calhire
ComplianceComplianceUAECandidate experience

UAE PDPL and candidate data: what recruiters in the Emirates need to know

The UAE has a federal data protection law plus separate free-zone regimes. Which applies to your hiring, and what changes about handling candidate data.

CCompliance & Fairness8 min read

Recruitment in the UAE can fall under the federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, or under a separate financial free-zone regime such as the DIFC or ADGM data protection laws. Which one applies depends on where the hiring entity is established, so the first step is always to establish which regime governs the entity doing the hiring.

  • The UAE is not one regime. Mainland sits under the federal PDPL; DIFC and ADGM have their own data protection laws.
  • Establish which regime governs the hiring entity before designing anything, the obligations differ.
  • Data-subject rights include access, correction, erasure and restriction, so candidate notes and scores must be retrievable.
  • Cross-border transfer rules matter for any UAE hiring run on systems hosted elsewhere.
  • Emiratization reporting needs nationality data. Keep it in reporting and out of scoring, always.

This is general information, not legal advice. UAE data protection includes a federal law, separate financial free-zone regimes, and sector-specific rules, and implementing detail continues to develop. Confirm the current position with UAE-qualified counsel before relying on anything here.

First question: which regime are you in?

Teams often ask "what does UAE data protection require?" as though there is one answer. There is not, and getting this wrong invalidates everything downstream.

Where the hiring entity is establishedRegime that generally applies
Mainland UAEFederal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021
Dubai International Financial Centre (DIFC)The DIFC's own data protection law
Abu Dhabi Global Market (ADGM)The ADGM's own data protection regulations
Certain sectors and categoriesSeparate sector legislation may govern instead

The financial free zones are common law jurisdictions with their own regulators and their own statutes, and their data protection laws are broadly GDPR-shaped. The federal law covers the mainland and has its own scope provisions and exclusions.

Practical consequence: a group hiring into a mainland entity, a DIFC entity and an overseas entity is running three compliance analyses, not one. Start by writing down which legal entity each role sits in. Everything else follows from that, and it is the question most often skipped.

What is broadly consistent across the regimes

Whichever applies, the shape of the obligations for recruitment is familiar if you have worked with GDPR:

A lawful basis for processing. The federal law treats consent as a general basis with defined exceptions. As in Europe, consent is a weak choice in recruitment because a candidate seeking a job is not freely choosing, so map each activity to the most defensible ground rather than gathering a signature and calling it done. The reasoning is the same as the consent problem under GDPR.

Purpose limitation and minimisation. Collect what the assessment needs. This is where a resume-heavy process is quietly expensive: a CV carries date of birth, marital status, photograph and nationality far more often in this region than in Europe or the US, none of which the evaluation needs and all of which you then hold.

Data-subject rights. Access, correction, erasure, restriction of processing, and objection in defined circumstances. The operational implication is the same everywhere: interview notes and assessment scores are personal data, so they must be findable. Feedback scattered across chat threads cannot be produced on request.

Security and breach handling. Appropriate technical and organisational measures, and notification obligations when things go wrong. Know your reporting path before you need it.

Cross-border transfer. Both the federal law and the free-zone regimes address transfers out of the jurisdiction. If your ATS or assessment platform stores data in Europe or the US, that is a transfer, and it needs a basis.

Governance. Records of processing, and a data protection officer in defined circumstances. Confirm the current triggers for the DPO requirement in your regime.

The regional detail that actually bites: what a CV contains

This is the point most worth acting on, because it is specific to the region and entirely within your control.

Resumes submitted in the Gulf commonly include a photograph, date of birth, nationality, marital status, and sometimes visa status and religion. The résumé norms are simply different.

Which means a résumé-based process here does three unhelpful things at once:

  1. Collects far more personal data than the assessment needs. A minimisation problem before anyone has made a decision.
  2. Puts protected and quasi-protected attributes directly in front of every reviewer, where they will influence judgement whether or not anyone intends it.
  3. Creates a retention liability for data you never wanted, in a system you now have to be able to erase from.

Requiring a photograph, age or marital status on an application form is worth reviewing critically. There is rarely a genuine job-related reason, and the data has to be lawfully held, secured, disclosed on request, and deleted on schedule.

The structural fix is to stop putting it on the evaluation surface at all, which is the same conclusion blind evaluation reaches from the fairness direction.

Emiratization: the line that must not blur

UAE mainland employers face Emiratization targets in skilled roles, which requires processing nationality data and reporting on it. Two things have to stay true simultaneously:

  • Nationality is a lawful and necessary input to sourcing and to compliance reporting.
  • Nationality is never an input to an assessment score or ranking.

Keeping those in separate systems, or separate surfaces of the same system, is what makes a programme both compliant and defensible. Once nationality can influence a score, every selection decision in the programme becomes harder to justify, and the reporting you built to demonstrate compliance becomes evidence of something else.

For the target mechanics and process design, see our practical guide to Emiratization-compliant hiring.

A checklist for UAE hiring

  • Identify the legal entity for each role and the regime that governs it.
  • Map processing activities to lawful grounds; do not default to consent.
  • Write a candidate privacy notice in clear language, provided at collection.
  • Remove photograph, date of birth and marital status requirements unless you can state a job-related reason.
  • Set retention periods per purpose and automate deletion.
  • Ensure a rights request can reach interview notes and scores within the deadline.
  • Document where data is hosted and the basis for any cross-border transfer.
  • Keep nationality data in reporting, structurally out of scoring.
  • Confirm whether a DPO is required for you.
  • Keep an audit trail of person-affecting decisions you can export.

The regional lesson

Most guidance on candidate data is written for markets where a CV carries a name, a work history and little else. That assumption does not hold here.

In a region where résumés routinely arrive with a photograph, a date of birth, a nationality and a marital status, the résumé is not a neutral document you happen to store. It is a concentrated collection of personal and quasi-protected data, gathered before anyone has decided anything, held under a retention obligation, disclosable on request, and sitting in front of every reviewer while they score.

Which reframes the fix. Removing the résumé from the decision reads elsewhere as a fairness measure. Here it is also a data-protection control, and probably the single most effective one available: data you never collect needs no lawful basis, no retention schedule, no deletion mechanism, and cannot leak.

That is the reasoning behind how CalHire handles it, with residency configured per region and agreed before onboarding, an evaluation surface holding skills and scores only, and Emiratization reporting drawn from the same records as the decisions while nationality stays out of scoring. But the principle stands whatever you build on. Look at what your application form asks for, and ask which fields you could simply stop collecting.

In this market that question usually has an uncomfortable number of good answers.

Frequently asked questions

Which data protection law applies to hiring in the UAE?
It depends on the entity. A mainland UAE company generally falls under the federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. An entity established in the Dubai International Financial Centre or Abu Dhabi Global Market falls under that centre’s own data protection law instead. Some sectors and categories are handled under separate legislation. Establish the applicable regime first; take local advice.
Do we need consent to process candidate data in the UAE?
The federal law treats consent as a general basis with a set of exceptions where processing is necessary for other specified purposes. As with GDPR, consent in a recruitment context is fragile because of the power imbalance, so map your processing to the most appropriate lawful ground rather than defaulting to consent, and take local advice on which exceptions apply to you.
Can we host candidate data outside the UAE?
Cross-border transfer is addressed in both the federal law and the free-zone regimes, generally permitting transfer to jurisdictions with adequate protection or subject to appropriate safeguards. In practice: know where your systems store data, whether in-region hosting is available, and what safeguards cover any transfer. Verify the current requirements and any list of approved jurisdictions.
How does this interact with Emiratization reporting?
Emiratization requires you to know and report the nationality of hires, which means processing that data lawfully and for a stated purpose. It does not permit nationality to influence an assessment score or ranking. Keep the two in separate places: nationality informs sourcing and compliance counting; skills alone drive evaluation.
Share this post

Keep reading

Compliance8 min

What an AI bias audit actually measures

A bias audit is an outcome analysis, not a code review. What impact ratios are, what an audit cannot tell you, and how to read a summary you have been handed.

Compliance9 min

The EU AI Act and hiring: what recruitment teams are responsible for

AI used to recruit or evaluate candidates is high-risk under the EU AI Act. What that means for employers, what providers owe you, and what to ask vendors.

Hiring decided by proven skills

Create a free verified profile, or see how anonymous-first hiring works for your team.