Data Protection Addendum Template for the United Arab Emirates

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Protection Addendum?

The Data Protection Addendum (DPA) is essential for businesses operating in the UAE that process personal data on behalf of others. It becomes necessary when one party (the data processor) processes personal data on behalf of another party (the data controller), ensuring compliance with UAE Federal Decree-Law No. 45/2021, as well as DIFC and ADGM data protection regulations where applicable. The DPA details specific obligations regarding data security, processing limitations, confidentiality, breach notifications, and cross-border transfers. It addresses both mandatory requirements under UAE law and international best practices, making it particularly important for organizations handling personal data across multiple jurisdictions or operating within UAE free zones. The document should be customized based on the specific type of data being processed, the industry sector, and whether any special categories of personal data are involved.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Protection Addendum

A Data Protection Addendum is a specialized contract that governs the relationship between data controllers and processors under United Arab Emirates data protection law. This document ensures your organization meets strict compliance requirements when handling personal data on behalf of others, protecting both parties from regulatory penalties and establishing clear accountability frameworks.

When do you need this document?

You need a Data Protection Addendum whenever your business processes personal data for another organization under Federal Decree-Law No. 45/2021. This includes cloud service providers handling customer databases, marketing agencies managing client contact lists, payroll companies processing employee information, and IT support firms accessing business systems containing personal data. The requirement applies whether you operate in UAE mainland, Dubai International Financial Centre (DIFC), or Abu Dhabi Global Market (ADGM), each with specific regulatory frameworks that may impose additional obligations beyond federal requirements.

Key legal considerations

Your Data Protection Addendum must address several critical legal obligations under UAE law. The document should specify exactly what personal data will be processed, define clear processing purposes, and establish retention periods that comply with regulatory requirements. Security measures must meet UAE standards, including technical and organizational safeguards appropriate to the data sensitivity level. Cross-border transfer provisions are essential, as UAE law restricts international data transfers unless adequate protection mechanisms are in place. The addendum must also establish breach notification procedures, ensuring incidents are reported to relevant authorities within required timeframes. Additionally, you need provisions covering data subject rights, audit requirements, and termination procedures that ensure proper data deletion or return.

Legal requirements in United Arab Emirates

UAE data protection compliance varies significantly depending on your operational jurisdiction within the emirates. Under Federal Decree-Law No. 45/2021, processors must implement appropriate security measures, maintain processing records, and notify controllers of data breaches within 72 hours. If you operate within DIFC, Law No. 5 of 2020 imposes GDPR-aligned requirements including mandatory data protection impact assessments for high-risk processing. ADGM entities must comply with Data Protection Regulations 2021, which establish specific consent requirements and individual rights procedures. Healthcare organizations face additional obligations under Federal Law No. 2 of 2019, requiring enhanced protections for medical data. Your addendum must also address UAE residency requirements for certain data types and establish clear procedures for regulatory inspections and information requests from authorities like the UAE Data Office or relevant free zone regulators.

GOVERNING LAW

Applicable law

This Data Protection Addendum is drafted to comply with United Arab Emirates law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it