Data Protection Policy
1. Introduction
AI Ghurair Exchange LLP (AGEX) is committed to protecting the privacy of its employees, customers, Third Parties and other stakeholders and ensuring the protection of personal data we collect, process, and store. This Data Protection Policy outlines our obligations and responsibilities in relation to the processing of personal data and our commitment to protecting the data.
This Document should be read in conjunction with Record Retention Policy and Data Handling Policy which will provide the detail understanding of the Data Protection Process.
2. Scope of the Policy
This policy applies to employees, customers, Third Parties and other stakeholders who handle personal information on behalf of AGEX.
3. Purpose of the Policy
The purpose of this Data Protection Policy is to establish guidelines for the collection, use, storage, and disposal of personal information by AGEX.
4. Administration and Circulation of this Policy
This policy is the property of Al Ghurair Exchange. The policy is meant for internal use by the Management and its Employees. The circulation of the policy outside, of Al Ghurair Exchange is strictly prohibited and can only be disclosed on the written approval of the Chief Executive Officer.
5. Data Management Control Framework
AGEX shall maintain a Data Management Control Framework comprising policies, procedures, system controls, and checks and balances to protect Consumer Data and Personal Data, and to identify, respond to, and resolve information security incidents and breaches when they occur.
6. Data Protection Principles
AGEX is committed to upholding the following data protection principles:
6.1 Lawfulness, fairness and transparency:
AGEX will only process personal data lawfully, fairly and in a transparent manner.
6.2 Purpose limitation:
AGEX will only process personal data for specified, explicit, and legitimate purposes.
6.3 Data minimization:
AGEX will only process personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
6.4 Accuracy:
AGEX will ensure that personal data is accurate and kept up to date.
6.5 Integrity and Data confidentiality:
AGEX will implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction, and ensure the confidentiality, integrity, Availability of transaction database held/stored confidential and available within the UAE at all times.
AGEX shall have a legal obligation of confidentiality towards a consumer except:
- When disclosure of Consumer Data is Properly Imposed by a legal authority; or
- When disclosure is made with the expressed consent of the Consumer, or through representative nominated by the Consumer.
6.6 Data Collection and Use
AGEX will only collect and use personal data for the specific purposes for which it was collected and will inform individuals about the purposes for which the personal data has been collected after obtaining their consent wherever necessary.
6.7 Data Storage and Protection
AGEX will take appropriate technical and organizational measures to ensure the security of personal data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage as following:
- Encryption of Sensitive Data
- Implementation of Appropriate Firewall systems and protection shall be available for PCs, Servers, Operating Systems, Database and network equipment;
- Access to personal information and Personal Data of Consumers will be limited to authorized business lines and their Staff only.
- Regular backups to ensure the protection of Data's
- Logs will be maintained to record the names of Staff who have accessed Consumer databases and the timing to avoid any unauthorized access.
- Periodic security assessments will be conducted.
6.8 Data Sharing
AGEX will only share personal data with third parties where necessary for the purposes for which it was collected, and where we have obtained the individual's consent or where it is legally required to do so.
6.9 Data Movement, Database and Back-up
- Where the data is shared outside of own network, AGEX Shall use stronger encryption techniques to suitably encrypt such data;
- Outside parties will be given access to the customer/ transaction database which shall be held completely proprietary at all times.
- Restricted access shall be given to the IT service provider, in case the IT function is outsourced, to carry out maintenance of computer hardware, network or applications.
- Appropriate policies shall be introduced for the back-up and off-site storage back-up data of all servers, databases, network servers and system software;
- AGEX shall have a procedure for the back-up of systems that may include details of back-up frequency, information to be backed-up, storage media, back-up retention period, recirculation of the media and periodical testing of the back-up copies for data availability;
- Disaster Recovery (DR) drills shall be conducted at least once a year to ensure that the DR set-up is functional.
6.10 Third-Party Data Processing:
Where AGEX engage third parties to process personal data on our behalf, AGEX will ensure
- Appropriate contractual arrangements are in place to protect the personal data and that the third-party processors are subject to appropriate data protection obligations.
- Contractual rights to take legal action against the Service Provider in the event of breach of confidentiality.
- All customer data shall be returned to Al Ghurair Exchange in the event of the termination of agreements without retaining any copies.
7. Data Breach Notification
In the event of a breach of personal information AGEX will
- Notify All the affected parties without undue delay.
- Take immediate action to identify and contain the breach, access the risk to individuals, and notify the relevant authorities.
Significant Personal Data Breaches, Escalation, and CBUAE Reporting
- AGEX shall define and maintain internal criteria to classify a personal data breach as significant, considering at minimum: Consumer impact, number of affected Consumers, regulatory breach risk, and reputational impact.
- All suspected personal data breaches must be reported immediately to the designated Data Protection Owner and IT Security for containment and assessment.
- AGEX must report significant personal data breaches to the Central Bank without undue delay and no later than seventy-two (72) hours after becoming aware of the breach, including impact on Consumers and remediation actions.
- Reporting shall be made using the Central Bank’s prescribed template/format and in the manner required by the Central Bank.
8. Responsibilities
All employees, third parties and other stakeholder who handle personal data on behalf of AGEX are responsible for complying with this policy.
- The Board shall designate responsibility and accountability for the Data Management and Protection function to a senior management position reporting to Senior Management.
- The designated Data Protection Owner shall ensure oversight of and compliance with the Data Management Control Framework and applicable UAE and Central Bank data protection and privacy requirements.
9. Access Controls and Audit Logging
- Access to Personal Data and Consumer databases shall be limited to authorized business lines and authorized Staff only, based on role and business need.
- The Exchange shall maintain access logs for audit and supervisory purposes, recording at minimum the name/ID of Staff accessing Consumer databases, the date/time of access, and the activity performed.
- Access logs and monitoring records shall be retained for at least five (5) years and shall be provided to the Central Bank upon request.
10. Training
Agex will provide relevant training to our employees on data protection and ensure that they are aware of their responsibilities under this policy.
- AGEX shall provide employee training and awareness programs on the Data Control Framework for accessing and handling Consumer Data and for reporting security and policy breaches.
- AGEX shall promote protecting Consumer Data as an ongoing Staff responsibility, with reminders issued at least annually.
- Training completion shall be recorded in a Training Register (attendees, dates, content), and non-completion shall be escalated to Senior Management.
11. Annual Review and Reporting of Data Management Control Framework
- The Data Management and Protection function shall annually review and improve the adequacy of the Data Management Control Framework for the collection, classification, storage, usage, transfer, protection, correction, and destruction of Personal Data.
- The function shall monitor, investigate, and report to Senior Management any material incidents of accidental or unauthorized access, loss, alteration, transfer, destruction, use, modification, or disclosure of Data.
- The function shall issue reports to Senior Management and the Board on significant data management violations and breaches immediately.
12. Review of the Policy
This policy will be reviewed and updated on an annual basis or as required by changes in regulations or business practices.