← Insights

UAE Employers Must Comply with 2025 PDPL Amendments on Employee Data

The 2025 PDPL amendment introduces explicit consent, impact assessments and strict breach-notification rules for employee data across the UAE.

This article explains the 2025 amendment to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, detailing new obligations for employers regarding employee personal data, cross-border transfers and breach notifications. It outlines the requirement for explicit consent or legitimate-interest basis, mandatory processing registers, data-protection impact assessments and the appointment of a Data Protection Officer where relevant.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

Employers in the UAE must now comply with the 2025 amendment to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), which introduces specific obligations for employee data handling, cross-border transfers, and breach notification across the UAE mainland and free zones.

Related Services: Explore our Data Protection Officer Service and Data Regulation & Compliance services for practical legal support in this area.

WHAT ARE THE NEW OBLIGATIONS FOR EMPLOYERS REGARDING EMPLOYEE PERSONAL DATA UNDER THE 2025 PDPL AMENDMENT?

The amendment requires employers to obtain explicit consent or rely on a legitimate-interest basis before processing employee personal data, to maintain a record of processing activities, and to implement appropriate technical and organisational measures to ensure data security. Employers must also appoint a Data Protection Officer if they process large volumes of special categories of data or engage in systematic monitoring of employees.

The 2025 amendment adds Article 12-bis to Federal Decree-Law No. 45 of 2021, stating that any processing of employee data must be documented in a processing register that includes the purpose, legal basis, data categories, retention period, and security measures. Employers must conduct a data-protection impact assessment when processing is likely to result in a high risk to employees' rights, particularly when using biometric systems or monitoring software. Failure to maintain the register or to carry out a required impact assessment can attract administrative fines of up to AED 500,000 under Article 66 of the PDPL. Employers must also provide employees with a clear privacy notice at the time of data collection, detailing the rights to access, rectify, erase, and restrict processing, as prescribed in Articles 13-15 of the law.

HOW DOES THE AMENDMENT AFFECT CROSS-BORDER TRANSFERS OF EMPLOYEE DATA?

Cross-border transfers of employee personal data are now subject to the same adequacy, contractual, and safeguard requirements that apply to any personal data under the PDPL, meaning employers must ensure the recipient country offers an equivalent level of protection or put in place approved standard contractual clauses, binding corporate rules, or obtain explicit employee consent for the transfer.

Article 28 of Federal Decree-Law No. 45 of 2021, as amended in 2025, mandates that a transfer outside the UAE may only occur if the destination is deemed adequate by the UAE Data Office, or if the employer implements one of the recognised transfer mechanisms. Employers must keep a copy of the transfer mechanism and make it available to the Data Office upon request. If no adequacy decision exists and no safeguard is in place, the transfer is prohibited unless the employee gives explicit, informed consent after being informed of the possible risks. Non-compliance can lead to fines of up to AED 1 million under Article 66, in addition to potential civil liability for damages suffered by employees.

WHAT BREACH-NOTIFICATION REQUIREMENTS MUST EMPLOYERS FOLLOW AFTER A DATA-PROTECTION INCIDENT INVOLVING EMPLOYEE DATA?

Employers must notify the UAE Data Office of a personal-data breach affecting employee data without undue delay and, where feasible, within 72 hours of becoming aware of the breach, and must inform affected employees if the breach is likely to result in a high risk to their rights and freedoms.

Article 33 of Federal Decree-Law No. 45 of 2021, as updated in 2025, sets the 72-hour notification window to the Data Office, requiring a description of the breach, the categories and approximate number of employee records concerned, the likely consequences, and the measures taken or proposed to mitigate the adverse effects. If the breach is likely to result in a high risk-such as exposure of identification documents, salary details, or health information-employers must also communicate the breach directly to the affected employees, providing clear guidance on protective steps they can take. Failure to meet the notification deadline or to inform employees when required can attract fines of up to AED 500,000 under Article 66, and may also lead to regulatory sanctions or corrective orders issued by the Data Office.

WHAT STEPS SHOULD EMPLOYERS TAKE TO PREPARE FOR A DATA-PROTECTION IMPACT ASSESSMENT?

Employers should first identify whether the planned processing is likely to result in a high risk to employees' rights, considering factors such as the use of new technologies, large-scale monitoring, or processing of special categories of data. If a high risk is identified, they must conduct an impact assessment that describes the processing, assesses necessity and proportionality, evaluates risks to employees, and outlines mitigation measures, as stipulated in Article 35 of Federal Decree-Law No. 45 of 2021. The assessment must be documented and made available to the UAE Data Office upon request.

Key practical actions include:

  • Mapping all employee-data flows (recruitment, payroll, performance monitoring, health-and-safety records, etc.).
  • Determining the legal basis for each flow and recording it in the processing register.
  • Evaluating whether the processing involves special categories (e.g., health, biometric, religious-belief data) or systematic monitoring (e.g., CCTV, keystroke logging).
  • Engaging an internal or external Data Protection Officer to oversee the assessment and ensure it meets the proportionality test.
  • Drafting mitigation measures such as pseudonymisation, access-control policies, regular staff training, and incident-response plans.
  • Retaining the assessment for the duration of the processing activity and making it available to the regulator on request.

HOW CAN EMPLOYERS ENSURE COMPLIANCE WITH THE PDPL'S RETENTION AND DELETION RULES?

The PDPL does not prescribe a universal retention period; instead, employers must define and justify retention periods in the processing register, ensuring data is kept no longer than necessary for the purposes for which it was processed, in line with Article 5(1)(e) of Federal Decree-Law No. 45 of 2021.

To operationalise this requirement, employers should:

  1. Classify data - Separate employee data into categories (e.g., contractual, payroll, health, performance) and assign a purpose to each.
  2. Set retention schedules - For each category, determine the minimum period required by law (e.g., labour-law payroll records for five years) or by legitimate business needs, and document the rationale.
  3. Implement automated deletion - Where feasible, configure HRIS or payroll systems to flag records approaching the end of their retention window for review and secure deletion.
  4. Maintain an audit trail - Keep logs of deletion actions, including who authorised the deletion and the method used, to demonstrate compliance during regulator inspections.
  5. Review periodically - Conduct an annual review of retention schedules to reflect changes in legislation, business operations, or technological capabilities.

If an employee requests erasure under Article 17, employers must verify whether any overriding legal obligation (e.g., retention for tax or litigation purposes) applies. If no such obligation exists, the data must be deleted promptly and any third-party recipients notified, unless retention is required for a legitimate claim.

WHAT ARE THE PENALTIES FOR FAILING TO APPOINT A DATA PROTECTION OFFICER WHEN REQUIRED?

If an employer is obliged to appoint a Data Protection Officer under Article 37 of Federal Decree-Law No. 45 of 2021 (triggered by large-scale processing of special categories or systematic monitoring) and fails to do so, the UAE Data Office may impose an administrative fine of up to AED 500,000 under Article 66, in addition to ordering compliance. The regulator may also issue a corrective order mandating the appointment within a specified timeframe, and continued non-compliance can escalate to higher fines or suspension of certain data-processing activities.

Employers should assess their processing scale early:

  • Large-scale - Generally understood as processing affecting a significant number of employees (e.g., >1,000 records) or involving special categories across multiple sites.
  • Systematic monitoring - Includes continuous video surveillance, keystroke logging, location tracking, or automated performance-scoring tools that operate without intermittent human review.

When either condition is met, appointing a qualified DPO-either internally (with adequate training and independence) or externally through a licensed service provider-is not only a legal requirement but also a risk-management best practice.

ARE FREE-ZONE COMPANIES SUBJECT TO THE SAME PDPL REQUIREMENTS AS MAINLAND EMPLOYERS?

Yes. Although DIFC and ADGM have their own data-protection regimes, companies operating in UAE free zones that are not DIFC or ADGM remain subject to the federal PDPL, including the 2025 amendment, unless they have opted into a free-zone-specific law that provides equivalent protection.

Employers in free zones such as Jebel Ali, Ras Al Khaimah Economic Zone, or Sharjah Research, Technology and Innovation Park must therefore:

  • Register their processing activities with the UAE Data Office if they meet the thresholds for mandatory registration.
  • Observe the same consent, impact-assessment, breach-notification, and cross-border-transfer rules as mainland entities.
  • Ensure any data-transfer agreements with entities outside the UAE comply with the PDPL's adequacy or safeguard mechanisms.

If a free-zone operator chooses to rely on the DIFC Data Protection Law or the ADGM Data Protection Regulations, they must confirm that the chosen regime offers a level of protection deemed equivalent by the UAE Data Office; otherwise, the federal PDPL applies by default.

WHAT PRACTICAL STEPS CAN EMPLOYERS TAKE TODAY TO ACHIEVE PDPL COMPLIANCE?

  1. Conduct a data-inventory audit - Identify all employee-data sources, storage locations, and processing purposes.
  2. Update privacy notices - Draft clear, concise notices that explain the legal basis, retention periods, and employee rights; distribute them at onboarding and whenever processing changes.
  3. Establish a processing register - Use a spreadsheet or dedicated GRC tool to capture the information required by Article 12-bis.
  4. Implement security controls - Apply encryption at rest and in transit, role-based access controls, regular vulnerability scanning, and incident-response playbooks.
  5. Train HR and line managers - Provide regular workshops on data-protection principles, consent management, and recognising high-risk processing activities.
  6. Engage a DPO or data-protection lead - Even if not strictly required, having a dedicated point of contact improves accountability and facilitates regulator interactions.
  7. Review third-party contracts - Ensure processors (payroll providers, cloud-HR vendors, background-check agencies) sign data-processing agreements that incorporate PDPL-standard clauses.
  8. Schedule periodic impact assessments - Particularly before deploying new monitoring technologies, biometric time-clocks, or employee-wellness apps that collect health data.

By embedding these practices into everyday HR operations, employers not only mitigate the risk of fines-ranging from AED 500,000 to AED 1 million per violation-but also foster trust with their workforce, enhance data-governance maturity, and position themselves favourably in an increasingly privacy-conscious market.

This article provides general information about the UAE PDPL 2025 amendment and does not constitute legal advice for any specific situation.

FREQUENTLY ASKED QUESTIONS

What must employers do before processing employee personal data under the 2025 PDPL amendment?

Employers must obtain explicit consent or rely on a legitimate-interest basis, maintain a record of processing activities, implement appropriate technical and organisational security measures, and appoint a Data Protection Officer when processing large volumes of special-category data or engaging in systematic employee monitoring.

How does the 2025 amendment regulate cross-border transfers of employee data?

Cross-border transfers must meet the same adequacy, contractual, or safeguard rules as any personal data: the destination must be deemed adequate by the UAE Data Office, or employers must use approved standard contractual clauses, binding corporate rules, or obtain explicit employee consent after informing them of risks.

What breach-notification obligations apply to employers after a data-protection incident involving employee data?

Employers must notify the UAE Data Office without undue delay and, where feasible, within 72 hours of awareness, providing breach details, affected records, likely consequences, and mitigation measures; if the breach poses a high risk to employees, they must also inform the affected individuals directly.

When is a data-protection impact assessment required for employee data processing?

An impact assessment is required when processing is likely to result in a high risk to employees' rights-such as using biometric systems, large-scale monitoring, or processing special-category data-and must describe the processing, assess necessity and proportionality, evaluate risks, and outline mitigation measures.

How should employers handle retention and deletion of employee data to comply with the PDPL?

Employers must define and justify retention periods in the processing register, keeping data no longer than necessary; they should classify data, set retention schedules based on legal or business needs, implement automated deletion where possible, maintain audit trails, and review schedules annually.

If your matter involves data protection in the United Arab Emirates, you are welcome to request a consultation with Nour Attorneys. Our team can assess your position under the law currently in force and outline the options available to you. Request a consultation

This article is provided for general informational purposes only and does not constitute legal advice. Reading this article or contacting Nour Attorneys through this website does not create an attorney-client relationship; such a relationship arises only after a conflicts-of-interest check and a signed engagement agreement. Do not send confidential information through this website; information submitted before engagement is not protected by legal privilege. Past results do not guarantee future outcomes. The firm's lawyers practice in the jurisdictions stated in their individual profiles; this article addresses the law of the United Arab Emirates only.

DISCLAIMER

This article is for informational purposes only and does not constitute legal advice.

Additional Resources

Explore more of our insights on related topics:

UAE Employers Must Comply with 2025 PDPL Amendments on Employee Data
Call Us NowChat With Our Team On WhatsApp