UAE Data Protection update: DIFC firms advised to re-evaluate transfers of personal data to the United States

The ECJ’s decision in Schrems gives cause to re-examine the adequacy status given to Safe Harbor-certified companies under DIFC law.

07 January 2016

Publication

​In Case C-362/14 - Maximillian Schrems v Data Protection Commissioner of 06 October 2015, the European Court of Justice ruled that the European Commission Decision (2000/520) confirming the adequacy of protection offered by Safe Harbor-certified companies in the US to personal data transferred from the EU is invalid. We have previously commented on the implications of this decision for transfers of personal data from the EU to the US - see the conference call and accompanying slides available here.

Although federal UAE has no standalone data protection law, entities incorporated in the Dubai International Financial Centre (DIFC) have had to comply with a data protection law based on the European model for several years. As part of that, transfers of personal data from the DIFC to Safe Harbor-certified US companies have also been granted adequate protection status. However, following the Schrems decision, the DIFC Data Protection Commissioner issued guidance which:

  • notes how the European Court of Justice's (ECJ’s) decision in Schrems calls into question the adequacy status given to Safe Harbor-certified companies, and
  • recommends that entities incorporated in the DIFC should now rely on alternative legal bases for transfers of data to the US as set out in Article 12 of the DIFC Data Protection Law.

The EU and US authorities were already in the process of re-negotiating the terms of the Safe Harbor framework at the time of the ECJ’s decision, and such negotiations are on-going. It is possible that the negotiations will culminate in a form of “Safe Harbor II” which will, again, serve as the model for the DIFC’s approach to assessing the adequacy of data transfers to the US. In the meantime, entities based in the DIFC are advised to evaluate the legal basis on which they currently transfer personal data to the US and, if necessary, take steps to ensure compliance with Article 12 of the DIFC Data Protection Law.

We have recently contributed to the consultation documents around the introduction of data protection regulations for Abu Dhabi Global Markets, and this issue will be relevant to the “adequate level of protection” and qualifying jurisdictions debate as those regulations take shape.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.