What the laws require
- UAE PDPL (Federal Decree-Law 45/2021): biometric data is sensitive; processing generally needs consent or a statutory exception, and large-scale sensitive processing points to appointing a DPO.
- Cross-border transfers require an adequate destination or contractual safeguards — keeping data in-country is the simple answer.
- Saudi PDPL (in force since 2024): explicit consent as the default basis, controller registration, transfer assessments, and data-subject rights with real penalties.
- Free zones: DIFC Law No. 5/2020 and the ADGM DP Regulations apply their own GDPR-style rules to companies registered there.
How NCheck supports it
- On-premises deployment keeps biometric data inside the UAE or KSA — the cleanest answer to residency and transfer rules.
- Encrypted, non-reversible templates; raw images are not retained.
- Consent capture at enrolment, with RFID or manual check-in as an alternative.
- Retention limits, deletion tools and audit trail.
Practical checklist
- Identify your regime first: mainland PDPL vs DIFC/ADGM.
- Prepare consent notices in Arabic and English (use our free template).
- Assess whether you need a DPO.
- Run a transfer assessment before using any cloud hosted abroad — or choose on-premises.
- Define retention and deletion schedules (use our free template).
Free templates: Download the free consent-form and retention-policy templates →
This page is general information, not legal advice. Laws change — confirm current requirements with your counsel.
Where this matters most
See how NCheck handles attendance in the sectors where these rules bite hardest: Construction · Oil & gas · Hospitality · High security · all industries.
Deploy it the compliant way
Run NCheck fully on your own server — data never leaves your network — or in our EU-hosted cloud. Either way, only encrypted templates are stored, never raw images. About on-premises → · Security & compliance →