1. Introduction
At EXCELLENCE, we are committed to safeguarding personal data in compliance with all relevant UAE laws and regulations, including the UAE Cyber Crimes Law, UAE Penal Code, UAE Federal Law No. 2 of 2019 (Data Protection Law), and other applicable legal frameworks. This policy outlines how we manage, process, and protect personal data, ensuring full compliance with legal obligations while maintaining the highest standards of privacy and security.
2. Purpose
The purpose of this policy is to ensure that all personal data we collect, process, store, and transfer is handled in accordance with the legal and regulatory requirements set forth by UAE laws and international standards. We aim to maintain transparency, security, and trust with all individuals whose personal data we handle.
3. Scope
This policy applies to all individuals within the EXCELLENCE, including employees (meaning permanent, fixed term, and temporary staff, any third-party representatives or sub-contractors, agency workers, volunteers, interns and agents engaged with the Company in the UAE or overseas)consultants, contractors, third-party service providers, shareholders and any other stakeholders engaged in processing personal data, both within the UAE and abroad. All individuals must comply with the provisions outlined in this policy.
4. Legal Framework
This policy is based on and compliant with the following UAE laws and regulations:
- UAE Federal Law No. 2 of 2019 (Data Protection Law)
- UAE Cyber Crimes Law (Federal Law No. 5 of 2012)
- UAE Penal Code (Federal Law No. 3 of 1987)
- UAE Civil Code and E-Commerce Law
In addition, we ensure that our practices meet international best standards, including the General Data Protection Regulation (GDPR) where or if applicable.
5. Key Principles of Data Protection
EXCELLENCE adheres to the following key principles in all data processing activities:
- Lawfulness, Fairness, and Transparency: We collect personal data for legitimate business purposes, ensuring all data is processed fairly and transparently in compliance with applicable laws.
- Data Minimization: We only collect personal data that is necessary for specific, lawful purposes and avoid unnecessary data collection.
- Accuracy: We ensure that personal data is accurate, complete, and kept up to date. Data subjects can update their information as required.
- Storage Limitation: We retain personal data only as long as necessary to fulfil the purposes for which it was collected or to meet legal obligations.
- Integrity and Confidentiality: We ensure the security, confidentiality, and integrity of personal data through appropriate technical and organizational measures.
- Accountability: We are responsible for complying with this policy and all applicable data protection laws, ensuring regular audits and assessments to verify compliance.
6. Data Collection and Processing
We collect personal data in a lawful and transparent manner, including but not limited to:
- Employee Data: Name, address, contact details, personal details, employment history, performance information, health information, and other important details if needed.
- Customer and Supplier Data: Name, contact details, contract details, financial data, or any data which we feel is necessary (excluding bank/credit card details).
- Sensitive Data: Health data, emergency contact details.
Personal data is only collected for legitimate business purposes, such as providing services, complying with contractual obligations, or fulfilling legal requirements. We do not collect sensitive data unless it is required by law or consented to by the data subject.
7. Data Protection Measures
We implement strong data protection measures to ensure personal data is protected against unauthorized access, destruction, or misuse, in compliance with UAE legal standards:
- Encryption: All personal data is encrypted both at rest and in transit to protect against unauthorized access.
- Access Control: Access to personal data is restricted to authorized personnel only, based on a need-to-know basis, and managed through multi-factor authentication (MFA).
- Data Anonymization & Pseudonymization: Where feasible, we anonymize or pseudonymize personal data to mitigate risks in the event of unauthorized access.
- Secure Systems & Networks: We use state-of-the-art technologies, including firewalls, anti-virus protection, and secure servers, to protect personal data from cyber threats.
- Regular Audits & Assessments: We conduct regular internal audits, vulnerability assessments, and Data Protection Impact Assessments (DPIAs) to ensure compliance with data protection laws and minimize risks.
8. Rights of Data Subjects
Under the UAE Data Protection Law and relevant regulations, individuals have the following rights concerning their personal data:
- Right to Access: Individuals may request access to their personal data held by the company.
- Right to Rectification: Individuals can request corrections to inaccurate or incomplete data.
- Right to Erasure: Individuals may request the deletion of their data when it is no longer necessary or if consent is withdrawn.
- Right to Restrict Processing: Individuals can request restrictions on how their data is processed in certain circumstances.
- Right to Object: Individuals can object to processing for direct marketing or profiling purposes.
- Right to Data Portability: Data subjects can request their data in a structured, commonly used format to transfer it to another service provider.
9. Data Protection Governance
- EXCELLENCE has appointed a Data Protection and Documents Control Department to oversee compliance.
- We provide executive oversight through regular reporting to senior management.
10. Data Retention
Personal data is stored only for the period necessary to fulfil the purposes for which it was collected or to meet legal obligations. After the retention period, personal data is securely deleted or anonymized in accordance with our data retention policy.
11. Data Transfers and International Data Protection
When personal data is transferred outside the UAE, we ensure compliance with applicable UAE laws and implement appropriate safeguards to protect personal data, such as the use of Standard Contractual Clauses (SCCs) for international transfers (if applicable).
12. Incident Response and Data Breach Management
In accordance with the UAE Cyber Crimes Law and UAE Data Protection Law, we have a dedicated breach notification process in place. In the event of a data breach:
- We will assess the impact of the breach and take steps to mitigate harm.
- If necessary, we will notify affected individuals and regulatory authorities (including the UAE Data Protection Authority) within 72 hours of discovering the breach.
13. Employee Training, Awareness & Third-Party Obligations
All employees and third-party vendors who handle personal data are required to comply with this policy. Non-compliance can result in disciplinary action, termination of contracts, or legal consequences in accordance with UAE laws.
- Training: Employees and contractors undergo online data protection training programs to ensure that they understand the importance of safeguarding personal data.
- Awareness: We promote a data protection culture through internal campaigns and leadership messaging.
- Third-Party Compliance:
- All third-party service providers must demonstrate compliance with this policy through data protection agreements.
- We perform due diligence on third-party vendors, ensuring they meet data protection standards.
- Continuous monitoring of third-party compliance is conducted.
14. Disciplinary Consequences
Violations of this policy may result in severe consequences, including termination of employment or contracts and legal action in accordance with the UAE Penal Code and other relevant legislation. Fines of up to AED 1 million and imprisonment of up to 1 year may apply in case of data protection violations, as outlined in the UAE Cyber Crimes Law.
15. Continuous Improvement
We are committed to the continuous improvement of our data protection practices. Our policy is reviewed regularly to reflect updates in UAE legislation, industry standards, and emerging risks.
16. Conclusion
EXCELLENCE is committed to maintaining the highest standards of data security and privacy, fully complying with UAE laws and international data protection standards. This policy ensures the safety of personal data and demonstrates our commitment to trust, security, and legal compliance.