Data Privacy Addendum Template for the United Arab Emirates
Generate a bespoke document
What is a Data Privacy Addendum?
The Data Privacy Addendum is essential for businesses operating in the UAE that process personal data, whether in mainland UAE or free zones like DIFC and ADGM. It is specifically designed to complement existing commercial agreements by incorporating comprehensive data protection provisions that align with Federal Decree-Law No. 45 of 2021 and other applicable regulations. This document becomes necessary when one party processes personal data on behalf of another, or when parties jointly determine the purposes and means of data processing. It covers crucial aspects such as data security measures, breach notification procedures, cross-border transfer mechanisms, and compliance with UAE data protection requirements. The addendum is particularly important given the UAE's evolving data protection landscape and the need to ensure compliance with both federal and free zone-specific regulations.
About the Data Privacy Addendum
A Data Privacy Addendum is a crucial legal document that establishes comprehensive data protection obligations between parties in the United Arab Emirates. This addendum supplements your existing commercial agreements by incorporating specific provisions required under UAE data protection laws, ensuring compliance with Federal Decree-Law No. 45 of 2021 and applicable free zone regulations.
When do you need this document?
You need a Data Privacy Addendum whenever your business relationship involves processing personal data in the UAE. This includes situations where you engage third-party service providers to process customer data, collaborate with business partners who access personal information, or operate across different UAE jurisdictions with varying data protection requirements. The addendum is particularly essential for cloud service agreements, outsourcing contracts, joint ventures, and any arrangement where personal data is shared between organizations. Free zone entities in DIFC and ADGM must ensure their addenda comply with jurisdiction-specific regulations that may impose stricter requirements than federal law.
Key legal considerations
Your Data Privacy Addendum must clearly define the roles of each party as data controller, processor, or joint controller under UAE law. Essential provisions include detailed data processing instructions, security measures aligned with industry standards, and incident response procedures for data breaches. The document should specify permitted data categories, processing purposes, and retention periods while establishing clear protocols for data subject requests. Cross-border transfer mechanisms require particular attention, as UAE law restricts international data transfers without adequate safeguards. You must also address sub-processing arrangements, ensuring any third parties meet the same protection standards and obtain necessary approvals before engaging additional processors.
Legal requirements in United Arab Emirates
UAE data protection compliance varies significantly depending on your operational jurisdiction. Under Federal Decree-Law No. 45 of 2021, your addendum must establish lawful bases for processing, implement appropriate technical and organizational measures, and ensure data subject rights protection. DIFC entities operating under Law No. 5 of 2020 face GDPR-inspired requirements including data protection impact assessments and mandatory breach notifications within 72 hours. ADGM's Data Protection Regulations 2021 impose similar obligations with specific free zone authority oversight. Your addendum must accommodate data localization requirements under Federal Law No. 19 of 2018 and cybercrime provisions under Federal Law No. 5 of 2012. Regular compliance audits, staff training programs, and documented consent mechanisms are mandatory across all jurisdictions, with penalties ranging from administrative fines to criminal liability for serious violations.
GOVERNING LAW
Applicable law
This Data Privacy Addendum is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Law No. 5 of 2020: The Data Protection Law specific to Dubai International Financial Centre, which is heavily influenced by GDPR and provides comprehensive data protection requirements for DIFC entities
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations that govern the processing of personal data within the ADGM free zone
Federal Law No. 19 of 2018: Foreign Direct Investment Law that may impact data localization requirements and cross-border data transfers
Federal Law No. 5 of 2012: The Cybercrime Law that includes provisions related to privacy and confidentiality of electronic information
UAE Cabinet Resolution No. 31 of 2019: Regulations concerning the Federal Law on Medical Liability, including provisions for health data privacy
UAE Central Bank Consumer Protection Regulation: Includes provisions for protecting financial consumer data and privacy in the banking sector
Federal Law No. 2 of 2019: The Use of ICT in Healthcare Law, which contains provisions for protecting health information and electronic health data
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it