100%
Institutional legal counsel · Amman, Jordan
NASHASHIBI LAW OFFICE · LEGAL COUNSEL

Precise legal insight. More confident decisions.

We represent individuals and businesses through rigorous legal analysis, clear communication, and genuine attention to outcomes.

Litigation & ArbitrationCorporate & BusinessContracts & AgreementsReal Estate & InvestmentInternational Advisory
1936منذ عام 1936

Privacy and Data Protection under the European GDPR: How Does It Impact Arab Websites and Applications?

0views
SARAH ASMAR

Introduction
In the era of big data and smart applications, privacy has become a core concern—not only for European citizens but for anyone operating in the global digital space. With the enforcement of the General Data Protection Regulation (GDPR) on May 25, 2018, the European Union set a new standard for data protection that has far-reaching implications, even beyond its borders.
But how does GDPR affect Arab-owned websites and apps? Do they face legal obligations even if based outside the EU? The answer, as we will explore, is a definitive yes—under specific conditions.

What is the GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive legal framework designed to govern the collection, processing, and protection of personal data within the European Union.
According to Article 3 of the GDPR, its scope extends beyond EU borders to include:
  • Any organization that offers goods or services to individuals in the EU (even for free), or
  • Monitors the behavior of individuals located within the EU

Thus, any Arab website or application that targets users in Europe—through advertising, service provision, or even analytics—is subject to GDPR obligations.

What is Personal Data under the GDPR?
Article 4 of the regulation defines personal data as:
“Any information relating to an identified or identifiable natural person... including names, identification numbers, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural or social identity.”
(GDPR, Article 4(1))
This broad definition means that basic data such as email addresses, IP addresses, geolocation, or even cookies may be considered personal data if they relate to a user residing in the EU.

Implications for Arab Websites and Apps. 1.
Transparency and Privacy Policies
Websites and apps must maintain a clear and accessible privacy policy, written in user-friendly language, and must disclose:
  • What data is collected
  • Why the data is collected
  • With whom the data is shared
  • How long the data is retained
  • The user’s rights (e.g., right to access, modify, delete, or object)
Failure to comply may result in legal penalties—even for businesses located outside the EU.

2. Explicit User Consent
GDPR mandates that consent must be freely given, specific, informed, and unambiguous, particularly when it comes to:
  • Tracking cookies
  • Email marketing
  • Behavioral targeting
This means pre-ticked boxes or implied consent are not acceptable. Consent must be opt-in, not opt-out.

3. Data Minimization Principle
Under Article 5(1)(c), websites must collect only the minimum data necessary for the stated purpose.
For example, a food delivery app asking for a passport number would violate GDPR, as this information is not relevant to the service.


What Are the Penalties for Non-Compliance?
As per Article 83, GDPR provides for two tiers of fines:
  • Up to €10 million or 2% of global annual turnover (whichever is higher) for standard violations
  • Up to €20 million or 4% of global turnover for serious breaches (e.g., failure to honor user rights)

In 2022, the French data protection authority CNIL noted that some Arabic-language websites had been investigated due to improper cookie banners and non-transparent data practices (CNIL, 2022 Enforcement Reports).

Should Arab Businesses Be Concerned?
The short answer: Yes, if their digital presence reaches or targets EU residents. This includes:
  • Displaying prices in euros
  • Offering services in a European language
  • Running EU-targeted social media ads
Even if based in the Middle East or North Africa, businesses can fall within GDPR’s scope.
In fact, adopting GDPR principles is increasingly being seen as a mark of credibility and professionalism, especially as similar regulations emerge across the Arab world, such as:
  • The UAE Personal Data Protection Law (2021)
  • The Saudi Personal Data Protection Law (2023)
  • Egypt’s Data Protection Law No. 151 of 2020

Practical Steps for Arab Websites and Apps
  1. Draft a clear and GDPR-compliant Privacy Policy
  2. Implement a cookie consent management system
  3. Enable users to access, correct, or delete their data
  4. Limit data collection to only what is necessary
  5. Ensure secure storage and encryption of data

Conclusion
Privacy is no longer just a regional concern—it is a global legal standard. For Arab developers, content creators, and online business owners, the GDPR presents both a challenge and an opportunity:
A challenge to ensure legal compliance, and an opportunity to build user trust and digital integrity.
In a connected world where digital borders are virtually non-existent, understanding and aligning with international data protection laws like GDPR is no longer optional—it is essential.

Looking forward to sharing more legal insights with you soon

Discussion 0

Be the first to join the discussion.