Book an appointment with us, or search the directory to find the right lawyer for you directly through the app.
Find out moreWelcome to the first edition of Law Update for 2025. As we begin this exciting year, we are pleased to turn our attention to one of the most dynamic sectors in the UAE and the broader GCC region – healthcare. Over the past several years, the region has seen unprecedented growth in this sector, driven by legislative advancements, technological innovations, and the increasing focus on sustainability and AI. As such, healthcare is set to be one of the most important sectors in the coming decade.
In this issue, we explore key themes that are significantly shaping the future of healthcare in the UAE, such as recent changes in foreign ownership laws. These reforms present a major opportunity for foreign investors, opening up new avenues for international collaborations and improving the overall healthcare infrastructure. The changes in ownership laws are an important milestone, and we provide an analysis of what this means for the industry and the various players involved.
Read Now2025 is set to be a game-changer for the MENA region, with legal and regulatory shifts from 2024 continuing to reshape its economic landscape. Saudi Arabia, the UAE, Egypt, Iraq, Qatar, and Bahrain are all implementing groundbreaking reforms in sustainable financing, investment laws, labor regulations, and dispute resolution. As the region positions itself for deeper global integration, businesses must adapt to a rapidly evolving legal environment.
Our Eyes on 2025 publication provides essential insights and practical guidance on the key legal updates shaping the year ahead—equipping you with the knowledge to stay ahead in this dynamic market.
The Saudi Data and AI authority has recently published the Rules governing National Register of Controllers within the Kingdom of Saudi Arabia (“Kingdom”) pursuant to Article 34, of the Personal Data Protection Law Issued by Royal Decree No. (M/19) dated 9/2/1443 AH, amended by Royal Decree No.(M/148) dated 5/9/1444 AH.
The Rules define essential terms such as who the competent authority is, whilst explicitly mentioning the need for Controllers in the Kingdom to register on the National Data Governance Platform. This requirement applies to public entities, entities primarily processing personal data, those handling sensitive data, and individuals processing data beyond personal or family use. Controllers are obligated to appoint representatives for registration using the form provided within the Rules, with procedures differing for public and private entities versus individuals who act as their own representatives.
Article 4 mandates the representatives to complete procedures on the Platform if the above-mentioned conditions[1] are met, including the need to appoint a Personal Data Protection Officer in accordance with Article 32 of the executive regulations of the Personal Data Protection Law. Controllers are responsible for ensuring all required data fields are accurately filled out, covering controller entity details, representative information, and, if applicable, details of the appointed Data Protection Officer (“DPO”), who may be an employee of the Controller, an external contractor or a contractor located outside the Kingdom. Furthermore, controllers may designate themselves as the DPO whilst emphasizing compliance with Article 4’s mandate to complete all registration procedures on the Platform.
The issuance of a registration certificate follows the successful completion of the registration process, containing entity or individual-specific information (registration serial number, entity logo, contact details, and validity period up to 5 years). Upon expiry of the same, the Competent Authority will notify Controllers of the impending expiration at least thirty days in advance, upon which they may submit a renewal request ensuring compliance with data protection regulations. The Competent Authority will allow the public to verify registration details, enhancing transparency and trust in data protection practises.
The Rules mention the various e-services provided on the Platform aimed at safeguarding data integrity and protecting individuals’ rights. These services include personal data breaches, conducting privacy impact assessments, providing legal support services, and compliance assessment services in consonance with data protection laws and regulations.
The Competent Authority can update or amend the rules as needed, enforcing them upon publication to ensure Kingdom-wide data protection compliance.
Look out for our more detailed analysis in our next Law Update edition.
[1] Conditions refer to the applicability of the Rules in the following instances:
To learn more about our services and get the latest legal insights from across the Middle East and North Africa region, click on the link below.