Article-by-article contents · Page 1 / 1

Personal Data Protection Lawarticles 1–31

  1. Article 1 — Article (1) Definitions

    In application of the provisions of this Decree by Law, the following words and phrases shall have the meanings assigned to each of them, unless the context otherwise requires: State: The United Arab Emirates Office: The

  2. Article 2 — Article (2) Scope of Application of the Decree by Law

    1. Provisions of this Decree by Law shall apply to the processing of all or part of the Personal Data by means of electronic systems which operate automatically, or by other means, by the following: 2. Each Data Subject

  3. Article 3 — Article (3) Bureau's Power of Exemption

    Without prejudice to any other competencies prescribes for the Bureau under any other legislation, the Bureau may exempt some establishments that do not process a large volume of Personal Data from part, or all of the re

  4. Article 4 — Article (4) Cases of Processing Personal Data without the Consent of its Owner

    It is prohibited to process Personal Data without the consent of its owner. The following cases shall be excluded from such prohibition: 1. If the processing is necessary to protect public interest. 2. If the processing

  5. Article 5 — Article (5) Personal Data Processing Controls

    Personal Data shall be processed according to the following controls: 1. Processing shall be carried out in a fair, transparent and lawful manner. 2. Personal Data shall be collected for a specific and clear purpose. It

  6. Article 6 — Article (6) Terms of Consent to Data Processing

    1. To be considered, the consent of the Data Subject to the processing of date shall require the following: a. The Controller shall be able to prove the consent of the Data Subject in the event that the processing of Per

  7. Article 7 — Article (7) The Controller's General Obligations

    The Controller shall abide by the following: 1. Take appropriate technical and organizational measures to implement the necessary standards to protect and secure Personal Data in order to preserve its confidentiality and

  8. Article 8 — Article (8) The Processor's General Obligations

    The Processor shall abide by the following: 1. Carry out the processing in accordance with the instructions of the Controller and contracts and agreements concluded between them, which specify in particular the scope, su

  9. Article 9 — Article (9) Reporting Personal Data Breach

    1. In addition to the obligations of the Controller stipulated in this Decree by Law, the Controller shall, at the time it becomes aware of the existence of any breach or violation of Personal Data of the Data Subject th

  10. Article 10 — Article (10) Appointing Data Protection Officer

    1. The Controller and Processor shall appoint a Data Protection Officer, who has sufficient skills and knowledge of the Personal Data Protection Law, in any of the following cases: a. If processing would cause a high-lev

  11. Article 11 — Article (11) Roles of Data Protection Officer

    1. The Data Protection Officer shall ensure the extent of compliance of the Controller or the Processor with the application of provisions of this Decree by Law, its Executive Regulations and instructions issued by the B

  12. Article 12 — Article (12) Duties of the controller and the processor towards the Data Protection Officer

    1. The Controller and the Processor shall provide all means to ensure that the Data Protection Officer performs the duties and tasks assigned to it as stipulated in Article (11) of this Decree by Law in the required mann

  13. Article 13 — Article (13) Right to Receive Information

    1. The Data Subject has the right, by submitting a request to the Controller without any consideration, to obtain the following information: a. The types of its Personal Data that are being processed. b. Purposes of proc

  14. Article 14 — Article (14) Right to Request Transfer of Personal Data

    1. The Data Subject shall have the right to receive his/her personal data that has been provided to the Controller for processing, in an orderly and machine-readable manner, whenever the processing is based on the consen

  15. Article 15 — Article (15) Right to correction or erasure of Personal Data

    1. The Data Subject shall have the right to request the correction of his/her inaccurate Personal data, or request to complete the data held by the Controller without undue delay 2. Without prejudice to the legislations

  16. Article 16 — Article (16) Right to Restrict Processing

    1. The Data Subject shall have the right to oblige the Controller to restrict and stop processing in any of the following cases: a. The Data Subject's objection to the accuracy of the Personal Data, in which case the pro

  17. Article 17 — Article (17) Right to Stop Processing

    The Data Subject shall have the right to object to the processing of his/her Personal Data and stop it in any of the following cases: 1. If the processing is intended for the purposes of direct marketing, including profi

  18. Article 18 — Article (18) Right to Processing and Automated Processing

    1. The Data Subject shall have the right to object to any decisions resulting from automated processing, including profiling, particularly those decisions which have legal impact on or adversely affect the Data Subject.

  19. Article 19 — Article (19) Contacting the Controller

    The Controller shall provide clear and appropriate ways for the Data Subject to contact the Controller to request any of the rights set forth in this Decree by Law.

  20. Article 20 — Article (20) Personal Data Security

    1. The Controller and the Processor shall develop and take appropriate technical and regulatory measures to ensure the highest standard of information security that is suitable for the risks related to data processing in

  21. Article 21 — Article (21) Assessment of the Impact of Personal Data Protection

    1. Taking into account the nature, scope and purposes of data processing, the Controller shall, before carrying out the processing, evaluate the impact of the proposed processing operations on the protection of Personal

  22. Article 22 — Article (22) Cross-Border Transfer and Sharing of Personal Data for Processing Purposes if a Proper Protection Level is Available

    Personal Data may be transferred to outside of the State in the following cases approved by the Bureau: 1. The State or Province to which the Personal Data is transferred shall have legislations addressing Personal Data

  23. Article 23 — Article (23) Cross-Border Transfer and Sharing of Personal Data for Processing Purposes if a Proper Protection Level is not Available

    1. Notwithstanding Article (22) of this Decree by Law, Personal Data may be transferred to outside the State in the following cases: a. Companies, operating in countries where there are no laws for Data Protection, may t

  24. Article 24 — Article (24) Complaints

    1. The Data Subject shall have the right to submit complaints to the Bureau if he/she believes that there is a violation of this Decree by Law or that the Controller or the Processor is processing his/ her Personal Data

  25. Article 25 — Article (25) Grievance against the Bureau's Decisions

    Any stakeholder may submit a written grievance to the General Director of the Bureau against any decision or administrative penalty or any other action taken by the Bureau against such stakeholder within (30) thirty days

  26. Article 26 — Article (26) Administrative Penalties

    The Council of Ministers, based upon a suggestion from the General Director of the Bureau, shall issue a decision to limit the actions which constitute a violation of this Decree by Law and its Executive Regulations, inc

  27. Article 27 — Article (27) Authorization

    The Council of Ministers, based upon a suggestion from the General Director of the Bureau, may authorize any competent local government authority within the scope of its local competence, to exercise some of the Bureau'

  28. Article 28 — Article (28) The Executive Regulation

    The Council of Ministers, based upon a suggestion from the General Director of the Bureau, shall issue the Executive Regulations of this Decree by Law within six (6) months as of the date on which the Decree by Law is pr

  29. Article 29 — Article (29) Regularisation

    The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months as of the date on which its Executive Regulations are

  30. Article 30 — Article (30) Repeals

    Any provision that violates or contradicts the provisions of this Decree by Law shall be repealed.

  31. Article 31 — Article (31) Publication & Enforcement of this Decree by Law

    This Decree by Law shall by published in the Official Gazette and shall come into force as of 02 January 2022.

WAWhatsAppTGTelegram