UAE · Privacy & Data Governance

Personal data:
from system map to transfer

Federal PDPL, DIFC and ADGM are three separate modes. We define the applicable law, roles, legal basis, people's rights, security and international transfers.

3 modesmore than one universal PDPL
Controllerdefines goals and means
Processorprocesses on behalf of
Before transferlegal mechanism + security

01

First select the applicable mode

Federal PDPL

UAE's main private sector with statutory exceptions and extraterritorial scope.

DIFC

DIFC Data Protection Law and Commissioner of Data Protection.

ADGM

ADGM Data Protection Regulations and Office of Data Protection.

Sector rules

Health, banking, telecom, credit and government data may have additional requirements.

02

Scope, personal data and roles

Personal data is associated with an identified or identifiable person. The company describes each processing operation and defines controller, joint controllers, processor and subprocessor. The name in the contract does not replace the actual role.

Data subjects
Clients, employees, candidates, UBOs, counterparties and visitors
Data
Identity, contact, finance, device, location, communications and documents
Sensitive / special
Health, biometric, religion and other protected categories - according to the regime
Controller
Determines why and how to process
Processor
Acts on the documented instructions of the controller

03

Consent is not the only reason

For each purpose, an acceptable legal basis is selected for a specific regime. Consent must comply with legal requirements and be revocable; it cannot be used automatically where the relationship is not free or the processing is necessary for contract or law.

Contract
Processing objectively necessary for the contract with the subject
Legal obligation
KYC, tax, employment, accounting and regulatory records
Consent
Specific, informed and demonstrable consent
Legitimate interests
Only where the regime allows and after balance assessment
Sensitive data
Separate enhanced test and safeguards

04

Privacy notice and purpose limitation

The person is informed of the controller, goals, data categories, recipients, transfers, retention, rights and contact point. A new incompatible purpose requires re-evaluation and possibly a new basis and notice.

Customer notice
Onboarding, KYC, service, fraud, marketing and analytics
Employee notice
Recruitment, payroll, monitoring, benefits and investigations
Cookies / apps
Identifiers, SDK, analytics, advertising and location
Languages
Notice must be accessible and understandable to the audience
Evidence
Version, publication date, consent logs and change history

05

Subject rights and request workflow

The modes provide rights of access, correction, restriction or termination of processing and other rights to the established extent. The company verifies identity, exceptions, third-party data and response time.

  1. 01
    Intake

    A single channel and recording the date of the request.

  2. 02
    Verify

    Proportional identification of the applicant.

  3. 03
    Search

    Systems, vendors, email, archive and backups.

  4. 04
    Review

    Exceptions, legal privilege and data of other persons.

  5. 05
    Respond

    Action, explanation and audit trail during the regime.

06

Security by data risk

Organizational and technical measures are selected based on scope, sensitivity, threats and consequences. The minimum program includes access control, encryption, logging, vulnerability management, backups, training and vendor security.

Identity
Least privilege, MFA, joiner-mover-leaver and privileged access
Data
Classification, encryption, DLP, retention and secure deletion
Systems
Secure development, testing, patching and change control
People
Confidentiality, training, phishing and disciplinary process
Evidence
Risk assessment, controls, tests, incidents and remediation

07

Data breach response

An incident becomes a personal data breach when it affects the confidentiality, integrity or availability of data. The facts, affected persons, harm, containment and the need to notify the regulator and subjects under the applicable regime are assessed.

Detection

Save evidence, limit the incident and launch an incident team.

Evaluation

What data, people, systems, countries and possible harm.

Solution

Notification test, content and deadline for a specific mode.

After

Root cause, remediation, lessons learned and documented decision.

08

Cross-border transfer

Cloud, group access and remote support can be international transfer. Before transfer, destination, adequacy or other valid mechanism, contract, onward transfer, government access risk and security are checked.

Map
Exporter, importer, countries, systems, data and purpose
Mechanism
Adequacy or provided safeguard/derogation
Contract
Processing instructions, security, breach, rights, audit and deletion
Assessment
Law and practice destination, access risk and supplementary measures
Onward transfer
Subprocessors and new countries are only under control

09

Processors, cloud and SaaS

Vendor due diligence is carried out before loading production data. The Controller remains responsible for the choice of processor and contract. Data locations, subprocessors, encryption, support access, deletion and exit are checked.

Practical risk

The marketing phrase “data is stored in the UAE” does not answer where support, analytics, security and group administrators have access.

10

HR, monitoring and direct marketing

Employee monitoring must have a specific purpose, legal basis, transparency and proportionality. For marketing, consent/opt-out, channel rules and suppression list are checked separately. Children's data requires enhanced protection.

Recruitment
CV, screening, retention and sharing within group
Workplace
CCTV, email/device monitoring, access logs and investigations
Marketing
Audience, source, consent, unsubscribe and evidence
Children
Age, guardian consent, profiling and targeted advertising restrictions
AI
Training data, automated decisions, bias, explainability and vendor roles

11

Working privacy program

  1. 01

    Data map and register of processing by entity and mode.

  2. 02

    Legal basis, notices, consent and retention schedule.

  3. 03

    Vendor DPAs, transfers and subprocessor control.

  4. 04

    Rights, breach, security and employee procedures.

  5. 05

    DPO/owner, training, audit and annual review.

Official basis

Three modes - three sets of rules

The withdrawal and validity period are confirmed by federal law, DIFC or ADGM.

01

UAE Government — Data Protection Laws

Federal Decree-Law Official Review No. 45 of 2021, subject rights and cross-border transfers.

Open official source
04

ADGM — Office of Data Protection

Official ADGM Data Protection Regulations and regulator materials.

Open official source

Privacy readiness

Let's collect a data map and a legal international circuit

Let's check roles, documents, cloud, transfers and incident response.

Discuss data
WAWhatsAppTGTelegram