Global Privacy Notice Template for the United Arab Emirates
Generate a bespoke document
What is a Global Privacy Notice?
The Global Privacy Notice is a fundamental document required for compliance with UAE Federal Decree-Law No. 45/2021 and other applicable data protection regulations. It is essential for any organization operating in the UAE that processes personal data, whether dealing with customers, employees, or other stakeholders. The notice must be implemented when an organization begins collecting personal data and should be regularly updated to reflect changes in data processing activities or regulatory requirements. This document serves multiple purposes: ensuring compliance with UAE data protection laws, providing transparency to data subjects, and establishing clear guidelines for internal data handling practices. The Global Privacy Notice becomes particularly important when organizations operate across multiple jurisdictions or UAE free zones, as it must harmonize various privacy requirements while maintaining compliance with UAE federal law.
About the Global Privacy Notice
A Global Privacy Notice is your organization's comprehensive statement explaining how you collect, use, and protect personal data in compliance with UAE data protection laws. This document serves as the foundation of your privacy compliance program, providing transparency to customers, employees, and other stakeholders about your data handling practices.
When do you need this document?
You need a Global Privacy Notice before beginning any personal data collection activities in the UAE. This includes launching a website with data collection forms, implementing customer relationship management systems, processing employee information, or engaging with third-party service providers who handle personal data on your behalf. If your organization operates across multiple UAE jurisdictions, including DIFC or ADGM free zones, you must ensure your notice addresses the varying regulatory requirements. Companies expanding internationally also require this document to demonstrate compliance when transferring data across borders or working with global partners.
Key legal considerations
Your Global Privacy Notice must clearly identify your legal basis for processing personal data under UAE law, whether for contract performance, legal compliance, legitimate interests, or consent. The document should specify data retention periods, outline data subject rights including access and deletion requests, and explain your security measures for protecting personal information. You must also address cross-border data transfers, particularly if you share data with processors outside the UAE or operate in multiple jurisdictions. Include clear contact information for privacy inquiries and detail your complaint handling procedures. The notice should also specify how you handle sensitive personal data categories and any automated decision-making processes.
Legal requirements in United Arab Emirates
Under Federal Decree-Law No. 45/2021 and its Executive Regulations, your Global Privacy Notice must be written in clear, plain language and made easily accessible to data subjects. The law requires specific disclosures about data processing purposes, recipient categories, and international transfers. If operating in DIFC, you must also comply with DIFC Law No. 5 of 2020, which incorporates GDPR-like principles including enhanced consent requirements and stricter transfer restrictions. ADGM entities must follow the ADGM Data Protection Regulations 2021, which similarly align with international standards. Your notice must be available in Arabic for UAE mainland operations, and you're required to notify the UAE Data Office of certain high-risk processing activities. Regular updates to your notice trigger notification obligations to data subjects, and you must maintain records demonstrating compliance with all applicable privacy laws across your operational jurisdictions.
GOVERNING LAW
Applicable law
This Global Privacy Notice is drafted to comply with United Arab Emirates law. Key legislation includes:
Executive Regulations of Federal Decree-Law No. 45/2021: Detailed implementation regulations for the UAE Federal Data Protection Law, providing specific requirements and procedures
DIFC Law No. 5 of 2020: Data Protection Law for the Dubai International Financial Centre (DIFC) free zone, which is largely aligned with GDPR principles
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations, applicable to entities operating in the ADGM free zone
EU GDPR (Regulation 2016/679): While not UAE legislation, it's relevant for a global privacy notice as it affects UAE businesses dealing with EU residents' data
Federal Law No. 2 of 2019: UAE Cybercrimes Law which includes provisions related to privacy and data protection in digital contexts
UAE Consumer Protection Law (Federal Law No. 15 of 2020): Contains provisions related to consumer data protection and privacy rights in commercial transactions
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it