August 28, 2026
What is an information security policy? Learn the core components, policy types, step-by-step writing guide, and get a free template.

August 27, 2026
Which UAE data protection law applies to your business? Compare federal PDPL, DIFC, and ADGM rules, plus GDPR differences and compliance steps.

Navigate Compliance Challenges for GCC Enterprises with confidence. Learn VARA, ISO 27001, CBUAE, PDPL, and PCI DSS requirements, compliance strategies.
GDPR the General Data Protection Regulation is the European Union's law governing how organizations collect, store, and process personal data. It took effect on May 25, 2018, and applies to any company worldwide that handles the personal data of EU residents, regardless of where that company is based.
That last point is what catches many businesses off guard. A fintech platform in Dubai, a real estate developer in Abu Dhabi, or a crypto exchange serving European clients doesn't need an EU office to fall under GDPR; it just needs an EU resident's data in its systems. Non-compliance carries real financial weight: fines can reach €20 million or 4% of a company's global annual revenue, whichever is higher, and regulators have shown they're willing to use that ceiling. This guide breaks down what GDPR actually requires, the articles that matter most in practice, and how it compares to the data protection regulations already shaping compliance across the UAE.
GDPR stands for General Data Protection Regulation, the European Union's legal framework for protecting personal data. The acronym itself is straightforward, but each word signals something specific about what the law does: it's "general". It applies broadly across nearly every industry and data type, "data protection" because its core concern is how personal information is collected, used, and safeguarded, and "regulation". After all, unlike a directive, which EU member states can interpret and implement differently, a regulation applies uniformly and directly across all 27 EU member states without needing separate national legislation.
That distinction matters more than it seems.
Before GDPR, EU data protection was governed by a 1995 directive, which meant each country had its own version of the rules, creating inconsistency for any business operating across borders. GDPR replaced that patchwork with a single, enforceable standard, which is part of why it has become the reference point that other regions including several GCC jurisdictions building out their own data protection frameworks have looked to when drafting comparable laws.
The purpose of GDPR is to give individuals control over their personal data and to hold organizations accountable for how they collect, use, and protect it. Before the regulation, companies could gather personal information with minimal transparency and few consequences for mishandling it. GDPR changed that by making consent, transparency, and accountability legal obligations rather than best practices a business now has to justify why it holds someone's data, not just what it does with it. That obligation is typically formalized through a documented information security policy that governs how data is classified, accessed, and retained.
GDPR protects "personal data," a deliberately broad category that covers anything that can identify a living person names, email addresses, IP addresses, location data, financial details, and even things like cookie identifiers or biometric data. It also creates a stricter tier called "special category data," which includes health information, religious beliefs, sexual orientation, and racial or ethnic origin. Processing this special category data requires a higher legal bar to justify, since misuse of this information carries a greater risk of discrimination or harm to the individual a risk organizations typically evaluate through a vulnerability assessment of the systems where that data resides.
GDPR applies to any organization established in the EU, but its reach doesn't stop there. Under Article 3, a company outside the EU including one based in Dubai, Riyadh, or anywhere else in the GCC still falls under GDPR if it offers goods or services to people in the EU or monitors the behavior of EU residents, such as tracking website visitors through analytics or advertising cookies. This extraterritorial scope is one of GDPR's most distinctive features: physical presence in the EU isn't the trigger, contact with EU residents' data is.
A GCC-based e-commerce platform shipping to European customers, or a SaaS company with EU-based users, is squarely in scope even without a single employee on European soil which is why mapping external-facing exposure through attack surface management has become a practical first step for regionally based companies assessing their GDPR footprint.
The European Parliament and Council adopted the GDPR on April 27, 2016, and it became enforceable on May 25, 2018, giving organizations a two-year window to bring their data practices into compliance before penalties were applied. That gap between adoption and enforcement wasn't incidental it reflected how significant a shift the regulation represented, requiring companies to rebuild consent mechanisms, data inventories, and breach-response processes from the ground up.
Formally, GDPR is known as Regulation (EU) 2016/679, and it replaced the EU's 1995 Data Protection Directive (Directive 95/46/EC), which had governed data protection across member states for over two decades. The move from a directive to a regulation is what gave GDPR its force: a directive requires each country to pass its own implementing legislation, whereas a regulation is directly binding and enforceable in the same form across all EU member states. Since it entered into force in 2018, GDPR has become the most-cited data protection framework globally, prompting comparable laws in regions ranging from California (CCPA) to the UAE, where local frameworks now echo several of its core principles around consent and data subject rights.
GDPR contains 99 articles, but a handful recur in compliance discussions because they define the regulation's operational core how data can be legally processed, what companies must disclose, and what happens when things go wrong.
Article 6 sets out the legal grounds a company must have before processing anyone's personal data processing without one of these bases is unlawful regardless of intent. The regulation recognizes six: consent, contractual necessity, legal obligation, protection of vital interests, performance of a public task, and legitimate interests. In practice, most commercial data processing relies on either consent (an explicit, informed opt-in) or legitimate interests (a documented business justification that doesn't override the individual's rights), and choosing the wrong basis is one of the most common gaps that surfaces during a governance, risk, and compliance review.
Article 13 requires organizations to tell people, at the point data is collected, exactly what's being collected, why, how long it will be kept, and with whom it might be shared. This is the legal basis behind every privacy notice and cookie banner transparency isn't optional disclosure, it's a mandated component of lawful data collection, and omitting any of the required elements can itself constitute a violation independent of how the data is later used.
Article 22 gives individuals the right not to be subject to decisions made solely by automated processing including profiling when those decisions produce legal or similarly significant effects, such as loan approvals or job application screening. As AI-driven decision tools have become standard in hiring, lending, and insurance, this article has become more relevant: companies deploying AI-driven systems for consequential decisions typically need to build in human review or an appeals mechanism to remain compliant.
Article 28 governs the relationship between a data controller (the organization that decides why and how data is processed) and a data processor (a third party that processes data on the controller's behalf, such as a cloud host or payment provider). It requires a binding data processing agreement between the two, spelling out the processor's obligations, security measures, and limits on subprocessing. Any company outsourcing data handling which is nearly all of them, given how common cloud infrastructure and SaaS tools are needs these agreements backed by verified security controls, typically confirmed through vendor and application source code reviews rather than taken on trust.
Article 49 addresses one of the more complex aspects of the GDPR: transferring personal data outside the EU. Transfers to countries without an EU "adequacy" decision generally require additional safeguards, such as Standard Contractual Clauses, or must fall under one of Article 49's specific exceptions, like explicit consent for a one-off transfer. This is directly relevant to GCC businesses processing EU customer data on regional infrastructure, and it's a consideration that belongs in any enterprise cybersecurity platform evaluation, rather than being addressed only after infrastructure decisions are already made.
Article 82 gives individuals the right to claim compensation from an organization if they've suffered material or non-material damage as a result of a GDPR violation meaning harm doesn't have to be financial to be compensable; documented distress can qualify too. This article is part of why GDPR enforcement carries real teeth beyond regulatory fines: it opens the door to individual and class-action-style claims, and European courts have increasingly allowed non-material damage claims to proceed, raising the stakes of a poorly handled incident response well beyond the headline regulatory fine.
GDPR compliance means an organization can demonstrate, not just claim, that its data practices align with the regulation's core principles. This distinction matters because the burden of proof sits with the company, not the regulator. Compliance isn't a one-time checklist; it's an ongoing operational discipline covering how data is collected, stored, secured, and eventually deleted.
GDPR is built on seven core principles, but three tend to drive the most day-to-day compliance work. Lawfulness, fairness, and transparency require that data be processed on a valid legal basis and that individuals understand how their information is used the same obligation that underlies Article 6 and Article 13. Data minimization requires that organizations collect only what's genuinely necessary for a stated purpose, rather than gathering data broadly on the chance it might be useful later.
Accountability requires that companies not only comply but also be able to prove it through records of processing activities, documented risk assessments, and internal policies that hold up under regulatory scrutiny. Together, these principles shift the compliance question from "did we follow the rules" to "can we show we followed the rules," which is why compliance advisory support has become as central to GDPR readiness as the technical controls themselves.
The most frequent compliance failures aren't dramatic data breaches they're foundational gaps that go unnoticed until an audit or a regulator inquiry surfaces them. Relying on the wrong lawful basis for processing, such as defaulting to "legitimate interests" without documenting the balancing test required by Article 6, is one of the most common issues. Vague or bundled consent asking users to accept a blanket privacy policy rather than obtaining specific, granular consent for each processing purpose is another common target of regulatory fines. Missing or outdated data processing agreements with third-party vendors under Article 28 is a third: many companies assume their cloud provider or payment processor is automatically compliant, when the obligation to have a binding agreement in place sits with the data controller. Underlying most of these gaps is a lack of regular vulnerability assessments and penetration testing to verify that the technical controls behind those policies actually hold up which is part of why security awareness training is treated as a compliance requirement, not just a security nice-to-have. According to the DLA Piper GDPR Fines and Data Breach Survey, cumulative GDPR fines issued since 2018 have passed €5.88 billion, with a significant share tied to exactly these kinds of foundational lapses rather than sophisticated cyberattacks.
GDPR doesn't operate in isolation it's the template most other modern data protection laws have been measured against. Still, it isn't identical to every framework it inspired, and the differences matter for any organization operating across multiple jurisdictions.
UK GDPR and EU GDPR share the same origin and nearly identical text, but they became separate legal regimes after Brexit. When the UK left the EU, it incorporated GDPR directly into domestic law as the "UK GDPR," which is enforced by the Information Commissioner's Office rather than an EU data protection authority. The practical effect is that a company handling both UK and EU personal data now has two parallel though largely overlapping compliance obligations rather than one, including separate registers, separate breach notification duties, and its own rules on transferring data between the UK and EU, which no longer automatically qualifies as an "adequate" transfer under EU law without a specific adequacy decision.
Several GCC jurisdictions have introduced their own data protection laws in the years since GDPR took effect, and the resemblance isn't a coincidence lawmakers across the region drew directly on GDPR's structure when building frameworks like the UAE's Federal Decree Law No. 45 of 2021. These regional laws typically mirror GDPR's core concepts lawful basis for processing, data subject rights, breach notification duties but differ in scope, enforcement mechanics, and sector-specific carve-outs, particularly around free zones like DIFC and ADGM, which run their own independent data protection regimes distinct from UAE federal law.
Businesses operating in regulated sectors also need to reconcile GDPR with frameworks like VARA compliance for virtual asset businesses or ISO 27001 and understanding how these frameworks compare, much like the distinctions covered in ISO 27001 vs SOC 2 vs PCI DSS, is essential for any regional company with EU-facing operations. A GCC business handling both EU and UAE resident data isn't choosing between frameworks; it needs to satisfy both simultaneously, which is why understanding UAE's own data protection law alongside GDPR has become a standard part of regional compliance planning.
GDPR matters for GCC businesses because compliance isn't determined by where a company is headquartered it's determined by whose data it touches and a growing share of the region's fintech, real estate, and Web3 companies now handle EU-resident data as a routine part of doing business.
As covered under Article 3, GDPR applies to any organization that offers goods or services to people in the EU or monitors their online behavior, regardless of where that organization is based. For GCC companies, this shows up in ordinary business activity more often than it might seem: a Dubai-based real estate platform marketing to European investors, a Saudi enterprise fintech app accepting EU cardholders, or a crypto exchange with European users all fall under GDPR's reach the moment they collect that data. The exposure isn't theoretical European regulators have pursued enforcement action against companies with no EU physical presence, treating the data subject's location, not the company's, as the jurisdictional trigger. Government Cybersecurity entities that handle EU citizens' data as part of cross-border programs face the same exposure.
Once a GCC business collects EU-resident data, the next question is where that data is stored and processed, since moving it outside the EU triggers transfer restrictions under Article 49. The UAE currently doesn't have an EU adequacy decision, which means GCC companies including smart contract-based platforms handling EU user data typically need to rely on mechanisms such as Standard Contractual Clauses to legally justify transferring EU data to regional servers or systems. This is a detail that's easy to overlook when infrastructure decisions are made for performance or cost reasons rather than compliance ones a company choosing regional cloud hosting for latency reasons still needs a valid transfer mechanism in place, independent of why the infrastructure choice was made in the first place.
GDPR compliance ultimately rests on verified security posture, not policy documents alone. Femto Security supports GCC businesses navigating GDPR and regional frameworks by providing dark web monitoring for exposed customer data, red teaming and penetration testing to validate technical controls, threat intelligence to track region-specific risks, and a free domain data breach scan to check for prior exposure. For virtual asset businesses managing both GDPR and VARA obligations, our guides on VARA compliance standards and VASP assessment requirements cover the overlapping ground in more depth.
GDPR is the European Union's law that requires organizations to protect the personal data of EU residents and be transparent about how that data is collected, used, and stored. It applies to any company that handles EU residents' data, whether or not it is based in the EU.
Yes. Under Article 3, GDPR applies to any organization regardless of location that offers goods or services to people in the EU or monitors their behavior, such as through website tracking or targeted advertising.
Violations can result in fines of up to €20 million or 4% of global annual revenue, whichever is higher, along with potential compensation claims from affected individuals under Article 82. Cumulative GDPR fines issued since 2018 have passed €5.88 billion, according to the DLA Piper GDPR Fines and Data Breach Survey.
No. The UK GDPR and EU GDPR share nearly identical text. Still, they are separate legal regimes since Brexit, each enforced by different regulators and governing cross-border data transfers between the UK and the EU independently.
Any GCC business that collects or processes the personal data of EU residents whether through e-commerce, marketing, or app use falls within the GDPR's extraterritorial scope, regardless of whether it has a physical presence in the EU.
The UAE's federal data protection law closely mirrors the GDPR's core structure but has its own scope, enforcement mechanisms, and free-zone-specific regimes under the DIFC and ADGM. Businesses handling data from both EU and UAE residents need to comply with both frameworks, not just one.