United Arab Emirates Data Privacy
Overview
Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) regulates the collection, use and processing of personal data in the UAE (excluding the Dubai Financial Centre (“DIFC”) and the Abu Dhabi Global Market (“ADGM”)) (“onshore UAE”). The PDPL sets out the conditions for lawful processing and protection of personal data. The PDPL states that Executive Regulations will be issued to supplement the PDPL. These Executive Regulations have not been issued to date.
The PDPL does not apply in the DIFC and the ADGM. Both the DIFC and the ADGM have their own data protection regulations which are not addressed on this webpage.
AWS is vigilant about customers’ privacy and data security. Security at AWS starts with our core infrastructure. Custom-built for the cloud and designed to align with the most stringent security requirements in the world, our infrastructure is monitored 24x7 to help ensure the confidentiality, integrity, and availability of our customer's data. The same world-class security experts who monitor this infrastructure also build and maintain our broad selection of innovative security services, which can help customers simplify meeting their own security and regulatory requirements. As an AWS customer, regardless of customers’ size or location, our customers benefit from our experience, and support of the highest privacy standards and compliance certifications.
AWS implements and maintains technical and organizational security measures applicable to AWS cloud infrastructure services under globally recognized security assurance frameworks and certifications, including ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1, and SOC 1, 2, and 3. These technical and organizational security measures are validated by independent third-party assessors, and are designed to prevent unauthorized access to or disclosure of customer content.
For example, ISO 27018 is the first International code of practice that focuses on the protection of personal data in the cloud. It is based on ISO information security standard 27002 and provides implementation guidance on ISO 27002 controls applicable to Personally Identifiable Information (PII) processed by public cloud service providers. The ISO 27018 certification demonstrates to customers that AWS has a system of controls in place that specifically address the privacy protection of their content.
These comprehensive AWS technical and organizational measures are consistent with the goals of the APPs to protect personal data. Customers using AWS services maintain control over their content and are responsible for implementing additional security measures based on their specific needs, including content classification, encryption, access management and security credentials.
AWS does not have visibility into or knowledge of what customers are uploading onto AWS Services. Customers are ultimately responsible for their own compliance with the PDPL and other data protection and privacy laws applicable to them. The content on this page supplements the existing Data Privacy resources to help customers align their requirements with the AWS Shared Responsibility Model when they store and process personal data using AWS services.