AVMDEVS
Journal

2 min readAVMDEVS

Your Website and UAE Data Protection: A Practical Checklist

The UAE has a federal personal data protection law and most business websites quietly ignore it. What to fix, in the order that reduces risk fastest.

Your Website and UAE Data Protection: A Practical Checklist
Fig. 01

The UAE's federal personal data protection law establishes obligations most business websites here do not meet: lawful basis for processing, transparency about what you collect, and rights for the individual whose data it is. Free zones such as the DIFC and ADGM operate their own regimes on top of that.

This is not legal advice and you should take proper counsel on your specific position. It is the engineering checklist that makes the legal position achievable, which is the part that usually gets skipped.

Start with what you are actually collecting

Most companies cannot answer this. The contact form is obvious. The analytics, the chat widget, the pixel your agency added for a campaign in 2023, the newsletter tool, the heatmap script somebody trialled: each of these collects personal data, and several are probably sending it somewhere nobody has reviewed.

Open the network tab on your own site and list every third party it contacts. That list is your actual data processing inventory, and it is usually longer than expected.

The checklist

  • A privacy notice that describes reality. Not a template naming laws you are not subject to. What you collect, why, who you share it with, how long you keep it.
  • Consent that is a real choice. Non-essential tracking should not fire before the visitor agrees. A banner that sets cookies while asking permission is decorative.
  • A working route to exercise rights. An address that a person monitors, for access, correction and deletion requests, with someone who knows what to do when one arrives.
  • Retention that actually expires. Form submissions from four years ago sitting in an inbox are data you are holding without a reason.
  • Know where it goes. Cross-border transfer has conditions. If your CRM, your mail provider and your analytics are all hosted elsewhere, that is a question worth having an answer to.

The two fixes with the best return

Remove the trackers you are not using. Most sites carry scripts nobody has looked at in years, each one a liability with no offsetting benefit. Deleting them improves compliance, privacy and page speed simultaneously, which is rare.

Then make the contact form honest: collect only fields you genuinely use, say where the data goes, and route it into a system with an owner rather than a shared inbox.

Why this is worth doing beyond the law

Enterprise and government procurement in this market increasingly asks these questions in the vendor assessment. Being able to answer them quickly is a commercial advantage, and it is much cheaper to build than to retrofit under deadline during a tender.

Let's build what's next.

Tell us what you are trying to ship. You will talk to the people who will actually build it, not a sales layer.