal of the Supreme Council for Communications and Information Technology, And upon the draft law submitted by the Council of Ministers,

Have decided the following Law:

Article (1) The provisions of the Law on Electronic Transactions and E-Commerce, attached to this Law, shall be implemented.


Article (2) In the absence of specific provisions in the attached Law, the substantive provisions governing electronic transactions and e-commerce in the legislations regulating each shall apply.

Article (3) The Supreme Council for Communications and Information Technology shall issue the regulations and decisions necessary to implement the provisions of the attached Law.

Article (4) All competent authorities shall implement this Law within their respective jurisdictions. It shall be published in the Official Gazette.

Tamim bin Hamad Al Thani Deputy Emir of the State of Qatar

Issued at the Diwan Amiriy on: 1431/9/9 AH Corresponding to: 2010/8/19 AD


Law on Electronic Transactions and E-Commerce

Chapter One Definitions

Article (1) In the application of the provisions of this Law, the following words and expressions shall have the meanings indicated alongside each, unless the context requires otherwise:

The Council: The Supreme Council for Communications and Information Technology. Person: A natural or legal person. Electronic: The technology of using electrical, electromagnetic, optical, or any other similar form of technology. Electronic Communication: A communication made by means of any wired or wireless communications. Automated Message System: A computer system, or any other electronic or automated communication means, used to initiate or respond entirely or partially to electronic communications, or related actions, without review or intervention by a natural person. Information System: A set of software and hardware used to create, extract, send, receive, display, process, or store information.


Data Message: Information created, sent, processed, received, stored, or displayed by an electronic system. Information Accessibility: The ability to view, retrieve, use, or obtain information. Originator of the Data Message: The person who creates or causes to be created, sends, or stores a data message, on whose behalf it is done. A person acting as an intermediary with respect to that message is not considered an originator of the data message. Addressee: The person to whom the originator of the data message intends to deliver the message. A person acting as an intermediary with respect to that message is not considered an addressee. Information: Data in the form of text, symbols, graphics, images, speech, or sounds. Personal Information: Data about a person whose identity is specified or can be reasonably determined, whether from that data alone or by combining it with any other data. Electronic Signature: What is placed on a data message, taking the form of letters, numbers, symbols, signs, or otherwise, having a unique character, used to identify the signatory, indicate them, and indicate the signatory's consent to the data message.


Signature Creation Data: The information or symbols or private encryption keys used by the signatory in creating the electronic signature. Signatory: The person having the legal right to access signature creation data, acting either in their own name or on behalf of a person they represent, to use this information to create the electronic signature. Certification Service Provider: A person licensed to maintain a public key infrastructure, issue certification certificates, and provide services related to electronic signatures. Certification Certificate: A document issued by a certification service provider confirming the validity of the link between the signatory and the signature creation data. Reliant Electronic Party: A person acting based on a certification certificate or signature. Electronic Transaction: Any transaction, contract, or agreement concluded or performed, in whole or in part, by means of electronic communications. E-Commerce Service: A service usually provided for remuneration, or of a non-commercial nature, provided by combining an information system with any wired or wireless network or communication service, including e-government services. Service Provider: The person providing the e-commerce service. Place of Business: Non-transient establishments or facilities used for conducting business, including providing any service, used exclusively for this purpose.


Client: A person conducting a transaction as part of an e-commerce service. Consumer: A person acting for purposes other than those related to their trade, profession, or business. Wired and Wireless Communications: The sending, broadcasting, or receiving of signals, texts, shapes, sounds, images, data, or information of any kind, by wired, radio, optical, or other electromagnetic communication means, or by any other similar communication means. Wired and Wireless Communication Network: A wired, radio, optical, or other electromagnetic communication system used to pass, convert, or send wired and wireless communication services between endpoints in the network, including fixed and mobile terrestrial networks, satellite networks, and transmission systems, to the extent used for wired and wireless communications and circuit or packet switching networks, including those used for Internet Protocol services, and networks used for broadcasting services encryption, including cable television networks. Wired and Wireless Communication Service: A form of transmission of signals, texts, shapes, or other means, by a wired and wireless communication network, except for radio and television broadcasting services. Internet Protocol: Any set of communication protocols that determine the operational communication standards of the Internet network and transmissions, and other related applications, including Transmission Control Protocol TCP/IP and the TCP protocol suite. Hosting Services: Electronic services provided to users with the ability to store information on the service provider's information systems, so that they can be accessed by other e-commerce service users. Cache: Temporary storage of information in one or more information systems where information is stored for the purpose of frequent access.

Chapter Two Scope of Application

Article (2) The provisions of this Law apply to transactions conducted between persons who have agreed to conduct their transactions using electronic communications. A person's consent to conduct transactions using electronic communications may be inferred from their positive conduct. The consent of government entities and agencies must be explicit, with respect to electronic transactions in which they are a party. Competent government entities and agencies may, if they decide to perform any of their duties via electronic communications, specify any additional specifications or conditions.


Article (3) The provisions of this Law do not apply to the following engines, documents, and transactions:

  • 1 - Engines and documents related to family matters and personal status.
  • 2 - Engines and documents related to property taxes on real estate.
  • 3 - Engines and documents that must be notarized according to the law.
  • 4 - Negotiable instruments subject to the provisions of the Commercial Law. The Council of Ministers may, upon the proposal of the Supreme Council and for public health reasons, delete from or add to the exceptions stipulated in the preceding paragraph by decision.

Chapter Three Requirements for Electronic Transactions

Article (4) When concluding contracts or conducting transactions, an offer or acceptance may be expressed, in whole or in part, by a data message made via electronic communications. The validity of contracts or transactions, or their enforceability, is not affected by the use of one or more data messages in their conclusion.

Article (5) A data message is considered to have been sent by the originator if it was sent by them personally, and is also considered sent by them in the following cases:


  • 1 - If the data message was sent by a person authorized to act on behalf of the originator with respect to that data message, even if sent from an information system or automated message system programmed to be operated by the originator or on their behalf.
  • 2 - If the addressee correctly applied an procedure approved by the originator for the purpose of verifying that the data message was sent by the originator.
  • 3 - If the data message received by the addressee resulted from the actions of a person who was able, by means used by the originator to identify that the data message was sent by them.

Article (6) A data message is not considered to have been sent by the originator in the following two cases:

  • 1 - If the addressee mistakenly received from the originator a notice that the data message was not sent by them, provided that the addressee was given a reasonable time to act accordingly.
  • 2 - If the addressee knew, or ought to have known, when exercising reasonable care or using any agreed procedure, that the data message was not sent by the originator.

Article (7) The addressee may, within the framework of the relationship existing between them and the originator, rely on the data message sent by the originator and act on this basis. The addressee may not rely on the aforementioned data message if they knew, or ought to have known, when exercising reasonable care or using any agreed procedure, that this message, according to what was received, resulted from an error in the wired and wireless communication process.

Article (8) The addressee has the right to consider every data message they receive as an independent data message and act on this basis, unless it is a second copy of another data message, and the addressee knew, or ought to have known, when exercising reasonable care or using any agreed procedure with the originator.

Article (9) If the originator requested the addressee or agreed with them, before or upon sending the data message, to send a receipt of receipt, the data message is considered received by the addressee when the originator receives the mentioned receipt, and this does not imply that the data message sent corresponds to the message received.

Article (10) If the originator has not specified or agreed with the addressee that the receipt of the data message should be in a specific form or method, the addressee may acknowledge receipt by any automatic communication, or by other means, or by conduct on the part of the addressee, which is sufficient to inform the originator that the data message has been received.


Article (11) If the originator stated that the data message is conditional upon receiving a receipt of receipt, it is considered as not sent by the originator until this receipt is received. If the originator did not state that the data message is conditional upon receiving the receipt of receipt, and did not receive this receipt, the originator may send a notice to the addressee stating that the previous data message requires a receipt of receipt, and specify a reasonable period within which the receipt must be received. If the receipt of receipt is not received within the specified period after notifying the addressee, the originator may consider the data message as not sent, or exercise any other rights they may have.

Article (12) When the receipt of receipt states that the data message has met the technical requirements, whether agreed upon or specified in established standards, it is presumed that those requirements have been met.

Article (13) The provisions of Articles (9), (10), (11), and (12) of this Law are limited to proving the fact of sending or receiving data, and these provisions do not extend to processing the legal effects that may result from the data message itself, or the receipt of its receipt.

Article (14) Unless the originator and the addressee agree to determine the time of sending a data message, the time of sending is determined as follows:

  • 1 Upon its entry into an information system outside the control of the originator.
  • 2 Upon its entry into the first information system, if the data message enters alternately into more than one information system outside the control of the originator.

Article (15) Unless otherwise agreed between the originator and the addressee, the time of receiving a data message is determined as follows:

  • 1 If the addressee has designated an electronic address for receipt, the time of receipt is the time when the data message becomes accessible to the addressee at this electronic address.
  • 2 If the data message is sent to an electronic address belonging to the addressee other than the designated one, the time of receipt is the time of accessibility, with the addressee knowing that the data message was sent to this address, or the time the addressee retrieves the data message, whichever is earlier.

Article (16) Unless otherwise agreed between the originator and the addressee:

  • 1 The data message is considered sent from the place where the originator's place of business is located, and considered received at the place where the addressee's place of business is located.

  • 2 If the originator or the addressee has more than one place of business, the place of business is the one most closely related to the transaction in question.

  • 3 If the originator or the addressee has more than one place of business, and the provisions of the preceding paragraph do not apply to any of them, the place of business is the principal place.

  • 4 If the originator or the addressee has no place of business, the habitual residence is considered.

Article (17) A place is not considered a place of business merely due to the presence of equipment and technology supporting the information system used therein or any other part of an information system used by a party to the transaction, or where other parties can access the mentioned information system.

Article (18) The mere use by a person of a domain name or email address associated with a particular country is not evidence that their place of business is located in that country.

Article (19) If a natural person enters information with intent, or by mistake, in a data message exchanged with another party's automated message system that does not provide this person with an opportunity to correct the error, the person who entered the information, or their representative, has the right to withdraw that part of the data message in which the error was made, according to the following conditions:

  • 1 Notifying the other party of the error as soon as possible after becoming aware of it.
  • 2 Not using the goods or services, or deriving any benefit or monetary value from them, in the case where the error relates to goods or services.

Chapter Four Effects and Evidentiary Value of Electronic Transactions

Article (20) Information contained in a data message does not lose its legal effect, validity, or enforceability merely because it is in the form of a data message. Nor does this information lose its legal effect, validity, or enforceability merely because it is presented briefly, provided that clear reference is made in the data message to how to access the details of that information, and access to it is available, such that it can be accessed in a manner that allows its use, by referring to it later, by every person who has the right to access and use this information, and the method of access does not impose an unreasonable burden on them.

Article (21) If the law requires any instrument, document, or transaction to be in writing, or attaches certain effects to non-compliance with this, the instrument, document, or transaction satisfies this condition if it is in the form of a data message, provided it is accessible in a manner that allows its use by referring to it.

Article (22) If the law requires a signature on an instrument, document, or transaction, or attaches legal effects to the absence of a signature, the electronic signature, meeting the conditions stipulated in Article (28) of this Law, satisfies this condition.

Article (23) If the law requires the provision or retention of information or its retention in its original form, or attaches legal effects to the failure to achieve this, providing or retaining it in the form of a data message satisfies this condition, provided the following are met regarding it:

  • 1 That it is reasonably possible to demonstrate the integrity and reliability of the information, from the time it was first created in its final form as a data message, until the time of its access and display.
  • 2 That the criterion for assessing the integrity of the data message, according to the previous principle, is determining whether it remains complete without alteration, except for any changes resulting from the transmission, storage, or display of the data message which do not change its content, and the degree of reliance on the information is assessed in light of the purpose for which the data message was created and all other relevant circumstances.
  • 3 The ability to access the data message, allowing its use and reference, by every person who has the right to access and use it.

Article (24) If the law requires the retention of any information, instrument, or document, or attaches legal effects to non-compliance with this, retaining it in the form of a data message satisfies this condition, provided the following are met regarding it:

  • 1 The ability to access the data message in a manner that allows its use, by reference, by any person who has the right to access and use it.

  • 2 Retaining the data message in the original form in which it was created, sent, or received, or in a form that can prove that it accurately represents the information contained in the data message, as it was created, sent, or received in its original form.

  • 3 Retaining the data message information, which enables the determination of its source and destination, and the date and time of its sending or receipt, if any.

Article (25) No instrument, document, or transaction may be rejected as evidence merely because it came in the form of a data message, even if not in its original form, if it is the only evidence that the person relying on it can obtain.

Article (26) When assessing the evidentiary value of information, an instrument, or a document in the form of a data message, the following must be taken into account:

  • 1 The procedures and circumstances under which the data message was created, stored, or delivered.
  • 2 The procedures and circumstances under which the integrity of the instrument or document was maintained.
  • 3 The procedures and circumstances under which the originator of the data message was identified.
  • 4 Any other relevant procedures or circumstances.

Article (27) The validity or enforceability of a contract concluded by interaction between an automated message system and a natural person, or by interaction between automated message systems, may not be denied merely due to the lack of review or intervention by a natural person in the actions performed by the automated message system or in the contract resulting from those actions.

Chapter Five Electronic Signature

Article (28) An electronic signature may have evidentiary value if it meets the following conditions:

  • 1 That the signature creation data is linked to the signatory and not to any other person.
  • 2 That the signature creation data, at the time of signing, is under the control of the signatory and not any other person.
  • 3 The ability to detect any change made to the electronic signature after the signing occurred.
  • 4 The ability to detect any change made to the data message information after the time of signing, if the purpose of requiring the signature by law is to confirm the integrity of the information to which the signature relates. The Council shall issue the necessary decisions to determine which electronic signature processes and technologies meet the previous provisions.

Article (29) The signatory, when creating an electronic signature, must adhere to the following:

  • 1 Exercising reasonable care to avoid the unauthorized use of their signature creation information.
  • 2 Using the means available from the certification service provider, according to the provisions of Articles (36) and (37) of this Law, without delay, to notify any person presumed to be affected by the use of the electronic signature, and to take necessary actions to enhance the electronic signature, in the event that the signature creation information is exposed to indications of suspicion.
  • 3 Exercising reasonable care when using the certification certificate to enhance the electronic signature, to ensure the accuracy and completeness of all material confirmations provided by the signatory related to the certification certificate, for its duration or until its listing in the certification certificate ends.

Article (30) The signatory bears the legal effects resulting from their failure to fulfill the obligations mentioned in the previous article.

Article (31) The relying party bears the legal effects resulting from their failure to take reasonable steps to verify that the electronic signature meets the conditions stipulated in Article (28) of this Law, or to verify the validity of the certification certificate, its source, time, or cancellation, or any restriction on it, in the event that the electronic signature is enhanced by a certification certificate.

Article (32) The electronic signature is legally effective, regardless of the geographical location where this signature is created or used, or the geographical location of the signatory's place of business.

Article (33) The electronic signature created or used outside the State has the same legal effect inside it, if it provides a level of identification equivalent to, not less than, the level required under Article (28) of this Law.

Article (34) Subject to the provisions of Article (28) of this Law, parties may agree to use specific types of electronic signatures, provided that the agreement is valid according to the law.

Chapter Six Certification Service

Article (35) The certification service provider, when providing services to enhance the electronic signature, must adhere to the following:

  • 1 Acting in accordance with the data they provide regarding their practice of the activity.

  • 2 Exercising reasonable care to ensure the accuracy and completeness of all data they provide.

  • 3 Using in performing their services a system, procedures, and human resources worthy of trust, according to the standards and controls specified by a decision of the Council.

Article (36) The certification service provider must provide the signatory with a means that enables them to provide notice that the signature creation information has been exposed to indications of suspicion, and ensure for them the provision of a signature cancellation service that can be used in a timely manner.

Article (37) The certification service provider must provide means, which can be accessed reasonably, that enable the relying party to verify that the certification certificate:

  • 1 Identifies the certification service provider.
  • 2 That the signatory was in control of the signature creation data at the time of issuing the certification certificate.
  • 3 That the signature creation data was correct at the time of issuing the certification certificate.

Article (38) The certification service provider must provide the relying party with means, which can be accessed reasonably, that enable the relying party to verify the following:

  • 1 Identifying the certification service provider.

More like this from QCB

We email you every new QCB publication the day it's published.

Share