The United Arab Emirates has issued for the first time a federal law for the protection of personal data, namely the 'Federal Decree-Law no. 45/2021 on the Protection of Personal Data' ('Personal Data Protection Law').
The provisions of the personal data protection law apply to the processing of personal data in the UAE, whether done automatically through electronic systems or via other means. Apart from the newly introduced Law, there exists separate data protection laws applicable to the Dubai International Financial Centre (DIFC), the Abu Dhabi Global Market (ADGM) and the Dubai Healthcare City.
Applicability
The Personal Data Protection Law is wide-reaching in its applicability which applies to:
A data subject who resides or carries out business in the UAE. A data subject refers to any natural person who is the subject of data that could be used to identify such a person;
Any controller or processor of data located in the UAE who carries out activities involving processing personal data of data subjects whether residing inside or outside the UAE; and
A controller or processor of data located outside the UAE, but carries out activities of processing personal data of data subjects inside the UAE.
'Personal Data' Defined
The personal data protection law clearly defines personal data into two types: Personal Data and Sensitive Personal Data.
Wherein, Personal Data refers to any data relating to an identified natural person, or one who can be identified directly or indirectly by way of linking data, using identifiers such as name, voice, picture, identification number, online identifier, geographic location, or one or more special features that express the physical, psychological, economic, cultural or social identity of such person. It also includes Sensitive Personal Data and Biometric Data.
Whereas, Sensitive Data, refers to any data that directly or indirectly reveal a natural person's family, racial origin, political or philosophical opinions, religious beliefs, criminal records, biometric data, or any data related to the health of such people, such as his/her physical, psychological, mental, genetic or sexual condition, including information related to health care services provided thereto that reveals his/her health status.
What Constitutes a Breach?
Article 5 of the UAE Personal Data Protection Law lays out the legal parameters for processing personal data and states that personal data must be collected only for a specific and clear purpose and should not be processed at any given period in a manner that is incompatible with that purpose. Further, personal data should be stored securely with adequate technical protections included in place, and it should be stored only with the identity of the data subject anonymized.
The controller of the personal data should obtain the consent of the data subject either in writing or in an electronic format, and the consent letter should indicate the right of the data subject to withdraw such consent at a later date.
A data breach may comprise of breach of information security and personal data by illegal or unauthorized access, including copying, sending, distributing, exchanging, transmitting, circulating or processing data in a way that leads to disclosure thereof to third parties, or damage or alteration thereof during the processes of storage, transmission and Processing.
The UAE Personal Data Protection Law provides for the Council of Ministers to issue a decision, based on the proposal of the Data Office’s General Manager, on the acts constituting a breach of this law and the administrative penalties to be imposed.
The new Personal Data Protection Law has come into force on 2 January 2022. One of the main objectives of this law has been to ensure that strict controls are in place for the Processing of personal data, to maintain its security, confidentiality and privacy.
The rights of the data subject have been clearly defined, including the right to object to and stop the processing of his or her personal data if the processing is for direct marketing purposes, including profiling related to direct marketing or whether the processing is for conducting statistical surveys unless the processing is necessary to achieve the public interest.
Copyright © of this article is retained by the author and/or other copyright owners. We explicitly grant you permission to download a copy, without any alteration, of this article for personal non-commercial research or study, without prior permission or any charge. This article can be utilized on your website or for marketing, however, we grant you permission to host this article on your website and no other rights. This content should not be altered in any way or sold commercially in any format without prior permission of the copyright holder. During reference of this article, full biographic details entailing the name of the author, his designation, the institute and the publishing date of the article shall be provided.
Your email address will not be published. Required fields are marked *
I owe the success of my case to Dr. Hassan's diligent approach. He remained focused, put me at ease and always went the extra mile. Dr. Hassan tirelessly put my case in the best possible light and I cannot thank him enough. I would highly recommend Dr. Hassan - I am grateful to him from the bottom of my heart.
Dr. Hassan Elhais is among the best legal consultants I have ever worked with. He has an amazing ability to reduce complex issues into a simple concept that non-legal people can understand. He consistently develops innovative litigation strategies that help us to achieve our ultimate legal goals.
...the extraordinary effort that has been exerted by the staff, and we specially thank Dr. Hassan Mohsen Alhais. Wishing your continues success & excellence...
I believe everyone should recognize what a difference Dr. Hassan Elhais work has made to people's lives; and especially to our family's life, because we will remain forever grateful to each and every one of his team.
Dr. Hassan Elhais never fears cases that involve exposure and he always gives me his honest assessment of our chances of success, which is invaluable to me.
He aided us not only in providing legal advice but also in all legal issues that required a long term strategic approach to achieve most favorable and optimum outcomes he provided us with high level of professional service.
Dr. Hassan Elhais is a responsible, reputable counsel who operates to high levels of service.
Dr Hassan Elhais is responsive, thorough and creative with his advice, and is a valued advisor and legal consultant.
Regardless of the complexity of the matter I know Dr. Hassan Elhais will consider not only legal strategy but also business practicalities in providing advice and litigation options.
I recommend Dr. Hassan Elhais to anyone who says 'I'm in legal trouble'. I was extremely satisfied with the high standard of his work. He has always been there when I have needed him and I refer all my clients, family and friends to him/his firm.
Dr. Hassan Elhais was very professional and he listened to my needs. He was very prompt, efficient and always kept me informed. Dr. Hassan Elhais's service was excellent and I would definitely recommend him to friends and colleagues.
Contact Me