No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

The Evolution of Data Privacy Legislation in the Middle East

Comprehensive Saudi law most recent in region

by Noah Usman
March 4, 2024
in Data Privacy
saudi flag

The well-known Brussels effect has been felt from North America to Oceania, as GDPR-modeled data privacy measures continue to emerge. Middle Eastern countries, similarly, have been heavily influenced by European regulations. But, as UCLA law student Noah Usman explores, newly passed laws sport some key differences.

As privacy and cybersecurity have become increasingly relevant concerns in healthcare and technology, the GDPR (General Data Protection Regulation) has enjoyed an almost uncontested reputation as the world’s foremost privacy law. Its influence, known as the “Brussels effect,” has shaped the regulatory landscape far beyond the European Union.

Indeed, jurisdictions in places like Asia, North American and Australia have emulated the strict protections pioneered by the EU, and the comprehensive nature of many incoming regulations in other parts of the world shows that the space between regulation in various regions is rapidly closing.

In the Middle East, recently passed data privacy and protection legislation in Saudi Arabia, the United Arab Emirates and Bahrain, for example, has demonstrated an increased commitment to consumer rights, business interests and the protection of the personal information of these nations’ respective citizens.

Saudi Arabia

Saudi Arabia recently transitioned from interim regulations, which were superseded by a comprehensive measure, the Personal Data Protection Law, which went into effect Sept. 14, 2023.

The Saudi data protection law shares many similarities with the GDPR, including data subject rights and privacy notice requirements, but differs significantly in how data transfers are regulated. While the European Commission determines the permissibility of data transfers according to the adequacy of the recipient country’s data protection regulations, the Saudi government imposes more stringent requirements, including harsher restrictions pertaining to data localization and residency.

The Saudi law requires that data transfers be approved by the Saudi Authority for Data and Artificial Intelligence on a case-by-case basis, and that only the minimum amount of data necessary to accomplish the corresponding objective is transferred[JG1] [NU2] .

While these stricter data transfer regulations position Saudi Arabia as a potential regional leader in data protection and security, the enforcement of such regulations may prove a barrier in the country’s efforts to attract offshore investment. The dynamic between these competing interests will be important to monitor in the coming years.

us data privacy legislation concept
Data Privacy

Will 2024 Finally Be the Year for Federal Data Privacy Law in US?

by Scott Allendevaux
January 17, 2024

With a notoriously ineffective legislative body at the federal level, hope may seem thin, but cybersecurity expert Scott Allendevaux makes the case that 2024 may be perfect time.

Read moreDetails

UAE

The UAE Federal Data Protection Law, passed in 2021, covers a wide range of topics, including data transfers, subject rights, marketing and data protection impact assessments. (The law is also supplemented by a set of consumer protection standards that apply exclusively to the finance and healthcare industries.) While many of the provisions are like the GDPR, some of the guidelines — especially regarding response to subject requests to exercise rights — remain vague, most explicitly by not articulating a clear timeline for response to inquiries. In contrast, the GDPR sets a deadline of one calendar month for response to a data subject request.

However, the scope of the UAE Federal Data Protection Law is considerably broader than that of the GDPR in that the former applies to both data controllers and processors, while the GDPR applies directly to controllers.  The UAE legislation is also more explicit in its criteria for how other countries can be evaluated for “adequacy” for data transfer: Criteria include data subject consent, the necessity for execution of a contract and protection of the public interest. While the GDPR contains similar criteria, these provisions are not mentioned in the context of international data transfers, which are never explicitly referenced.

Bahrain

Circa 2018, the Bahraini Personal Data Protection Law similarly establishes guidelines for data quality control, incident response and notification, and the exercise of rights by consumers. The Bahraini legislation is most similar to the GDPR out of the new Middle Eastern privacy laws, especially in its far-reaching scope, in that they both apply to entities that process data of their respective citizens (the Bahraini regulation refers to “natural or legal person[s]”).

Similarly to the GDPR, the Bahraini Personal Data Protection Law specifies that data transfers may be carried out to a pre-approved adequate country.

The main deviation of the Bahraini law from the GDPR occurs in how data subject rights are delineated: although the legislation does provide data subjects the opportunity to be notified when their personal data is processed, the right to access personal data is not clearly articulated. Given the limited history of enforcement of the regulation, it remains to be seen how robustly this prerogative is protected for Bahraini data subjects.[JG3] [NU4] 

What does the future hold?

Within the past five years alone, Middle Eastern privacy legislation has drastically expanded in scope and power, which owes a significant amount of influence to the GDPR, as evidenced by the provisions that closely reflect those in the GDPR. However, the new Middle Eastern privacy laws remain extremely protective of local data, possibly due to the still-expanding nature of Gulf economies and their dependence on a narrow range of economic sectors, most notably petroleum. As the economic landscape of the Middle East continues to evolve, it may prove useful to monitor how the current array of privacy legislation and enforcement also continues to change. Such activity may help analysts to gain a deeper understanding of the motivations and economic interests of individual governments as well as adherence to the relevant local data privacy requirements.


Tags: GDPR
Previous Post

SEC Broadens Definition of ‘Dealer’

Next Post

What Is Carbon Accounting & How Can Companies Prepare?

Noah Usman

Noah Usman

Noah Usman is a second-year JD candidate at UCLA’s school of law, expecting to complete his education in 2025. He is passionate about privacy-related issues and analyzing trends in technology legislation. Based in Orange County, he holds a B.A. in linguistics from UC Berkeley. Outside of law school, Noah has published in multiple academic linguistics journals, including the Journal of the Acoustical Society of America and U-Lingua, the official magazine of the Undergraduate Linguistics Association of Britain.

Related Posts

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

gdpr website screenshot

In the World of JavaScript, GDPR Consent Forms Merely Scratching the Surface

by Rui Ribeiro
December 16, 2024

Consent forms alone don’t mean much when consumers are so tired of checking boxes they don’t even read the policies

us map black and white

Minnesota Latest State to OK Consumer Data Privacy Law

by Amanda Novak
August 26, 2024

Measure set to go into effect for most covered entities next summer

Next Post
pollution against sunset sky

What Is Carbon Accounting & How Can Companies Prepare?

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights