Blog / UAE compliance
UAE compliance
UAE PDPL for a 30-Person Company: What the Federal Data Law Asks of You
UAE PDPL compliance for a small company: who the federal data law covers, what the 72-hour breach notice means, and six practical fixes for this week.
The lead's Emirates ID lives in a WhatsApp group
The office manager of a 30-agent real-estate brokerage in Business Bay runs the busiest group chat in the company. A new lead comes in, the agent photographs the Emirates ID and the passport page, drops both into the "Leads 2026" WhatsApp group, and the admin team opens the file. It has worked this way since 2019. Forty-one people are in the group, including nine agents who left, two former interns and a photographer.
On a Wednesday in August a buyer from Sharjah sends an email. He wants to know what personal data the brokerage holds on him, who it has been shared with, and a copy of the privacy notice he was shown when he handed over his ID. His lawyer is copied.
The office manager searches the website. There is no privacy notice. She searches the shared drive for a data policy and finds a tenancy contract template. The managing partner asks the IT company, who say they "do the network, not the legal side."
Nobody in the building knows how many copies of that buyer's ID exist, how many phones hold them, or how to delete one from the handset of an agent who resigned last year. The buyer's lawyer has given them ten working days.
What the heck does this mean
PDPL is the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. It is the UAE's federal rule for how any organisation collects, uses, stores and shares information about people. It has been in force since 2 January 2022, and it reaches a 30-person brokerage exactly as it reaches a bank.
A few terms, one line each.
Personal data: anything that identifies a person, an Emirates ID scan, a phone number, a passport photo in a chat.
Controller: the business that decides why and how the data is used. That is you.
Processor: a supplier that handles the data on your instructions, the CRM vendor, the payroll firm, the marketing agency.
Data subject rights: a person can ask what you hold, correct it, or have it erased, and you have to be able to answer.
The UAE Data Office: the federal regulator that receives breach notices under the law.
The practical test is short. If someone asked you today what data you hold on them, where it sits and who can see it, could you answer within a week? If the honest reply is "it depends which agent you ask," the law is not your problem. The filing system is.
The numbers that matter
PDPL has been in force since 2 January 2022 and applies to any entity processing the personal data of UAE residents, with no small-business exemption, under Federal Decree-Law 45 of 2021. Headcount does not get you out of it.
Article 11 of the same law requires the controller to notify the UAE Data Office within 72 hours of becoming aware of a qualifying breach (Federal Decree-Law 45 of 2021, Article 11). Seventy-two hours is one long weekend. If your first call on Friday evening is to find out who owns the problem, the clock has already eaten a day.
Phishing incidents in the UAE rose 32% in the first quarter of 2026, according to the UAE Cyber Security Council's 2026 figures. A stolen mailbox is the most common way a company finds out it has a breach to report, and the mailbox usually belongs to someone in admin, sales or finance.
What to do this week
- Build the data map on one sheet: what you collect, why, where it sits, who can see it, how long you keep it. Start with ID scans, lead forms and staff files, because those are what a complainant will ask about first. (CIS 3 Data Protection)
- Get the ID scans out of WhatsApp. Create a controlled folder with named access, move the images there, and remove every leaver from the group before you go home tonight. (CIS 3 Data Protection)
- Write a plain privacy notice and put it on the website and the lead form. Say what you collect, why, who you share it with and how someone asks for a copy or deletion. Two hundred words is enough to start. (CIS 3 Data Protection)
- List every supplier that touches personal data, the CRM, the property portal, the marketing agency, payroll, and get their processing terms in writing, including where the data is hosted. (CIS 15 Service Provider Management)
- Turn on audit logging in the CRM and in Microsoft 365 or Google Workspace, and make sure it keeps at least a year, so you can see who opened or exported a record when you need to. (CIS 8 Audit Log Management)
- Write the 72-hour page: who decides an incident is a reportable breach, who contacts the Data Office, who tells the people affected, and the phone numbers for each. Tape it inside the server cupboard. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment maps what you hold and how it is handled against PDPL and the sector rules that sit on top of it, with the gaps ranked so you know which to fix first. The read-only compliance agent then keeps that picture current: it gives you read-only insight into where the gaps are, we have no access to your systems and we do not remediate, and you or your IT partner make the fix while we show you where. A falcon does not scan the whole desert. It picks one thing out of the noise, and so should you.
Questions people ask
Do I need a data protection officer under PDPL? Only in specific cases. The law reserves the formal DPO role for organisations whose processing is large-scale or involves sensitive data and systematic evaluation of people. A 30-person brokerage or clinic usually sits outside that, but you still need one named person who owns the data map, the privacy notice and the 72-hour process. Write the name down; the regulator will ask who it is.
Does PDPL apply to employee data? Yes. The law protects the personal data of any natural person, and your staff are natural persons. Passport copies, visa files, salary records and the medical certificate someone sent in for sick leave all count. Keep them in HR's controlled folder, not the manager's inbox.
Can I store customer data outside the UAE? Sometimes, with conditions. PDPL allows transfers to countries the regulator recognises as offering adequate protection, and otherwise with safeguards such as contractual terms or the person's consent. Most cloud tools your team already uses store data abroad, so the practical step is to list them and get the transfer basis in writing from each vendor.
The buyer from Sharjah did not want money. He wanted to know who had his passport. Make sure you can tell him.
Questions people ask
Do I need a data protection officer under PDPL?
Only in specific cases. The law reserves the formal DPO role for organisations whose processing is large-scale or involves sensitive data and systematic evaluation of people. A 30-person brokerage or clinic usually sits outside that, but you still need one named person who owns the data map, the privacy notice and the 72-hour process. Write the name down; the regulator will ask who it is.
Does PDPL apply to employee data?
Yes. The law protects the personal data of any natural person, and your staff are natural persons. Passport copies, visa files, salary records and the medical certificate someone sent in for sick leave all count. Keep them in HR's controlled folder, not the manager's inbox.
Can I store customer data outside the UAE?
Sometimes, with conditions. PDPL allows transfers to countries the regulator recognises as offering adequate protection, and otherwise with safeguards such as contractual terms or the person's consent. Most cloud tools your team already uses store data abroad, so the practical step is to list them and get the transfer basis in writing from each vendor.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
DIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
UAE complianceCBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
UAE complianceISO 27001 for UAE Tenders: Why the Certificate Is Now a Bid Document
ISO 27001 UAE tender guide: why a current certificate is now a prequalification document, how long it takes a small firm, and what to do this week.
