---
title: "Why nobody should see your team’s health data: employee health data privacy in the UAE"
description: "Employee health data privacy in the UAE and Saudi Arabia: what the PDPL says, why wearables at work need trust, and how to offer one without seeing data."
canonical: https://www.sisly.ai/en/blog/why-nobody-should-see-your-teams-health-data/
published: 2026-09-01
updated: 2026-09-29
language: en
---

# Why nobody should see your team’s health data: employee health data privacy in the UAE

Employee health data privacy matters because a wellbeing benefit only works if people trust it. In the UAE, health information is sensitive personal data under the Personal Data Protection Law, and health data linked to health services has its own federal law. The simplest safe design is one where the employer never sees anyone's readings.

- The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, treats any data related to health as sensitive personal data.
- Health data connected to health services in the UAE is also covered by Federal Law No. 2 of 2019, which restricts storing it outside the country.
- Saudi Arabia's Personal Data Protection Law, in force since 14 September 2023, also treats health data as sensitive.
- Research on workplace wellness programmes points to trust, transparency and no penalties as the conditions for people to take part.
- An employer can judge a wellbeing programme by uptake and anonymous surveys, without holding a single reading.
## Why should nobody see your team's health data?

A wellbeing benefit only works if people use it, and people only use it if they trust it. The moment an employee wonders whether their manager can see last night's sleep or this week's stress readings, the ring goes back in the drawer.

That is the practical case. There is also a legal one. In the UAE and Saudi Arabia, health information is among the most protected kinds of personal data. Every reading an employer holds is a reading it has to justify, secure and explain. The simplest way to protect employee health data privacy is not to hold it at all.

This guide is for HR and people teams in the UAE, with notes for Saudi Arabia. It sets out what the law says, what the research on workplace wellness says about trust, and how to offer a wearable at work without seeing anyone's data. It is general information, not legal advice; your own adviser can apply it to your company.

## What counts as health data at work?

The UAE Personal Data Protection Law defines sensitive personal data to include any data related to health. That covers a person's physical, psychological, mental, genetic or sexual condition, and the health services they receive.

A wearable produces exactly this kind of information. Heart rate, heart rate variability, sleep, skin temperature, stress readings and activity all describe a person's body. Some can hint at more: a pattern in skin temperature can reflect a menstrual cycle, and a change in resting heart rate can come with illness. Read together and over time, they say a great deal about someone.

## What does UAE law say about employee health data?

### The personal data protection law

Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law (PDPL), came into force on 2 January 2022. According to the UAE Government portal, it requires organisations to secure personal data and keep it confidential, prohibits processing without the person's consent except in defined cases such as the public interest or legal obligations, and gives people the right to ask for inaccurate data to be corrected.

One of those defined cases relates to employment. Processing without consent is allowed where it is necessary for the employer or the employee to meet obligations and exercise rights set out in law in the field of employment, social security or social protection. That covers what the law requires, such as payroll or leave records. It is not a general permission to collect readings from a voluntary wellbeing benefit.

The UAE Data Office, set up by Federal Decree-Law No. 44 of 2021, is the federal regulator for data protection. Its role includes preparing data protection policy and issuing guidance on applying the law.

### The health data law

Health data has its own federal law. Federal Law No. 2 of 2019 on the use of information and communication technology in health fields says that health information and data related to health services provided in the UAE may not be stored, processed, generated or transferred outside the country, except in cases set by the health authority. The PDPL does not apply to health data that is regulated by its own legislation.

Whether a particular wellness product falls under the health data law, the PDPL or both depends on what it does and who provides it. That is a question for your legal adviser, and a reason to prefer a provider that already keeps readings in the UAE.

### The free zones

The PDPL leaves in place the separate data protection laws of the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM), and the rules of Dubai Healthcare City. A company registered in one of these zones follows its own zone's law for the data it handles there.

## What about Saudi Arabia?

Saudi Arabia's Personal Data Protection Law was issued by Royal Decree M/19 in 2021 and amended by Royal Decree M/148 in 2023. It came into force on 14 September 2023, and organisations had until 14 September 2024 to comply. The Saudi Data and Artificial Intelligence Authority (SDAIA) oversees it.

SDAIA's guide to the law lists personal data related to a person's health as sensitive data, alongside genetic and biometric data. For sensitive data, the guide says legitimate interest cannot be used as a legal basis, and consent, where it is the basis, must be explicit. For a company with teams in both countries, a benefit that gives the employer no access to readings avoids most of the differences between the two laws.

## Why does trust decide whether a wellbeing benefit works?

A 2020 peer-reviewed study by Hendricks-Sturrup and colleagues looked at the debate over workplace wellness programmes in the United States, drawing on public comments, court papers, hearings and interviews with legislators and their staff. The two strongest concerns were the lack of privacy protection for health information shared with employers and third parties, and financial penalties for people who chose not to take part.

The authors proposed two principles for sound practice. A culture of trust: be transparent about what is collected and how it is used, do not penalise people who decline, and never let health information feed hiring or promotion decisions. A culture of health: reward taking part rather than reaching a health number, and make the programme easy to use in working hours.

The legal setting in the Gulf is different, but the design lesson carries over: a benefit that watches asks people for far more trust than one that does not.

## Is aggregate data safe to use?

Aggregate figures, such as a team's average sleep, feel safer than individual readings, and in large groups they often are. In small groups they are not. In a team of five, an average that drops sharply in one week can point straight at one person, especially if everyone knows who has just had a baby or come back from surgery.

If you want numbers, keep groups large, publish exactly what you see to the whole team, and ask your legal adviser whether the figures still count as personal data. Often, uptake and an anonymous survey answer the same question with less exposure.

## How to offer a wearable at work without seeing the data

1. **Choose a product with no employer view.** If there is no dashboard, there is nothing to misuse, leak or explain.
2. **Keep it voluntary.** No targets, no rewards tied to readings and no cost for saying no.
3. **Put it in writing.** Tell people exactly what the company can and cannot see, before they accept the device.
4. **Let each person own the account.** The device and its readings belong to the person, including after they leave.
5. **Check where readings are kept.** Ask the provider where data is hosted and read its privacy policy.
6. **Measure the programme, not the people.** Count how many people take part, and run short anonymous surveys on whether it helps.
7. **Take legal advice once.** Confirm which law applies to your company and the provider before launch.

## Questions to ask a wearable provider

- Where are readings stored and processed?
- Can anyone at our company see an individual's readings, now or in a future version?
- Is there any aggregate reporting, and how large must a group be?
- Can an employee delete their data, and what happens to it when they leave?
- Does the provider use or share readings for any other purpose? See the provider's privacy policy.

## Common mistakes

- **Collecting because you can.** A dashboard that exists will be looked at.
- **Tying readings to rewards.** It turns a benefit into monitoring, and people notice.
- **Assuming consent solves it.** Consent has to be freely given, and a request from an employer is hard to refuse. The design matters more than the form.
- **Small-group reports.** A team average can identify one person.
- **Forgetting leavers.** Decide in advance what happens to someone's data when their contract ends.

For how to support teams through the hottest months without any health data, read [wellbeing at work through a Gulf summer](https://www.sisly.ai/en/blog/wellbeing-at-work-gulf-summer/). For the other season that reshapes working life, see [running a wellbeing programme through Ramadan](https://www.sisly.ai/en/blog/wellbeing-programme-through-ramadan/). And for ideas people can use on their own, see [finding the quiet hours in a loud week](https://www.sisly.ai/en/blog/find-the-quiet-hours/). For how privacy fits into a whole programme, see our [guide to corporate wellness in the UAE](https://www.sisly.ai/en/blog/corporate-wellness-uae/).

## Where Sisly fits

Sisly is a titanium ring or band that reads sleep, energy, stress, heart rate variability, activity and skin temperature against each person's own normal. Readings are hosted in the UAE, and the app is in Arabic and English. Sisly never shows an employer, a partner or an organisation an individual's readings, including when the device was a gift from one of them. Our [your data](https://www.sisly.ai/en/your-data/) page sets out who sees what. For HR, that means one less thing to hold, protect and explain: you offer the benefit, and your people keep their data. More for employers is on our [teams page](https://www.sisly.ai/en/business/teams/).



## FAQ

**Can my employer see my health data from a wearable?**

It depends on the product and on how your employer set it up. Some workplace schemes include an employer dashboard; others give the employer no view at all. Ask your HR team in writing what they can see, and read the provider's privacy policy. Under UAE law, health data is sensitive personal data and needs a clear legal basis to process.

**Is health data sensitive data under the UAE PDPL?**

Yes. The Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, defines sensitive personal data to include any data related to health, covering physical, psychological, mental, genetic or sexual conditions and health services. The law has been in force since 2 January 2022 and is overseen by the UAE Data Office.

**Does the PDPL apply in DIFC and ADGM?**

No. The federal law leaves in place the separate data protection laws of the two financial free zones, the Dubai International Financial Centre and Abu Dhabi Global Market, and the rules of Dubai Healthcare City. A company based in one of them follows its own free zone's law. A legal adviser can confirm which rules apply to you.

**What does Saudi law say about employee health data?**

Saudi Arabia's Personal Data Protection Law, issued by Royal Decree M/19 and amended in 2023, came into force on 14 September 2023, with a year to comply. It treats health data as sensitive data, which cannot be processed on the basis of legitimate interest and needs explicit consent where consent is the basis. The Saudi Data and Artificial Intelligence Authority (SDAIA) oversees it.

**Can an employer use anonymous, aggregate wearable data?**

Aggregate data is lower in sensitivity, but small groups make it easy to identify people. In a team of five, an average that drops sharply can point at one person. If you do use aggregate figures, keep groups large, share them openly with staff, and take advice on whether they still count as personal data.

**Does Sisly have an employer dashboard?**

No. Sisly never shows an employer, a partner or an organisation an individual's readings, including when the ring or band was a gift from one of them. Readings are hosted in the UAE and belong to the person who wears the device. An employer can offer Sisly as a benefit without holding any health data.
