Under the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), your company is subject to specific compliance requirements if you process data of subjects residing in the UAE, even if you are based abroad .
1. Cross-Border Data Transfer
Transferring personal data outside the UAE is generally permitted if the destination country has an adequate level of protection. If the destination lacks such laws, you may still transfer data under Article 23 in the following cases :
- Contractual Safeguards: The transfer is governed by a contract obligating the recipient to adopt the measures and controls set out in the UAE PDPL.
- Explicit Consent: The data subject provides express consent for the transfer.
- Contractual Necessity: The transfer is necessary to execute or perform a contract between you and the data subject.
- Legal Requirements: The transfer is necessary for international judicial cooperation or to protect the public interest.
2. Data Protection Officer (DPO)
Under Article 10, companies must appoint a DPO if their processing involves high risks to data privacy (due to new technologies or the volume of data) or involves the systematic and extensive evaluation of sensitive data .
The DPO's responsibilities include :
- Monitoring compliance with the PDPL and its executive regulations.
- Verifying the quality and correctness of internal data processing procedures.
- Acting as a point of contact for the UAE Data Office (the Bureau) and handling data subject complaints.
3. General Compliance Requirements
- Lawful Processing: Ensure data is processed based on consent or other legal grounds defined in the law.
- Security Measures: Implement technical and organizational measures to protect data from unauthorized access or breaches.
- Data Subject Rights: Establish procedures for users to exercise their rights (e.g., access, correction, or deletion of data).
Next Steps:
- Audit your data flow: Identify exactly which countries your cloud servers are located in to determine if they meet "adequate protection" standards.
- Update Contracts: Ensure your agreements with cloud providers include the mandatory data protection clauses required by Article 23 .
- Assess DPO Necessity: Evaluate your processing volume to decide if a DPO appointment is legally mandatory for your specific operations.