A UAE company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. The wrinkle here is specific to the UAE: there is no single national data protection law to check against. A federal law and two independent free-zone laws run in parallel, and which one applies to you turns on where you are established. What none of them changes is the EU obligation.

Key takeaways

  • GDPR Article 27 applies to UAE companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.
  • The UAE runs three parallel data protection regimes: the federal PDPL under the UAE Data Office, the DIFC Data Protection Law under the DIFC Commissioner, and the ADGM Data Protection Regulations under the ADGM Office of Data Protection. Which one governs you depends on where you are established.
  • The DIFC and ADGM laws are establishment-based and neither imposes a GDPR Article 27 style local representative on a foreign company. None of the UAE regimes appoints an EU contact point for you.
  • Most UAE companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
  • We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.

How does a UAE company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

This catches the ordinary shape of a UAE business trading into Europe. A Dubai-based ecommerce, travel or tourism operator, or a crypto or fintech business, that ships to or takes orders from consumers in the EU is offering goods and services to people in the EU. A UAE-based mobile app or adtech firm that tracks EU users is monitoring their behavior. Nothing about being established in the UAE removes Article 3(2), and either activity triggers Article 27.

Which UAE data protection law applies, and does it require an EU representative?

None of them requires an EU representative, but which one governs you at home is worth being precise about, because the UAE runs three regimes side by side.

  • Federal. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the federal regime, and its provisions reach processing carried out inside or outside the country. It is regulated by the UAE Data Office, established under Federal Decree-Law No. 44 of 2021. This is the law that applies to a company in mainland UAE.
  • DIFC. The Dubai International Financial Centre applies its own DIFC Data Protection Law No. 5 of 2020 within the jurisdiction of the DIFC, to controllers and processors incorporated there. It is regulated by the DIFC Commissioner of Data Protection, and it does not impose a GDPR Article 27 style local representative on foreign companies.
  • ADGM. The Abu Dhabi Global Market applies its own ADGM Data Protection Regulations 2021 to processing in the context of an establishment in the ADGM. It is regulated by the ADGM Office of Data Protection, headed by a Commissioner of Data Protection, and it has no local representative obligation for foreign companies.

The load-bearing point is that a company established in the DIFC or the ADGM is governed by that free zone’s own data protection law and its own regulator, not by the federal PDPL. These are independent financial free zones with their own frameworks, so where you are established decides which law and which authority you answer to. What stays constant across all three is that none of them gives you the EU representative that Article 27 asks for. That obligation is a requirement of EU law and sits outside every UAE regime.

Who regulates this?

At home, it depends on your establishment: the UAE Data Office for the federal PDPL, the DIFC Commissioner of Data Protection for the DIFC, and the ADGM Office of Data Protection for the ADGM. In the EU, it is the supervisory authority in the member state where your representative sits, working within the wider network of authorities coordinated through the European Data Protection Board. None of the UAE regulators administers Article 27, and no EU authority administers a UAE regime, which is why satisfying one says nothing about the other.

Do UAE companies also need a UK representative?

In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a UAE company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, and where you also target the UK we take the UK representation directly too. The same senior expert stays on your account rather than handing it to a junior.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are a UAE company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, whichever UAE regime governs you at home. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does a UAE company need an EU representative?

If your company is based in the UAE, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then yes, GDPR Article 27 requires you to appoint a representative established in an EU member state. The exemption in Article 27(2) is narrow, for occasional and low-risk processing that does not involve large-scale special category or criminal data, and a Dubai ecommerce, travel, crypto, fintech or adtech business running on EU users rarely fits it. Being in the UAE does not remove Article 3(2).

Which UAE data protection law applies to us?

It depends on where you are established. A company in mainland UAE sits under the federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, regulated by the UAE Data Office. A company incorporated in the DIFC sits under the DIFC Data Protection Law No. 5 of 2020, regulated by the DIFC Commissioner of Data Protection. A company established in the ADGM sits under the ADGM Data Protection Regulations 2021, regulated by the ADGM Office of Data Protection. The DIFC and ADGM are independent financial free zones with their own frameworks, so the law and the regulator change with your place of establishment.

Do any of the UAE regimes give us the EU representative we need?

No. The DIFC Data Protection Law and the ADGM Data Protection Regulations are establishment-based and neither imposes a GDPR Article 27 style local representative on a foreign company. Whichever UAE regime you fall under, it governs how you process personal data at home. None of them appoints a contact point inside the EU for a European regulator, because that is a requirement of EU law and sits outside the reach of any UAE framework.

Do UAE companies also need a UK representative?

Usually, yes. The UK runs its own Article 27 obligation under the UK GDPR, enforced by the Information Commissioner's Office, and a UAE business selling online into the EU is in most cases also reaching the UK. Meeting the EU requirement does nothing for the UK one, so a company that targets both markets appoints a representative in each.

Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity.