Data Protection Addendum Template for the United Arab Emirates
Generate a bespoke document
What is a Data Protection Addendum?
The Data Protection Addendum (DPA) is essential for businesses operating in the UAE that process personal data on behalf of others. It becomes necessary when one party (the data processor) processes personal data on behalf of another party (the data controller), ensuring compliance with UAE Federal Decree-Law No. 45/2021, as well as DIFC and ADGM data protection regulations where applicable. The DPA details specific obligations regarding data security, processing limitations, confidentiality, breach notifications, and cross-border transfers. It addresses both mandatory requirements under UAE law and international best practices, making it particularly important for organizations handling personal data across multiple jurisdictions or operating within UAE free zones. The document should be customized based on the specific type of data being processed, the industry sector, and whether any special categories of personal data are involved.
About the Data Protection Addendum
A Data Protection Addendum is a specialized contract that governs the relationship between data controllers and processors under United Arab Emirates data protection law. This document ensures your organization meets strict compliance requirements when handling personal data on behalf of others, protecting both parties from regulatory penalties and establishing clear accountability frameworks.
When do you need this document?
You need a Data Protection Addendum whenever your business processes personal data for another organization under Federal Decree-Law No. 45/2021. This includes cloud service providers handling customer databases, marketing agencies managing client contact lists, payroll companies processing employee information, and IT support firms accessing business systems containing personal data. The requirement applies whether you operate in UAE mainland, Dubai International Financial Centre (DIFC), or Abu Dhabi Global Market (ADGM), each with specific regulatory frameworks that may impose additional obligations beyond federal requirements.
Key legal considerations
Your Data Protection Addendum must address several critical legal obligations under UAE law. The document should specify exactly what personal data will be processed, define clear processing purposes, and establish retention periods that comply with regulatory requirements. Security measures must meet UAE standards, including technical and organizational safeguards appropriate to the data sensitivity level. Cross-border transfer provisions are essential, as UAE law restricts international data transfers unless adequate protection mechanisms are in place. The addendum must also establish breach notification procedures, ensuring incidents are reported to relevant authorities within required timeframes. Additionally, you need provisions covering data subject rights, audit requirements, and termination procedures that ensure proper data deletion or return.
Legal requirements in United Arab Emirates
UAE data protection compliance varies significantly depending on your operational jurisdiction within the emirates. Under Federal Decree-Law No. 45/2021, processors must implement appropriate security measures, maintain processing records, and notify controllers of data breaches within 72 hours. If you operate within DIFC, Law No. 5 of 2020 imposes GDPR-aligned requirements including mandatory data protection impact assessments for high-risk processing. ADGM entities must comply with Data Protection Regulations 2021, which establish specific consent requirements and individual rights procedures. Healthcare organizations face additional obligations under Federal Law No. 2 of 2019, requiring enhanced protections for medical data. Your addendum must also address UAE residency requirements for certain data types and establish clear procedures for regulatory inspections and information requests from authorities like the UAE Data Office or relevant free zone regulators.
GOVERNING LAW
Applicable law
This Data Protection Addendum is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Law No. 5 of 2020: Data Protection Law applicable in Dubai International Financial Centre, closely aligned with GDPR principles and establishing specific requirements for companies operating in DIFC
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection framework, establishing requirements for organizations operating within ADGM
UAE Federal Law No. 2 of 2019: Concerning the Use of Information and Communication Technology in Healthcare Fields, setting specific requirements for health data protection
SCA Decision No. (21/R.M) of 2020: Securities and Commodities Authority decision regarding data protection in financial services
UAE Cyber Crime Law (Federal Decree-Law No. 5 of 2012): Provides legal framework for cybersecurity and data protection violations, including penalties for unauthorized data access or disclosure
TDRA Data Protection Regulations: Telecommunications and Digital Government Regulatory Authority's requirements for data protection in the telecommunications sector
Central Bank Regulations: Various circulars and regulations related to data protection in the banking and financial services sector
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it