A website Europeans can reach does not put you under GDPR.
The regulation says so directly. Mere accessibility of your website, an email address, or using English is explicitly insufficient. What catches a UAE business is targeting people in the EU or monitoring their behaviour. We establish which applies to you before anybody spends anything.

- Article 3(2)The test that reaches outside the EU
- Recital 23Says accessibility is not enough
- Article 27An EU representative, in writing
- Not lawyersTechnical readiness, not legal advice
Eight things to establish, and the first one settles most cases.
Whether it applies to you at all
Article 3 has two limbs that matter here. The first catches processing in the context of the activities of an establishment in the Union, so a UAE company with an EU office or subsidiary is generally in scope for that activity. The second reaches organisations with no EU establishment at all, and that is the one most UAE businesses need to think about carefully rather than assume.
The offering limb, and what does not trigger it
Article 3(2)(a) covers offering goods or services to data subjects in the Union, whether or not payment is required. Recital 23 then narrows it usefully: it must be apparent that you envisage offering to people in the Union. The regulation states directly that mere accessibility of your website, an email address or other contact details, or using a language common in your own country, is insufficient to show that intention.
The monitoring limb, which catches people quietly
Article 3(2)(b) covers monitoring the behaviour of data subjects as far as that behaviour takes place within the Union. This is the limb organisations miss, because it does not require you to sell anything. Analytics, advertising pixels, behavioural tracking and profiling of visitors who are in Europe can engage it, which means a UAE business with no EU customers at all may still need to think about this.
The evidence that shows intention either way
Recital 23 names factors that may make it apparent you envisage offering into the Union: using a language or a currency generally used in Member States with the ability to order in that language, or mentioning customers or users who are in the Union. That gives you something concrete to assess rather than a feeling. It also means your marketing and your website are part of the analysis, not just your systems.
The EU representative, which almost nobody appoints
Article 27 states that where Article 3(2) applies, the controller or processor shall designate a representative in the Union in writing, established in a Member State where the relevant data subjects are. There is a narrow exemption for processing that is occasional, does not involve large-scale special category or criminal offence data and is unlikely to result in a risk. This is a real obligation with a real cost, and it is the one UAE businesses most often overlook entirely.
Breach notification within a defined window
Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is later than 72 hours it must be accompanied by reasons for the delay. Meeting that in practice is an operational readiness question rather than a legal one, which is where we work.
Knowing what data you hold and where it goes
Whether or not GDPR applies, this is the work that makes any data protection obligation manageable. What personal data you hold, whose it is, why you have it, where it is stored, who you share it with and how long you keep it. UAE businesses generally need this for the federal data protection law regardless, and it is the same underlying exercise, which is why doing it once is considerably cheaper than twice.
What the exposure actually is
Article 83 sets two tiers of administrative fine. The lower tier reaches up to 10 million euro, or for an undertaking up to 2 percent of total worldwide annual turnover in the preceding financial year, whichever is higher. The upper tier reaches up to 20 million euro, or 4 percent on the same basis, for infringements including the basic principles for processing and the conditions for consent. Those are ceilings rather than expectations, and they are why the applicability question deserves a proper answer.
Plenty of UAE businesses are wrong about whether GDPR applies to them.
This question gets answered by instinct far more often than by reading Article 3, and instinct gets it wrong in both directions. Both errors are expensive in different ways.
- The over-inclusive error. A UAE company with a website in English, an info address and no European customers concludes that GDPR applies because Europeans could theoretically find them. The regulation addresses this directly: mere accessibility of the website, an email address or other contact details, or using a language common in your own country, is explicitly insufficient to establish the intention that the offering limb requires. Building a compliance programme on that basis spends money against an obligation you may not have.
- The under-inclusive error, which is the more dangerous one. A UAE business assumes it is outside GDPR because it has no EU customers and does not sell into Europe, while running analytics, advertising pixels or behavioural profiling that reaches visitors who are in the Union. The monitoring limb of Article 3(2) does not require you to sell anything at all, and this catches organisations that never considered themselves in scope.
- The obligation people forget even when they get applicability right. Article 27 says that where Article 3(2) applies, you shall designate a representative in the Union in writing, established in a Member State where the relevant data subjects are. In our experience this is the least observed requirement affecting UAE businesses, partly because it costs money and partly because nobody mentions it.
- What to do about it. Answer the applicability question properly and in writing before building anything, because the answer determines whether you need a programme, a narrow set of measures, or nothing beyond what UAE law already requires of you. This is exactly the point at which involving qualified counsel is worth the cost, and we will say so rather than answering a legal question ourselves.
Four positions, including one about the limits of what we do.
We are not lawyers, and we say so before you ask
We do technical and operational readiness: data inventories, systems, access, retention, security measures, and whether an obligation is actually achievable in practice. Whether the regulation applies to your specific facts, and anything turning on interpretation, is for qualified counsel. We work alongside your lawyers rather than substituting for them, and we will tell you when a question is one for them.
We start from the text, not from a template
Every point we make about scope traces to Article 3, Recital 23, Article 27, Article 33 or Article 83, and we will show you the wording. That matters here because a great deal of published GDPR guidance aimed at businesses outside Europe overstates applicability, and a programme built on an overstatement costs real money.
We do the UAE obligations in the same exercise
The federal data protection law applies to you regardless of anything European, and free zone entities in DIFC or ADGM carry their own regimes. The underlying work, knowing what data you hold, where it sits, who can reach it and how long you keep it, is the same for all of them. Doing it once against every applicable regime is materially cheaper than doing it repeatedly.
We size the work to the actual answer
If the applicability review concludes the regulation does not reach you, that is the deliverable and the engagement ends there. If it does reach you, the response is usually narrower than expected: a representative, a defensible basis for the processing concerned, and readiness to meet the notification window, rather than a wholesale programme.
Six UAE situations where the question is worth answering properly.
A UAE company selling online into Europe
Pricing in euro, shipping to EU addresses, marketing aimed at European buyers. Recital 23 names currency and the ability to order in an EU language as indicators of exactly the intention the offering limb requires, so this is the clearest case for applicability. The practical consequences follow: a lawful basis for the processing, an EU representative under Article 27, and readiness to meet the notification window.
A services firm with European clients
Consultancies, agencies and technology providers serving EU-based businesses. Here two things run in parallel: whether the regulation reaches you directly under Article 3, and what your client contracts require of you regardless, because an EU client will push obligations down to you contractually whether or not you are independently in scope.
Travel, hospitality and anyone hosting European visitors
A hotel or tour operator taking bookings from people who are in Europe at the time is a genuinely fact-specific case, and it is one where the difference between actively marketing into the Union and simply being bookable matters. Worth working through properly rather than assuming either way, because both assumptions are commonly made and both are sometimes wrong.
A business running analytics and advertising pixels
The one that surprises people. If you profile or track visitors whose behaviour takes place in the Union, the monitoring limb of Article 3(2) may be engaged even with no European customers and nothing sold into Europe. Many UAE businesses have marketing technology doing exactly this without anyone having considered it a data protection question.
A UAE group with a European office or subsidiary
The establishment limb of Article 3(1) is engaged for processing in the context of that establishment activities, regardless of where the processing physically happens. Group structures make this less obvious than it sounds, because the question is about the activities of the establishment rather than simply about which entity owns the server.
A business that only sells within the GCC
No EU marketing, no euro pricing, no EU customers, no behavioural tracking of European visitors. Here the text points away from applicability, and the useful outcome of the review is a written conclusion to that effect plus a focus on the UAE federal obligations that do apply to you. That is a good result and it is worth having on record for the next client questionnaire.
Where UAE businesses actually stand on this.
| Feature | Applicability established | Assumed it applies | Assumed it does not |
|---|---|---|---|
Article 3 worked through against your facts | |||
Written record of the conclusion | |||
Monitoring limb considered, not just selling | Rarely | ||
EU representative appointed if required | Usually not | Not considered | |
Spend matches the actual obligation | Over | Under | |
Data inventory exists | Sometimes | Rarely | |
Breach notification is operationally possible | On paper | ||
UAE federal obligations addressed alongside | Overlooked | Overlooked | |
Could answer a client due diligence question | Vaguely | ||
Risk if a supervisory authority ever asks | Low | Low but costly | Unquantified |
Situations, and what Article 3 suggests about each.
| Situation | What the text points to | |
|---|---|---|
| You have an office or subsidiary in an EU Member State | Article 3(1) establishment limb is likely engaged for that activity | |
| Your website is in English and reachable from Europe | Recital 23: accessibility alone is insufficient | |
| You list prices in euro and can ship to EU addresses | Recital 23 names currency and ordering as indicators of intention | |
| Your site names customers who are in the Union | Recital 23 names this as a factor that may show intention | |
| You run analytics or ad pixels reaching EU visitors | Article 3(2)(b) monitoring limb may be engaged | |
| You process EU staff data for a UAE employer | Depends on establishment and where the individuals are | |
| You are a processor for an EU-based client | Your client obligations flow to you contractually regardless | |
| You sell only within the GCC, no EU marketing, no tracking | Article 3(2) points away from applicability | |
| Article 3(2) applies to you | Article 27 requires an EU representative designated in writing | |
| You hold personal data of anyone, anywhere | UAE federal data protection law applies on its own terms |
Five steps, and it often stops at the second.
- 1
Establish the facts that Article 3 turns on
Where you have establishments, who your customers actually are and where, how you market and in what languages and currencies, whether you can transact with people in the Union, and what tracking or profiling technology you run. These are factual questions with checkable answers, and gathering them takes a short workshop rather than a project.
- 2
Work the applicability test and write down the conclusion
Against Article 3(1), Article 3(2)(a) with Recital 23, and Article 3(2)(b). Where the answer is finely balanced or commercially significant we say so and recommend qualified counsel rather than giving you a confident answer we are not qualified to give. Where it is clear, the written conclusion is itself a useful artefact for client questionnaires.
- 3
If it applies, scope the response to what is required
A representative in the Union under Article 27 unless an exemption applies, a defensible lawful basis for the processing concerned, transparency to the data subjects involved, and the operational ability to handle requests and to notify inside the Article 33 window. Usually narrower than a full programme, and the scope depends on which limb caught you.
- 4
Do the data work once, against every regime that applies
The inventory, the flows, the retention position, the third parties and the security measures. This serves GDPR where relevant, the UAE federal data protection law, and any free zone regime you sit under. Building it separately for each is the most common avoidable cost in this area.
- 5
Make the obligations operationally real, and keep them current
Rehearse a data subject request and a breach notification rather than documenting them, because a 72-hour clock is not met by a policy. Then review when the business changes: a new market, a new tracking tool, a European hire or a new client can move you across the line without anybody noticing.
What UAE businesses ask about GDPR.
Fifteen questions, in the order they should be asked.
Does it reach you
- Do you have any establishment in an EU Member State?Office, branch, subsidiary, or staff based there.
- Do you deliberately market or sell to people in the Union?Intention is the test, not theoretical reachability.
- Do you price in euro or allow ordering in an EU language?Recital 23 names both as indicators.
- Does your site mention customers or users in the Union?Also named in Recital 23.
- Do you track or profile visitors whose behaviour is in the Union?The monitoring limb needs no sale at all.
If it does apply
- Have you designated an EU representative in writing?Article 27, and the most overlooked obligation.
- Do you know which supervisory authority is relevant?Tied to where the data subjects are.
- Could you notify a breach inside 72 hours of becoming aware?Operationally, not just as a policy statement.
- Can you evidence a lawful basis for each processing activity?And for consent, that it met the conditions.
- Could you answer a data subject access request within the deadline?Test it once before it arrives for real.
Worth doing either way
- Do you have a current record of what personal data you hold?Needed for UAE federal law regardless of GDPR.
- Do you know where each category of data physically sits?Including in cloud services and third parties.
- Do your vendor contracts address data protection at all?Frequently absent, and increasingly asked about.
- Is there a retention position, or does everything stay forever?Indefinite retention is a decision nobody made.
- Would you detect a personal data breach in the first place?A notification clock you cannot start is meaningless.
The pages around this one.
UAE PDPL compliance
The federal data protection obligations that apply to you regardless of anything European, and the same underlying data work.
DIFC Data Protection Law
The separate regime for entities in the DIFC free zone, which is frequently confused with both the federal law and GDPR.
IT audit services in Dubai
The wider audit practice, including the data inventory and access work that underpins any data protection obligation.
Answer two questions before you spend anything.
Do you deliberately market or sell to people in Europe, and does your site profile visitors who are there. Those two go to the offering limb and the monitoring limb, and between them they resolve most cases. We will work through the rest with you and tell you plainly when the question belongs with a lawyer.
Related Services
Explore more solutions that work great with this service
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
DIFC DPL 5/2020
DIFC Data Protection Law readiness and Commissioner reporting
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Virtual CISO Dubai
Security governance and accountability, not more tools
Cybersecurity Audit
Security assessment and compliance audit
DLP Solutions
Microsoft Purview DLP and labels