Common Data Regulation Compliance Advisory Mistakes to Avoid in Dubai
The first deliverable is a jurisdiction map. A wrong map produces documents that look complete and comply with nothing.
"The UAE law" is rarely the whole answer to which data protection rules apply. A mainland company answers to Federal Decree-Law No. 45 of 2021 and the UAE Data Office, a DIFC company to the DIFC regime and its Commissioner of Data Protection, an ADGM company to ADGM's own regulations and office — and a group with entities in more than one place is subject to all of them at once. This article covers why a policy written for one regime does not carry the others, what a record of processing activities has to contain before the business can answer an access request or assess a breach, what signing standard contractual clauses actually commits the exporter and importer to, and why an intra-group transfer from DIFC to a mainland affiliate counts as a cross-border transfer.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
Ask a business in Dubai which data protection law applies to it and the answer is often "the UAE law". That answer is usually incomplete. A company on the Dubai mainland is subject to the federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, supervised by the UAE Data Office. A company registered in the Dubai International Financial Centre (DIFC) is subject to the DIFC's own data protection regime, supervised by the DIFC Commissioner of Data Protection. A company in the Abu Dhabi Global Market (ADGM) is subject to ADGM's regulations and its own data protection office. A group with entities in more than one of those places is subject to more than one regime at the same time, each with its own registrations, notices and contact points.
Most of the expensive failures in data compliance work start by skipping that question, or answering it once at incorporation and never revisiting it after the group added an entity, a cloud provider or a new customer database. The mistakes below are the ones that cost the most to unwind after a complaint or a breach.
Related: The same customer files usually sit inside an anti-money-laundering file as well. See our AML compliance advisory work, where record-keeping duties under the two regimes have to be reconciled rather than run separately.
Mistake 1: Treating DIFC, ADGM and federal rules as one regime
The DIFC regime is closely modelled on the EU General Data Protection Regulation. It works from the same building blocks: a lawful basis for each processing activity, defined roles for controller and processor, rights for the data subject to access, correct and erase, and controls on transferring personal data out of the Centre. ADGM's regulations follow similar principles but differ in their detail, including how consent must be obtained and how a breach is reported. The federal law applies to the rest of the UAE and has its own registration and notification requirements.
The practical consequence is that a single group policy written for one of these regimes will not carry the others. A privacy notice drafted for a DIFC entity does not discharge the obligations of an affiliate on the mainland. A data protection officer appointed for one entity is not automatically the point of contact for the others. Where a regime requires an annual notification or filing with its regulator, that filing is entity-specific.
Related: Our data regulation compliance advisory team starts every engagement by fixing which regime applies to which entity, and to which processing activity, before any policy is drafted.
The first deliverable in any credible advisory engagement is therefore a jurisdiction map: each legal entity, the regime that governs it, the regulator it answers to, the registration or notification it owes, and the processing activities it carries out. Everything else is built on that map, and a wrong map produces documents that look complete and comply with nothing.
Mistake 2: No record of what data the business actually holds
Policies are easy to buy. A record of processing activities has to be built from the inside, and it is what a regulator asks for first. It should say what categories of personal data the business holds, why it holds them, on what lawful basis, who inside the organisation can reach them, which third parties receive them, where those recipients are located, and how long the data is kept.
Without that record, three things become impossible. The business cannot answer a data subject access request within the period the applicable regime allows, because it does not know where the person's data sits. It cannot assess a breach, because it does not know what was in the affected system. And it cannot demonstrate accountability, which every one of these regimes requires as a standing obligation rather than a one-off exercise.
Assign the record to a named owner, review it when a system or vendor changes, and keep evidence of the reviews. A record that was accurate two years ago is not evidence of anything today.
Related: Businesses handling virtual assets carry a further layer of licensing and reporting duties. See our crypto regulation compliance advisory practice for how those obligations interact with data rules.
Mistake 3: Cross-border transfers handled by template
Each of the UAE regimes restricts sending personal data outside its jurisdiction. Broadly, a transfer is permitted where the destination has been recognised as offering an adequate level of protection, or where the exporter puts an approved safeguard in place, or where a specific exception applies. The safeguards available include standard contractual clauses and, for groups, binding corporate rules.
The recurring error is signing standard clauses and treating the file as closed. Standard clauses commit the exporter to assess whether the importer can in fact honour them given the laws it operates under, and to act if it cannot. They also commit the importer to specific security measures and to notify the exporter of government access requests. If nobody has read the schedules and confirmed that the stated measures are the ones actually in place, the contract records a promise the business is already breaching.
Note also that a transfer from a DIFC entity to a mainland UAE affiliate is a cross-border transfer for these purposes. Intra-group transfers between UAE entities in different regimes are the ones most often missed entirely.
Mistake 4: Impact assessments treated as paperwork
Where processing is likely to result in high risk to individuals, these regimes require an assessment before the processing begins. Large-scale monitoring, profiling that drives decisions about people, and processing of sensitive categories such as health or biometric data are typical triggers.
The assessment is useful only if it is done before the system is procured. Completed after go-live, it becomes a written record that the business identified a risk and proceeded anyway. Build it into the vendor approval process, not the compliance calendar.
What UAE businesses should do
Four steps carry most of the value. First, confirm which regime governs each entity and register or notify where that regime requires it. Second, build and maintain the record of processing activities, with a named owner. Third, review every contract under which personal data leaves the business, including cloud, payroll, marketing and group service agreements, and check that the transfer mechanism matches the route the data actually takes. Fourth, write and rehearse a breach response procedure that identifies who decides, who notifies the regulator, and who notifies affected individuals, within the timeframe the applicable regime sets.
None of this requires the largest possible programme. It requires knowing which rules apply and being able to show the regulator that you knew. Our data protection compliance team can carry out that review entity by entity.
Related Services: Explore our Data Regulation Compliance Advisory and wider data compliance services for practical legal support in this area.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Additional Resources
Explore more of our insights on related topics: