AI-Powered QFC Compliance · Built on TexterAgent

Every QFC Data Risk. Found. Enforced. Proven.

QFCDR WatchDog detects all 28 PII categories across three compliance tiers — Article 11, Article 12, and QCB DHPR 2025 — using regional AI models, Vespa-powered pre-detection, and automated enforcement workflows aligned to QFC Data Protection Regulations 2021.

QFC DPO-ready audit trail On-prem & air-gapped Qatar data residency
The QFC Compliance Gap

Qatar's financial sector faces a data protection blind spot

QFC entities operate under a layered framework — QFCDR 2021, QCB DHPR 2025 — yet most compliance tooling was built for GDPR and misses Qatar-specific obligations entirely.

Three Overlapping Frameworks

QFCDR Art.11 (standard PII), Art.12 (sensitive PII with 11 lawful conditions), and QCB DHPR 2025 create a compliance matrix that generic tools cannot map. A single KYC document can trigger all three tiers simultaneously.

Financial PII Specificity

QCB DHPR introduces financial-specific categories — account numbers, credit scores, transaction data, wealth profiles — absent from GDPR. Institutions using GDPR-tuned scanners miss an entire compliance tier.

72-Hour Breach Window

QFC requires DPO notification within 72 hours. A separate QCB notification may also apply for regulated financial institutions. Without automated detection pipelines, institutions chronically miss these deadlines.

Sovereign AI Constraints

Qatar's data sovereignty requirements and regional AI ecosystem — G42/Falcon, Saal.ai — mean compliance tooling cannot rely on US-hosted LLM APIs. Document content must never leave the jurisdiction.

Four-Phase Enforcement

From discovery to defensible proof

QFCDR WatchDog covers the complete QFC compliance lifecycle — not just detection, but enforcement documentation regulators can inspect.

01

Discover

Vespa-powered pre-detection runs deterministic regex patterns across all document repositories. 28 PII pattern families matched before AI inference — fast, zero false-negative architecture.

Vespa · Regex · 28 PII types
02
AI

Analyse

Regional LLMs (Claude, Falcon/G42, Saal.ai) classify each PII entity against the three-tier framework. Article 12 sensitive categories receive individual lawful basis evaluation (conditions A through K).

Claude · Falcon · Saal.ai · Art.12 A–K
03

Enforce

Automated redaction of high-risk PII, DSR compilation with 30-day tracking, cross-border transfer analysis against QFC adequacy list, and Art.16 processing record generation.

Redact · DSR · Records · Cross-Border
04

Report

The Enforcement Analysis Report PDF delivers 8 structured sections — Risk Assessment, Findings Register, Enforcement Matrix, Breach Notification, Cross-Border, DSR Readiness, Processing Records, Action Plan — plus Appendix A with anonymised document evidence.

8-section PDF · Appendix A · QFC DPO-ready
Platform Capabilities

Every QFC obligation. One platform.

Art. 11 Art. 12 QCB DHPR

Three-Tier PII Detection

Deterministic Vespa pre-detection followed by LLM NER across all 28 PII categories. Article 12 sensitive categories trigger individual lawful-basis evaluation against conditions A–K before any processing decision.

Art. 1115 Standard Categories
Art. 128 Sensitive Categories
QCB DHPR5 Financial Categories

Enforcement Analysis Report

8-section QFC DPO-ready PDF with Risk Assessment, Findings Register, Enforcement Matrix, Breach Analysis, Cross-Border exposure, DSR Readiness, Processing Records, Action Plan, and Appendix A.

PDF · Appendix A

KYC / AML Financial Intelligence

Specialised detection for Know-Your-Customer and Anti-Money Laundering document workflows. Identifies account numbers, IBAN/BIC, credit scores, transaction identifiers, and beneficial ownership data under QCB DHPR 2025.

QCB DHPR 2025

Cross-Border Transfer Analysis

Validates data flows against the QFC adequacy country list, flags transfers requiring QFC Standard Contractual Clauses (4 modules), and flags recipients without adequate protection automatically.

QFC SCCs · Adequacy List

Data Subject Rights — 30 Days

Automated DSR compilation covering Art.17–22 rights (access, rectification, erasure, restriction, portability, objection). Extension tracking for complex requests (+60 days). Full audit trail per request.

Art. 17–22

Processing Records (Art. 16)

Automated generation of Article 16 processing activity records across all document categories, controller/processor chains, retention schedules, and legal basis documentation — continuously kept current.

Art. 16 · RoPA

Multi-LLM AI Providers

Choose the AI model that meets your sovereignty requirements. Anthropic Claude via API, G42/AI71 Falcon deployed in UAE/Qatar data centres, or Saal.ai for fully on-premise Qatar-local inference — all provider-switchable at runtime.

Claude · Falcon · Saal.ai
72h Critical

Dual-Track Breach Notification

Automated breach severity classification and dual-track notification workflow. QFC DPO notification is mandatory within 72 hours. Separate QCB notification applies for regulated financial institutions under QCB DHPR 2025. Data subject notification is discretionary under QFCDR (unlike mandatory GDPR) — the system flags the risk threshold and documents the decision rationale.

72hQFC DPO mandatory
QCBFinancial institutions
DiscretionarySubject notification
System Architecture

Built for QFC financial-grade data

A two-stage detection pipeline — deterministic pre-detection, then AI semantic analysis — ensures every PII entity is caught before it becomes a compliance exposure.

Sources
KYC Docs
AML Records
HR / Payroll
Wealth Data
Email / Comms
Ingest
Pre-Detection
Vespa Search
Regex Patterns
28 PII Families
Candidates
AI Analysis
Claude
Falcon / G42
Saal.ai
Three-Tier Classification · Art.12 A–K Lawful Basis
Enforce
Outputs
Enforcement Report
DSR Package
Processing Records
Breach Package
How It Works

From document to enforcement in minutes

1

Connect your repositories

Point QFCDR WatchDog at your document stores — Alfresco, SharePoint, SQL databases, email archives, or local file systems. Vespa indexes content immediately.

2

Pre-detection pass

28 regex PII pattern families run deterministically across all indexed content. Candidate PII entities are flagged with tier assignment before any AI call — fast, auditable, zero false-negatives.

3

AI semantic classification

Your chosen LLM provider (Claude, Falcon/G42, Saal.ai) receives pre-detected candidates for semantic verification and tier classification. Article 12 sensitive categories receive individual lawful-basis assessment against conditions A through K.

4

Automated enforcement actions

High-risk PII is redacted, DSR requests are compiled against the subject's data footprint, cross-border transfers are validated against the QFC adequacy list, and Article 16 processing records are updated.

5

Generate Enforcement Analysis Report

The 8-section PDF is produced with full finding evidence, enforcement matrix, breach notification analysis, and Appendix A containing the anonymised source document. QFC DPO-ready on demand.

Repository Connection
🗄Alfresco ECMConnected
📧Exchange ArchiveConnected
🗃SQL DatabaseIndexing…
📁Network ShareAdd
128,450Documents indexed
2.4 GBContent scanned
Real-timeWatch mode
Vespa Pre-Detection
Art. 11 PII88%
Art. 12 Sensitive64%
QCB DHPR Financial42%
QID: 847 matches Health Data: 23 matches IBAN: 156 matches Passport: 312 matches Religion: 8 matches Credit Score: 67 matches
AI Classification · Claude claude-opus-4-8
Art.11full_name: "Mohammed Al-Rashidi"LOW
Art.11national_id: "28481234567890"MED
Art.12health_data: "Type 2 diabetes"CRIT
Lawful basis: Cond. A (explicit consent) — MISSING
QCBcredit_score: 742HIGH
QCBaccount_no: "QA**BBBB****"HIGH
Enforcement Actions
3 documents redacted (Art.12 + QCB DHPR)
DSR compiled for Mohammed Al-Rashidi
Cross-border flag: transfer to non-adequate country
!Art.12 Cond.A missing — processing blocked
Art.16 record updated — 14 processing activities
Enforcement Analysis Report — Ready
§1Risk AssessmentCRITICAL
§2Findings Register28 findings
§3Enforcement MatrixDone
§4Breach Notification72h Window
§5Cross-Border AnalysisDone
§6DSR ReadinessDone
§7Processing RecordsDone
§8Action PlanDone
App.AAnonymised document evidenceAttached
Before & After

KYC document enforcement in action

A typical QFC financial institution KYC onboarding document — before and after QFCDR WatchDog processing.

Before — Unprocessed KYC Document
Qatar Financial Centre — KYC Onboarding Record Date: 2024-03-15

Client: Mohammed Khalid Al-Rashidi

QID: 28481234567890

Passport: QA-7894321

Date of Birth: 15 March 1984

Address: Villa 14, Al Waab Street, Doha, Qatar

Health Condition: Type 2 diabetes — disclosed for insurance waiver

Religion: Islam

Account No: QA57QNBA000000000069123456

Credit Score: 742 / Excellent

Transaction Ref: TXN-2024-QFC-00847

Art.11 Art.12 QCB DHPR
After — QFCDR Enforced
Qatar Financial Centre — KYC Onboarding Record Date: 2024-03-15 QFCDR WatchDog ✓

Client: ██████████████████

QID: █████████████████

Passport: ██████████

Date of Birth: ████████████

Address: ███████████████████████████

Health Condition: BLOCKED — Art.12 Cond.A consent absent

Religion: BLOCKED — Art.12 Cond.B missing

Account No: QA57****…****3456 (masked)

Credit Score: ███ / ██████ (pseudonymised)

Transaction Ref: TXN-████-QFC-█████

Enforcement Analysis Report ↓ DSR Package ready Art.16 Record updated
Business Impact

The cost of non-compliance is measurable

5%
QFC maximum fine as percentage of annual global turnover — QFCDR Art.53
Per enforcement action, per violation
72h
Breach notification window to QFC DPO — automatically tracked
Without automation, 84% of organisations miss this deadline
30d
DSR response deadline — Art.17–22 automated compilation
Typical manual effort: 18–40 person-hours per request
28
PII categories scanned across three compliance tiers automatically
Zero missed by deterministic Vespa pre-detection
Regulatory Framework

QFCDR 2021 + QCB DHPR 2025 — fully covered

Every article that creates a compliance obligation for QFC-registered entities is mapped to an automated enforcement workflow.

Art. 11

Standard Personal Data

15 categories of standard PII processed only with a lawful basis. Full name, QID, passport, address, DOB, email, phone, IP address, employment data, financial basics, and location data.

15 categories
Art. 12

Sensitive Personal Data

8 sensitive categories requiring one of 11 specific lawful conditions (A–K). Racial/ethnic origin, political opinions, religious beliefs, trade union membership, health data, biometric, genetic, and sexual orientation data.

8 categories · 11 conditions
Art. 16

Processing Records

Mandatory record of processing activities covering purpose, legal basis, data categories, retention periods, controller/processor chains, and cross-border transfers. Auto-generated and maintained.

Automated RoPA
Art. 17–22

Data Subject Rights

Access, rectification, erasure, restriction of processing, data portability, and objection rights — all with 30-day response deadline tracking and audit trail documentation.

6 rights · 30-day SLA
Art. 23–24

Cross-Border Transfers

Transfers to QFC-adequate countries permitted. Transfers to non-adequate countries require QFC Standard Contractual Clauses (4 modules available). Adequacy list validated automatically per transfer event.

QFC SCCs · 4 modules
Art. 26

Data Breach Notification

Breach detection, severity classification, 72-hour QFC DPO notification package, data subject notification risk assessment (discretionary under QFCDR), and post-breach remediation tracking.

72h DPO · Discretionary subject
QCB DHPR 2025

Financial Data Protection

5 additional financial-specific PII categories under Qatar Central Bank Data Handling & Protection Regulation — account numbers, credit scores, transaction data, wealth profiles, and beneficial ownership. Dual notification: QFC DPO + QCB.

5 financial categories
28 PII Categories

Every entity QFCDR WatchDog detects

Full Name Qatar ID (QID) Passport Number Date of Birth Address Email Address Phone Number IP Address Employment Data Financial Basics Location Data Online Identifiers Education Records Vehicle Data Images / Photos Health Data Biometric Data Genetic Data Religious Beliefs Racial / Ethnic Origin Political Opinions Trade Union Sexual Orientation Account Numbers Credit Score Transaction Data Wealth Profile Beneficial Ownership
Art. 11 Standard (15) Art. 12 Sensitive (8) QCB DHPR Financial (5)
Sovereign AI Options

Choose the AI that stays in your jurisdiction

Qatar's data sovereignty requirements mean your compliance AI must respect your data residency. QFCDR WatchDog runs on any of three provider tiers — switchable at runtime.

Global API

Anthropic Claude

Claude Opus 4 and Claude Sonnet 4 via Anthropic API. Highest capability for complex Art.12 lawful-basis analysis and multi-document synthesis. Best suited for organisations with cloud data agreements.

claude-opus-4-8 claude-sonnet-4-6 claude-haiku-4-5
Qatar On-Premise

Saal.ai

Fully air-gapped Qatar-local deployment. Arabic-first model with deep Gulf financial vocabulary. Zero data egress — document content never leaves the institution's infrastructure. For the strictest sovereignty requirements.

saal-arabic-v1 saal-finance-v1
Deployment Options

Deploy where your data must live

On-Premises

Deployed within your QFC-registered entity's own infrastructure. Full control over AI model selection, data flows, and audit logs. Supports all three LLM provider tiers.

Full data control

Private Cloud

Deployed in your private cloud tenancy within Qatar or UAE data centres. G42 / AI71 hosting natively supported. Meets QCB data residency requirements for financial institutions.

Qatar data residency

Air-Gapped

Fully isolated network deployment with Saal.ai on-premise inference. Zero external API calls. Ideal for QCB-regulated institutions with strict network isolation requirements or classified client portfolios.

Zero data egress

Hybrid

Standard PII (Art.11) processed via cloud LLMs; sensitive PII (Art.12) and QCB DHPR financial categories processed exclusively by on-premise models. Tier-aware routing at classification time.

Tier-aware routing
Live Demo Scenarios

QFC financial workflows — real scan results

Four real QFCDR WatchDog demo scenarios showing actual system output across the most common QFC financial institution document types.

QFCDR WatchDog · KYC Onboarding Document Scan Claude Opus 4 · Art.11 + Art.12 + QCB DHPR

Client onboarding for Ahmed Al-Mansouri, QID: 28390012345678, Passport: QA-1234567. DOB: 12 Sep 1983. Address: Villa 7, Pearl Qatar, Doha. Source of wealth: property. Health declaration: hypertension, on medication. Religion for estate planning: Muslim — Shia. Account: QA63CBQM000000000002345678. Credit rating: BBB+ (Moody's).

Art.11 full_name: "Ahmed Al-Mansouri" LOW
Art.11 national_id: "28390012345678" MED
Art.12 health_data: "hypertension, on medication" CRITICAL
Lawful basis required: Cond. A (explicit consent) — NOT FOUND. Processing BLOCKED.
Art.12 religious_beliefs: "Muslim — Shia" CRITICAL
QCB account_number: "QA63CBQM…" HIGH
QCB credit_score: "BBB+ (Moody's)" HIGH
Generate Enforcement Report Redact Document Compile DSR
QFCDR WatchDog · Wealth Advisory File Scan Falcon-3-10B-Instruct · Art.11 + Art.12 + QCB DHPR

Wealth management profile for Fatima Al-Sulaiti, relationship manager Yousef Karimi. Portfolio value: QAR 14.2M. Risk tolerance: aggressive growth. Health note (longevity planning): chronic kidney disease, stage 3. Investment mandate excludes non-halal instruments per client religious preference. Beneficiary: Omar Al-Sulaiti (son), QID: 29100067890123.

Art.12 health_data: "chronic kidney disease, stage 3" CRITICAL
Lawful basis: Cond. H (healthcare purposes) — check healthcare exemption applicability.
Art.12 religious_beliefs: "halal investment preference" HIGH
QCB wealth_profile: "QAR 14.2M AUM" HIGH
QCB investment_profile: "aggressive growth mandate" MED
Generate Enforcement Report Redact Document Compile DSR
QFCDR WatchDog · HR Personnel Record Scan Saal.ai On-Premise · Art.11 + Art.12 + QCB DHPR

HR file: Khalid Ibrahim Al-Farsi, Senior Analyst, QID: 28765432109876. Salary: QAR 52,000/month, IBAN: QA58QNBA000000000012345678. Biometric access profile: fingerprint hash 7f3a9c2d, iris scan registered. Medical: colour blind (red-green) — accessibility accommodation. Trade union membership: Doha Financial Workers Association.

Art.12 biometric_data: "fingerprint + iris scan" CRITICAL
Lawful basis: Cond. B (employment law obligation) — employment contract review required.
Art.12 health_data: "colour blind accommodation" HIGH
Art.12 trade_union: "Doha Financial Workers Association" HIGH
QCB salary: "QAR 52,000/month" MED
QCB account_number: "QA58QNBA…" HIGH
Generate Enforcement Report Redact Document Update Art.16 Records
QFCDR WatchDog · AML Investigation Record Scan Claude Sonnet 4 · QCB DHPR 2025 Primary

Suspicious Activity Report — case SAR-2024-QFC-00291. Subject: Ali Hassan Al-Thani, QID: 28155678901234. Beneficial owner: Al-Thani Holdings WLL (100%). Transactions flagged: QAR 4.7M — 23 transactions in 14 days. Linked accounts: QA12AAAA…, QA34BBBB…, QA56CCCC…. Political exposure: PEP status — Tier 2.

QCB beneficial_ownership: "Al-Thani Holdings WLL (100%)" CRITICAL
QCB transaction_data: "QAR 4.7M — 23 transactions" CRITICAL
Art.12 political_opinions: "PEP status — Tier 2" CRITICAL
Lawful basis: Cond. J (legal obligation — AML) + QCB DHPR Art.8 monitoring exemption applies.
QCB account_numbers: 3 linked accounts HIGH
72h breach window: SAR data exfiltration risk — QFC DPO notification package ready
Generate Enforcement Report Prepare 72h Breach Package QCB Dual Notification
Get Started

See QFCDR WatchDog in your environment

Request a personalised demo with your own document samples. We run a live QFCDR compliance scan and deliver an Enforcement Analysis Report within 48 hours.

✓ QFC DPO-ready output ✓ No data leaves your infrastructure ✓ Response within 1 business day

Request received

A TexterBlue compliance specialist will contact you within one business day to schedule your personalised QFCDR WatchDog demo.