Meet UAE PDPL obligations with your CRM data
HelloGrowthCRM is a sales CRM built by Soor LLC. If you sell to customers in the United Arab Emirates, Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to the contact records and notes you keep. This page explains what the law covers, where the implementing detail still stands open, and which controls the platform provides. It is aimed at procurement and security reviewers. It is not legal advice, and UAE counsel should confirm your position before you rely on any of it.
What Federal Decree-Law No. 45 of 2021 covers
The PDPL is the UAE's federal data protection law. It applies to data subjects inside the UAE, to controllers and processors established in the UAE that process personal data whether inside or outside the country, and to controllers and processors based outside the UAE that process the personal data of people inside it. For a sales CRM, that means contact records for UAE-based prospects and customers can be in scope even when your company sits elsewhere. The financial and healthcare free zones keep their own regimes: the DIFC has its own data protection law and commissioner, the ADGM has its own regulations, and Dubai Healthcare City operates separately again.
The law defines personal data broadly and treats a subset as sensitive, including health, biometric and genetic data, racial origin, religious belief, political opinion and criminal records. Processing generally requires the data subject's consent, subject to a list of exceptions covering contract performance, legal obligations, protection of the public interest, legal claims, employment duties and similar grounds. Controllers must apply purpose limitation, data minimisation, accuracy and security. Consent must be clear, specific and capable of being withdrawn. In CRM terms, that pushes you towards recording a basis for each record rather than treating a whole imported database as consented by default.
One practical point for sales teams: the PDPL is a data protection law, not a marketing law. Electronic marketing to UAE numbers and inboxes also touches telecommunications rules and, in some sectors, additional regulator expectations. Treat consent to hold a contact record and consent to market to that contact as two separate fields in the CRM. Teams routinely conflate the two and then cannot answer a simple question when somebody objects. Two tick boxes and a source field captured at import time save a great deal of reconstruction later on.
Where the position stands today
The PDPL was issued in 2021 and was expected to be followed by Executive Regulations setting out operational detail: transfer mechanisms, breach procedures, Data Protection Officer thresholds, registration and enforcement. Those regulations have taken considerably longer than the original timetable envisaged, and the detailed implementing framework has continued to be described as forthcoming rather than final. That is not a reason to ignore the law. The substantive obligations in the decree-law stand, and the UAE Data Office is established as the federal supervisory body. It does mean specific procedural answers remain open, and this position is still developing.
Because of that, verify the current status against the Official Gazette or your UAE counsel before relying on a particular date, cabinet decision number or transition period. Organisations are generally expected to receive a compliance window once regulations are published. Our advice to buyers is to build the practices now, because a lawful basis record, a rights-handling process, a subprocessor register and a documented transfer assessment will not become less necessary when the detail lands. HelloGrowthCRM makes no claim to be PDPL certified. There is no certification scheme under the PDPL, and the phrase would carry no meaning if there were one.
Free zone entities should check which law actually binds them before applying federal analysis by default. A company registered in the DIFC follows the DIFC data protection law, with its own registration, transfer and breach rules and its own commissioner. An ADGM entity follows ADGM regulations. A mainland company follows the federal PDPL. Groups spanning both often standardise CRM handling on the strictest applicable standard, simply to avoid running two sets of practices over one contact list. That decision is much easier to make at procurement than after the data is already loaded.
Data subject rights inside a CRM
The PDPL gives data subjects a recognisable set of rights: to receive information about processing, to access their data and obtain a copy, to request portability in a structured machine-readable format, to have inaccurate data corrected and unlawfully processed data erased, to restrict or stop processing in defined circumstances, and to object to automated processing including profiling where it produces legal effects. A CRM is frequently where these requests actually land, because it holds the contact record, the email history and the notes. The system therefore needs to make retrieval and deletion straightforward rather than a bespoke engineering exercise.
Handling requests well is mostly operational. You need to find every record about a person, decide what is genuinely theirs, produce it in a usable format and act on the result. HelloGrowthCRM supports that directly: administrators can search and export account data at any time without raising a ticket, and deletion requests are honoured. The documented process is published at /legal/data-rights. Our practices also align with India's DPDPA, and customers in the EU, UK and California have equivalent rights, so a single set of tooling and process serves several regimes rather than one jurisdiction at a time.
Two decisions are worth making before a request arrives. First, who owns a rights request that reaches a sales representative's inbox rather than a privacy address. Set a route and train the team, because the clock does not wait for the message to find the right desk. Second, what you do with free-text notes. Call notes and meeting summaries often contain opinions about a person that remain personal data. Decide whether they fall inside your access responses, write the policy down, and then apply it the same way every single time.
Cross-border transfers and hosting
The PDPL restricts transfers of personal data outside the UAE. Broadly, transfers are permitted to jurisdictions recognised as providing an adequate level of protection, or where appropriate safeguards such as binding contractual commitments are in place, with further exceptions including the data subject's explicit consent, necessity for performance of a contract, international judicial cooperation and protection of the public interest. The list of adequate jurisdictions and the approved form of contractual clauses are among the details expected from the implementing framework, which is why UAE transfer assessments currently rest heavily on contract terms and documented reasoning.
Sector rules can bite harder than the general law. Health data is subject to separate federal requirements that restrict storage and transfer outside the UAE, and parts of the financial sector carry their own regulator expectations about where records sit. If your CRM will hold health-related or regulated-sector records, resolve that question before signing rather than during implementation. For everything else, what a reviewer needs from a vendor is the same anywhere: who processes the data, under what contract, with which subprocessors, and in which region the systems actually run.
HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The region that applies to your account is confirmed during onboarding or a security review, so ask for it in writing and record the answer in your transfer file. The subprocessor list at /subprocessors shows the third parties involved in running the service, and a Data Processing Agreement is available covering processing instructions, confidentiality, security and assistance with data subject requests. Region confirmation, subprocessor list and DPA are usually the three documents a UAE transfer assessment needs in order to be complete.
Security controls and vendor due diligence
The PDPL requires controllers and processors to apply appropriate technical and organisational measures and to assess risk where processing is likely to be high risk. HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Tenant isolation is enforced by row-level security inside Supabase-managed Postgres rather than by application filtering alone, so records belonging to one account are not reachable from another. Role-based access control governs what your own users can see and do. Production access on our side is least-privilege, multi-factor gated, logged and reviewed periodically, so administrative reach is bounded and evidenced.
For independent assurance, Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window. The report is available under NDA from sales@hellogrowthcrm.com, and it is the right artefact to request during due diligence because it describes tested controls rather than asserting a status. We make no claim to ISO 27001 or PCI DSS. If your questionnaire asks about either, the honest answer is that we do not hold them, and the SOC 2 Type II report is what we offer in their place. Precision here beats an unbroken run of yes answers.
On resilience and incidents, automated backups run with point-in-time recovery and a documented incident-response workflow covers detection, containment and customer notification. The PDPL requires controllers to notify the UAE Data Office of breaches that would prejudice the privacy, confidentiality or security of personal data, and to inform affected data subjects where relevant, with much of the procedural detail expected from the implementing regulations. Define your internal escalation path now, so that a notification from us reaches the person who has to act on it, rather than landing in a shared inbox that nobody has owned since the person who set it up left.
Controls and capabilities at a glance
- Data is protected with TLS in transit and encrypted at rest, across the application and the managed Postgres database behind it.
- Row-level security in Supabase-managed Postgres on AWS enforces tenant isolation at the database layer, not only in application code.
- Role-based access control lets you apply data minimisation inside the CRM by limiting which users reach which records and actions.
- Production access at Soor LLC is least-privilege, multi-factor gated, logged and reviewed periodically rather than standing open.
- Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window, available under NDA on request.
- Administrators can export account data at any time, supporting PDPL access and portability requests without vendor intervention.
- Deletion requests are honoured and the documented data rights process is published at /legal/data-rights for reference.
- The subprocessor list at /subprocessors and an available Data Processing Agreement support your cross-border transfer assessment.
- Automated backups with point-in-time recovery allow restoration to a chosen moment, supporting availability and integrity duties.
- A documented incident-response workflow covers detection, containment and customer notification so your own reporting path can start.
Questions reviewers ask
- Is HelloGrowthCRM PDPL certified?
- No. The PDPL is a law you comply with, not a certification scheme, so no vendor can hold PDPL certification. What we can provide is evidence a reviewer can examine: a SOC 2 Type II report covering a February to June 2025 observation window, available under NDA, plus a Data Processing Agreement, a published subprocessor list and documented data rights and vulnerability disclosure processes. If a vendor advertises PDPL certification, ask them to name the issuing body.
- Do the Executive Regulations exist yet?
- The implementing detail has been slower to arrive than the original timetable suggested and has continued to be described as forthcoming, so treat this as a developing position. The substantive obligations in Federal Decree-Law No. 45 of 2021 still apply, and the UAE Data Office is the federal supervisory body. Verify the current status against the Official Gazette or your UAE counsel before relying on a specific date, decision number or transition period, and build your practices now rather than waiting.
- Does the federal PDPL apply if we are registered in the DIFC or ADGM?
- Generally no. The DIFC and ADGM operate their own data protection regimes with their own registration, transfer and breach requirements and their own supervisory bodies, and Dubai Healthcare City is separate again. A mainland UAE entity follows the federal PDPL. Groups that span both often standardise CRM handling on the strictest applicable standard to avoid maintaining two sets of practices over one contact list. Confirm which regime binds each entity before you configure the account.
- Where will our CRM data be stored?
- HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The region that applies to your account is confirmed during onboarding or a security review, so request it in writing and record it in your transfer assessment. If a specific location is a hard requirement, raise it before signing rather than during migration. Do not infer hosting location from a regional sales presence, a local number or a domain suffix, because none of those indicate where the database actually runs.
- Can we transfer UAE personal data outside the country?
- Transfers are permitted to jurisdictions recognised as providing adequate protection, or where appropriate safeguards such as binding contractual commitments are in place, with further exceptions including explicit consent and necessity for a contract. The list of adequate jurisdictions and approved clause forms are among the details expected from the implementing framework. In the meantime, document your reasoning, rely on contract terms, and keep the DPA, subprocessor list and region confirmation together in one transfer file.
- Do we need to appoint a Data Protection Officer?
- The PDPL requires a DPO where processing is likely to create a high risk to privacy, including processing involving new technologies, systematic evaluation of sensitive data or large volumes of sensitive personal data. Ordinary sales contact data will often fall below that bar, but the assessment is yours to make and record. Even where no appointment is required, name someone internally who owns privacy questions about the CRM, because rights requests and incident notifications need a defined destination.
- What happens to our data if we leave?
- Administrators can export account data at any time, so you are not dependent on a vendor process to get your records out. Deletion requests are honoured, and the documented process is at /legal/data-rights. Plan the exit at purchase time: decide what format you want, who will hold the export, and how long you will retain it under your own retention schedule. We do not publish a fixed retention period, because the right answer depends on your obligations rather than ours.
- What assurance can we review during due diligence?
- Ask for the SOC 2 Type II report covering the February to June 2025 observation window, available under NDA from sales@hellogrowthcrm.com, and read the scope section rather than the summary. Alongside it, request the Data Processing Agreement, review the subprocessor list at /subprocessors, and note our vulnerability disclosure process at /legal/vulnerability-disclosure. We do not hold ISO 27001 or PCI DSS certification, and would rather state that plainly than let a questionnaire assume otherwise.
Ask for the UAE review pack
Write to sales@hellogrowthcrm.com for the SOC 2 Type II report under NDA, the Data Processing Agreement and written confirmation of the hosting region for your account. The subprocessor list is at /subprocessors and the data rights process is at /legal/data-rights. Bring your UAE counsel's questions to the security review and we will answer them in writing.