This comprehensive federal data protection law applies across the UAE (except in financial free zones like DIFC and ADGM which have their own laws). The law regulates the processing of personal data and aims to protect individual privacy while facilitating legitimate data use. It establishes core principles including lawfulness, transparency, purpose limitation, data minimization, accuracy, and security. The law grants data subjects rights including access, rectification, erasure, restriction, and data portability. Organizations must implement appropriate technical and organizational measures, conduct impact assessments for high-risk processing, and report data breaches. Cross-border data transfers require adequate protection levels or appropriate safeguards. The law establishes the UAE Data Office as the supervisory authority with powers to investigate and impose administrative penalties up to AED 10 million for violations.
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality,