Data Privacy Addendum Template for the United Arab Emirates

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Privacy Addendum?

The Data Privacy Addendum is essential for businesses operating in the UAE that process personal data, whether in mainland UAE or free zones like DIFC and ADGM. It is specifically designed to complement existing commercial agreements by incorporating comprehensive data protection provisions that align with Federal Decree-Law No. 45 of 2021 and other applicable regulations. This document becomes necessary when one party processes personal data on behalf of another, or when parties jointly determine the purposes and means of data processing. It covers crucial aspects such as data security measures, breach notification procedures, cross-border transfer mechanisms, and compliance with UAE data protection requirements. The addendum is particularly important given the UAE's evolving data protection landscape and the need to ensure compliance with both federal and free zone-specific regulations.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Privacy Addendum

A Data Privacy Addendum is a crucial legal document that establishes comprehensive data protection obligations between parties in the United Arab Emirates. This addendum supplements your existing commercial agreements by incorporating specific provisions required under UAE data protection laws, ensuring compliance with Federal Decree-Law No. 45 of 2021 and applicable free zone regulations.

When do you need this document?

You need a Data Privacy Addendum whenever your business relationship involves processing personal data in the UAE. This includes situations where you engage third-party service providers to process customer data, collaborate with business partners who access personal information, or operate across different UAE jurisdictions with varying data protection requirements. The addendum is particularly essential for cloud service agreements, outsourcing contracts, joint ventures, and any arrangement where personal data is shared between organizations. Free zone entities in DIFC and ADGM must ensure their addenda comply with jurisdiction-specific regulations that may impose stricter requirements than federal law.

Key legal considerations

Your Data Privacy Addendum must clearly define the roles of each party as data controller, processor, or joint controller under UAE law. Essential provisions include detailed data processing instructions, security measures aligned with industry standards, and incident response procedures for data breaches. The document should specify permitted data categories, processing purposes, and retention periods while establishing clear protocols for data subject requests. Cross-border transfer mechanisms require particular attention, as UAE law restricts international data transfers without adequate safeguards. You must also address sub-processing arrangements, ensuring any third parties meet the same protection standards and obtain necessary approvals before engaging additional processors.

Legal requirements in United Arab Emirates

UAE data protection compliance varies significantly depending on your operational jurisdiction. Under Federal Decree-Law No. 45 of 2021, your addendum must establish lawful bases for processing, implement appropriate technical and organizational measures, and ensure data subject rights protection. DIFC entities operating under Law No. 5 of 2020 face GDPR-inspired requirements including data protection impact assessments and mandatory breach notifications within 72 hours. ADGM's Data Protection Regulations 2021 impose similar obligations with specific free zone authority oversight. Your addendum must accommodate data localization requirements under Federal Law No. 19 of 2018 and cybercrime provisions under Federal Law No. 5 of 2012. Regular compliance audits, staff training programs, and documented consent mechanisms are mandatory across all jurisdictions, with penalties ranging from administrative fines to criminal liability for serious violations.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it