The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, PDPL) came into full force in 2022 and has been progressively enforced since. It establishes a comprehensive framework for the processing of personal data of individuals in the UAE and applies to all businesses that collect, process, or store personal data of UAE residents, regardless of where the business is incorporated.

Core Obligations Under the PDPL

Businesses subject to the PDPL must: have a lawful basis for processing personal data (consent, contract, legal obligation, legitimate interest, or vital interests), provide individuals with a clear privacy notice, implement appropriate technical and organisational security measures, respond to data subject rights requests within the specified timeframes, and notify the UAE Data Office of data breaches within 72 hours of discovery. A data protection officer must be appointed by businesses that process sensitive personal data at scale.

Sensitive Personal Data: Extra Requirements

The PDPL imposes heightened requirements for sensitive personal data including health data, biometric data, genetic data, data revealing racial or ethnic origin, religious beliefs, and criminal records. Processing sensitive data requires explicit consent from the data subject or specific legal authority. Health businesses, HR departments holding employee medical records, and businesses using biometric access systems all process sensitive data and must ensure their data handling practices meet the elevated standard.

Cross-Border Data Transfers

The PDPL restricts transfer of personal data outside the UAE to countries that provide an adequate level of data protection as determined by the UAE Data Office, or where appropriate safeguards are in place such as standard contractual clauses. Businesses that use global cloud services, offshore data centres, or share customer data with international group entities must review whether their data transfer arrangements comply with the PDPL's cross-border transfer provisions.

Penalties for PDPL Non-Compliance

The PDPL provides for fines up to AED 5 million for violations, with higher fines for certain specific violations including unlawful transfer of sensitive data. The UAE Data Office can also order cessation of data processing activities. Reputational damage from a publicly reported data breach or regulatory action can significantly exceed the direct financial penalty. Gulf Oasis Business Management assists businesses with PDPL compliance reviews, privacy notice drafting, and data protection policy implementation.