Back to Compliance & Regulatory

Data Protection Compliance in the UAE: An Overview

At a Glance

  • Several regimes may apply
  • Transparency and security are core themes
  • Cross-border transfers need attention

Topic Hub

The UAE has a federal personal data protection law (Federal Decree-Law No. 45 of 2021) and separate regimes in financial free zones such as DIFC and ADGM, in addition to sector-specific rules. Which applies depends on where and how a business processes personal data.

Implementation details have been developing, so check current guidance and regulations for your situation.

Which regime applies

A business onshore may fall under the federal law, while companies in DIFC or ADGM are generally subject to those zones' own data protection laws. Some sectors, such as health and finance, have additional rules.

Common principles

  • Process personal data for specified and lawful purposes
  • Be transparent through privacy notices
  • Collect only what is needed
  • Keep data accurate and secure
  • Retain data only as long as necessary
  • Respect individuals' rights as the law provides

Consent and other bases

Consent is one lawful basis, but others may exist. Consent should be clear and specific where relied on.

Security and incidents

Take appropriate technical and organisational measures. Have a plan for responding to incidents, including assessing whether notification is required.

Cross-border transfers

Transferring data outside the UAE or between regimes may be subject to conditions. Review contracts with overseas service providers.

Employees and customers

Employee data, monitoring and recruitment records are personal data. Policies should be clear and proportionate. See employment policy review.

Contracts

Agreements with service providers that handle personal data should include data protection terms. See service agreement review.

How a consultation can help

A consultation can help map data use, review notices and contracts and identify gaps. Your Legal Key is not a regulator and cannot certify compliance.

Frequently asked questions

Does data protection law apply to small businesses?

Often yes, if they process personal data, subject to the scope and exemptions of the applicable regime.

Do I need a privacy notice?

Generally, transparency is expected. A clear notice is good practice.

Can I send marketing messages?

Subject to consent and telecommunications and consumer rules, so check requirements.

Related guides and services

General information only. Please read our Legal Disclaimer.

COMPLIANCE QUERY?

Discuss compliance documentation and regulatory questions for your business.

Connect Directly