Compliance

UAE PDPL: a practical compliance checklist for SMEs

The law is written in obligations. Your team needs it written in controls. This is the translation.

Note: This article is general information, not legal advice. The PDPL implementation timeline has moved more than once and public reporting on it is inconsistent, so confirm current obligations and deadlines with the UAE Data Office or your legal counsel before relying on them.

Federal Decree-Law No. 45 of 2021 is the UAE's federal personal data protection law. If you hold personal data about people in the UAE — staff records, customer databases, CCTV footage, a mailing list — it is aimed at you, and it reaches organisations outside the UAE that process UAE residents' data as well.

Most compliance guidance restates the legal obligations. That is not the hard part. The hard part is working out what you are supposed to do on Monday morning. Below is the checklist we work through with clients, expressed as controls rather than articles.

1. Find out what you actually hold

You cannot protect or justify data you have not catalogued. Build a data inventory covering, for each collection of personal data: what it is, where it lives, who has access, why you hold it, how long you keep it, and whether it leaves the country.

Start with the places data actually accumulates in a small business, which are rarely the places people name first: shared mailboxes, the HR folder on the file server, WhatsApp on staff phones, the CCTV recorder, spreadsheets on individual laptops, and whatever the marketing agency has.

This step routinely takes a week and routinely finds something nobody expected. It is the foundation for everything else.

2. Establish a lawful basis for each one

For every item in that inventory you need a defensible reason for holding it. Consent is one basis and, in practice, not the most useful one — consent must be freely given and withdrawable, which makes it fragile for anything operational. Contractual necessity, legal obligation and legitimate interest cover most ordinary business processing.

The practical failure here is data collected for one purpose and quietly reused for another: a customer list gathered to fulfil orders, later used for marketing.

3. Delete what you should not still have

Retention is where most SMEs are furthest from compliant, because the default behaviour of every system is to keep everything forever. Set retention periods per data type, document the reasoning, then actually enforce them.

In Microsoft 365 that means Purview retention policies rather than trusting individuals to tidy up. For file shares it usually means an archive-and-purge exercise nobody will enjoy. Old data you have no reason to hold is pure liability: it cannot help you, and it can be breached.

4. Be able to answer a data subject request

Individuals have rights over their data — to access it, correct it, have it erased, object to processing, and receive it in a portable form. You need a process that works before the first request arrives, not after.

Concretely: a named owner, a monitored channel for requests, an identity-verification step, a documented search procedure covering every system in your inventory, and a log of what you did and when. The search is the part that fails, and it fails because of step 1.

5. Secure it proportionately

The law requires appropriate technical and organisational measures rather than prescribing a product list. For a typical UAE SME, "appropriate" realistically means:

  • Multi-factor authentication on every account, with no standing exceptions
  • Access on a least-privilege basis, reviewed when people change role — not only when they leave
  • Encryption at rest and in transit, which you largely get by default in Microsoft 365 and Azure
  • Managed, patched endpoints, with the ability to remotely wipe a lost device
  • Tested backups, held separately from the live system
  • Logging that would let you reconstruct who accessed what, retained long enough to be useful
  • Staff awareness training, recorded — phishing remains the entry point in the majority of incidents

None of that is exotic, and most of it is included in licensing you may already own.

6. Know your breach procedure before you need it

A breach obliges you to notify, and notification runs to a clock. Write the runbook now: who is called first, who decides whether it is notifiable, who contacts the regulator and affected individuals, and where the incident log lives. Rehearse it once. An untested plan is a document, not a capability.

7. Check whether you need a Data Protection Officer

A DPO is required where processing is large-scale, involves sensitive categories of data, or relies on systematic profiling. Many SMEs fall below that, but you should be able to show you assessed it rather than assumed it. Record the assessment either way.

8. Control cross-border transfers

Personal data leaving the UAE is restricted, and what is permitted depends on the destination's protection regime and the safeguards in place. For most businesses this is really a question about cloud services: where your tenant is hosted, where your backups land, and where your SaaS vendors process data. Microsoft publishes data residency commitments and the UAE has in-country regions, so it is worth knowing which applies to you rather than assuming.

9. Put your processors under contract

Anyone processing personal data on your behalf — payroll bureau, CRM vendor, marketing agency, IT provider — needs a written agreement covering security obligations, breach notification, sub-processors and what happens to the data at the end of the relationship. Your obligations do not transfer to them; you remain accountable.

That applies to your IT provider too, and it is a fair question to ask us.

10. Write it down

Accountability means being able to demonstrate compliance, not merely achieve it. The inventory, the lawful basis register, the retention schedule, the DPO assessment, the training records, the breach runbook and the processor agreements are the evidence. Undocumented good practice is indistinguishable from luck when someone asks.

Where to start if this is all new

Do step 1. Everything else depends on it, and it is the step you can begin without budget approval, legal input or a project plan. A week spent finding out what personal data your business actually holds will tell you more about your exposure than any amount of reading about the law.

Questions

Frequently asked

Does the UAE PDPL apply to small businesses?

Yes. The law applies based on whether you process personal data of people in the UAE, not on company size. A small business holding staff records, a customer database or CCTV footage is in scope. Some obligations, such as appointing a Data Protection Officer, are triggered by the scale and sensitivity of processing rather than applying universally.

Do we need a Data Protection Officer?

A DPO is required where processing is large-scale, involves sensitive categories of personal data, or relies on systematic profiling. Many SMEs fall below that threshold, but you should document the assessment you made rather than simply assuming it does not apply.

Can we store UAE personal data outside the UAE?

Cross-border transfers are restricted and depend on the protection regime in the destination country and the safeguards in place. In practice this is usually a question about where your cloud tenant, backups and SaaS vendors process data, so it is worth confirming the data residency of the services you already use.

What is the first practical step towards PDPL compliance?

Build a data inventory: what personal data you hold, where it lives, who can access it, why you hold it, how long you keep it and whether it leaves the country. Every other obligation depends on knowing this, and it is the one step you can start without budget or legal input.

Let's talk

Ready to get started?

Tell us your team size, your current systems and your biggest IT headache. We'll come back with a clear, fixed-price proposal.

Book a Free Consultation
💬