The UAE Personal Data Protection Law (PDPL β Federal Decree-Law No. 45 of 2021) establishes a comprehensive data privacy framework for businesses operating in the UAE. Here is a business compliance guide.
UAE PDPL Overview
The PDPL came into force in 2022 (with implementation regulations issued in 2023). It applies to: any entity that processes personal data of UAE residents or citizens, regardless of where the entity is based. Key requirements: lawful basis for processing (consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests), privacy notice (inform data subjects about how their data is used), data subject rights (access, correction, deletion, objection, portability), data breach notification (to the UAE Data Office within 72 hours), data retention limits, and cross-border data transfer restrictions (data cannot be transferred outside the UAE unless the destination country has adequate protection or specific safeguards are in place). Exemption: DIFC and ADGM have their own data protection laws (DIFC DP Law and ADGM PDPP Regulations) β entities in DIFC/ADGM follow these instead of the federal PDPL.
PDPL Compliance Steps for UAE Businesses
Step 1: Data mapping β identify what personal data you collect, where it comes from, how it is used, and where it is stored. Step 2: Legal basis β determine the lawful basis for each processing activity. Step 3: Privacy policy β update your website privacy policy to reflect PDPL requirements (in Arabic as the official language). Step 4: Consent mechanisms β add consent checkboxes and opt-out options for marketing. Step 5: Data subject rights process β create a process to handle access/deletion requests within 30 days. Step 6: Data breach plan β have a documented response plan. Penalties for non-compliance: up to AED 5 million per violation.