Description

Adopted Personal Data Protection Law

On 27 November 2021, the United Arab Emirates adopted the Personal Data Protection Law (PDPL) through Federal Decree-Law No. 45, a large legal reform. The PDPL applies to any organisation that controls or processes personal data which is either established in the UAE or handles personal data of subjects within the UAE. The PDPL establishes the lawful bases for personal data processing, namely consent, public interest, public health protection or the performance of a contract, as well as the principles of data processing, namely fairness, transparency, minimisation, accuracy, and security. Moreover, the PDPL introduces obligations regarding the presence of a Data Protection Officer in data processing organisations, the creation of a record of processing activities, mandatory data breach reporting and data protection impact assessments. Furthermore, the PDPL introduces the subjects' rights to data access, rectification, erasure and portability. Cross-border data transfers are allowed only with approved countries or in case of contractual necessity, public interest or data subject's request. Finally, the PDPL introduces the penalties in case of violations and delegates to the data office the enforcement of the PDPL. The PDPL does not cover the UAE’s financial free zones, which possess their own personal data regulations, and does not apply to data processed by public authorities as well as health, banking and credit data. The PDPL will enter into force on 2 January 2022 but it will not be implemented until six months after the publication of dedicated executive regulations.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2021-11-27
adopted

On 27 November 2021, the United Arab Emirates adopted the Personal Data Protection Law (PDPL) throu…

2022-01-02
in grace period

The United Arab Emirates Personal Data Protection Law (PDPL) enters into force, but it will not be …

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data processing
Regulatory tool
Risk or other impact assessment requirement
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): data collection
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): transfer: cross-border

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data processing

personal data (all forms): storage (any form)

personal data (all forms): data collection

personal data (all forms): transfer: cross-border