Our Team

STA's Team of Lawyers in Abu Dhabi, Bahrain, Doha, UAE, Luxembourg, Moscow, RAK, Sharjah, and Singapore. Find a Lawyer. ..

Read more information

UAE issues Landmark Federal Data Protection Law

UAE issues Landmark Federal Data Protection Law

The United Arab Emirates has recently published a landmark federal data protection law as part of the legal reforms issued by the UAE Cabinet Office. This Federal Decree-Law No. 45 of 2021 will come into force on the 2nd of January 2022 and will have extraterritorial jurisdiction. The Data Protection Law offers a framework to maintain confidentiality and preserve the privacy of persons by mandating organizations that fall under the scope of the Data Protection Law to have adequate governance for the administration and protection of personal data. The law will apply to both controllers and processors based in the UAE and those outside the UAE who will process the personal data of UAE residents (i.e., data subjects). This applicability expressly excludes government authorities, health, banking, and credit industries as they have sector-specific legislation and companies located in free zones as they have their data protection laws. The Data Protection Law will grant data subjects several rights regarding their data, including the right to request the transfer of their data, to access their data held by a controller, to have their data amended or erased, to restrict the processing of their data in certain circumstances, and to object to automatic processing - and certain types of data processing, such as marketing.

This Data Protection Law also establishes a Data Office enforced through Federal Decree-Law No. 44/2021 on Establishing the UAE Data Office. The office will also be in charge of developing data protection policies, overseeing the implementation of federal legislation governing personal data, and establishing methods for complaints and grievances. It will also guide authorities, including how to execute the data protection legislation.

In comparison to international data protection regimes, The UAE Data protection law can be compared to the 'GDPR,' or formally, the European Union's General Data Protection Regulation and Saudi Arabia's recent data protection law.  The UAE, like the GDPR, would prohibit the processing of personal data without data subjects' particular, clear, and unambiguous consent, expressed in the form of a clear positive statement or action. The consent requirement is waived if the processing is required to fulfill a contract with a data subject, comply with legal responsibilities, or defend the public interest.

Owing to this new law, all organizations subject to this new law should assess their activities and align themselves with the requirements. Data processors and controllers will have six months from the 2nd of January to ensure compliance with the new law.

 

Related Articles