[HEADER — replace with your organisation’s letterhead, if used]
Personal Data Protection Policy
UAE Federal PDPL — [COMPANY NAME]
One point must be checked before this policy is adopted. Federal Decree-Law 45/2021 has been in force since January 2022, but the status of its Executive Regulations is reported inconsistently by reputable sources — some describe them as issued with a compliance deadline, others as still unpublished. That affects notification periods, breach timelines and registration duties. Verify the current position with the UAE Data Office before relying on any specific deadline in this document.
| Item | Detail |
|---|
| Organisation | [COMPANY NAME], trade licence [NUMBER] |
| Jurisdiction of the entity | [Mainland / Free zone — name it] — if DIFC or ADGM, this policy does not apply; use the DIFC or ADGM policy instead |
| Data Protection Officer | [NAME], [DESIGNATION] |
| DPO contact | [EMAIL], [PHONE] |
| Approved by | [NAME], [DESIGNATION], on [DATE] |
| Effective from | [DATE] |
| Executive Regulations status verified on | [DATE] — source: [RECORD IT] |
| Review | Annually, and on publication of or amendment to the Executive Regulations |
1. Which Law Applies to Us
| Where the entity is established | Governing law | Regulator |
|---|
| UAE mainland | Federal Decree-Law 45/2021 (PDPL) | UAE Data Office |
| Free zone without its own data law (DMCC, JAFZA, RAKEZ, IFZA and others) | Federal PDPL | UAE Data Office |
| DIFC | DIFC Data Protection Law 5/2020, as amended | DIFC Commissioner of Data Protection |
| ADGM | ADGM Data Protection Regulations 2021 | ADGM Office of Data Protection |
| Outside the UAE, processing data of people in the UAE | Federal PDPL applies extraterritorially | UAE Data Office |
| Sector-regulated data — health, banking, telecoms, credit | Sector legislation in addition | Sector regulator |
1.1Mapping is per entity and per dataset, not per group. A group with a mainland company, a DMCC entity and a DIFC entity is operating under two regimes at once, and data moving between them is a cross-border transfer for DIFC purposes.
2. Scope
2.1This policy applies to all personal data the Company collects, uses, discloses, stores or transfers, whether about customers, employees, job applicants, suppliers or any other individual.
2.2"Personal data" means data relating to an identified natural person, or one who can be identified directly or indirectly by reference to identifiers.