UAE Federal Decree-Law 45/2021
Data Protection: Know your obligations
The UAE Data Protection Law (PDPL) governs how businesses collect, store, and use personal data. Understand DPO triggers, data subject rights, and penalties for breach.
Key requirements at a glance
- DPO (Data Protection Officer): Required if you handle sensitive personal data or systematically monitor individuals; optional for small businesses collecting basic contact info only.
- Data subject rights: Access, correction, deletion (right to be forgotten), data portability.
- Security: Technical and organizational measures to protect data; notification of breaches within 24 hours to DFSA.
- Consent: Explicit opt-in for marketing; legitimate interest for business purposes (contracts, compliance).
- Penalties: Up to AED 2,000,000 fine + order to cease processing + reputational damage.
Understanding PDPL scope
Who must comply and what data is covered
Does PDPL apply to me if I'm a small business?
Yes โ if you collect any personal data (even names and emails). The law applies to all businesses in the UAE, regardless of size. However, small businesses collecting only basic contact info (name, phone, email) for transactional purposes typically don't need a DPO and face lower compliance burden.
What counts as "personal data"?
Any information relating to an identified or identifiable natural person: name, email, phone, ID number, IP address, cookies, photos, video, employment history, etc. Anonymized data (genuinely not traceable to an individual) is excluded.
What is "sensitive personal data"?
Data revealing racial/ethnic origin, political views, religious beliefs, union membership, genetic data, biometrics (for ID), sex life, or health info. PDPL restrictions are stricter for sensitive data โ generally you need explicit consent.
When do I need to appoint a Data Protection Officer (DPO)?
You need a DPO if: (a) you systematically and routinely monitor individuals (e.g., CCTV surveillance, detailed web tracking), or (b) you process large volumes of sensitive personal data. Small businesses collecting basic contact info for normal business don't typically need a DPO.
Compliance checklist
Steps to meet PDPL obligations
- โ Map the personal data you collect (names, emails, IDs, etc.) and where it's stored.
- โ Document your processing activities (why, how long, who has access, retention period).
- โ Update your privacy policy: explain what data you collect, why, who you share it with, and individuals' rights.
- โ Implement technical security: encrypt data, restrict access, regular backups.
- โ Establish a data breach response plan: log incidents, notify DFSA within 24 hours if high-risk breach.
- โ Get explicit consent for marketing (email, SMS, calls); legitimate interest suffices for business communications.
- โ Honor data subject requests: respond to access/deletion requests within 30 days.
- โ If you meet DPO triggers, appoint one and notify DFSA.
- โ Conduct annual reviews โ PDPL rules evolve.
Common questions
PDPL Q&A
Can I share customer data with third parties?
Only with explicit customer consent or if required by law. You must disclose who you share with (e.g., payment processors, email marketing platforms) in your privacy policy. Data processing agreements must be in place with any third party.
What's the difference between consent and legitimate interest?
Consent: explicit opt-in (e.g., "Yes, send me marketing emails"). Legitimate interest: you process data for business reasons without consent (e.g., sending an invoice to a customer). Sensitive data requires consent; normal business data can use legitimate interest.
What if I get a customer request to delete their data?
Respond within 30 days. Delete personal data from active systems, but you may retain it for legal/tax compliance (e.g., invoices for 7 years). Explain in your response what you're keeping and why.
What penalties can I face?
Up to AED 2,000,000 fine for serious breaches (processing without consent, no security, failure to report breach). Minor compliance gaps may trigger warnings or smaller fines (AED 100,000โ500,000). Always report breaches quickly to minimize risk.