Privacy,operationalised.
Every business operating in or through the UAE now sits inside at least one data protection regime, and most sit inside three. RPLC UAE designs, documents and runs privacy programmes that satisfy the UAE PDPL, the DIFC and ADGM regimes, India's DPDP Act and the GDPR at once, so that compliance becomes a single operating system rather than a stack of conflicting policies.
The UAE's Federal Decree-Law No. 45 of 2021 (the PDPL) established the country's first federal data protection framework, supervised by the UAE Data Office, with lawful-basis, purpose-limitation, data-subject-rights, breach-notification and cross-border transfer obligations familiar to anyone who has worked with the GDPR. The free zones go further: the DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 are mature, actively enforced regimes with their own commissioners, registration duties and fines. Sector rules from the Central Bank, the TDRA and the health authorities layer on top.
In India, the Digital Personal Data Protection Act, 2023 and its Rules have turned a decade of debate into binding obligations: notice and consent standards, Consent Managers, Significant Data Fiduciary designations, children's data, breach notification to the Data Protection Board and affected individuals, and penalties reaching INR 250 crore. For UAE–India businesses, an HR file in Dubai, a support centre in Pune and a cloud region in Frankfurt now sit under three regulators with three transfer regimes.
Our practice, led by Rajas Pingle, who holds an LL.M. in Cyber Law and Privacy & Data Protection Laws, builds the programme once and maps it to every regime that applies. That means a single record of processing, one set of lawful-basis decisions defended under each law, transfer mechanisms that actually work between the UAE, India, the EU and the USA, a breach playbook with every notification clock on it, and, where needed, RPLC acting as your outsourced Data Protection Officer with a direct line to the board.
Every mandate is staffed by a founding partner and a small, dedicated team. Where formal representation before UAE courts or authorities is required, we instruct and coordinate registered Emirati advocates so that clients receive one accountable file across legal consultancy and formal representation. Cross-border work between the UAE, India and the USA is run from the same file, with local counsel engaged where applicable law requires.
Gap assessments, records of processing, lawful-basis mapping, privacy notices, data-subject-rights procedures and UAE Data Office readiness for onshore controllers and processors.
Registration and annual assessments with the DIFC and ADGM Commissioners, DIFC Regulation 10 for AI systems, high-risk processing notifications and commissioner engagement.
Notice and consent redesign, Consent Manager integration, Significant Data Fiduciary readiness, children's data controls, grievance mechanisms and Data Protection Board engagement.
Article 3 applicability analysis, EU representative arrangements, Article 27 and 28 documentation, and alignment of GDPR programmes with PDPL and DPDPA obligations.
Data protection impact assessments for new products, AI features, adtech, biometrics and employee monitoring, with engineering-ready remediation.
Transfer-mechanism strategy across UAE, DIFC, ADGM, India, EU and UK regimes: standard contractual clauses, adequacy analysis, transfer impact assessments and processor agreements.
RPLC as designated DPO under PDPL, DIFC or ADGM law: regulator liaison, rights requests, breach coordination, training and quarterly board reporting on a retainer.
72-hour incident playbooks, privilege-protected forensics, parallel notification to the UAE Data Office, DIFC or ADGM Commissioner, CBUAE, India's DPB and affected individuals.
The work, on record.
Client names withheld under counsel duties; details rendered indicative.
Outsourced DPO for a Fortune-500 MENA subsidiary
Full-lifecycle DPO mandate: records of processing across 40 systems, DPIAs for a customer-analytics platform, cross-border transfer strategy to the US parent, breach playbook and quarterly board reporting.
DIFC Regulation 10 assessment for an AI-driven wealth platform
Autonomous-system assessment under DIFC Regulation 10, high-risk processing notification, explainability documentation and commissioner engagement for a DFSA-licensed digital wealth manager.
DPDP readiness for a UAE-headquartered consumer app
Consent redesign, Consent Manager integration plan, children's data controls, grievance workflow and Significant Data Fiduciary analysis for a Dubai app with 9M Indian users.
Cross-border data breach at a logistics group
Coordinated response to a supplier compromise exposing employee data across the UAE, India and Saudi Arabia: forensic scoping, notifications to three regulators and affected individuals, and contractual recovery from the vendor.
Data Privacy, Cybersecurity & Digital Trust
Reading, between the codes.
Speak to the practice.
A discreet, no-obligation first conversation, usually within one working day. Urgent matters are triaged the same day.
