Tax& Law+7 (495) 221 31 46Discuss a matter
Article-by-article contents · Page 1 / 1
Personal Data Protection Law — articles 1–31
- Article 1 — Article (1) Definitions
In application of the provisions of this Decree by Law, the following words and phrases shall have the meanings assigned to each of them, unless the context otherwise requires: State: The United Arab Emirates Office: The…
- Article 2 — Article (2) Scope of Application of the Decree by Law
1. Provisions of this Decree by Law shall apply to the processing of all or part of the Personal Data by means of electronic systems which operate automatically, or by other means, by the following: 2. Each Data Subject …
- Article 3 — Article (3) Bureau's Power of Exemption
Without prejudice to any other competencies prescribes for the Bureau under any other legislation, the Bureau may exempt some establishments that do not process a large volume of Personal Data from part, or all of the re…
- Article 4 — Article (4) Cases of Processing Personal Data without the Consent of its Owner
It is prohibited to process Personal Data without the consent of its owner. The following cases shall be excluded from such prohibition: 1. If the processing is necessary to protect public interest. 2. If the processing …
- Article 5 — Article (5) Personal Data Processing Controls
Personal Data shall be processed according to the following controls: 1. Processing shall be carried out in a fair, transparent and lawful manner. 2. Personal Data shall be collected for a specific and clear purpose. It …
- Article 6 — Article (6) Terms of Consent to Data Processing
1. To be considered, the consent of the Data Subject to the processing of date shall require the following: a. The Controller shall be able to prove the consent of the Data Subject in the event that the processing of Per…
- Article 7 — Article (7) The Controller's General Obligations
The Controller shall abide by the following: 1. Take appropriate technical and organizational measures to implement the necessary standards to protect and secure Personal Data in order to preserve its confidentiality and…
- Article 8 — Article (8) The Processor's General Obligations
The Processor shall abide by the following: 1. Carry out the processing in accordance with the instructions of the Controller and contracts and agreements concluded between them, which specify in particular the scope, su…
- Article 9 — Article (9) Reporting Personal Data Breach
1. In addition to the obligations of the Controller stipulated in this Decree by Law, the Controller shall, at the time it becomes aware of the existence of any breach or violation of Personal Data of the Data Subject th…
- Article 10 — Article (10) Appointing Data Protection Officer
1. The Controller and Processor shall appoint a Data Protection Officer, who has sufficient skills and knowledge of the Personal Data Protection Law, in any of the following cases: a. If processing would cause a high-lev…
- Article 11 — Article (11) Roles of Data Protection Officer
1. The Data Protection Officer shall ensure the extent of compliance of the Controller or the Processor with the application of provisions of this Decree by Law, its Executive Regulations and instructions issued by the B…
- Article 12 — Article (12) Duties of the controller and the processor towards the Data Protection Officer
1. The Controller and the Processor shall provide all means to ensure that the Data Protection Officer performs the duties and tasks assigned to it as stipulated in Article (11) of this Decree by Law in the required mann…
- Article 13 — Article (13) Right to Receive Information
1. The Data Subject has the right, by submitting a request to the Controller without any consideration, to obtain the following information: a. The types of its Personal Data that are being processed. b. Purposes of proc…
- Article 14 — Article (14) Right to Request Transfer of Personal Data
1. The Data Subject shall have the right to receive his/her personal data that has been provided to the Controller for processing, in an orderly and machine-readable manner, whenever the processing is based on the consen…
- Article 15 — Article (15) Right to correction or erasure of Personal Data
1. The Data Subject shall have the right to request the correction of his/her inaccurate Personal data, or request to complete the data held by the Controller without undue delay 2. Without prejudice to the legislations …
- Article 16 — Article (16) Right to Restrict Processing
1. The Data Subject shall have the right to oblige the Controller to restrict and stop processing in any of the following cases: a. The Data Subject's objection to the accuracy of the Personal Data, in which case the pro…
- Article 17 — Article (17) Right to Stop Processing
The Data Subject shall have the right to object to the processing of his/her Personal Data and stop it in any of the following cases: 1. If the processing is intended for the purposes of direct marketing, including profi…
- Article 18 — Article (18) Right to Processing and Automated Processing
1. The Data Subject shall have the right to object to any decisions resulting from automated processing, including profiling, particularly those decisions which have legal impact on or adversely affect the Data Subject. …
- Article 19 — Article (19) Contacting the Controller
The Controller shall provide clear and appropriate ways for the Data Subject to contact the Controller to request any of the rights set forth in this Decree by Law.
- Article 20 — Article (20) Personal Data Security
1. The Controller and the Processor shall develop and take appropriate technical and regulatory measures to ensure the highest standard of information security that is suitable for the risks related to data processing in…
- Article 21 — Article (21) Assessment of the Impact of Personal Data Protection
1. Taking into account the nature, scope and purposes of data processing, the Controller shall, before carrying out the processing, evaluate the impact of the proposed processing operations on the protection of Personal …
- Article 22 — Article (22) Cross-Border Transfer and Sharing of Personal Data for Processing Purposes if a Proper Protection Level is Available
Personal Data may be transferred to outside of the State in the following cases approved by the Bureau: 1. The State or Province to which the Personal Data is transferred shall have legislations addressing Personal Data …
- Article 23 — Article (23) Cross-Border Transfer and Sharing of Personal Data for Processing Purposes if a Proper Protection Level is not Available
1. Notwithstanding Article (22) of this Decree by Law, Personal Data may be transferred to outside the State in the following cases: a. Companies, operating in countries where there are no laws for Data Protection, may t…
- Article 24 — Article (24) Complaints
1. The Data Subject shall have the right to submit complaints to the Bureau if he/she believes that there is a violation of this Decree by Law or that the Controller or the Processor is processing his/ her Personal Data …
- Article 25 — Article (25) Grievance against the Bureau's Decisions
Any stakeholder may submit a written grievance to the General Director of the Bureau against any decision or administrative penalty or any other action taken by the Bureau against such stakeholder within (30) thirty days…
- Article 26 — Article (26) Administrative Penalties
The Council of Ministers, based upon a suggestion from the General Director of the Bureau, shall issue a decision to limit the actions which constitute a violation of this Decree by Law and its Executive Regulations, inc…
- Article 27 — Article (27) Authorization
The Council of Ministers, based upon a suggestion from the General Director of the Bureau, may authorize any competent local government authority within the scope of its local competence, to exercise some of the Bureau' …
- Article 28 — Article (28) The Executive Regulation
The Council of Ministers, based upon a suggestion from the General Director of the Bureau, shall issue the Executive Regulations of this Decree by Law within six (6) months as of the date on which the Decree by Law is pr…
- Article 29 — Article (29) Regularisation
The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months as of the date on which its Executive Regulations are …
- Article 30 — Article (30) Repeals
Any provision that violates or contradicts the provisions of this Decree by Law shall be repealed.
- Article 31 — Article (31) Publication & Enforcement of this Decree by Law
This Decree by Law shall by published in the Official Gazette and shall come into force as of 02 January 2022.