The federal personal data protection regime for the United Arab Emirates, establishing lawful basis, data subject rights and controller obligations.
Organisations processing the personal data of individuals in the United Arab Emirates, including controllers and processors established outside the country where they process the data of UAE data subjects. Certain free zones operate their own regimes, which is a scoping question rather than an exemption.
The first task is almost always discovery rather than control implementation. Most organisations cannot state, at the point they begin, what personal data they hold, where it lives, or who has access to it. Until that is established, a policy is a statement of intent. Cross-border transfer deserves particular attention: the law permits it with appropriate safeguards, and safeguards must be evidenced rather than asserted.
Supervisory compliance rather than a certificate. There is no PDPL certificate to display; there is a position you must be able to defend to a regulator, and to a customer performing due diligence.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.