Data Protection

Personal Data Protection Policy

One point must be checked before this policy is adopted. Federal Decree-Law 45/2021 has been in force since January 2022, but the status of its **Executive Regulations** is reported inconsistently by reputable sources — some describe them as issued with a compliance deadline, others as still unpublished. That affects notification periods, breach timelines and registration duties. Verify the current position with the UAE Data Office before relying on any specific deadline in this document.

Download as Word8 pages23 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Personal Data Protection Policy

UAE Federal PDPL — [COMPANY NAME]

One point must be checked before this policy is adopted. Federal Decree-Law 45/2021 has been in force since January 2022, but the status of its Executive Regulations is reported inconsistently by reputable sources — some describe them as issued with a compliance deadline, others as still unpublished. That affects notification periods, breach timelines and registration duties. Verify the current position with the UAE Data Office before relying on any specific deadline in this document.

ItemDetail
Organisation[COMPANY NAME], trade licence [NUMBER]
Jurisdiction of the entity[Mainland / Free zone — name it]if DIFC or ADGM, this policy does not apply; use the DIFC or ADGM policy instead
Data Protection Officer[NAME], [DESIGNATION]
DPO contact[EMAIL], [PHONE]
Approved by[NAME], [DESIGNATION], on [DATE]
Effective from[DATE]
Executive Regulations status verified on[DATE] — source: [RECORD IT]
ReviewAnnually, and on publication of or amendment to the Executive Regulations

1. Which Law Applies to Us

Where the entity is establishedGoverning lawRegulator
UAE mainlandFederal Decree-Law 45/2021 (PDPL)UAE Data Office
Free zone without its own data law (DMCC, JAFZA, RAKEZ, IFZA and others)Federal PDPLUAE Data Office
DIFCDIFC Data Protection Law 5/2020, as amendedDIFC Commissioner of Data Protection
ADGMADGM Data Protection Regulations 2021ADGM Office of Data Protection
Outside the UAE, processing data of people in the UAEFederal PDPL applies extraterritoriallyUAE Data Office
Sector-regulated data — health, banking, telecoms, creditSector legislation in additionSector regulator

1.1Mapping is per entity and per dataset, not per group. A group with a mainland company, a DMCC entity and a DIFC entity is operating under two regimes at once, and data moving between them is a cross-border transfer for DIFC purposes.

2. Scope

2.1This policy applies to all personal data the Company collects, uses, discloses, stores or transfers, whether about customers, employees, job applicants, suppliers or any other individual.

2.2"Personal data" means data relating to an identified natural person, or one who can be identified directly or indirectly by reference to identifiers.

Generated from www.helionerp.com1

7 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Verify the Executive Regulations status before adopting this policy

Federal Decree-Law 45/2021 has been in force since 2 January 2022, but the status of its Executive Regulations is reported inconsistently — some sources describe them as issued with a compliance deadline, others as still unpublished as of mid-2026. The regulations bear on notification periods, breach timelines, registration duties and the exemption for small-volume processors. Check with the UAE Data Office or a UAE data protection adviser, record the date and source in the header, and revisit this policy when the position settles.

Work to the law in the meantime, not to silence

Where the regulations are unresolved, the sensible course is to comply with the decree-law text, adopt international good practice for anything the text leaves open, document the approach taken, and keep the reasoning. An organisation that did nothing while waiting is in a materially worse position than one that implemented a defensible interim standard.

Map the jurisdiction first, per entity and per dataset

A DIFC entity follows DIFC Law 5/2020. An ADGM entity follows the ADGM Regulations. Everyone else, including most free zones, follows the federal PDPL. A group operating across two of these is running two regimes simultaneously, and the mapping is per entity and per dataset — not one answer for the group.

DIFC and ADGM are closer to GDPR than the federal law is

Both financial free zone regimes track European concepts closely, including legitimate interests as a lawful basis. The federal PDPL leans more heavily on consent. A legitimate-interests assessment prepared for a DIFC entity does not carry across to a mainland entity, and assuming it does is a common error in groups.

Mainland is not adequate for DIFC transfers

DIFC maintains its own adequacy list, and the UAE mainland is not on it. A transfer of personal data from a DIFC entity to a mainland affiliate requires contractual safeguards or another valid ground. Groups routinely move data between their own entities without treating it as a cross-border transfer at all.

Consent under the federal law must be evidenced

Consent must be specific, clear and capable of being demonstrated, and it can be withdrawn. Bundled consent buried in terms and conditions will not support processing. Where consent is the basis, keep the record of what was asked and when.

Identify sensitive data explicitly

Health, biometric, criminal record, religious and political data attract stricter requirements. Health data in particular arises in almost every UAE employer through mandatory medical testing and health insurance administration — it is usually present even where the organisation believes it holds no sensitive data.

Sector rules apply on top

Banking, healthcare, telecoms and credit data are subject to their own federal legislation and regulators in addition to the PDPL. Compliance with the PDPL alone is not sufficient in a regulated sector.

Report breaches first, assess second

Clause 7.2 instructs staff to report immediately and not to investigate first. The costliest delays come from someone trying to resolve a problem quietly before telling anyone, which loses containment time and often destroys the evidence needed to establish scope.

Record why a breach was not notified

Organisations document notified breaches and document nothing about those they assessed and dismissed. If the decision is later questioned, the absence of a record is indistinguishable from never having assessed. Clause 7.5 requires the reasoning either way.

Use 72 hours as the working standard until confirmed

Reported practice has included a 72-hour breach notification standard. Clause 7.4 adopts it internally as an interim position while documenting that the statutory deadline needs confirmation. That is defensible; guessing a longer period is not.

The record of processing is the foundation

Annexure A underpins everything else — retention, breach assessment, subject requests, transfer analysis and processor management all depend on knowing what data is held, why, where and for how long. Organisations that cannot complete it cannot do the rest properly.

Penalties are substantial

Administrative fines under the federal regime have been reported in the range of AED 50,000 to AED 5,000,000 depending on severity. This is not a regime to treat as aspirational.

Employee data is in scope

Payroll, Emirates ID copies, passport and visa records, medical test results, health insurance and WPS data are all personal data, much of it sensitive. Issue an employee privacy notice at onboarding — it is the document most often missing from an otherwise complete policy set.

Current as of

Reflects UAE law current as of {{DATE OF USE}}. **The status of the PDPL Executive Regulations is specifically unresolved in current sources and must be verified before this policy is relied on.** DIFC Law 5/2020 was amended with effect from July 2025 and DIFC introduced AI-specific regulation from January 2026 — confirm the current position for each jurisdiction with a UAE data protection adviser.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.