Honest answers

Does UAE law require secure document sharing?

We sell document security. It would suit us to tell you the PDPL will fine you. It won't, and you should know why before someone sells you software on that basis.

Last updated 16 July 2026 · SightSealer · Not legal advice

Short answer: No. As of July 2026 the UAE Personal Data Protection Law is in force on paper but not enforced in practice: no executive regulations, no operational regulator, no penalty schedule, no enforcement action in four years. RERA's broker bylaw has no data-security article at all. The enforcement risk that is real for a Dubai brokerage today is anti-money-laundering, where brokers took 495 violations and AED 18.5 million in fines in the first half of 2025 alone.

A warning about what you will read elsewhere. Search "PDPL fines" and you will find confident figures — AED 50,000 to AED 5 million is the usual range — on consultancy and software-vendor blogs. Those numbers cannot be traced to any published instrument, and the blogs contradict each other. Article 26 of the PDPL says penalties will be set by a future Cabinet decision. That decision has not been issued. If a vendor quotes you a PDPL fine, they are either repeating something they did not check, or they are counting on you not checking.

What the PDPL actually is, and isn't

Federal Decree-Law No. 45 of 2021 is a real law and it is in force. It looks broadly like GDPR: lawful basis, data subject rights, breach notification, cross-border transfer rules.

But a law needs machinery to bite, and the machinery was never built:

What you need for enforcementStatus, July 2026
Executive RegulationsNever issued. Four years on.
An operational regulatorThe UAE Data Office was announced but has not become fully operational.
A penalty scheduleArticle 26 defers it to a Cabinet decision that has not been made.
Any enforcement actionNone publicly recorded.

This is not a fringe reading. International law firms say it plainly: as of June 2026, Morgan Lewis noted that although the PDPL has been in force for several years, its implementing regulations have still not been issued, and that the Data Office, though formally announced, never became fully operational in practice. Baker McKenzie's guidance records that penalties are deferred to a future Cabinet decision.

None of this means the PDPL will stay dormant. It could be activated with a single Cabinet decision, and when it is, the obligations were always there. It means only this: today, nobody is going to fine you under it, and any pitch built on that fear is built on nothing.

What about RERA?

Dubai's Bylaw No. 85 of 2006 governs real estate brokers. It contains no explicit confidentiality or data-security article. The Code of Ethics carries a general privacy principle, but there is no rule requiring any particular technology, process or standard for handling a client's documents.

If someone tells you RERA requires secure document sharing, ask which article.

The obligation that is real: AML

This is the part most vendors skip, because it doesn't sell viewing software.

Real estate brokers are designated non-financial businesses and professions under the UAE AML regime. That means goAML registration, customer due diligence, and record retention for five years. It is inspected, and it is fined.

In the first half of 2025, the Ministry of Economy imposed over AED 42 million in AML-related fines across sectors. Real estate brokers alone accounted for 495 violations and nearly AED 18.5 million.

Note the direction of that obligation, because it is the opposite of what you might assume: AML requires you to collect and keep passport copies, Emirates IDs and proof of funds, and to produce them on demand. It is a duty to retain, not a duty to protect.

Which creates the actual exposure. AML forces every brokerage to accumulate a large pile of other people's identity documents. Nothing in the AML regime tells you how to hold that pile safely, and the PDPL that would have told you is not operational. So the risk is not a regulator's fine. It is the pile itself.

The risk that is real, and has a body count

In December 2023, Goyzer — a Dubai real estate CRM — exposed around 690,000 people's records through a database left without a password. The exposed data reportedly included scanned copies of receipts, cheques, contracts and identity documents, with over 100,000 document links.

Read that again, because it is the whole argument. The tool the brokerage bought to manage client documents was the breach. Not an employee, not WhatsApp, not a hacker with a zero-day. A database with no password.

Meanwhile, the everyday behaviour continues. As Khaleej Times reported in July 2026, residents "are often asked to send copies of their Emirates IDs via WhatsApp, email, or other unsecured channels" and "once shared, individuals often lose control over where the data is stored".

Neither of those is a compliance event. Both are real.

So should you buy document security?

Not for compliance. There is nothing to comply with, and buying software against an imaginary fine is a bad reason that survives only until someone's lawyer checks.

The honest reasons are commercial:

If those reasons are not enough for your business, don't buy anything. We would rather say that than invent a fine.

Related: is WhatsApp View Once actually safe? (four bypasses, and it never covered documents at all) and can you stop someone screenshotting a document?

Common questions

Is the UAE PDPL currently enforced?

No, not in practice. As of July 2026 Federal Decree-Law No. 45 of 2021 is in force, but its Executive Regulations have never been issued, the UAE Data Office has not become fully operational, Article 26 defers penalties to a future Cabinet decision that has not been made, and no public enforcement action has been taken. There is currently no penalty schedule to be fined under.

What are the fines under the UAE PDPL?

There are none set. Article 26 states administrative penalties will be determined by a Cabinet decision, and that decision has not been issued. Figures such as AED 50,000 to AED 5 million appear only on consultancy and SEO blogs, contradict each other, and cannot be traced to any published instrument. Treat any specific PDPL fine figure as unsourced.

Does RERA require brokers to protect client documents?

Not explicitly. Dubai Bylaw No. 85 of 2006, governing real estate brokers, contains no specific confidentiality or data-security article. The RERA Code of Ethics includes a general privacy principle. There is no rule mandating any particular technology for handling client documents.

What data rules do Dubai real estate brokers actually get fined for?

Anti-money laundering, not data protection. Brokers are designated non-financial businesses and professions under the UAE AML regime, must register with goAML, perform KYC and retain records for five years. In the first half of 2025 the Ministry of Economy imposed over AED 42 million in fines across sectors, with real estate brokers alone accounting for 495 violations and nearly AED 18.5 million.

Is it safe to send an Emirates ID over WhatsApp?

It is common practice and it is a poor idea, but as of July 2026 it is not a specifically penalised act under an enforced UAE data protection regime. The practical risk is loss of control: once sent, the copy sits in the recipient's chat history, gallery and cloud backup indefinitely, and can be forwarded without your knowledge. The reputational and civil exposure is real even where the regulatory exposure is not.

Not legal advice. This is our reading of the public position as at 16 July 2026, written because the alternative on offer is invented fines. Laws change, and the PDPL could be activated by a single Cabinet decision. Take advice from a UAE-qualified lawyer before making compliance decisions, and if any part of this is out of date, tell us and we will correct it.

Buy it for the commercial reason, or not at all

Send an off-market pack that carries the viewer's name on every page, expires when you say, and tells you exactly who read what. No sign-up to try it.

Watch it work