We are currently operating in the United Arab Emirates, Bahrain, Kuwait, Qatar, Saudi Arabia, the United Kingdom, and Sri Lanka — providing top-tier recruitment solutions across multiple industries.

Our Blog

UAE Data Protection Law (PDPL) and HR: Employee Data Rules
Information · September 21, 2026

UAE Data Protection Law (PDPL) and HR: Employee Data Rules

An Abu Dhabi logistics company reviewing its onboarding form last quarter found questions about employees' religion, marital status and even next of kin's employer, none of which anyone in HR could explain a use for. Nobody had ever removed them since the form was built years earlier. A short exercise in collecting the right data during onboarding cut the form by a third.

Federal Decree-Law No. 45 of 2021, the UAE Personal Data Protection Law, applies to employee records the same way it applies to customer data. HR teams that only think of PDPL as a marketing or IT compliance issue are missing a category of personal data sitting in their own files.

This piece sets out what HR data employers can legally collect and store, when consent is actually required, what counts as sensitive data, and where PDPL stops applying because a different framework takes over.

 

Quick Answer

Federal Decree-Law No. 45 of 2021 (PDPL) covers employee personal data for mainland UAE employers and most free zones, but not DIFC or ADGM, which run their own laws.

Core HR data needed to run the employment relationship, such as salary and Emirates ID, is generally justified by contractual or legal necessity, not consent.

Health, biometric and other sensitive data categories need extra care and a specific documented basis.

The PDPL's executive regulations' publication status is genuinely unclear as of 2026, despite some vendors citing specific Cabinet Decision numbers.

 

Why PDPL Applies to HR Data at All

The PDPL treats any employer holding employee personal data as a data controller, the party that decides how that data is used, with the employee as the data subject. the UAE government's official data protection overview confirms the law covers processing of personal data whether in full or in part through electronic systems, which includes an ordinary HR system or spreadsheet.

The UAE Data Office, established to oversee the law, is responsible for preparing standards, handling complaints and issuing implementation guidance. It does not police HR departments specifically, but an employee complaint about how their data was handled falls squarely inside its remit.

For the exact statutory language, the official PDPL legislation text remains the authoritative source, and is worth checking directly rather than relying solely on third-party summaries that sometimes disagree on specifics.

That last point matters more than it sounds. Several PDPL compliance guides circulating online cite different article numbers, different penalty figures and different implementation dates for the same provisions, likely a byproduct of AI-generated content repeating each other's errors. Going back to the primary legislation is the only reliable way to settle a genuine dispute over what the law actually says.

 

Consent Is Not Always the Right Basis for HR Data

A common misconception is that every piece of employee data needs signed consent. In practice, most core HR processing, payroll, contract administration, leave tracking, rests on contractual necessity or legal obligation rather than consent, since the data is required to perform the employment contract or comply with UAE labour law itself.

Consent carries a specific problem in an employment relationship: it is supposed to be freely given, and an employee asked to consent to data processing by their employer is rarely in a position to refuse without consequence. Relying on consent for data the employer needs regardless is generally weaker practice than citing the actual legal basis that applies.

A useful test is to ask what would happen if an employee withdrew consent. If withdrawing consent would not actually stop the employer from processing that data, because the contract or the law requires it regardless, then consent was never the real basis to begin with, and documenting it as such creates a false sense of compliance rather than genuine protection.

 

What HR Data Falls Into Which Category

 

Data Category

Example

Typical Lawful Basis

Core identity and contract data

Name, Emirates ID, passport, visa, job title, salary

Contractual necessity / legal obligation

Payroll and banking data

Bank account, WPS salary details

Contractual necessity / legal obligation

Performance and disciplinary records

Appraisals, warnings, attendance logs

Legitimate interest, proportionate to purpose

Sensitive data

Health records, biometric identifiers, religion, criminal history

Explicit consent or a specific legal exception

Optional or promotional data

Staff photo for a newsletter, voluntary survey responses

Consent

 

Recruitment data deserves its own thought, since candidates are also data subjects before they are ever hired. limiting the data collected during recruitment to what the role actually requires avoids building a bloated file that outlives its original purpose.

 

Sensitive Data: Biometric Attendance and Health Records

Fingerprint and facial recognition attendance systems are common across UAE offices, warehouses and construction sites, and biometric data used to identify a specific person falls into the PDPL's sensitive category. That does not make biometric attendance unlawful, but it does mean employers should be able to point to a documented basis and a clear purpose.

Medical fitness certificates, sick leave documentation and any health screening results carry the same heightened sensitivity. HR teams should limit access to that data internally, avoid storing it in the same general personnel file everyone with system access can open, and keep it only as long as the underlying purpose requires.

The safest practical pattern is separation rather than restriction alone: keep sensitive categories in a distinct system or folder with its own access list, rather than trusting a single shared HR database's permission settings to quietly do the job. Permission settings drift over time as staff change roles; a physically or logically separate store is harder to accidentally expose.

 

Do Executive Regulations Exist Yet? The Honest Answer

This is worth stating plainly rather than glossing over. Several compliance vendors and consultancy sites confidently cite a specific Cabinet Decision number for the PDPL's executive regulations, but those citations disagree with each other, some pointing to a 2022 decision, others to 2023 or 2024 numbers.

The UAE Legislation portal's own entry for the PDPL does not list a confirmed related executive regulation as of this writing, and established law firm trackers describe the regulations as still pending. Employers are better served treating the PDPL's own text as the operative standard rather than assuming detailed implementing rules already exist.

 

Where PDPL Stops Applying

PDPL does not cover government authorities, security and judicial bodies, or data already regulated under separate health and banking data laws. It also excludes entities registered in the DIFC and ADGM, which run the DIFC Data Protection Law and the ADGM Data Protection Regulations respectively.

Groups running both a mainland entity and a DIFC or ADGM entity need two separate HR data policies, not one PDPL-based policy stretched to cover both. For the mainland employment context this data sits within, the 2024 labour law amendment overview is a useful companion piece on how the broader mainland framework has evolved.

This distinction is not academic for HR teams. A privacy notice or handbook clause drafted for a DIFC entity, referencing the DIFC Commissioner of Data Protection, is the wrong reference point for a mainland sister company, and copying it across without adjustment is a common and avoidable documentation error.

 

Retention, Payroll Data and Practical Handling

Salary and banking data collected for payroll ties directly into WPS compliance, and it is worth understanding how UAE payroll data flows through WPS when deciding how long to retain that specific dataset and who inside the company should have access to it.

Wage data rules connected to WPS payroll confirm that salary information must be accurate and payable on time, which is itself a reason payroll data needs to stay current and correctable rather than static once entered.

The PDPL's storage-limitation principle means data should not outlive its purpose. In practice, aligning HR record retention with the UAE government's private-sector labour guidance and the two-year labour claim window gives employers a defensible, documented retention period rather than an indefinite one.

 

Building a PDPL-Aligned HR Data Policy

A practical starting point is to document a data protection policy in the employee handbook, stating what data is collected, why, who can access it and how long it is kept. Employees should be able to find this in one place rather than piecing it together from separate onboarding forms.

Following that, auditing what personal data your HR files actually hold surfaces exactly the kind of unused fields the Abu Dhabi logistics company found in its onboarding form: data collected out of habit rather than any documented purpose.

 

The Bottom Line for HR Teams

PDPL compliance for HR data is less about a single sweeping policy and more about matching each category of employee data to an actual, documented reason for holding it. Core contract and payroll data rests on solid legal ground; sensitive categories need more care; anything collected out of habit is a liability with no upside.

The employers doing this well are not the ones with the longest privacy policy. They are the ones who can explain, field by field, why each piece of employee data sits in their system and how long it is staying there.

 

Get Your HR Data Practices PDPL-Aligned

Not sure what your onboarding forms, HR system, and payroll files actually hold? ReapHR audits HR data collection and builds handbook policies that match what the PDPL actually requires.

 

Start with an HR data audit, or move to documenting your data policy in the handbook if you already know where the gaps sit.

 

Frequently Asked Questions

Does the UAE PDPL apply to employee data on the mainland?

Yes. Federal Decree-Law No. 45 of 2021 covers personal data processing by mainland UAE employers and most free zones, including employee records. DIFC and ADGM are excluded, since they run their own separate data protection laws, so a group with entities in both areas needs to apply different rules to each.

Do employers need employee consent to collect HR data?

Not always. Core HR data needed to perform the employment contract, such as salary, bank details and Emirates ID, is generally justified under contractual or legal necessity rather than consent. Consent becomes more relevant for optional processing, like using a photo for internal newsletters or non-essential monitoring.

What counts as sensitive personal data in an HR file?

Health records, biometric data used for identification, and information revealing religion, race or criminal history are treated as sensitive categories under the PDPL. Employers collecting fingerprint attendance data, medical fitness certificates or DNA-adjacent health screening results should apply extra safeguards and a documented lawful basis for that specific data.

Have the PDPL executive regulations been issued yet?

This remains genuinely unclear. Several compliance vendors claim executive regulations were published in 2023 or 2024, citing different Cabinet Decision numbers, but neither the UAE Legislation portal nor major law firm trackers confirm a published instrument as of mid-2026. Employers should follow the PDPL's own text rather than assume detailed rules already exist.

How long can employers keep former employees' HR data?

The PDPL does not set a fixed retention period itself, but its storage-limitation principle means data should not be kept longer than the purpose requires. In practice, UAE labour law record-keeping expectations and the two-year claim window make retaining core employment records for at least two years after exit a reasonable baseline.