PDPL
Does my UAE business need a Data Protection Officer?
Updated 2026-09-25
Most small UAE businesses do not need a formal Data Protection Officer under the PDPL. Some clearly do. Article 10 sets out when.
The three conditions
A controller or processor must appoint a DPO where its processing:
- poses a high risk to the privacy and confidentiality of personal data because of the adoption of new technologies or the volume of data;
- involves a systematic and comprehensive assessment of sensitive personal data, including profiling and automated processing; or
- involves a large volume of sensitive personal data.
What that looks like in practice
- A clinic group holding thousands of patient records: large volume of sensitive (health) data.
- A lender scoring applicants automatically: systematic assessment including profiling.
- A retailer using facial recognition on CCTV: new technology posing high risk.
- A ten-person consultancy holding client contacts and staff files: normally none of the above.
What the DPO does
Articles 11 and 12 describe the role: advising on compliance, monitoring processing, handling contact with the Data Office, and being reachable by data subjects. The DPO can be an employee or an external provider and does not have to be in the UAE, which makes a part-time external DPO a realistic option for smaller organisations.
If you do not need one
You still need someone accountable. Requests from individuals, breach decisions and keeping records current all need an owner. Name a privacy lead and publish a contact address in your privacy notice.
Not sure which side you fall on? The free assessment checks the Article 10 conditions against your answers and tells you.
Where does your company stand on PDPL?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.