The UAE Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021, establishes data protection rights for individuals and obligations for organisations that process personal data in the UAE. It applies to all businesses processing UAE residents’ personal data.
Key PDPL Principles
- Lawful Processing: Personal data may only be processed with valid consent or another lawful basis (contract, legal obligation, legitimate interest)
- Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes
- Data Minimisation: Only collect data that is necessary for the stated purpose
- Accuracy: Keep personal data accurate and up to date
- Storage Limitation: Delete data when it is no longer needed
- Security: Implement appropriate technical and organisational security measures
Individual Rights Under UAE PDPL
- Right to access their personal data
- Right to correct inaccurate data
- Right to delete data (right to be forgotten)
- Right to restrict processing
- Right to data portability
- Right to object to processing
Business Compliance Checklist
| Action | Status |
|---|---|
| Appoint a Data Protection Officer (if large-scale processor) | Required |
| Maintain Records of Processing Activities (RoPA) | Required |
| Publish a compliant Privacy Policy | Required |
| Obtain valid consent for marketing communications | Required |
| Implement breach notification procedure (72-hour notice to UAE Data Office) | Required |
| Conduct Data Protection Impact Assessment (DPIA) for high-risk processing | Required |
UAE PDPL Penalties
Administrative fines up to AED 5 million for data breaches caused by inadequate security measures. Up to AED 20 million for unlawful transfer of sensitive data abroad. Criminal penalties for intentional data misuse.