What is EU’s GDPR Law?

What Is GDPR, and Does It Apply to UAE Businesses?

A customer in Germany fills out your contact form. Your team in Dubai receives their name, email address, and message. Does GDPR apply?

The answer depends on what your business does in the EU. A website visit or an EU passport alone cannot settle that question.

Before adding a cookie banner, check whom the business serves and what information it collects. Those details help you understand which website settings and business processes need attention.

What Is GDPR?

The EU’s personal data law is called the General Data Protection Regulation, or GDPR. Its rules have been in effect since May 25, 2018.

Personal data is information that identifies someone or can help identify them. Names and email addresses are familiar examples. IP addresses and identifiers used by advertising tools can count too.

GDPR covers how businesses collect, use, store, share, and delete that information. It also gives people rights over their data.

For a website owner, this affects ordinary tasks. A visitor might request a quote or join an email list. An analytics tool might record how they use the site.

Each activity needs a purpose and an appropriate legal basis. The business must explain how it uses the information.

When Does GDPR Apply to a UAE Business?

A company does not need a European office for GDPR to apply. Businesses outside the EU can fall within its scope if they target people there. This includes offering goods or services and monitoring certain behavior within the EU.

Having an EU establishment can also bring processing within the regulation’s scope.

For example, a Dubai retailer might advertise to customers in France. Its checkout accepts French delivery addresses and shows shipping charges for those orders. These details suggest that the business is selling to people there.

A training provider in Dubai may only offer classes at its local premises. Someone in France could still find the website and ask about a course. That question alone does not mean the provider is offering courses to people in the EU.

Simply allowing people in Europe to open your website is not enough. Advertising, delivery options, currencies, and other details can show which customers you intend to serve.

Citizenship is not the deciding factor for this targeting test. A person’s location and the business’s activities matter more than their passport.

Before reviewing the website, look at how the business operates:

  • Are any campaigns aimed at customers in EU countries?
  • Does the checkout accept orders for delivery there?
  • Are visitors in the EU tracked to build advertising profiles?
  • Does the team handle personal data for an EU company?

Working for an EU company may bring contractual and data-transfer requirements. It does not automatically mean every part of your business falls under GDPR.

What Personal Data Does Your Website Collect?

Open your website’s forms and note what each one asks for. The contact form might request a name, phone number, email address, and message. For bookings, there may be extra fields for an address or appointment details.

Pay attention to open message boxes. People may share information you did not ask for. A job applicant could upload a résumé with a detailed employment history.

Forms are only part of the picture. Your server may keep a record of visitors’ IP addresses. Advertising tools can assign identifiers to browsers. A chat service may retain messages after a conversation ends.

List the places where this information is collected. Include connected tools such as a CRM, booking system, or email platform.

For each tool, record who can access the data and how long it remains there. Check whether copies are saved in more than one place.

You need this information before checking the privacy notice. Otherwise, the notice may describe only part of what the website does.

What Does GDPR Require a Business to Do?

Under GDPR, a business needs a valid legal reason to use someone’s personal information. Consent is one option. Other bases include fulfilling a contract or meeting a legal obligation.

The appropriate basis depends on the purpose and circumstances.

A quote request gives you a reason to reply to that person. Adding their address to a newsletter is another use of the information. Check the rules for that use before sending marketing emails.

Collect only what the stated purpose requires. If someone wants a callback, consider whether the form needs their full address. Explain how their details will be used when collecting them.

Decide how long to keep the information too. Form entries may remain in a website database after being copied into a CRM. Review whether both copies are needed.

People may request access to their data or ask for corrections or deletion. The right that applies depends on the circumstances. Your team needs to know where the information is stored.

Security also needs attention. Restrict access to people who need it for their work. Remove access when staff leave. Keep systems updated and prepare for a data breach.

Some businesses may have further duties, such as appointing an EU representative. These depend on the activities involved.

How to Review Your Website

Review what the site actually does. An installed plugin or copied policy cannot tell you whether the setup works correctly.

Check Every Form

Go through your contact, booking, newsletter, and job application forms. List the details they ask for and whether each field is necessary.

Submit a test entry to see where it goes. It may reach an employee’s inbox and stay saved on the website too.

Read the wording beside the form. Does it explain how the information will be used? If there is a marketing consent box, check that it starts unticked.

Submit a test entry and follow it through the connected systems. Check the inbox, website database, and CRM where relevant.

This helps the team understand where to look when handling a data request.

Compare the Privacy Notice With the Website

The privacy notice should describe the business’s actual practices. Compare it with the forms and tools found during the review.

Read the notice and look for these details:

  • What the business uses personal information for
  • The legal basis for each use
  • Who the information is shared with
  • When records are deleted, or how that timing is decided
  • What people can ask the business to do with their data
  • Where to send a question or request

The notice should also cover relevant advertising tools and embedded services.

Templates can leave out tools the business uses. They may also mention services that were removed long ago. Update the notice to reflect the website and the company’s processes.

Test Cookies and Tracking

Use a browser that has not visited the site before. Leave the cookie banner alone for now. Ask your developer to check whether analytics or advertising tracking starts before you click anything. They should also check the video embeds and chat tool.

Then reject optional cookies and reload the page. Check whether those tools stay off. Also try changing the choice later to see whether the settings respond.

The banner’s wording is only part of the check. What happens after someone accepts or rejects cookies needs to match it.

GDPR is not the only rule involved. European cookie rules also cover storing or reading information on a visitor’s device. The requirements depend on the tools and the countries involved.

Check Storage and Outside Providers

Submit a test form and check every place the entry appears. It may arrive in an inbox, a booking system, or a CRM.

Check which staff accounts can open it. Ask each provider where the data is stored and what happens when it is deleted.

Review the relevant agreements as well. A provider’s role and responsibilities should match how it handles the information.

If an EU company transfers personal data to your UAE team, you may need additional safeguards. A website setting cannot resolve the contractual and transfer questions.

How Does GDPR Differ From UAE Data Protection Law?

GDPR is an EU regulation. The UAE also has its own data protection framework.

A UAE business may need to consider more than one set of rules. Its location, activities, and the information involved affect that assessment. Some sectors and free zones have separate requirements.

Start by recording where the business operates and whom it serves. Include the providers receiving personal data and the countries where it is stored.

A legal adviser can then assess which rules apply.

Adding a privacy page does not establish that the whole business complies with GDPR. The claim would need to reflect its wider handling of personal data.

What Happens if a Business Breaks GDPR Rules?

Data protection authorities can investigate complaints and examine how a business handles personal data. Their responses may include reprimands, orders to change processing, and fines.

The highest fine tier can reach €20 million or 4% of annual worldwide turnover, whichever is higher. This is a legal maximum, not a standard fine for every website mistake.

The response depends on the infringement and its circumstances.

For a website review, begin with problems you can identify. A notice may name the wrong provider. A form may collect unnecessary details. Tracking may continue after a visitor rejects it.

Record each finding and decide who will fix it. Then test the change.

Where Should You Start?

First, record your business activities involving people in the EU. Include sales, advertising, tracking, and work carried out for EU companies.

Get legal advice where those activities raise questions about GDPR’s scope.

Next, list what your website collects and where the information goes. Follow it into inboxes, databases, and connected services.

Compare those findings with the forms, privacy notice, and cookie settings. Fix mismatches and check that the changes work.

The same review should cover the team’s handling of that information afterward. Website settings matter, but so do access, storage, deletion, and responses to customer requests.