We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

UAE PDPL for a 30-Person Company: What the Federal Data Law Asks of You

UAE PDPL compliance for a small company: who the federal data law covers, what the 72-hour breach notice means, and six practical fixes for this week.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The lead's Emirates ID lives in a WhatsApp group

The office manager of a 30-agent real-estate brokerage in Business Bay runs the busiest group chat in the company. A new lead comes in, the agent photographs the Emirates ID and the passport page, drops both into the "Leads 2026" WhatsApp group, and the admin team opens the file. It has worked this way since 2019. Forty-one people are in the group, including nine agents who left, two former interns and a photographer.

On a Wednesday in August a buyer from Sharjah sends an email. He wants to know what personal data the brokerage holds on him, who it has been shared with, and a copy of the privacy notice he was shown when he handed over his ID. His lawyer is copied.

The office manager searches the website. There is no privacy notice. She searches the shared drive for a data policy and finds a tenancy contract template. The managing partner asks the IT company, who say they "do the network, not the legal side."

Nobody in the building knows how many copies of that buyer's ID exist, how many phones hold them, or how to delete one from the handset of an agent who resigned last year. The buyer's lawyer has given them ten working days.

What the heck does this mean

PDPL is the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. It is the UAE's federal rule for how any organisation collects, uses, stores and shares information about people. It has been in force since 2 January 2022, and it reaches a 30-person brokerage exactly as it reaches a bank.

A few terms, one line each.

Personal data: anything that identifies a person, an Emirates ID scan, a phone number, a passport photo in a chat.

Controller: the business that decides why and how the data is used. That is you.

Processor: a supplier that handles the data on your instructions, the CRM vendor, the payroll firm, the marketing agency.

Data subject rights: a person can ask what you hold, correct it, or have it erased, and you have to be able to answer.

The UAE Data Office: the federal regulator that receives breach notices under the law.

The practical test is short. If someone asked you today what data you hold on them, where it sits and who can see it, could you answer within a week? If the honest reply is "it depends which agent you ask," the law is not your problem. The filing system is.

The numbers that matter

PDPL has been in force since 2 January 2022 and applies to any entity processing the personal data of UAE residents, with no small-business exemption, under Federal Decree-Law 45 of 2021. Headcount does not get you out of it.

Article 11 of the same law requires the controller to notify the UAE Data Office within 72 hours of becoming aware of a qualifying breach (Federal Decree-Law 45 of 2021, Article 11). Seventy-two hours is one long weekend. If your first call on Friday evening is to find out who owns the problem, the clock has already eaten a day.

Phishing incidents in the UAE rose 32% in the first quarter of 2026, according to the UAE Cyber Security Council's 2026 figures. A stolen mailbox is the most common way a company finds out it has a breach to report, and the mailbox usually belongs to someone in admin, sales or finance.

What to do this week

  1. Build the data map on one sheet: what you collect, why, where it sits, who can see it, how long you keep it. Start with ID scans, lead forms and staff files, because those are what a complainant will ask about first. (CIS 3 Data Protection)
  2. Get the ID scans out of WhatsApp. Create a controlled folder with named access, move the images there, and remove every leaver from the group before you go home tonight. (CIS 3 Data Protection)
  3. Write a plain privacy notice and put it on the website and the lead form. Say what you collect, why, who you share it with and how someone asks for a copy or deletion. Two hundred words is enough to start. (CIS 3 Data Protection)
  4. List every supplier that touches personal data, the CRM, the property portal, the marketing agency, payroll, and get their processing terms in writing, including where the data is hosted. (CIS 15 Service Provider Management)
  5. Turn on audit logging in the CRM and in Microsoft 365 or Google Workspace, and make sure it keeps at least a year, so you can see who opened or exported a record when you need to. (CIS 8 Audit Log Management)
  6. Write the 72-hour page: who decides an incident is a reportable breach, who contacts the Data Office, who tells the people affected, and the phone numbers for each. Tape it inside the server cupboard. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment maps what you hold and how it is handled against PDPL and the sector rules that sit on top of it, with the gaps ranked so you know which to fix first. The read-only compliance agent then keeps that picture current: it gives you read-only insight into where the gaps are, we have no access to your systems and we do not remediate, and you or your IT partner make the fix while we show you where. A falcon does not scan the whole desert. It picks one thing out of the noise, and so should you.

Questions people ask

Do I need a data protection officer under PDPL? Only in specific cases. The law reserves the formal DPO role for organisations whose processing is large-scale or involves sensitive data and systematic evaluation of people. A 30-person brokerage or clinic usually sits outside that, but you still need one named person who owns the data map, the privacy notice and the 72-hour process. Write the name down; the regulator will ask who it is.

Does PDPL apply to employee data? Yes. The law protects the personal data of any natural person, and your staff are natural persons. Passport copies, visa files, salary records and the medical certificate someone sent in for sick leave all count. Keep them in HR's controlled folder, not the manager's inbox.

Can I store customer data outside the UAE? Sometimes, with conditions. PDPL allows transfers to countries the regulator recognises as offering adequate protection, and otherwise with safeguards such as contractual terms or the person's consent. Most cloud tools your team already uses store data abroad, so the practical step is to list them and get the transfer basis in writing from each vendor.

The buyer from Sharjah did not want money. He wanted to know who had his passport. Make sure you can tell him.

Questions people ask

Do I need a data protection officer under PDPL?

Only in specific cases. The law reserves the formal DPO role for organisations whose processing is large-scale or involves sensitive data and systematic evaluation of people. A 30-person brokerage or clinic usually sits outside that, but you still need one named person who owns the data map, the privacy notice and the 72-hour process. Write the name down; the regulator will ask who it is.

Does PDPL apply to employee data?

Yes. The law protects the personal data of any natural person, and your staff are natural persons. Passport copies, visa files, salary records and the medical certificate someone sent in for sick leave all count. Keep them in HR's controlled folder, not the manager's inbox.

Can I store customer data outside the UAE?

Sometimes, with conditions. PDPL allows transfers to countries the regulator recognises as offering adequate protection, and otherwise with safeguards such as contractual terms or the person's consent. Most cloud tools your team already uses store data abroad, so the practical step is to list them and get the transfer basis in writing from each vendor.

Controls this post maps to

CIS 3 Data ProtectionCIS 8 Audit Log ManagementCIS 15 Service Provider Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.