UAE Mainland: Processing by Local Establishment
\markdown The UAE Federal Personal Data Protection Law (PDPL) applies to establishments processing personal data within the UAE, with the definition of "establishment" extending to both local and foreign entities. ## Text of Relevant Provision Federal PDPL Article 1 defines "Establishment" as: "Any company or sole proprietorship established inside or outside the State, including companies which the federal or local government partially or wholly owns or has a shareholding therein." In the original Arabic: "المنشأة: أي شركة أو مؤسسة فردية داخل الدولة أو خارجها، بما فيها الشركات المملوكة بشكل جزئي أو كامل للحكومة الاتحادية أو المحلية أو التي تساهم فيها." ## Analysis of Provisions The definition of "Establishment" in Article 1 of the UAE Federal PDPL is broad and inclusive. It encompasses "Any company or sole proprietorship established inside or outside the State", which means the law applies to: 1. Local companies and sole proprietorships within the UAE 2. Foreign companies and sole proprietorships operating in the UAE 3. Government-owned or partially owned companies, both at the federal and local levels This broad definition ensures that the law covers a wide range of entities processing personal data in the UAE, regardless of their place of incorporation or ownership structure. It's important to note that Article 3 of the PDPL grants the UAE Data Office the power to exempt certain establishments from some or all of the law's requirements. Specifically, it states: "Without prejudice to any other competencies established for the Office under any other legislation, the Office may exempt those Establishments that do not process a large amount of Personal Data from all or some of the requirements and conditions of the provisions of Personal Data Protection stipulated herein, in accordance with the standards and controls set by the Executive Regulations of this Decree Law." This provision allows for flexibility in the law's application, potentially reducing the compliance burden for smaller entities or those processing limited amounts of personal data. ## Implications The broad definition of "Establishment" in the UAE Federal PDPL has several implications for businesses: 1. Wide applicability: Both local and foreign companies operating in the UAE must comply with the PDPL, regardless of where they are incorporated. 2. Government-linked entities: Companies with full or partial government ownership are explicitly included, ensuring that such entities are not exempt from data protection obligations. 3. Potential for exemptions: Smaller businesses or those processing limited personal data may be eligible for exemptions from certain requirements, though this depends on the standards set in the Executive Regulations. 4. Extra-territorial effect: The inclusion of entities "established outside the State" suggests that foreign companies processing personal data of UAE residents may fall under the law's scope, even if they don't have a physical presence in the UAE. 5. Compliance considerations: International companies operating in the UAE need to ensure their data protection practices align with the PDPL, potentially necessitating adjustments to global data handling procedures. 6. Level playing field: The broad definition helps ensure that all entities processing personal data in the UAE are subject to the same rules, promoting fair competition and consistent data protection standards. \