The United Arab Emirates has no single rulebook for retiring IT hardware. It has four overlapping layers, and most organisations sit under three of them at once for the same laptop. The most common failure is not breaking a rule. It is not knowing which rules apply.
This guide is ordered so that you establish applicability before you establish process.
It also corrects something that a large amount of published UAE compliance content gets wrong. Numerous vendor guides state that the PDPL Executive Regulations have been issued and cite specific Cabinet decisions by number. Leading international law firm guidance and practitioner commentary consistently state the opposite: the implementing regulations remain outstanding, more than four years after they were due. If your internal policy, your supplier contracts or your tender responses cite a PDPL Executive Regulation by number, verify that citation before you rely on it. A confident reference to an instrument that has not been published is a serious credibility problem in a regulatory conversation.
The practical consequence for asset disposal is that there is no prescribed UAE federal standard for media sanitisation. No mandated method, no mandated verification regime, no mandated retention period for destruction evidence. That is not permission to do less. The obligation to protect personal data and to erase it is fully enforceable and unaffected by the gap. It means the method is your decision, and therefore yours to justify. The guide shows you how to select a standard, document the reasoning, and apply it consistently, which is a defensible position whatever the regulations eventually say.
Two other traps are handled directly. NESA no longer exists as an independent authority under that name; it operates within the UAE Signals Intelligence Agency, with the Cybersecurity Council setting national strategy. And there is no third-party certification against the UAE Information Assurance Standard, so any supplier presenting a NESA certificate is describing something that does not exist. Six supplier claims worth challenging appear in a verification table, alongside what to ask instead.
The third trap is jurisdictional. The Dubai International Financial Centre and the Abu Dhabi Global Market are expressly carved out of the federal PDPL. They are separate legal regimes with separate supervisory authorities, not lighter versions of the federal one. A group running a single refresh across a mainland trading company, a DIFC advisory entity and an Abu Dhabi branch is dealing with three data protection regimes on one purchase order. A decision diagram resolves it per legal entity rather than per building.
Inside the 33 pages: the four-layer regulatory map with an applicability table to complete per entity; where asset disposal actually sits within the UAE Information Assurance Standard control areas; what changed in DESC ISR v3 and why classification now drives disposal protocol directly; the three data protection regimes and how to build one process to the strictest applicable requirement; an eight-step disposal sequence; the three failure points that recur across UAE estates; defined exception routes for every failure mode; how to choose and document a sanitisation standard; the cross-border position on moving data-bearing media; supplier due diligence and ongoing oversight obligations; the evidence pack; and governance with a sign-off block.
Three appendices: a control mapping matrix that gives you one answer for four different assessors, a 21-question supplier due diligence questionnaire ready to issue, and a 24-point readiness checklist flagged mandatory or good practice.
Free, customisable, no email required. Everything in square brackets is a field you complete.