uae-pdp-law skill
Implements compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDP Law) and its Executive Regulations. Covers data controller and processor obligations, data subject rights, cross-border transfer requirements, sensitive data processing, and UAE Data Office enforcement. Keywords: UAE PDP, Federal Decree-Law 45, UAE Data Office, DIFC, ADGM, cross-border transfer.
Is the uae-pdp-law skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the uae-pdp-law skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/ae/data-protection/skills/uae-pdp-law ~/.claude/skills/uae-pdp-law
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
UAE Personal Data Protection Law Compliance
Overview
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDP Law) was issued on 20 September 2021 and entered into force on 2 January 2022, with a compliance grace period. The Executive Regulations were issued by Cabinet Decision No. 111 of 2023, published in the Official Gazette on 23 October 2023, and companies were given until 1 January 2025 to achieve compliance. The UAE Data Office (established under the law) is the supervisory authority responsible for enforcement.
The UAE PDP Law is the first comprehensive federal data protection law in the UAE. It is important to note that the UAE also has separate data protection regimes in the financial free zones: the Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020 and the Abu Dhabi Global Market (ADGM) Data Protection Regulations 2021. These free zone laws operate independently of the federal law.
Key Definitions
Lawful Bases for Processing (Article 5)
The controller may process personal data only where:
- Consent of the data subject — must be clear, specific, informed, unambiguous, easy to withdraw
- Necessary for performance or initiation of a contract with the data subject
- Necessary for compliance with legal obligations of the controller
- Necessary to protect the vital interests of the data subject or another person
- Processing concerns data made public by the data subject
- Necessary for legal proceedings — establishment, exercise, or defence of legal claims
- Necessary for medical purposes — preventive or occupational medicine, by a medical professional
- Necessary for public interest — archiving, statistical analysis, scientific research
- Necessary for the legitimate interests of the controller, provided data subject rights do not override
Sensitive Personal Data (Article 7)
Processing of sensitive personal data is prohibited except where:
- The data subject has given explicit consent
- Processing is necessary for the performance of obligations under employment, social security, or social protection law
- Processing is necessary to protect vital interests where the data subject is incapable of giving consent
- Processing relates to data manifestly made public by the data subject
- Processing is necessary for legal claims
- Processing is necessary for public interest, public health, or scientific research
Data Subject Rights (Articles 13-18)
- Right to be informed — notification of processing at the time of collection (Article 13)
- Right of access — obtain confirmation and a copy of personal data (Article 14)
- Right to rectification — correct inaccurate data (Article 15)
- Right to erasure — request deletion when data is no longer necessary (Article 15)
- Right to restrict processing — limit processing in specified circumstances (Article 16)
- Right to data portability — receive data in a structured, commonly used format (Article 17)
- Right to object — object to processing, including for direct marketing (Article 17)
- Right related to automated decisions — not be subject to solely automated decisions producing legal effects (Article 18)
Cross-Border Transfers (Article 22)
Transfer of personal data outside the UAE is permitted where:
- The recipient country or territory provides an adequate level of protection as determined by the UAE Data Office
- The controller provides appropriate safeguards including standard contractual clauses, binding corporate rules, or approved certification mechanisms
- The data subject has given explicit consent after being informed of the risks
- Transfer is necessary for contract performance, legal claims, vital interests, or public interest
The Executive Regulations specify the criteria for adequacy assessment and the process for approving standard contractual clauses.
Controller and Processor Obligations
Controller Obligations
- Maintain records of processing activities (Article 8)
- Conduct Data Protection Impact Assessments for high-risk processing (Article 9)
- Appoint a Data Protection Officer where required (Article 10)
- Implement appropriate technical and organisational measures (Article 11)
- Notify the UAE Data Office and data subjects of breaches (Article 12)
Processor Obligations
- Process data only on documented instructions of the controller
- Ensure persons processing data are bound by confidentiality
- Implement appropriate security measures
- Assist the controller with data subject requests and breach notification
- Formal written agreement required between controller and processor
Enforcement and Penalties
The UAE Data Office may:
- Issue warnings and corrective orders
- Impose administrative fines (amounts to be specified in implementing regulations)
- Order suspension of data processing
- Refer criminal violations to the public prosecutor
Key Exemptions
The UAE PDP Law does not apply to:
- Government data or data processed by government security and judicial entities
- Health data governed by specific health data legislation
- Banking and credit data subject to specific financial sector regulation
- Personal data processed by individuals for purely personal or family purposes
- Data processed by media entities in accordance with applicable media regulation
Free Zone Data Protection Regimes
DIFC Data Protection Law No. 5 of 2020
- Independent supervisory authority: Commissioner of Data Protection
- Closely aligned with GDPR
- Applies to entities registered in the DIFC processing personal data
ADGM Data Protection Regulations 2021
- Independent regulator: Office of Data Protection
- Based on international best practices
- Applies to entities registered in the ADGM processing personal data
Integration Points
- cross-border transfers: Article 22 transfer mechanisms and adequacy assessment
- vendor-privacy-due-diligence: Controller-processor agreement requirements under the Executive Regulations
- breach-72h-notification: UAE PDP Law breach notification obligations (timeframe specified in Executive Regulations)
- data-inventory-mapping: Article 8 records of processing activities
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway