01
First select the applicable mode
UAE's main private sector with statutory exceptions and extraterritorial scope.
DIFC Data Protection Law and Commissioner of Data Protection.
ADGM Data Protection Regulations and Office of Data Protection.
Health, banking, telecom, credit and government data may have additional requirements.
02
Scope, personal data and roles
Personal data is associated with an identified or identifiable person. The company describes each processing operation and defines controller, joint controllers, processor and subprocessor. The name in the contract does not replace the actual role.
- Data subjects
- Clients, employees, candidates, UBOs, counterparties and visitors
- Data
- Identity, contact, finance, device, location, communications and documents
- Sensitive / special
- Health, biometric, religion and other protected categories - according to the regime
- Controller
- Determines why and how to process
- Processor
- Acts on the documented instructions of the controller
03
Consent is not the only reason
For each purpose, an acceptable legal basis is selected for a specific regime. Consent must comply with legal requirements and be revocable; it cannot be used automatically where the relationship is not free or the processing is necessary for contract or law.
- Contract
- Processing objectively necessary for the contract with the subject
- Legal obligation
- KYC, tax, employment, accounting and regulatory records
- Consent
- Specific, informed and demonstrable consent
- Legitimate interests
- Only where the regime allows and after balance assessment
- Sensitive data
- Separate enhanced test and safeguards
04
Privacy notice and purpose limitation
The person is informed of the controller, goals, data categories, recipients, transfers, retention, rights and contact point. A new incompatible purpose requires re-evaluation and possibly a new basis and notice.
- Customer notice
- Onboarding, KYC, service, fraud, marketing and analytics
- Employee notice
- Recruitment, payroll, monitoring, benefits and investigations
- Cookies / apps
- Identifiers, SDK, analytics, advertising and location
- Languages
- Notice must be accessible and understandable to the audience
- Evidence
- Version, publication date, consent logs and change history
05
Subject rights and request workflow
The modes provide rights of access, correction, restriction or termination of processing and other rights to the established extent. The company verifies identity, exceptions, third-party data and response time.
- 01Intake
A single channel and recording the date of the request.
- 02Verify
Proportional identification of the applicant.
- 03Search
Systems, vendors, email, archive and backups.
- 04Review
Exceptions, legal privilege and data of other persons.
- 05Respond
Action, explanation and audit trail during the regime.
06
Security by data risk
Organizational and technical measures are selected based on scope, sensitivity, threats and consequences. The minimum program includes access control, encryption, logging, vulnerability management, backups, training and vendor security.
- Identity
- Least privilege, MFA, joiner-mover-leaver and privileged access
- Data
- Classification, encryption, DLP, retention and secure deletion
- Systems
- Secure development, testing, patching and change control
- People
- Confidentiality, training, phishing and disciplinary process
- Evidence
- Risk assessment, controls, tests, incidents and remediation
07
Data breach response
An incident becomes a personal data breach when it affects the confidentiality, integrity or availability of data. The facts, affected persons, harm, containment and the need to notify the regulator and subjects under the applicable regime are assessed.
Save evidence, limit the incident and launch an incident team.
What data, people, systems, countries and possible harm.
Notification test, content and deadline for a specific mode.
Root cause, remediation, lessons learned and documented decision.
08
Cross-border transfer
Cloud, group access and remote support can be international transfer. Before transfer, destination, adequacy or other valid mechanism, contract, onward transfer, government access risk and security are checked.
- Map
- Exporter, importer, countries, systems, data and purpose
- Mechanism
- Adequacy or provided safeguard/derogation
- Contract
- Processing instructions, security, breach, rights, audit and deletion
- Assessment
- Law and practice destination, access risk and supplementary measures
- Onward transfer
- Subprocessors and new countries are only under control
09
Processors, cloud and SaaS
Vendor due diligence is carried out before loading production data. The Controller remains responsible for the choice of processor and contract. Data locations, subprocessors, encryption, support access, deletion and exit are checked.
The marketing phrase “data is stored in the UAE” does not answer where support, analytics, security and group administrators have access.
10
HR, monitoring and direct marketing
Employee monitoring must have a specific purpose, legal basis, transparency and proportionality. For marketing, consent/opt-out, channel rules and suppression list are checked separately. Children's data requires enhanced protection.
- Recruitment
- CV, screening, retention and sharing within group
- Workplace
- CCTV, email/device monitoring, access logs and investigations
- Marketing
- Audience, source, consent, unsubscribe and evidence
- Children
- Age, guardian consent, profiling and targeted advertising restrictions
- AI
- Training data, automated decisions, bias, explainability and vendor roles
11
Working privacy program
- 01
Data map and register of processing by entity and mode.
- 02
Legal basis, notices, consent and retention schedule.
- 03
Vendor DPAs, transfers and subprocessor control.
- 04
Rights, breach, security and employee procedures.
- 05
DPO/owner, training, audit and annual review.
+7 (495) 221 31 46