Federal Decree-Law on the Protection of Personal Data, reach over scraped public personal data
Federal Decree-Law No. 45 of 2021, Art. 4 (reach over scraped public personal data)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 2 January 2022.
A personal data rule binding private bodies.
As of 6 September 2026.
What it requires
- A scraper collecting the personal data of an individual in onshore UAE from a public, unauthenticated page must still establish a lawful basis under Art. 4 for any use beyond the narrow act that made the data public, and must treat a biometric identifier derived from public photographs, video, or audio as Sensitive Personal Data requiring explicit consent.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 4(2) provides a lawful-basis exception for processing personal data that has become available and known to all by an act of the data subject, which the jurisdiction's privacy record confirms is a consent-basis exception rather than a scope exclusion: personal data a scraper collects from a public, unauthenticated page of a UAE resident remains Personal Data for the Law's other duties, including security, purpose limitation, cross-border transfer, and breach reporting, once collected outside the narrow act that made it public.
The Law carries no publicly-available-data carve-out of the kind some jurisdictions apply to a whole category of public records, and Art. 1's Biometric Data definition names facial images and fingerprints as worked examples of Sensitive Personal Data with no exclusion for an identifier derived from a public recording, so a scraper deriving a biometric identifier from publicly posted photographs or audio faces the Law's elevated consent requirement for Sensitive Personal Data.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics