What the laws require
- •UAE PDPL (Federal Decree-Law 45/2021): biometric data is sensitive; processing generally needs consent or a statutory exception, and large-scale sensitive processing points to appointing a DPO.
- •Cross-border transfers require an adequate destination or contractual safeguards — keeping data in-country is the simple answer.
- •Saudi PDPL (in force since 2024): explicit consent as the default basis, controller registration, transfer assessments, and data-subject rights with real penalties.
- •Free zones: DIFC Law No. 5/2020 and the ADGM DP Regulations apply their own GDPR-style rules to companies registered there.
How NCheck supports it
- •On-premises deployment keeps biometric data inside the UAE or KSA — the cleanest answer to residency and transfer rules.
- •Encrypted, non-reversible templates; raw images are not retained.
- •Consent capture at enrolment, with RFID or manual check-in as an alternative.
- •Retention limits, deletion tools and audit trail.
Practical checklist
- ✓Identify your regime first: mainland PDPL vs DIFC/ADGM.
- ✓Prepare consent notices in Arabic and English (use our free template).
- ✓Assess whether you need a DPO.
- ✓Run a transfer assessment before using any cloud hosted abroad — or choose on-premises.
- ✓Define retention and deletion schedules (use our free template).
Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
← All regulations