Compliance · GCC PDPL

Biometric attendance under the UAE & Saudi PDPL

Both the UAE and Saudi Arabia treat biometric data as sensitive personal data, with consent-first rules and cross-border transfer restrictions — and the free zones (DIFC, ADGM) run their own regimes.

What the laws require

  • UAE PDPL (Federal Decree-Law 45/2021): biometric data is sensitive; processing generally needs consent or a statutory exception, and large-scale sensitive processing points to appointing a DPO.
  • Cross-border transfers require an adequate destination or contractual safeguards — keeping data in-country is the simple answer.
  • Saudi PDPL (in force since 2024): explicit consent as the default basis, controller registration, transfer assessments, and data-subject rights with real penalties.
  • Free zones: DIFC Law No. 5/2020 and the ADGM DP Regulations apply their own GDPR-style rules to companies registered there.

How NCheck supports it

  • On-premises deployment keeps biometric data inside the UAE or KSA — the cleanest answer to residency and transfer rules.
  • Encrypted, non-reversible templates; raw images are not retained.
  • Consent capture at enrolment, with RFID or manual check-in as an alternative.
  • Retention limits, deletion tools and audit trail.

Practical checklist

  • Identify your regime first: mainland PDPL vs DIFC/ADGM.
  • Prepare consent notices in Arabic and English (use our free template).
  • Assess whether you need a DPO.
  • Run a transfer assessment before using any cloud hosted abroad — or choose on-premises.
  • Define retention and deletion schedules (use our free template).

Download the free consent-form and retention-policy templates →

This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.

← All regulations

Deploy it the compliant way

Run NCheck fully on-premises — or in the cloud.

small_c_popup.png

See NCheck in action on your own devices.

Let's talk