Data Privacy Laws in Dubai Mainland: Complete Guide
A privacy policy written before anyone has looked at the systems describes an imaginary company.
For a company licensed on the Dubai mainland the reference point is Federal Decree-Law No. 45 of 2021, and the first piece of work is deciding, activity by activity, whether the business decides how data is used or only handles it on someone else's instructions. The guide explains why mainland, DIFC and ADGM are three separate regimes and what that means for moving employee records to an affiliate, how to build a data inventory before writing any policy, when consent is the wrong basis to rely on, and why health and biometric data need a separate decision. It then covers requests from individuals and the channels they arrive through, the contain, assess, record and notify sequence after an incident, and written terms with vendors and transfers out of the UAE.
Where to start if you hold personal data in Dubai
Most Dubai mainland companies discover their data protection obligations at an awkward moment: a customer asks what you hold about them, an enterprise client sends a data processing addendum for signature, or a laptop goes missing. At that point the questions are practical. What law applies to us? What are we supposed to have written down already? And who do we have to tell?
For a company licensed by the Department of Economy and Tourism and operating on the Dubai mainland, the starting point is the federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. It applies to personal data — information relating to an identified or identifiable person — and it governs both organisations that decide why and how data is used and those that only process it on someone else's instructions. Those two roles carry different duties, so establishing which one you occupy for each activity is the first piece of work, not a formality.
Mainland, DIFC and ADGM are not the same regime
The federal law is the reference point for mainland operations. DIFC and ADGM each have their own data protection regime, with their own registration and notification requirements and their own supervision inside the centre. A Dubai mainland company with a DIFC affiliate is therefore running two frameworks, and the transfer of employee or customer records between them is a transfer that needs a basis and a record, even though both entities sit in the same emirate and share a shareholder.
Sector rules sit on top. Health regulators, financial regulators and telecom rules impose their own confidentiality and record-keeping requirements, and where a sector rule is stricter, the sector rule is the one that will be quoted back to you in an inspection.
Know what you hold before you write a policy
A privacy policy written before anyone has looked at the systems is a document that describes an imaginary company. The order that works is: inventory first, then decisions, then documents.
The inventory should cover, for each category of data: what is collected, from whom, why, which system it sits in, who inside the business can see it, which external vendors touch it, whether it leaves the UAE, and how long it is kept. In most small and mid-sized businesses this exercise turns up a payroll spreadsheet, a CRM, a marketing platform, a CCTV system and a recruitment inbox that nobody had thought of as a data holding at all.
Have a reason for each use
Every use of personal data needs a lawful basis, and consent is only one of them. Where consent is relied on, it has to be a real choice — freely given, specific, capable of being withdrawn — which rules out pre-ticked boxes and bundled permissions that make service conditional on marketing. Where the processing is necessary to perform a contract, to comply with a legal obligation, or for another basis the law recognises, say so internally and record it, so that a withdrawn consent does not knock out processing that never depended on consent in the first place.
Sensitive categories — health data, biometric data and the like — attract stricter treatment. If you are running fingerprint attendance or storing medical certificates, treat that as a separate decision with its own justification rather than folding it into general HR processing.
The rights people can exercise against you
Individuals can ask what you hold about them, ask for corrections, object to certain uses, and in defined circumstances ask for deletion. The operational point is that these requests arrive by whatever channel the person happens to use — a support ticket, a WhatsApp message to a salesperson, a letter to the manager — and the clock starts when they arrive, not when they reach the right desk.
So build a route: a single monitored address, a person who owns the response, an identity check proportionate to the sensitivity of the data, and a short internal note recording what was asked, what was searched and what was sent. Respond within the period the law and its regulations specify, and where you refuse part of a request, say which part and why. Silence is what turns a request into a complaint.
Security, incidents and who gets told
The law requires security measures appropriate to the risk. In practice that means access limited to people who need it, credentials that are not shared, encryption where it is proportionate, backups that have actually been tested, and prompt removal of access when someone leaves. Most incidents we see are not sophisticated attacks; they are a departed employee whose account still works, or a shared drive open to the whole company.
When something does go wrong, the sequence is: contain, assess, record, notify. Assess what data was affected and what the consequences for the individuals could be. Record the incident and your reasoning contemporaneously — a reconstructed timeline written weeks later is worth very little. Notify the regulator, and where required the affected individuals, within the period the law specifies. Deciding all this during the incident is how deadlines get missed; write the procedure now, and name the people in it.
Vendors, group companies and transfers abroad
Outsourcing the processing does not outsource the responsibility. If a payroll bureau, cloud provider, marketing agency or offshore support team handles your data, you need a written arrangement covering what they may do with it, the security they must maintain, whether they can sub-contract, what happens on a breach, and what they must do with the data when the contract ends. Many enterprise vendors will only offer their standard terms; read them, because those terms are the ones you will be judged against.
Transfers outside the UAE need their own basis. The law's approach turns on whether the destination provides an adequate level of protection or whether appropriate safeguards are in place through contract or other recognised mechanisms. If your CRM, ticketing system or backup sits on infrastructure abroad, that is a transfer, and it should appear in your records with the mechanism you rely on identified.
What good looks like on file
An organisation that can respond credibly to a regulator or a large customer usually has the same short set of documents: a data inventory that matches reality, a lawful basis recorded for each processing activity, a public privacy notice consistent with the inventory, an internal handling policy, signed processing terms with each vendor, a transfer record, an incident procedure with named owners, a retention schedule, and evidence that staff were trained. None of it is elaborate. It is the absence of it, rather than any single technical failing, that makes a complaint difficult to defend.
Where a complaint escalates into a claim by a customer or a dispute with a vendor over who caused a breach, the contractual allocation of responsibility written at the start of the relationship decides most of the argument, which is why our technology dispute resolution team asks for the data processing terms before anything else.
Practical next steps
Run the inventory. Assign the roles. Fix the vendor paperwork, starting with the vendors holding the most sensitive data. Write the incident procedure and name the people who execute it. Give data subject requests a monitored address and an owner. Then keep the inventory current, because the version that is eighteen months out of date is the one that will be produced in evidence.
For guidance on your own data protection position, contact the Nour Attorneys team.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Related Resources
Explore more of our insights on related topics:
- AI Regulations Compliance Requirements in the UAE
- Blockchain Legal Defense Strategies for Dubai Businesses
- Cryptocurrency Compliance Guidelines for UAE Operators
- Data Privacy Laws for Multinational Entities