OptiFi Technologies
Cybersecurity

UAE data protection: what a small business actually has to do

Federal Decree-Law 45 of 2021 sets a baseline for personal data. Most of what a UAE SME needs to do is unglamorous, cheap, and currently not done.

·2 min read

Data protection conversations tend to arrive as a customer questionnaire rather than as a regulator's letter, and the questionnaire is usually the more urgent of the two.

What applies to you

Federal Decree-Law 45 of 2021 — the UAE Personal Data Protection Law — sets a federal baseline. On top of that, entities in DIFC and ADGM operate under those jurisdictions' own regimes entirely, and sector rules apply in areas such as healthcare.

Which reach your business depends on where you are licensed, your sector and who your customers are. Any provider who tells you confidently which standard applies without asking those three questions is guessing, and a guess that turns out wrong surfaces in a supplier audit.

The unglamorous list

For a typical UAE SME, most of the work is not technical and not expensive. It is knowing what personal data you hold, why you hold it, who can see it, and how long you keep it.

  • An inventory of what personal data exists and where — usually shorter than expected, and usually including a spreadsheet nobody remembered
  • Access limited to people whose role needs it, reviewed when roles change rather than accumulating
  • Retention decided deliberately, so you neither delete what you must keep nor keep everything forever
  • A process for a subject request, agreed before one arrives rather than during
  • Records of consent where you rely on it

The part that is technical

Access control does most of the work. Multi-factor authentication, least-privilege permissions, and knowing who holds administrative rights are the controls that make the rest defensible — and they are the same controls that reduce your exposure to business email compromise, which is the loss that actually happens.

Encryption on devices matters because devices leave buildings. A laptop lost between sites is only a data incident if it was not encrypted and could not be wiped, and both of those are configuration rather than purchase.

What to do first

Establish what applies to you, in writing. Then assess honestly against it, fix the gaps that carry real risk, and keep evidence — because the form the asking party accepts is rarely raw scanner output.

We do that as cybersecurity work in Dubai, and the access side is usually configured through Microsoft 365 Business Premium, which most UAE businesses already pay for and have not switched on. This is not legal advice — obligations should be confirmed with a qualified adviser.

Free consultationCallWhatsApp