We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. GDPR for UAE businesses
GDPR for UAE businesses

A website Europeans can reach does not put you under GDPR.

The regulation says so directly. Mere accessibility of your website, an email address, or using English is explicitly insufficient. What catches a UAE business is targeting people in the EU or monitoring their behaviour. We establish which applies to you before anybody spends anything.

Book a GDPR applicability reviewSee the actual test
GDPR applicability and readiness for UAE businesses
  • Article 3(2)The test that reaches outside the EU
  • Recital 23Says accessibility is not enough
  • Article 27An EU representative, in writing
  • Not lawyersTechnical readiness, not legal advice
What the regulation actually says

Eight things to establish, and the first one settles most cases.

Everything below is taken from the text of the regulation rather than from commentary about it. We should say plainly at the outset that we are not lawyers: this is technical and operational readiness work, and any question that turns on legal interpretation belongs with qualified counsel.

Whether it applies to you at all

Article 3 has two limbs that matter here. The first catches processing in the context of the activities of an establishment in the Union, so a UAE company with an EU office or subsidiary is generally in scope for that activity. The second reaches organisations with no EU establishment at all, and that is the one most UAE businesses need to think about carefully rather than assume.

The offering limb, and what does not trigger it

Article 3(2)(a) covers offering goods or services to data subjects in the Union, whether or not payment is required. Recital 23 then narrows it usefully: it must be apparent that you envisage offering to people in the Union. The regulation states directly that mere accessibility of your website, an email address or other contact details, or using a language common in your own country, is insufficient to show that intention.

The monitoring limb, which catches people quietly

Article 3(2)(b) covers monitoring the behaviour of data subjects as far as that behaviour takes place within the Union. This is the limb organisations miss, because it does not require you to sell anything. Analytics, advertising pixels, behavioural tracking and profiling of visitors who are in Europe can engage it, which means a UAE business with no EU customers at all may still need to think about this.

The evidence that shows intention either way

Recital 23 names factors that may make it apparent you envisage offering into the Union: using a language or a currency generally used in Member States with the ability to order in that language, or mentioning customers or users who are in the Union. That gives you something concrete to assess rather than a feeling. It also means your marketing and your website are part of the analysis, not just your systems.

The EU representative, which almost nobody appoints

Article 27 states that where Article 3(2) applies, the controller or processor shall designate a representative in the Union in writing, established in a Member State where the relevant data subjects are. There is a narrow exemption for processing that is occasional, does not involve large-scale special category or criminal offence data and is unlikely to result in a risk. This is a real obligation with a real cost, and it is the one UAE businesses most often overlook entirely.

Breach notification within a defined window

Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is later than 72 hours it must be accompanied by reasons for the delay. Meeting that in practice is an operational readiness question rather than a legal one, which is where we work.

Knowing what data you hold and where it goes

Whether or not GDPR applies, this is the work that makes any data protection obligation manageable. What personal data you hold, whose it is, why you have it, where it is stored, who you share it with and how long you keep it. UAE businesses generally need this for the federal data protection law regardless, and it is the same underlying exercise, which is why doing it once is considerably cheaper than twice.

What the exposure actually is

Article 83 sets two tiers of administrative fine. The lower tier reaches up to 10 million euro, or for an undertaking up to 2 percent of total worldwide annual turnover in the preceding financial year, whichever is higher. The upper tier reaches up to 20 million euro, or 4 percent on the same basis, for infringements including the basic principles for processing and the conditions for consent. Those are ceilings rather than expectations, and they are why the applicability question deserves a proper answer.

The most common mistake, in both directions

Plenty of UAE businesses are wrong about whether GDPR applies to them.

This question gets answered by instinct far more often than by reading Article 3, and instinct gets it wrong in both directions. Both errors are expensive in different ways.

  • The over-inclusive error. A UAE company with a website in English, an info address and no European customers concludes that GDPR applies because Europeans could theoretically find them. The regulation addresses this directly: mere accessibility of the website, an email address or other contact details, or using a language common in your own country, is explicitly insufficient to establish the intention that the offering limb requires. Building a compliance programme on that basis spends money against an obligation you may not have.
  • The under-inclusive error, which is the more dangerous one. A UAE business assumes it is outside GDPR because it has no EU customers and does not sell into Europe, while running analytics, advertising pixels or behavioural profiling that reaches visitors who are in the Union. The monitoring limb of Article 3(2) does not require you to sell anything at all, and this catches organisations that never considered themselves in scope.
  • The obligation people forget even when they get applicability right. Article 27 says that where Article 3(2) applies, you shall designate a representative in the Union in writing, established in a Member State where the relevant data subjects are. In our experience this is the least observed requirement affecting UAE businesses, partly because it costs money and partly because nobody mentions it.
  • What to do about it. Answer the applicability question properly and in writing before building anything, because the answer determines whether you need a programme, a narrow set of measures, or nothing beyond what UAE law already requires of you. This is exactly the point at which involving qualified counsel is worth the cost, and we will say so rather than answering a legal question ourselves.
Ask us to work through the applicability test with you
How we work on this

Four positions, including one about the limits of what we do.

Data protection attracts advice that is confident about legal questions from people who are not qualified to answer them. We would rather be clear about where our work stops.

We are not lawyers, and we say so before you ask

We do technical and operational readiness: data inventories, systems, access, retention, security measures, and whether an obligation is actually achievable in practice. Whether the regulation applies to your specific facts, and anything turning on interpretation, is for qualified counsel. We work alongside your lawyers rather than substituting for them, and we will tell you when a question is one for them.

We start from the text, not from a template

Every point we make about scope traces to Article 3, Recital 23, Article 27, Article 33 or Article 83, and we will show you the wording. That matters here because a great deal of published GDPR guidance aimed at businesses outside Europe overstates applicability, and a programme built on an overstatement costs real money.

We do the UAE obligations in the same exercise

The federal data protection law applies to you regardless of anything European, and free zone entities in DIFC or ADGM carry their own regimes. The underlying work, knowing what data you hold, where it sits, who can reach it and how long you keep it, is the same for all of them. Doing it once against every applicable regime is materially cheaper than doing it repeatedly.

We size the work to the actual answer

If the applicability review concludes the regulation does not reach you, that is the deliverable and the engagement ends there. If it does reach you, the response is usually narrower than expected: a representative, a defensible basis for the processing concerned, and readiness to meet the notification window, rather than a wholesale programme.

Who this affects

Six UAE situations where the question is worth answering properly.

In two of these the likely answer is that GDPR does not reach you, which is a perfectly good outcome and worth establishing rather than assuming.

A UAE company selling online into Europe

Pricing in euro, shipping to EU addresses, marketing aimed at European buyers. Recital 23 names currency and the ability to order in an EU language as indicators of exactly the intention the offering limb requires, so this is the clearest case for applicability. The practical consequences follow: a lawful basis for the processing, an EU representative under Article 27, and readiness to meet the notification window.

A services firm with European clients

Consultancies, agencies and technology providers serving EU-based businesses. Here two things run in parallel: whether the regulation reaches you directly under Article 3, and what your client contracts require of you regardless, because an EU client will push obligations down to you contractually whether or not you are independently in scope.

Travel, hospitality and anyone hosting European visitors

A hotel or tour operator taking bookings from people who are in Europe at the time is a genuinely fact-specific case, and it is one where the difference between actively marketing into the Union and simply being bookable matters. Worth working through properly rather than assuming either way, because both assumptions are commonly made and both are sometimes wrong.

A business running analytics and advertising pixels

The one that surprises people. If you profile or track visitors whose behaviour takes place in the Union, the monitoring limb of Article 3(2) may be engaged even with no European customers and nothing sold into Europe. Many UAE businesses have marketing technology doing exactly this without anyone having considered it a data protection question.

A UAE group with a European office or subsidiary

The establishment limb of Article 3(1) is engaged for processing in the context of that establishment activities, regardless of where the processing physically happens. Group structures make this less obvious than it sounds, because the question is about the activities of the establishment rather than simply about which entity owns the server.

A business that only sells within the GCC

No EU marketing, no euro pricing, no EU customers, no behavioural tracking of European visitors. Here the text points away from applicability, and the useful outcome of the review is a written conclusion to that effect plus a focus on the UAE federal obligations that do apply to you. That is a good result and it is worth having on record for the next client questionnaire.

Three positions

Where UAE businesses actually stand on this.

The two outer columns are both wrong and both common. The middle is where you want to be, and reaching it costs a conversation rather than a programme.
Article 3 worked through against your facts
Applicability established
Assumed it applies
Assumed it does not
Written record of the conclusion
Applicability established
Assumed it applies
Assumed it does not
Monitoring limb considered, not just selling
Applicability established
Assumed it appliesRarely
Assumed it does not
EU representative appointed if required
Applicability established
Assumed it appliesUsually not
Assumed it does notNot considered
Spend matches the actual obligation
Applicability established
Assumed it appliesOver
Assumed it does notUnder
Data inventory exists
Applicability established
Assumed it appliesSometimes
Assumed it does notRarely
Breach notification is operationally possible
Applicability established
Assumed it appliesOn paper
Assumed it does not
UAE federal obligations addressed alongside
Applicability established
Assumed it appliesOverlooked
Assumed it does notOverlooked
Could answer a client due diligence question
Applicability established
Assumed it appliesVaguely
Assumed it does not
Risk if a supervisory authority ever asks
Applicability establishedLow
Assumed it appliesLow but costly
Assumed it does notUnquantified
Feature
Applicability established
Assumed it applies
Assumed it does not
Article 3 worked through against your facts
Written record of the conclusion
Monitoring limb considered, not just selling
Rarely
EU representative appointed if required
Usually notNot considered
Spend matches the actual obligation
OverUnder
Data inventory exists
SometimesRarely
Breach notification is operationally possible
On paper
UAE federal obligations addressed alongside
OverlookedOverlooked
Could answer a client due diligence question
Vaguely
Risk if a supervisory authority ever asks
LowLow but costlyUnquantified
Does it reach you

Situations, and what Article 3 suggests about each.

This is a structured way to think about the question, not a legal opinion, and a specific case can turn on facts this table cannot see. Where the answer matters commercially, get it confirmed by counsel rather than by a table on a website, including this one.
SituationWhat the text points to
You have an office or subsidiary in an EU Member StateArticle 3(1) establishment limb is likely engaged for that activity
Your website is in English and reachable from EuropeRecital 23: accessibility alone is insufficient
You list prices in euro and can ship to EU addressesRecital 23 names currency and ordering as indicators of intention
Your site names customers who are in the UnionRecital 23 names this as a factor that may show intention
You run analytics or ad pixels reaching EU visitorsArticle 3(2)(b) monitoring limb may be engaged
You process EU staff data for a UAE employerDepends on establishment and where the individuals are
You are a processor for an EU-based clientYour client obligations flow to you contractually regardless
You sell only within the GCC, no EU marketing, no trackingArticle 3(2) points away from applicability
Article 3(2) applies to youArticle 27 requires an EU representative designated in writing
You hold personal data of anyone, anywhereUAE federal data protection law applies on its own terms
How the review runs

Five steps, and it often stops at the second.

This is deliberately structured so the cheapest question is asked first. There is no reason to inventory data against a regulation that does not reach you.
  1. 1

    Establish the facts that Article 3 turns on

    Where you have establishments, who your customers actually are and where, how you market and in what languages and currencies, whether you can transact with people in the Union, and what tracking or profiling technology you run. These are factual questions with checkable answers, and gathering them takes a short workshop rather than a project.

  2. 2

    Work the applicability test and write down the conclusion

    Against Article 3(1), Article 3(2)(a) with Recital 23, and Article 3(2)(b). Where the answer is finely balanced or commercially significant we say so and recommend qualified counsel rather than giving you a confident answer we are not qualified to give. Where it is clear, the written conclusion is itself a useful artefact for client questionnaires.

  3. 3

    If it applies, scope the response to what is required

    A representative in the Union under Article 27 unless an exemption applies, a defensible lawful basis for the processing concerned, transparency to the data subjects involved, and the operational ability to handle requests and to notify inside the Article 33 window. Usually narrower than a full programme, and the scope depends on which limb caught you.

  4. 4

    Do the data work once, against every regime that applies

    The inventory, the flows, the retention position, the third parties and the security measures. This serves GDPR where relevant, the UAE federal data protection law, and any free zone regime you sit under. Building it separately for each is the most common avoidable cost in this area.

  5. 5

    Make the obligations operationally real, and keep them current

    Rehearse a data subject request and a breach notification rather than documenting them, because a 72-hour clock is not met by a policy. Then review when the business changes: a new market, a new tracking tool, a European hire or a new client can move you across the line without anybody noticing.

Straight answers

What UAE businesses ask about GDPR.

No, and the regulation addresses this directly rather than leaving it to interpretation. Recital 23 states that the mere accessibility of your website in the Union, of an email address or other contact details, or the use of a language generally used in your own country, is insufficient to establish that you envisage offering goods or services to people in the Union. Something more is needed to show that intention. This is the single most useful thing for a UAE business to know, because a great deal of published guidance implies the opposite.

Article 3(2) has two limbs. The first is offering goods or services to data subjects who are in the Union, whether or not payment is involved, where it is apparent that you envisage doing so. Recital 23 names indicators: using a language or currency generally used in Member States with the ability to order in that language, or mentioning customers or users who are in the Union. The second limb is monitoring the behaviour of data subjects as far as that behaviour takes place within the Union, which requires no sale at all.

Article 3(2)(b) covers monitoring the behaviour of people in the Union. It catches organisations because it does not depend on selling anything, so a business that has correctly concluded it does not offer goods or services into Europe can still be reached through it. In practice this is about analytics, advertising and behavioural profiling technology on your website or app. Many UAE businesses run tools that do this and have never considered them a data protection question, because they were installed by marketing rather than by IT.

Article 27 states that where Article 3(2) applies, the controller or processor shall designate a representative in the Union in writing, established in a Member State where the relevant data subjects are. The representative is mandated to be addressed by supervisory authorities and data subjects on issues relating to the processing. There is a narrow exemption where processing is occasional, does not involve large-scale special category or criminal offence data, and is unlikely to result in a risk. In our experience this is the least observed requirement affecting UAE businesses, and it is a real cost that should be in the plan from the start.

Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. If you notify later than 72 hours, the notification must be accompanied by reasons for the delay. The operational implication is the one worth planning for: a 72-hour clock is unmeetable if you would not detect a breach in the first place, or if nobody knows who decides.

Article 83 sets two tiers of administrative fine. The lower tier reaches up to 10 million euro, or in the case of an undertaking up to 2 percent of total worldwide annual turnover of the preceding financial year, whichever is higher. The upper tier reaches up to 20 million euro, or 4 percent on the same basis, and applies to infringements including the basic principles for processing and the conditions for consent. These are statutory ceilings rather than typical outcomes, and how enforcement would practically reach a business with no EU establishment is a question for counsel rather than for us.

They share a great deal of conceptual ground and they are separate obligations arising from separate legal systems. The UAE federal data protection law applies to you on its own terms regardless of anything European, and entities in DIFC or ADGM sit under those free zones own regimes as well. What this means practically is that the underlying work, knowing what personal data you hold, where it is, who can reach it and how long you keep it, serves all of them. The specific requirements differ and the foundation does not.

No, and separating the two saves a lot of confusion. Whether the regulation reaches you directly under Article 3 is one question. What your client requires of you contractually is a completely different one, and an EU client will often push obligations down through a data processing agreement whether or not you are independently in scope. You can be outside Article 3 and still be bound to substantial requirements by contract. Both are worth understanding, and only the first is a question about the regulation.

We can work through the test with you against your actual facts, show you the wording that governs each element and give you a structured written view. What we cannot do is give you a legal opinion, because we are not lawyers, and any question that turns on interpretation or where the answer is finely balanced should go to qualified counsel. We will say clearly which category your situation falls into. In many cases the facts are clear enough that the answer is not genuinely in doubt.

Two things. Write the conclusion down with the reasoning, because it is a useful artefact the next time a client questionnaire asks, and because the facts can change. And do the underlying data work anyway, since the UAE federal data protection law applies to you regardless and asks many of the same foundational questions. A business that knows what personal data it holds and where it sits is in a better position under every regime, including the one it has just concluded does not reach it.

Opening an office or hiring staff in an EU Member State. Starting to market into Europe, price in euro or accept orders in an EU language. Naming European customers on your website. Adding an analytics or advertising tool that profiles visitors. Acquiring a business that does any of these. The applicability conclusion is a point-in-time answer, and the trigger for revisiting it is a commercial change rather than a legal one, which is why it tends to be missed.

That is a separate question from the representative under Article 27 and the two are frequently confused. A representative is required where Article 3(2) applies, subject to the narrow exemption. A data protection officer is required in defined circumstances relating to the nature and scale of your processing, and those criteria are worth assessing separately rather than assuming one implies the other. For most UAE businesses reached by Article 3(2), the representative is the live obligation and the officer question needs its own answer.

The fact gathering is a short workshop, typically half a day, covering establishments, customers, marketing, currencies, languages and what tracking technology you run. Working the test and producing a written conclusion takes a few days after that. Where the answer is that the regulation does not reach you, the engagement ends there and that is the intended outcome. Where it does apply, scoping the response is a further short piece of work, and the size depends entirely on which limb caught you.

We scope the review per business and it is deliberately small, because its purpose is to prevent a much larger and possibly unnecessary spend. What we will tell you free in the first conversation is the handful of factual questions that drive the answer, so you can consider them internally before engaging anyone. In a meaningful number of cases that conversation alone makes the likely answer obvious.

With two questions you can answer today. Do you deliberately market or sell to people in Europe, in the sense of pricing in euro, accepting orders in an EU language or naming EU customers. And does your website or app run analytics, advertising or profiling tools that reach visitors who are in Europe. The first goes to the offering limb, the second to the monitoring limb, and between them they resolve most cases without anybody being engaged.
Work the question properly

Fifteen questions, in the order they should be asked.

The first group decides whether you need to go further at all. The second is what applies if you do. The third is the work that is worth doing regardless, because UAE law asks much of it anyway.

Does it reach you

  • Do you have any establishment in an EU Member State?
    Office, branch, subsidiary, or staff based there.
  • Do you deliberately market or sell to people in the Union?
    Intention is the test, not theoretical reachability.
  • Do you price in euro or allow ordering in an EU language?
    Recital 23 names both as indicators.
  • Does your site mention customers or users in the Union?
    Also named in Recital 23.
  • Do you track or profile visitors whose behaviour is in the Union?
    The monitoring limb needs no sale at all.

If it does apply

  • Have you designated an EU representative in writing?
    Article 27, and the most overlooked obligation.
  • Do you know which supervisory authority is relevant?
    Tied to where the data subjects are.
  • Could you notify a breach inside 72 hours of becoming aware?
    Operationally, not just as a policy statement.
  • Can you evidence a lawful basis for each processing activity?
    And for consent, that it met the conditions.
  • Could you answer a data subject access request within the deadline?
    Test it once before it arrives for real.

Worth doing either way

  • Do you have a current record of what personal data you hold?
    Needed for UAE federal law regardless of GDPR.
  • Do you know where each category of data physically sits?
    Including in cloud services and third parties.
  • Do your vendor contracts address data protection at all?
    Frequently absent, and increasingly asked about.
  • Is there a retention position, or does everything stay forever?
    Indefinite retention is a decision nobody made.
  • Would you detect a personal data breach in the first place?
    A notification clock you cannot start is meaningless.
Related reading

The pages around this one.

UAE PDPL compliance

The federal data protection obligations that apply to you regardless of anything European, and the same underlying data work.

Learn more

DIFC Data Protection Law

The separate regime for entities in the DIFC free zone, which is frequently confused with both the federal law and GDPR.

Learn more

IT audit services in Dubai

The wider audit practice, including the data inventory and access work that underpins any data protection obligation.

Learn more
Next step

Answer two questions before you spend anything.

Do you deliberately market or sell to people in Europe, and does your site profile visitors who are there. Those two go to the offering limb and the monitoring limb, and between them they resolve most cases. We will work through the rest with you and tell you plainly when the question belongs with a lawyer.

Book a GDPR applicability reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

DIFC DPL 5/2020

DIFC Data Protection Law readiness and Commissioner reporting

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

DLP Solutions

Microsoft Purview DLP and labels

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy