Federal Decree-Law No. 45 of 2021 is the UAE’s federal data protection law. It sets out how organisations that collect or process personal information are expected to behave, and what rights individuals have over their own data. Below is a plain-English summary of the parts that matter most to a business handling customer data online.
The core idea
The law treats personal data as something that belongs, in a meaningful sense, to the individual it describes — not to the organisation that happens to be holding it. That means organisations need a lawful reason to collect and use data, must be transparent about what they collect and why, and must give individuals meaningful control over it.
What it requires in practice
For most organisations, compliance comes down to a handful of practical commitments: collecting only the data actually needed for a stated purpose, keeping it only as long as necessary, protecting it with reasonable technical safeguards, being clear with individuals about what is collected and why, and honouring requests to access, correct, or delete personal data.
Rights individuals actually have
Under the law, individuals can ask to see what data an organisation holds about them, ask for inaccurate data to be corrected, ask for data to be deleted where there’s no continuing lawful reason to keep it, and withdraw consent where processing depends on it. A business that can respond to these requests promptly and clearly is doing the core of what the law asks.
Our own Privacy Policy sets out how we apply these principles to the information we collect through this website.