12 min read · Last updated July 2026
When compliance teams think about VARA, they tend to think about technology risk, algorithm governance, and wallet security. But the VARA Technology and Information Rulebook also contains a distinct set of data protection and confidentiality requirements that are operationally demanding in their own right.
Part II (Personal Data Protection) and Part III (Confidential Information) of that rulebook layer VARA-specific obligations on top of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the PDPL). Part II opens by requiring VASPs to comply with the data protection laws that apply to them in the UAE, including the PDPL, and then adds VARA-specific programme and reporting duties.
A common mistake is to treat Part II as a copy of GDPR. It is not. The UAE PDPL shares conceptual DNA with the European regulation, but the lawful bases, enforcement model, and the UAE Data Office as regulator differ, and VARA adds a supervisory layer on top - including a duty to notify VARA within twenty-four hours after the VASP notifies a data regulator or a data subject about a personal data incident.
This guide walks through the data protection and confidentiality obligations for VASPs under the VARA Technology and Information Rulebook, grounded in the rulebook text and the PDPL, with practical guidance on building a compliant programme.
Key Regulatory References
VARA Technology and Information Rulebook - Part II (Personal Data Protection), Part III (Confidential Information) · UAE Personal Data Protection Law - Federal Decree-Law No. 45 of 2021, enforced by the UAE Data Office
Section 1
The UAE PDPL: Foundation for VARA Data Protection
The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) is the federal data protection framework for organisations processing personal data in the UAE. For VASPs, it sets the baseline that VARA’s rulebook then builds on: Part II of the Technology and Information Rulebook requires compliance with the data protection laws that apply to the VASP in the UAE, "including the PDPL and any sectoral or free zone laws and regulations that may apply."

The PDPL shares structural similarities with the EU GDPR but has important differences. It establishes lawful bases for processing, data subject rights, cross-border transfer conditions, and breach notification to the UAE Data Office, but the enforcement mechanisms and specific requirements diverge from European law. Note too that the PDPL’s detailed implementing rules sit in Executive Regulations, so operational specifics such as penalty amounts are set separately and should be checked against the current text rather than assumed.
Lawful Basis for Processing
The PDPL requires a lawful basis for processing personal data. For KYC and AML purposes, a legal obligation provides a clear basis. For marketing, analytics, and behavioural monitoring, VASPs should document consent or another lawful basis.
Data Subject Rights
The PDPL grants data subjects rights including access, correction, erasure, restriction of processing, portability, and to object to processing. VASPs must implement processes to handle these requests, while navigating the tension between erasure and AML record retention.
Cross-Border Transfers
The PDPL permits transfers of personal data outside the UAE where the destination provides adequate protection, or subject to appropriate safeguards or a specified derogation. For VASPs with international infrastructure, this drives data flow mapping.
Impact Assessments
Under PDPL Article 21, a data protection impact assessment is required before processing using new technologies that is likely to result in high risk to data subjects. For VASPs this can reach transaction monitoring and automated decision-making affecting accounts.
The PDPL is not optional for VASPs. VARA’s Part II expressly requires compliance with the applicable data protection laws in the UAE, including Federal Decree-Law No. 45 of 2021. A programme that treats data protection as a side concern is built on an unstable foundation.
Section 2
VARA Part II: Personal Data Protection Requirements
Part II of the Technology and Information Rulebook is organised into three sections: compliance with applicable data protection law, a compliance programme, and provision of information to VARA. Together they add VARA-specific obligations on top of the PDPL baseline - enforceable requirements VARA can assess during supervisory reviews.
| VARA Requirement | What It Means for VASPs | Source |
|---|---|---|
| DPO Appointment | Every VASP must appoint a Data Protection Officer with the appropriate competencies and experience to perform the statutory duties associated with the role under applicable data protection laws. The rulebook allows the DPO to be the same person as the CISO. | Part II, Compliance Programme |
| Compliance Function & Programme | VASPs must establish an organisational function responsible for personal data management, with appropriate processes, procedures, and controls to meet applicable data protection laws. | Part II, Compliance Programme |
| Notify VARA of Reported Incidents | VASPs must notify VARA as soon as possible, and in any event within twenty-four hours, following their own notification to a data regulator or a data subject about a personal data incident. The clock runs from that downstream notification, not from discovery. | Part II, Provision of Information to VARA |
| Cross-Border Transfer Handling | Part II asks VASPs to account for where data is stored or located and how it is transferred; the substantive transfer conditions come from the PDPL. This matters for VASPs using cloud infrastructure hosted outside the UAE. | Part II + PDPL |
| Records of Processing | Under the PDPL, controllers keep records of processing activities. In practice VASPs should document purpose, data subject and data categories, retention, and the security measures applied. | PDPL |
| Third-Party Data Sharing | VASPs sharing personal data with third parties (analytics providers, KYC vendors, cloud services) should ensure contractual data protection obligations and assess third-party handling practices. | PDPL |
Reading the VARA notification duty correctly
VARA’s Part II duty is a downstream reporting step, not a primary breach clock. It requires the VASP to notify VARA as soon as possible, and in any event within twenty-four hours, after it has notified either a data regulator (including in the UAE) or a data subject about a personal data incident, unless doing so is prohibited by law. It is distinct from the PDPL’s own duty to notify the UAE Data Office. The practical takeaway: when your team decides an incident is reportable to the Data Office or to affected individuals, VARA notification must follow within a day, so build the VARA step into the same workflow.
Section 3
Part III: Confidential Information Obligations
Part III of the Technology and Information Rulebook addresses confidential information - a category that reaches beyond personal data. For VASPs this can include trading patterns, portfolio compositions, wallet addresses, and transaction histories that, even where not personally identifiable in isolation, could be misused if mishandled.
Two clauses anchor Part III. Staff must not share confidential information within the VASP or with other entities unless it is absolutely necessary for conducting the related VA activities (a need-to-know rule). And neither VASPs nor their staff may use or share confidential information for the purpose of trading virtual assets by any entity. That trading prohibition is stated without a carve-out.
Trading Prohibition (Rulebook)
The explicit rule is that confidential information must not be used or shared for the purpose of trading virtual assets. For a VASP that also runs proprietary trading or market making, meeting this means real separation between client information and trading functions, not just a policy statement.
Need-to-Know Access (Rulebook)
Sharing confidential information is limited to what is absolutely necessary for the related VA activities. Access controls, audit logging, and clear internal handling rules are practical ways to demonstrate the need-to-know principle is enforced.
Information Barriers (Practice)
Documented information barriers between units that hold client confidential information and units that could benefit from it are a recognised way to give effect to the rulebook’s restrictions. They are a practical control, not a separately numbered VARA mandate.
Disclosure Discipline (Practice)
Where confidential information is disclosed to third parties such as auditors or analytics providers, documented authorisation and logging help evidence that sharing stayed within the necessary purpose the rulebook allows.
Part III creates requirements that rhyme with what traditional financial institutions face under market abuse rules. For crypto exchanges that also trade on their own account, the practical challenge is that the trading prohibition and need-to-know rule are systems-architecture problems, not policy-document problems.
Section 4
Building a VARA Data Protection Programme: Practical Guide
A structured way to build a programme that satisfies both VARA and the PDPL is to treat data protection as an operational programme, not a one-time documentation exercise. The sequence below maps to the rulebook and the law.
Appoint a Data Protection Officer
Under Part II, every VASP appoints a DPO with the competencies and experience to carry out the statutory duties under applicable data protection laws. The rulebook permits the DPO to also serve as the CISO, which many smaller VASPs will use.
Key considerations: The DPO can be an internal hire or an outsourced specialist, but they should understand both UAE data protection law and the crypto-specific data handling that VASPs face - KYC and AML data, analytics data flows, and wallet address handling.
Map All Personal Data Processing Activities
Create a processing register that documents every activity involving personal data. For VASPs, this includes categories many traditional financial institutions do not encounter:
- KYC and AML data - identity documents, proof of address, source of funds documentation
- Transaction data - linked to individual clients, including wallet addresses and counterparty information
- Behavioural analytics data - login patterns, device fingerprints, and withdrawal behaviour
- Blockchain analytics data - risk scores, cluster analyses, and sanctions screening results for client wallet addresses
- Communication data - support interactions, trade confirmations, and marketing communications
Establish Cross-Border Data Transfer Mechanisms
Most VASPs transfer personal data internationally. Cloud infrastructure may sit outside the UAE, analytics providers are often US-based, and KYC vendors may process identity documents in various jurisdictions. Under the PDPL each transfer needs an adequacy basis, an appropriate safeguard, or a specified derogation.
Practical approach: Maintain a data flow map showing each cross-border transfer, the destination, the recipient, the data categories, and the transfer basis relied on. Review it as your technology stack and vendors change.
Wire the VARA Notification Step Into Incident Response
Because VARA must be notified within twenty-four hours of the VASP notifying a data regulator or a data subject, the VARA step should be built into the same incident workflow that decides on those primary notifications, so it cannot be forgotten once the decision to report is made.
Required elements: A clear trigger that fires the VARA notification when a Data Office or data subject notice goes out, a pre-approved VARA notification template, named owners with backups, and a documented chain from the reporting decision through to the VARA notice within the day.
Give Effect to the Confidential Information Rules (Part III)
For VASPs that conduct proprietary trading or market making alongside client services, the Part III trading prohibition and need-to-know rule have to be reflected in systems, not just policies.
Practical controls: Access segregation between client data and trading systems, audit logging of access to client order flow data, and alerting on unexpected cross-boundary access. Document each control, test it, and keep evidence for VARA supervisory reviews.
Comparison
VARA and UAE PDPL vs GDPR: Key Differences
VASPs with European operations or clients may need to comply with both the UAE regime and GDPR. The frameworks share common principles but differ in mechanics. The comparison below focuses on the points that diverge, stated at the level the sources support.
| Requirement | VARA / UAE PDPL | GDPR |
|---|---|---|
| Regulator Notification | PDPL: notify the UAE Data Office without undue delay. VARA: notify VARA within 24 hours after notifying a data regulator or data subject | Notify the supervisory authority within 72 hours of becoming aware of a personal data breach |
| DPO Requirement | VARA: mandatory for every VASP. PDPL Art. 10: required in specified high-risk cases | Required in specified cases (Art. 37) |
| Confidential Info Controls | Explicit confidentiality and trading-use rules (Part III) | No equivalent provision |
| Trading Use of Client Data | Explicit prohibition on using confidential information to trade virtual assets | Addressed indirectly via purpose limitation |
| Impact Assessment | PDPL Art. 21: DPIA for high-risk processing using new technologies | DPIA for high-risk processing (Art. 35) |
| Penalties | VARA supervisory and enforcement action; PDPL administrative penalties set by Cabinet resolution | Up to 4% of global turnover or €20M, whichever is higher |
Dual Compliance Strategy
For VASPs subject to both regimes, a workable approach is to implement the stricter requirement as the baseline for each overlapping obligation and to track the extras separately - for example, VARA’s mandatory DPO and its distinct notify-VARA step, alongside GDPR’s specific data subject rights and its 72-hour supervisory-authority notification. Cross-framework mapping keeps the shared controls in one place while flagging where the regimes genuinely differ.
Common Pitfalls
Five Mistakes VASPs Make With Data Protection
1. Treating Wallet Addresses as Never Personal Data
Some VASPs assume blockchain wallet addresses are outside data protection because they look pseudonymous. Under the PDPL, data relating to an identified or identifiable person is personal data, so a wallet address tied to a client account can qualify. Blockchain analytics that link addresses to real-world identities reinforce that.
2. Missing the VARA Notification Trigger
The VARA duty is easy to overlook because it does not fire on discovery. It fires when you notify a data regulator or a data subject, and VARA must then hear from you within 24 hours. If your incident process does not connect the primary notification to the VARA step, you can meet the PDPL duty and still miss VARA’s.
3. Ignoring the Tension Between Erasure and AML Retention
The PDPL grants a right to erasure, but AML rules require VASPs to retain transaction records and KYC documentation for set periods. VASPs must document how they reconcile these, typically by retaining what regulation requires while deleting data that exceeds retention needs.
4. No Impact Assessment for High-Risk Analytics
Behavioural anomaly detection and automated decisioning can be high-risk processing using new technologies. Under PDPL Article 21 that calls for a data protection impact assessment. Deploying such analytics without one leaves a gap under the PDPL.
5. Policy-Only Confidentiality Controls
A policy saying proprietary trading staff must not access client data is not, on its own, evidence of control. To show the Part III trading prohibition and need-to-know rule are effective, VASPs typically need access controls, audit logging, and detection of anomalous access that can be demonstrated during supervisory assessments.
Tools & Platforms
Managing VARA Data Protection With Compliance Software
A data protection programme for a VARA-licensed VASP ties together many moving parts: processing records, cross-border transfer documentation, impact assessments, DPO reporting, the VARA notification workflow, confidential information controls, and third-party sharing assessments. Running this on spreadsheets is possible but fragile - one missed review or undocumented data flow can surface during a VARA supervisory assessment.

A purpose-built platform provides structured workflows for each obligation, review reminders, evidence repositories, and audit trails that demonstrate continuous compliance.
Venvera supports VARA data protection work with tracking for Part II and Part III obligations, an incident and notification workflow that captures the VARA step, UAE PDPL management, and cross-framework mapping that connects VARA and PDPL controls to GDPR, UAE IA, and ISO 27001 for VASPs with wider obligations - so shared evidence is reused rather than recreated.
What to Look For in a Data Protection Platform for VASPs
Conclusion
Data Protection Is Not an Afterthought
VARA’s Technology and Information Rulebook treats data protection and confidentiality as core parts of virtual asset regulation. Part II requires PDPL compliance, a DPO for every VASP, a data management function, and the notify-VARA step; Part III restricts confidential information and prohibits its use for trading virtual assets.
For VASPs, that means a DPO from day one, a programme covering every category of personal data you process - including wallet addresses and analytics data that may not look obviously personal - an incident process that wires in the VARA notification, and, if you trade on your own account, technically enforced separation between client information and trading. Manual processes may pass an initial assessment, but they are harder to sustain under ongoing supervision.
Frequently Asked Questions
Does VARA require every VASP to appoint a Data Protection Officer?
Yes. The Compliance Programme section of Part II requires a VASP to appoint a Data Protection Officer with the appropriate competencies and experience to perform the statutory duties under applicable data protection laws. The rulebook allows the DPO to be the same person as the CISO. This is broader than the UAE PDPL itself, where Article 10 requires a DPO only in specified high-risk cases.
What exactly is VARA’s 24-hour notification requirement?
Under Part II, a VASP must notify VARA as soon as possible, and in any event within twenty-four hours, after it notifies either a data regulator (including in the UAE) or a data subject about a personal data incident, unless notifying VARA is prohibited by law. The 24-hour clock runs from that downstream notification, not from when the incident is discovered, and it is separate from the PDPL’s own duty to notify the UAE Data Office.
What does Part III say about using client information?
Part III restricts confidential information to a need-to-know basis - staff must not share it unless absolutely necessary for the related VA activities - and prohibits VASPs and their staff from using or sharing confidential information for the purpose of trading virtual assets by any entity. The trading prohibition is stated without a carve-out.
How does the UAE PDPL relate to VARA’s requirements?
The PDPL (Federal Decree-Law No. 45 of 2021) is the federal baseline: lawful bases, data subject rights, cross-border transfer conditions, records of processing, DPIAs for high-risk new-technology processing, and breach notification to the UAE Data Office. VARA’s Part II expressly requires compliance with the applicable data protection laws in the UAE, including the PDPL, and then adds the VARA-specific programme and notification duties on top.
Are wallet addresses personal data under this regime?
They can be. The PDPL applies to data relating to an identified or identifiable natural person, so a wallet address linked to a client account can be personal data even though the address is pseudonymous on-chain. Blockchain analytics that connect addresses to identities make that link stronger, which is why VASPs should treat client-linked wallet data within their data protection programme.
VARA data protection compliance with Venvera
Primary sources
This guide is drawn from the VARA rulebooks and the UAE PDPL: the VARA Technology and Information Rulebook, including Part II - Personal Data Protection (compliance with applicable data protection law, the compliance programme, and the provision-of-information-to-VARA notification duty) and Part III - Use and Protection of Confidential Information; and the UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, summarised on the UAE Government portal. Always confirm the current rulebook and law text before relying on a specific clause, date, or figure.
Published July 2026 · VARA data protection and UAE PDPL compliance for VASPs · venvera.com





