In this article

Kooky
Builder of Shaka, the payment router that pays every agent their commission on closing date.
About Kooky and Shaka →Take, as an illustration, a brokerage that holds its clients' names, telephone numbers and budgets, and types or uploads some of that into an artificial intelligence tool to draft a message or summarise a file. The law of the United Arab Emirates has a name for that operation. It is processing personal data, and since 2 January 2022 a federal decree-law has set out what that involves.
This guide reads the texts themselves. It covers Federal Decree-Law No. 45 of 2021 on the protection of personal data as published in English on the UAE's federal legislation portal, the separate regime of the Dubai International Financial Centre and its Regulation 10 on autonomous systems, and the national charter on artificial intelligence. It says what each asks, who it applies to, and where the published pages leave a question open. The brokerage scenarios used along the way are illustrations, not findings about how brokers work. The guide describes general rules, and how they apply to a given firm depends on that firm's facts.
Federal Decree-Law No. 45 of 2021, Articles 4 and 31, on the UAE legislation portal; the UAE Government portal for the charter.
Which law covers the brokerage
The first question is geographical, and the answer changes the whole rulebook. Article 2 of Federal Decree-Law No. 45 of 2021 applies the law to data subjects who reside in the UAE or have a place of business there, to controllers and processors established in the UAE, and to controllers and processors outside the UAE that process the data of people inside it. As an illustration, a tool provider based abroad that handles the details of a client living in Dubai falls within that third limb, and a brokerage established in Dubai within the second.
Related readSingapore property agents and AI: what the data and advert rules askThe same article then lists what the decree-law does not cover. Government data and government entities are outside it, as are data held by security and judicial authorities and a person's handling of their own data. Health data and banking and credit data are excluded where they have their own protection legislation. The last exclusion concerns geography: companies in free zones that have their own special data protection legislation.
The Dubai International Financial Centre is such a zone. The UAE Government portal lists its Data Protection Law, DIFC Law No. 5 of 2020, among the country's data protection laws, alongside the federal decree-law. A brokerage established in the DIFC looks to that law and to the DIFC Data Protection Regulations. A brokerage established in the rest of Dubai looks to the federal decree-law.
The federal decree-law steps back where a free zone has its own data protection law
Article 2 of Federal Decree-Law No. 45 of 2021 excludes companies in free zones that have their own special data protection legislation. Where the brokerage is established therefore decides which rulebook is read first.
The words the decree-law uses
Article 1 of the decree-law defines its terms. Personal data is any data about an identified or identifiable natural person, including sensitive and biometric data. Sensitive personal data is data that directly or indirectly reveals a person's family, ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or health, genetic or sexual condition.
Processing is any operation performed on personal data by electronic means. Automated processing is processing carried out by an electronic program or system, fully or partly without human intervention. Profiling is a form of automated processing that uses personal data to assess personal aspects of someone, and the definition lists financial standing, health, preferences, behaviour, location and reliability.
Two roles follow. The controller is the one that determines how and why personal data is processed. The processor handles personal data on the controller's behalf, under its instructions. As an illustration, a brokerage that decides to put its client list through a tool is, on those definitions, the one determining how and why. Whether the provider stays within the processor's role depends on the arrangement between them.
Related readUS mortgage AI denials: what the adverse action notice must sayConsent, and the ten cases that do without it
Article 4 states the starting rule in one line: processing personal data without the consent of its owner is prohibited. It then names ten cases where consent is not needed, and adds an eleventh item for any further cases the Executive Regulations may set.
Several of the ten concern public bodies or medicine. Others are of more general reach: processing is allowed without consent where the data subject has made the data publicly available, where it is necessary for legal claims or the defence of rights, where it is necessary for employment and social security obligations, and where it is necessary to meet obligations under other laws of the UAE.
One case is contractual. Processing is permitted where it is necessary to perform a contract to which the data subject is a party, or to take steps at the data subject's request before a contract. The word that carries the weight is "necessary". The decree-law does not say that anything convenient for serving a client is covered, and it does not contain a general ground based on the business's own interests among the ten.
Where consent is the basis, Article 6 sets three conditions for it to count. The controller must be able to prove it. It must be given in a clear, simple, unambiguous and easily accessible way, in writing or electronic form. And it must include the right to withdraw it, easily. The data subject may withdraw at any time, and withdrawal does not affect the lawfulness of processing done before it.
Related readUSA: eXp lets agents connect their own AI assistants to its dataWhat a controller owes when data enters a tool
Article 5 lists the controls every processing operation must respect. Processing must be fair, transparent and lawful. Data must be collected for a specific and clear purpose, and later processing must not be incompatible with it, though the article allows similar or close purposes. Data must be adequate and limited to what the purpose requires, accurate, and corrected or erased when wrong. It must be kept secure. And it must not be kept once its purpose has ended, unless it has been anonymised.
As an illustration of how these controls meet an AI tool: whether putting a client file into a tool is a "similar or close" purpose to the one the data was collected for is a question the article puts to the controller.
Article 7 turns the principles into duties. The controller must apply technical and organisational measures to protect confidentiality and privacy. It must apply suitable measures both when choosing the means of processing and during processing, and the article names pseudonymisation. The controller must keep a special record, to be given to the UAE Data Office on request, covering among other things the categories of data, the purposes, data moved across borders and the security measures. And it must appoint only processors that give sufficient guarantees of meeting the decree-law.
Article 8 sets the processor's side. The processor acts under a contract specifying the scope, subject, purpose and nature of the processing, the type of data and the categories of data subject. It does not disclose the data. Where several processors are involved, a written contract must define their roles, failing which they are jointly responsible. The table sets the two roles side by side.
Related readUS fake review rule: what the FTC bans for real estate agents| Duty | Controller (in the illustration, the brokerage) | Processor (in the illustration, a tool provider acting for it) |
|---|---|---|
| Basis for acting | Consent or one of the Article 4 cases | The controller's instructions and the contract |
| Record | Special record, given to the Office on request | Its own record of processing done for the controller |
| End of the period | No retention once the purpose has ended | Erase the data or hand it back |
| Breach | Notifies the Office and affected people | Notifies the controller as soon as aware |
Automated decisions and the client's rights
The decree-law gives the data subject a set of rights, and three of them speak directly to automated tools. Under Article 13, a person may ask the controller, at no cost, for information that includes the recipients inside and outside the UAE, the storage periods, and the decisions made on the basis of automated processing, including profiling. Before processing starts, the controller must already have told the person the purposes, the recipients and the protection measures for any cross-border processing. Article 13 also lists four grounds on which a request may be refused.
Under Article 17, a person may object to and stop processing for direct marketing, including profiling related to direct marketing.
Article 18 is the article on automated decisions. A person may object to decisions made by automated processing, including profiling, especially where they have legal effects or an adverse impact. The right does not apply in three cases: where the automated processing is agreed in a contract between the person and the controller, where it is required by other applicable laws, or where the person gave prior consent meeting Article 6. Even then, the controller must protect the person's privacy and must not prejudice their rights, and at the person's request it must include human review of the automated decision.
Article 15 allows a person to have inaccurate data corrected without undue delay, and to have data erased in the cases the article lists. Article 19 requires the controller to offer clear ways for people to reach it to exercise these rights. The decree-law itself sets no number of days for answering a request.
Related readUS housing algorithms: what HUD said on AI and what still appliesImpact assessments and the data protection officer
Article 21 requires the controller, before processing with modern technologies that pose a high risk to privacy, to assess the impact of the planned processing on personal data protection. The article names two situations where the assessment is required: where the processing systematically and comprehensively assesses personal aspects of people through automated processing, including profiling, with legal or serious effects on them; and where it involves a large volume of sensitive personal data. The article sets four minimum contents for the assessment. It is coordinated with the data protection officer and reviewed regularly, and the Office is to publish a list of processing that does not need one.
Article 10 requires a data protection officer in three situations: where processing creates a high risk to privacy because of new technologies or the volume of data; where it systematically and comprehensively assesses sensitive personal data, including through profiling and automated processing; and where it involves a large volume of sensitive personal data. The officer may be an employee or a person authorised by the controller or processor, inside or outside the UAE, and the officer's details must be notified to the Office. Under Article 12 the controller must not dismiss or discipline the officer for doing the job. The article leaves the types of technology and the volume criteria to the Executive Regulations, so the decree-law alone does not settle whether a given brokerage meets these triggers.
Sending client data outside the UAE
In the illustration, a tool hosted abroad means client data leaving the UAE. Article 22 allows transfers, in cases approved by the Office, to a state or territory that has data protection legislation and a judicial or regulatory authority able to impose measures on controllers and processors. It also allows them where the UAE has joined a bilateral or multilateral data protection agreement with the destination country.
Related readUS real estate AI this week: an MLS assistant, new data, title rulesArticle 23 covers destinations without that level of protection. A transfer is still possible under a contract that obliges the recipient to apply the measures, controls and requirements of the decree-law. It is possible with the data subject's explicit consent, provided the transfer does not conflict with the public or security interest of the UAE. It is possible where necessary to perform a contract between the controller and the data subject, and in a few further cases concerning legal rights, judicial cooperation and the public interest. Further conditions are left to the Executive Regulations.
None of the pages read for this guide carries a list of destinations approved by the Office under Article 22.
Breaches, complaints and penalties
Article 9 deals with a data breach, a term Article 1 defines. When the controller becomes aware of a breach that prejudices the privacy, confidentiality or security of someone's data, it must notify the UAE Data Office, with the content the article lists in six points. The controller must also notify the people affected. A processor that learns of a breach must tell the controller as soon as it becomes aware of it.
On timing, the decree-law gives no number of hours or days: both notices are due within the period set by the Executive Regulations.
Article 24 lets a data subject complain to the Office. Under Article 25, anyone affected by a decision of the Office may file a written grievance with its General Director within 30 days of being notified, the grievance must be decided within 30 days of being filed, and a decision cannot be challenged in court before that step.
Related readAustralia: what privacy law asks of an agency using AI toolsOn penalties, Article 26 does not set amounts. It provides that the Council of Ministers will issue a decision defining the violations and the administrative penalties.
Where the regulations and the Data Office stand
A good part of the decree-law waits on a second text. Article 28 says the Council of Ministers must issue the Executive Regulations within six months of the decree-law's promulgation. Article 29 gives controllers and processors no more than six months from the issue of those regulations to bring themselves into line, a period that may be extended by a similar one. Article 3 lets the Office exempt establishments that do not process large volumes of personal data from some or all of the requirements, under standards the regulations are to set.
- The decree-lawIssued on 20 September 2021 and in effect from 2 January 2022.
- Executive RegulationsDue within six months of promulgation. They set breach notice periods and the criteria for officers.
- Compliance periodNo more than six months after the regulations are issued, extendable by a similar period.
The federal legislation portal records the decree-law as active, with no update listed after its issue date. Its list of related legislation, as read on 10 October 2026, shows two later federal decree-laws, dated 2024 and 2025, on other subjects. The Executive Regulations for the decree-law and a Council of Ministers decision on penalties are not shown on the portal as read on 10 October 2026. The notice periods, the volume criteria and the penalties are the matters the decree-law leaves to those two texts.
The regulator is the UAE Data Office, established by Federal Decree-Law No. 44 of 2021. The UAE Government portal describes it as affiliated with the Cabinet and as the federal data regulator, responsible among other things for preparing the systems for complaints and grievances and issuing guidelines for applying the law.
Related readAustralia: PropertyMe links agencies' own AI assistants to live dataHow the DIFC and its Regulation 10 differ
Inside the Dubai International Financial Centre the rulebook is the Data Protection Law, DIFC Law No. 5 of 2020, enacted in May 2020 according to the DIFC, with the DIFC Data Protection Regulations beneath it. The Commissioner of Data Protection supervises and enforces the law.
The regulations in their Consolidated Version No. 2, in force from 1 September 2023, contain operating detail that the federal decree-law leaves to its Executive Regulations. An entity must notify the Commissioner within 30 days of starting to process personal data, renew on each anniversary while processing continues, and notify within 30 days of a change. A personal data breach is reported to the Commissioner without undue delay, and the Commissioner may direct the controller to tell the people affected. The record of processing is compulsory, with an exemption for entities with fewer than 50 employees unless they carry out what the law calls High Risk Processing. Appendix 3 lists the jurisdictions treated as adequate for transfers out of the centre. Abu Dhabi Global Market is on that list, and the UAE outside the free zones is not.
| Fee | Category I | Category II | Category III |
|---|---|---|---|
| Registration | US$1,250 | US$750 | US$250 |
| Annual renewal | US$500 | US$250 | US$100 |
| Amendment to notified particulars | US$100 | US$50 | US$10 |
DIFC Data Protection Regulations, Consolidated Version No. 2, in force 1 September 2023. Category I: entities authorised by the DFSA. Category II: other entities, except retail. Category III: retail entities.
A worked example, assuming an entity in Category II that registers, renews on its first and second anniversaries and files one amendment: US$750, plus two renewals of US$250, comes to US$1,250, and the amendment at US$50 brings the total to US$1,300. Which category a given brokerage falls in is for the DIFC's own classification.
Regulation 10, which the Commissioner's guidance says was enacted in September 2023, is addressed to personal data processed through autonomous and semi-autonomous systems. It defines a System as a machine-based system that operates autonomously or semi-autonomously, processes personal data for purposes defined by humans, by itself or both, and generates output from that processing. The Commissioner's frequently asked questions, last updated on 27 August 2024, say the definition draws on OECD guidelines and the European Union's AI Act, and that purely deterministic, human-controlled automated systems are not meant to be caught.
Related readCalifornia's law on digitally altered listing photos, explainedThe regulation then assigns roles. A Deployer is the person under whose authority, on whose direction or for whose benefit a System operates, or who receives the benefit of its output, whether or not that person hosts or operates it. An Operator is a provider that operates or supervises a System on behalf of a Deployer. A Deployer is deemed a controller and an Operator a processor. The Commissioner's frequently asked questions do not deal directly with a business that uses another company's chatbot.
The duties that follow are specific:
- Notice. On first use of or access to an application or website service that uses a System, users must be given a clear and explicit notice that the underlying technology may process personal data without human initiation, control or direction. The notice must also describe the human-defined purposes, the outputs and how they are used, the effect on individual rights, and the codes or certifications the System follows.
- Evidence on request, including the algorithms that trigger human intervention where processing may have unfair or discriminatory effects, with a risk and impact assessment.
- A register of Systems, available on request, covering use cases, necessity and proportionality, and whether a System makes solely automated decisions.
- Design principles. A System must be designed to be ethical, fair, transparent, secure and accountable, each of which the regulation defines.
Commercial use of a System that processes personal data is allowed only where it processes for purposes humans defined or approved, or for self-defined purposes strictly within human-set constraints, and meets those design principles. For High Risk Processing the bar is higher: the Commissioner must have set audit and certification requirements, the System must comply, and the Deployer or Operator must have appointed an Autonomous Systems Officer, a role the regulation models on the data protection officer. The two DIFC documents read here differ on where that stands. The regulations' own guidance text says no System may be used for High Risk Processing until the Commissioner issues the requirements, while the 2024 frequently asked questions say an Accreditation and Certification Framework has been published, under which certification of a System lasts a maximum of three years and accreditation of a certifying body five.
The DIFC consulted in 2026 on changes to Regulation 10
A DIFC Authority consultation paper dated June 2026, open for comment until 18 July 2026, proposed a new "Safety" concept, detailed duties and skills for the Autonomous Systems Officer and a new Regulation 11 on recognising certification frameworks. The paper says the draft is not final and gives no date for it to take effect.
The UAE charter on artificial intelligence
The UAE Charter for the Development and Use of Artificial Intelligence, as presented on the UAE Government portal on a page last updated on 3 July 2026, sets out twelve principles, seven policy objectives and five expected outcomes, and says it aims to achieve the goals of the UAE Strategy for Artificial Intelligence.
The twelve principles, in the charter's order, are strengthening human-machine ties, safety, algorithmic bias, data privacy, transparency, human oversight, governance and accountability, technological excellence, human commitment, peaceful coexistence with AI, promoting AI awareness for an inclusive future, and commitment to treaties and applicable laws. The second of the seven policy objectives is to protect privacy and data security.
The portal page does not say whether the charter is binding, and it does not name the body that issued it or the date.