Data Protection

IT and Information Security

Two UAE-specific points sit inside what looks like a standard IT policy. **Online conduct is regulated** — the cybercrime framework reaches speech, images and content in ways employees relocating from elsewhere do not expect. And **VPN use to access restricted services can itself be an offence** depending on purpose. Say both plainly.

Download as Word6 pages20 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

IT and Information Security

Acceptable use, access and incidents

Two UAE-specific points sit inside what looks like a standard IT policy. Online conduct is regulated — the cybercrime framework reaches speech, images and content in ways employees relocating from elsewhere do not expect. And VPN use to access restricted services can itself be an offence depending on purpose. Say both plainly.

ItemDetail
Company[COMPANY NAME], licence [NUMBER]
Applies toAll employees, contractors and anyone using Company systems
IT contact[NAME], [EMAIL]
Security incident reporting[EMAIL] / [PHONE]immediately
Data protection regime[Federal PDPL / DIFC / ADGM]
Personal devices permitted?[Y/N — see Section 4]
Monitoring in place[DESCRIBE]
Approved by[NAME] on [DATE]
ReviewAnnually

1. Acceptable Use

1.1Company systems, devices, accounts and data are provided for Company business. Reasonable personal use is permitted provided it does not interfere with work, consume significant resources, or breach this policy.

1.2Users shall not:

(a)share passwords or allow another person to use their account;

(b)install unapproved software, or connect unapproved devices;

(c)disable security controls, antivirus or encryption;

(d)access data they have no business need to see;

(e)copy Company data to personal accounts, devices or storage;

(f)use Company systems to harass, discriminate, or distribute offensive material; or

(g)use Company systems for any unlawful purpose.

2. Online Conduct — UAE Specific

2.1The UAE regulates online conduct more closely than many jurisdictions employees may have come from. The cybercrime framework reaches, among other things, defamation and insult, publishing images of people without consent, content offensive to religion or public morals, spreading false information, and unauthorised access to systems.

2.2This applies to personal social media as well as Company systems, and consequences can include criminal penalties and effects on residence status.

2.3Do not photograph or film people without their consent and do not post images of colleagues, customers or members of the public without permission. This is among the most commonly misunderstood rules.

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Cover UAE online conduct explicitly at induction

The cybercrime framework reaches defamation and insult, publishing images of people without consent, content offensive to religion or public morals, and spreading false information — with criminal penalties and possible effects on residence. Employees relocating from other countries assume their home norms apply. A short, plain paragraph at induction prevents a serious problem.

Photographing people without consent is the common trap

Posting a photograph of a colleague, a customer or a stranger without permission is among the most frequently misunderstood rules, and it arises constantly with team photos, event coverage and social media. Say it directly rather than burying it.

Be accurate about VPNs

Using a VPN is not automatically unlawful, and telling staff it is will simply be disbelieved. Using one to access restricted services or to commit or conceal an offence can be an offence. State the distinction precisely — an inaccurate policy loses credibility on everything else.

Personal social media is in scope

Conduct outside work reaches employment and residence status in ways that differ from many jurisdictions. This is not the employer being controlling; it is a factual position employees benefit from knowing.

Revoke access on the last working day

Resigning an office, leaving the country and having a visa cancelled remove none of a person’s system access. Dormant accounts belonging to former employees appear in almost every diligence exercise, and they are the easiest finding to avoid.

Rotate shared credentials on departure

Where a shared account genuinely cannot be avoided, its credentials must change whenever anyone with access leaves. Shared accounts also destroy accountability in an investigation, which is the second reason to minimise them.

Report incidents before investigating

The most damaging delays come from a well-intentioned attempt to fix something quietly. That loses containment time and frequently destroys the logs needed to establish what was accessed. Report first, contain second, investigate third.

Preserve logs before remediating

Rebuilding a compromised machine destroys the evidence needed to determine whether personal data was accessed — which is the question the breach assessment turns on. Image or preserve before restoring.

Know which data protection regime applies

Federal PDPL, DIFC or ADGM depends on where the entity is established, and they differ on breach notification and rights. An incident response plan citing the wrong regulator will fail at the worst moment.

Working abroad is a transfer question

An employee accessing UAE-held personal data from another country is receiving that data there. Where the employer is in DIFC or ADGM, or the destination lacks an adequacy finding, safeguards are needed. Remote access counts even where nothing is downloaded.

Employee data is sensitive and abundant

Passport copies, Emirates ID copies, visa records and medical test results all pass through a UAE employer, and much of it is sensitive personal data. Access to HR systems should be narrow and logged.

Tell people about monitoring

Monitoring is permissible and sensible, but it must be proportionate and disclosed. Covert monitoring without a clear lawful basis is a data protection breach and, separately, destroys trust once discovered.

Personal devices need a clear position

Either permit them with security requirements and a right to remove Company data, or prohibit them. The middle position — tolerating them without rules — is where Company data ends up on unmanaged phones and personal cloud accounts.

Review access quarterly against actual roles

Access accumulates as people move between roles and nobody removes what they no longer need. A quarterly review against current responsibilities is the control that prevents a single compromised account reaching everything.

Current as of

Reflects UAE law current as of {{DATE OF USE}}. The cybercrime framework, data protection regimes and their breach notification requirements, and rules on online content and VPN use all change — confirm the current position with a UAE adviser, and note that DIFC and ADGM entities follow their own data protection regimes.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.