28 March 2022 · Lukáš Steiniger

The Dubai GDPR

The Dubai GDPR
Legal status as of the publication date (28 March 2022). Later legislative changes may not be reflected in the text.

The United Arab Emirates has adopted a new personal data protection law, which entered into force at the beginning of 2022. Dubai is therefore now experiencing the same “frenzy” that we in the European Union went through in 2016 to 2018, arising from the many new obligations brought about by the then-new GDPR taking effect.

Who should be interested in this development in Dubai, and why?

For us, perhaps the most important piece of information is whether the new personal data protection law applies to us. The answer to this question may vary depending on whether you have set up a company directly in Dubai, or whether you are targeting the Dubai market with an offer of goods and services from Slovakia, or whether you are a European entrepreneur whose goods a citizen of the United Arab Emirates can indeed order, but whose offer is aimed at the European market, or primarily at Slovakia.

The Dubai personal data protection law applies to the processing of personal data, whether in part or fully by automated as well as non-automated means, of data subjects who have a so-called domicile or place of business in the United Arab Emirates. The law also governs all personal data controllers established in the territory of the Emirates and, last but not least, controllers from third countries that process the personal data of data subjects from the United Arab Emirates.

The above means that you are required to adopt the rules arising from the new law both if you have set up a company in the United Arab Emirates and if you process the personal data of persons resident in that country through your Slovak company.

In general, it can be said that, for most European companies, aligning their procedures with the new rules in the Emirates should not be difficult, provided that their documentation and internal procedures already comply with the GDPR. The new personal data protection law largely mirrors the provisions of our GDPR and, with a few exceptions, it can be said to be an almost identical set of rules. It is important, however, not to overlook those exceptions — in practice they could constitute grounds for imposing a penalty.

European entrepreneurs may be surprised, for example, by the impossibility of relying on so-called legitimate interest as a legal basis for the lawful processing of personal data. In Slovakia this legal basis is used most often in practice, for example, when monitoring business premises with a camera system, in certain forms of direct marketing, or in keeping records of the list of persons who have entered a building.

On the other hand, the new legislation adds several legal bases that the GDPR does not explicitly list — these include, for example, the authorisation to process personal data without the data subject’s consent where the data subject has made them public themselves. The new law also responds promptly to the still-current Covid issue by including a legal basis for processing personal data for the purposes of protecting public health.

The extensive documentation that we in Slovakia are used to when fulfilling the information obligation is, in Dubai, significantly limited to the necessary minimum defined in the law. Data subjects nevertheless retain the right to obtain additional information, exercised by submitting a request. The transfer of personal data from the United Arab Emirates outside its territory has also been given its own rules. A lawful transfer will take place in the case of a transfer to countries that, pursuant to a decision of the supervisory authority, ensure an adequate level of protection.  

In addition to formal obligations such as preparing documentation and fulfilling the information obligation, we must not — in the EU or in the territory of the United Arab Emirates — forget the practical implementation of the rules within company processes. The protection of personal data must also be ensured from a technical, or material, point of view. Where you store the data, who has access to them, how long they are stored, and how you terminate the processing — this is only a fraction of the total number of practical questions that must be resolved in order to process personal data lawfully. There are all the more obligations if you process a large amount of different types of data, which may include specially regulated data such as sensitive data or the data of minors.

The crypto sphere mentioned at the outset also brings, in the implementation of European AML rules (rules adopted to combat money laundering), an obligation to collect and verify a larger amount of data. In these cases, a functioning business needs to adopt the right know-how, which will ensure procedures that comply with the legislation while doing so in a form that places as little burden as possible on the customer or business partner, and on you as well.