Irfan Ali
In the current digitalized post-modern era, technological access to the personal data of natural persons devoid of obtaining consent exacerbates threats to the fundamental ‘right to privacy’ and self-determination. Protecting the collection, processing, storage, dissemination, and transfer of personal data in the wake of emerging data breaches seeks to safeguard the right to privacy. Following the promulgation of the General Data Protection Regulation (GDPR) in the EU in 2016, the risks associated with data breaches were closely examined, prompting major developing countries worldwide to seek a Personal Data Protection Law for their own jurisdictions, and the UAE is no exception. This article intricately explores the Personal Data Protection Law of 2021, promulgated through Amiri Decree No. 45 of 2021, focusing on the concepts and rights of personal data protection, including remedies for data breaches. The authors offer an in-depth analysis of the ongoing data breach in the UAE and the path toward adopting comprehensive data protection legislation. In this study, the authors expand on the articles of the UAE 2021 law, which serve as the benchmark for the UAE's adequate data protection regulation. The research plan presents a legal analysis of the UAE’s approach to the contents of ‘personal data protection’ and the ‘right to privacy’, as stipulated in the law. The article alludes to an amalgamation of court proceedings with the stipulated law, evaluating a state data protection legislation reminiscent of the EU GDPR. The scope of the article confines itself to the gaps between theory and practice, including the enactment of the law, the court's methodology for construing it to prevent data breaches, the application of punitive measures, and a legal analysis of how the framework for enacting this nascent law could be implemented.