M cenaly.ru
🇦🇪 United Arab Emirates · Customers

Privacy Policy (PDPL-Ready)

Privacy policy under Federal Decree-Law No. 45/2021 on the Protection of Personal Data ("PDPL") — legal basis for processing, data subject rights, breach notification, and cross-border transfer restrictions, ahead of the 1 January 2027 full-compliance deadline.

All templates
Country
🇦🇪 United Arab Emirates
Category
Customers
Language of the text
EN
Version
1

⚠️ This is a blank template, not legal advice: check the wording with a lawyer and adapt it to your jurisdiction and your case.

This template has no optional clauses: the text is the same for everyone. Field placeholders are shown as labels — on the site the template is read-only, values are entered inside the system.

Document

PRIVACY POLICY (PDPL)

Legal entity name (Trade Licence No. Trade licence number)

This policy is issued under Federal Decree-Law No. 45/2021 on the Protection of Personal Data ("PDPL") and its executive regulations. Full compliance is required by 1 January 2027 under the transitional deadline; this policy documents the legal basis for processing (consent is the default basis), the data subjects' rights, breach notification to the UAE Data Office, DPIAs where required, and restrictions on cross-border transfer.

1. DATA WE COLLECT 1.1. Categories of data collected

2. WHY WE COLLECT IT 2.1. Purposes of processing 2.2. Legal basis: Legal basis.

3. RETENTION 3.1. Retention period

4. THIRD PARTIES AND PROCESSORS 4.1. Third parties and processors

5. CROSS-BORDER TRANSFER 5.1. Cross-border transfer

6. DATA PROTECTION CONTACT 6.1. Data protection contact. A dedicated Data Protection Officer is mandatory only for large-scale processing of sensitive data, systematic monitoring, or high-risk profiling — a smaller business needs only a contact person.

7. YOUR RIGHTS 7.1. Data subject rights and request channel

8. SCOPE 8.1. This policy is written for UAE mainland entities under the PDPL. DIFC and ADGM apply their own data protection laws, not the PDPL — confirm which regime applies before use.

Version date: Policy version date

— — — ⚠️ This is a boilerplate template, not legal advice. It is written for UAE MAINLAND businesses under MOHRE (Federal Decree-Law No. 33/2021 and its executive regulations); free zones (DMCC, JAFZA, and others) have their own labour contract portals and forms, and DIFC/ADGM are separate common-law jurisdictions with their own employment law and data-protection law (DIFC Employment Law, DEWS instead of gratuity, and data-protection rules other than the PDPL) — confirm which regime applies before use. Emirate-level rules (Dubai DET/DM, Abu Dhabi ADDED/DCT/ADAFSA, Sharjah SEDD, and others) also diverge. Have this template reviewed by a UAE-qualified lawyer and verified against the current MOHRE, WPS, PDPL, and emirate-specific requirements before use.

Fields of the document

Fields that belong to a switched-off clause are dimmed — they are not asked for.

  • Legal entity nametextrequiredautomatic
  • Trade licence numbertextrequired
  • Categories of data collectedlong textrequired
  • Purposes of processinglong textrequired
  • Legal basischoicerequired
  • Retention periodtextrequired
  • Third parties and processorslong textoptional
  • Cross-border transferlong textoptional

    Destination countries and safeguards

  • Data protection contacttextrequired

    A dedicated DPO is mandatory only for large-scale sensitive processing / systematic monitoring / high-risk profiling

  • Data subject rights and request channellong textrequired
  • Policy version datedaterequired

In Cenaly this template fills itself in

1 of 11 fields are taken from the company, employee or counterparty record, the questionnaire can be dictated to the AI, and the finished document comes with a number, a PDF and an acknowledgement record.