Description

Entry into force with grace period of Personal Data Protection Law

The United Arab Emirates Personal Data Protection Law (PDPL) enters into force, but it will not be implemented until six months after the publication of dedicated executive regulations. The Law applies to any organisation that controls or processes personal data established in the UAE or that controls or processes personal data of subjects inside the UAE. The data processed by public authorities and health, banking and credit data are excluded from the PDPL scope. The Law establishes that the lawful bases for personal data processing can be consent, public interest, public health protection or the performance of a contract, and the data processing are required to follow the principles of fairness, transparency, minimisation, accuracy, and security. Therefore, the Law introduces obligations regarding the presence of a Data Protection Officer in data processing organisations, the creation of a record of processing activities, mandatory data breach reporting and data protection impact assessments. Moreover, the Law introduces the subjects' rights to data access, rectification, erasure and portability. The cross border data transfers are allowed only with approved countries or in case of contractual necessity, public interest or data subject's request. The Law does not cover the UAE’s financial free zones, which possess their own personal data regulations. Finally, the Law introduces the penalties in case of violations and delegates to the data office the enforcement of the Law.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2021-11-27
adopted

On 27 November 2021, the United Arab Emirates adopted the Personal Data Protection Law (PDPL) throu…

2022-01-02
in grace period

The United Arab Emirates Personal Data Protection Law (PDPL) enters into force, but it will not be …

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data processing
Regulatory tool
Risk or other impact assessment requirement
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): data collection
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
Regulator notification requirement
User right to restriction of personal data processing
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
User consent: Opt-in requirement
Technical standard adherence
User right against automated decision making
Sanctions
Determined by existing law or regulation
Regulated subjects
1
personal data (all forms): transfer: cross-border

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data processing

personal data (all forms): storage (any form)

personal data (all forms): data collection

personal data (all forms): transfer: cross-border