Company Privacy Notice Template for the United Arab Emirates

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Company Privacy Notice?

The Company Privacy Notice is a mandatory document for organizations operating in the UAE that collect, process, or store personal data. It is designed to comply with UAE Federal Decree Law No. 45 of 2021 and its Executive Regulations, which establish the UAE's comprehensive data protection framework. This document serves multiple purposes: it ensures regulatory compliance, provides transparency to data subjects about their rights and the organization's data handling practices, and establishes clear internal guidelines for data protection. The notice must be easily accessible to all stakeholders and should be updated regularly to reflect changes in data processing activities or regulatory requirements. For organizations operating in UAE free zones like DIFC or ADGM, additional provisions may need to be incorporated to address specific free zone regulations.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Company Privacy Notice

Your Company Privacy Notice is a critical legal document that demonstrates your organization's commitment to data protection and ensures compliance with United Arab Emirates privacy laws. This document serves as the primary communication tool between your company and data subjects, explaining how you collect, use, store, and protect personal information in accordance with UAE regulatory requirements.

When do you need this document?

You need a Company Privacy Notice whenever your organization processes personal data of UAE residents, employees, customers, or website visitors. This includes collecting contact information through websites, processing employee records, maintaining customer databases, or using third-party analytics tools. Organizations operating across multiple UAE jurisdictions, including free zones like DIFC or ADGM, must ensure their privacy notice addresses all applicable regulatory frameworks. The notice becomes essential when launching new digital services, implementing data-driven marketing campaigns, or establishing business operations that involve personal data processing.

Key legal considerations

Your privacy notice must clearly specify the legal basis for data processing under UAE law, whether based on consent, legitimate interest, or legal obligation. Include detailed information about data retention periods, cross-border transfer mechanisms, and data subject rights including access, rectification, and deletion. Address third-party data sharing arrangements and ensure your notice covers automated decision-making processes if applicable. Consider data localization requirements and specify whether data is stored within UAE borders or transferred internationally with appropriate safeguards. Include clear contact information for your Data Protection Officer and procedures for handling data subject requests and complaints.

Legal requirements in United Arab Emirates

Under Federal Decree Law No. 45 of 2021 and its Executive Regulations, your privacy notice must be written in clear, plain language and made easily accessible to all data subjects. The document must be provided at the point of data collection and updated whenever processing activities change significantly. For companies in DIFC, compliance with DIFC Law No. 5 of 2020 requires additional provisions regarding data breach notification and international transfer safeguards. ADGM-regulated entities must incorporate specific consent mechanisms and data subject right procedures under ADGM Data Protection Regulations 2021. Ensure your notice addresses sector-specific requirements if operating in regulated industries such as banking, healthcare, or telecommunications, and maintain records demonstrating how you provide notice to data subjects in compliance with UAE regulatory expectations.

GOVERNING LAW

Applicable law

This Company Privacy Notice is drafted to comply with United Arab Emirates law. Key legislation includes:

Federal Decree Law No. 45 of 2021: The UAE's primary federal data protection law that establishes the basic framework for personal data protection and processing. It includes requirements for data collection, processing, storage, and transfer.
Executive Regulations of Federal Decree Law No. 45 of 2021: Detailed implementation guidelines for the federal data protection law, specifying practical requirements for compliance, including specific provisions for privacy notices.
DIFC Law No. 5 of 2020: Data Protection Law specific to the Dubai International Financial Centre (DIFC) free zone, which may be relevant if the company operates within or processes data in the DIFC.
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations, applicable to companies operating within or processing data in the ADGM free zone.
UAE Consumer Protection Law (Federal Law No. 15 of 2020): Relevant for aspects of privacy notices that relate to consumer data protection and transparency in commercial transactions.
UAE Cyber Crime Law (Federal Decree Law No. 5 of 2012): Provides framework for cybersecurity and data protection requirements, including penalties for unauthorized access to personal data.
UAE Healthcare Data Protection Laws: Specific regulations governing health data privacy if the company handles medical or health-related information, including requirements from the Ministry of Health.
Central Bank Regulations on Data Protection: Specific requirements for financial institutions regarding data protection and privacy, relevant if the company operates in the financial sector.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it