A UAE company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. The wrinkle here is specific to the UAE: there is no single national data protection law to check against. A federal law and two independent free-zone laws run in parallel, and which one applies to you turns on where you are established. What none of them changes is the EU obligation.
Key takeaways
- GDPR Article 27 applies to UAE companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The Article 27(2) exemption is narrow and most products that run on EU users do not qualify.
- The UAE runs three parallel data protection regimes: the federal PDPL under the UAE Data Office, the DIFC Data Protection Law under the DIFC Commissioner, and the ADGM Data Protection Regulations under the ADGM Office of Data Protection. Which one governs you depends on where you are established.
- The DIFC and ADGM laws are establishment-based and neither imposes a GDPR Article 27 style local representative on a foreign company. None of the UAE regimes appoints an EU contact point for you.
- Most UAE companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.
How does a UAE company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.
This catches the ordinary shape of a UAE business trading into Europe. A Dubai-based ecommerce, travel or tourism operator, or a crypto or fintech business, that ships to or takes orders from consumers in the EU is offering goods and services to people in the EU. A UAE-based mobile app or adtech firm that tracks EU users is monitoring their behavior. Nothing about being established in the UAE removes Article 3(2), and either activity triggers Article 27.
Which UAE data protection law applies, and does it require an EU representative?
None of them requires an EU representative, but which one governs you at home is worth being precise about, because the UAE runs three regimes side by side.
- Federal. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the federal regime, and its provisions reach processing carried out inside or outside the country. It is regulated by the UAE Data Office, established under Federal Decree-Law No. 44 of 2021. This is the law that applies to a company in mainland UAE.
- DIFC. The Dubai International Financial Centre applies its own DIFC Data Protection Law No. 5 of 2020 within the jurisdiction of the DIFC, to controllers and processors incorporated there. It is regulated by the DIFC Commissioner of Data Protection, and it does not impose a GDPR Article 27 style local representative on foreign companies.
- ADGM. The Abu Dhabi Global Market applies its own ADGM Data Protection Regulations 2021 to processing in the context of an establishment in the ADGM. It is regulated by the ADGM Office of Data Protection, headed by a Commissioner of Data Protection, and it has no local representative obligation for foreign companies.
The load-bearing point is that a company established in the DIFC or the ADGM is governed by that free zone’s own data protection law and its own regulator, not by the federal PDPL. These are independent financial free zones with their own frameworks, so where you are established decides which law and which authority you answer to. What stays constant across all three is that none of them gives you the EU representative that Article 27 asks for. That obligation is a requirement of EU law and sits outside every UAE regime.
Who regulates this?
At home, it depends on your establishment: the UAE Data Office for the federal PDPL, the DIFC Commissioner of Data Protection for the DIFC, and the ADGM Office of Data Protection for the ADGM. In the EU, it is the supervisory authority in the member state where your representative sits, working within the wider network of authorities coordinated through the European Data Protection Board. None of the UAE regulators administers Article 27, and no EU authority administers a UAE regime, which is why satisfying one says nothing about the other.
Do UAE companies also need a UK representative?
In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and a UAE company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, and where you also target the UK we take the UK representation directly too. The same senior expert stays on your account rather than handing it to a junior.
Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are a UAE company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, whichever UAE regime governs you at home. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
- Data protection laws in the UAE, UAE Government portal
- DIFC Commissioner of Data Protection, Dubai International Financial Centre
- ADGM Office of Data Protection guidance, Abu Dhabi Global Market
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)