GDPR: Features of the Personal Data Protection Regulation in Dubai, UAE

The United Arab Emirates, seeking to strengthen its reputation as a global business center and attract foreign investment, is working to create a reliable personal data protection system. The European Union's General Data Protection Regulation (GDPR) served as inspiration, but the UAE decree has been adapted to local conditions and legislative specifics. Understanding the main provisions of this regulation is critical for all organizations operating in the country and processing the personal information of citizens and residents.
A key principle borrowed from the GDPR is the consent of the data subject. Companies are required to obtain specific and informed consent to process information. This means that the customer must understand what data is being collected, for what purposes, and how it will be used. The UAE Regulation establishes the principles of legality, fairness, and transparency of the information processing process for the data subject.

Personal data is defined as any information used to identify an individual. For example, full name, place of residence, contact number, email, etc.

Compliance with the Regulation is mandatory for all organizations, regardless of their size or legal form, that process the personal data of citizens and residents of the Emirates. This applies to government agencies, private companies operating in the UAE, and international corporations.

Certain categories of personal information (race, political views, religious beliefs, genetic data) are considered high risk. In such cases, organizations must appoint a Data Protection Officer (DPO).

Requirements for DPOs include: residence in the Emirates, high qualifications and experience in data protection, and close cooperation with the DIFC Commissioner, who plays an important role in overseeing compliance with the Regulation. Specific requirements for the qualifications and experience of DPOs are likely to be clarified in subsequent regulations.

The UAE Regulation, like the GDPR, provides for certain exceptions, for example, for data processing for medical purposes, national security, or law enforcement. However, these exceptions are strictly regulated and must be justified.
The Dubai Personal Data Protection Regulation is an important step towards creating a digital economy based on trust and transparency. Knowledge of and compliance with the provisions of this Regulation is mandatory for all organizations operating in the UAE and will help avoid significant fines and damage to reputation. Keeping up to date with regulatory developments and best practices in data protection is essential for successful operations in this rapidly evolving region.

Get a free consultation
with an individual analysis of your situation

By clicking on the "Get a consultation" button, you agree to the Privacy Policy

You may find this interesting:

© Wivo Consulting. All rights reserved. Copying of materials from this website is prohibited.
The information posted on the website is for informational purposes only and under no circumstances constitutes a public offer.
Saturday - Sunday
Weekend
Monday - Friday
09:00 - 19:00
information:
for business:
for individuals:
Business Bay, Aspect Tower, Zone B (near Business Bay metro station)
Office address in Dubai:
Office hours:
Контакты
10-year golden visa in the UAE
2-year real estate owner visa in the UAE
Family visa (Dependent visa) in the UAE
Company owner visa in the UAE
Legalization of documents
Drawing up a will
Legal services in the UAE
Accounting services in the UAE
Re-registration of companies and amendments to constituent documents
Renewal of company licenses in the UAE
Trademark registration and intellectual property protection
Closure or freezing of companies in the UAE
Work visa in the UAE
© Wivo Consulting. All rights reserved. Copying of materials from this website is prohibited.
The information posted on the website is for informational purposes only and under no circumstances constitutes a public offer.