Alexandre Brazeau
Partner
Article
8
Following our second article on managing Personal Data, DIFC-based companies should now be considering immediate practical steps to take in order to be compliant in their business operations.
Undefined capitalised terms in this article have the same definitions as provided in the first and second articles of this series.
We recommend that DIFC-based companies Processing any Personal Data carry out a thorough data audit to:
Companies Processing Personal Data should look to do the following compliance exercises to ensure compliance with the DPL 2020.
Implement "technical and organisational measures" within the business as a whole to ensure the lawfulness of Processing activities and the security of any Personal Data Processed. These measures essentially must:
Does your company provide Data Subjects with the following information, in writing, when Processing their Personal Data (e.g. in a privacy policy or notice)? If not, the company must ensure it provides Data Subjects with the following:
Unsurprisingly, the Middle East is now embracing new data protection frameworks and laws, aligning with the rest of the world and, in particular, with the principles of the GDPR. The UAE, particularly given the DIFC laws and regulations, has been at the forefront of this adoption. Data protection laws and frameworks are growing regionally, as are regulatory agencies and authorities responsible for the enforcement of the rights protected under the relevant laws. These rights and the laws protecting them will only continue to gain importance and attract higher degrees of attention, enforcement action and publicity across the region.
In view of this evolution towards more robust data protection regionally, we recommend that all companies active within the DIFC act quickly in their preparations for the enforcement of the DPL 2020 in order to minimise any future delays and avoid penalties for non-compliance.
Gowling WLG will continue to monitor the ongoing developments to guidelines and feedback from authorities before the introduction of the DPL 2020 and will continue to share these insights with you. If you have any questions or concerns please contact Tony Fielding of Gowling GWLG's Dubai office.
Should you wish to review the full draft of the DPL 2020, it has been published and is accessible on the DIFC's website.
For further information on data protection in the UAE please contact Alexandre Brazeau in our Gowling WLG Dubai office.
Read part 1 on the key changes and part 2 on how to manage personal data.
Co-authored by Rifdi Shuhaimi and Tony Fielding.
Footnotes
[1] The identified or identifiable natural person to whom Personal Data relates.
[2] Any person who, alone or jointly with others, determines the purposes and means of Processing Personal Data.
CECI NE CONSTITUE PAS UN AVIS JURIDIQUE. L'information qui est présentée dans le site Web sous quelque forme que ce soit est fournie à titre informatif uniquement. Elle ne constitue pas un avis juridique et ne devrait pas être interprétée comme tel. Aucun utilisateur ne devrait prendre ou négliger de prendre des décisions en se fiant uniquement à ces renseignements, ni ignorer les conseils juridiques d'un professionnel ou tarder à consulter un professionnel sur la base de ce qu'il a lu dans ce site Web. Les professionnels de Gowling WLG seront heureux de discuter avec l'utilisateur des différentes options possibles concernant certaines questions juridiques précises.