ARP Digital FZCO
Data Privacy & Protection Policy
1. Introduction and Policy Statement
ARP Digital FZCO (the "Firm") is committed to maintaining the highest standards of data privacy and security. This Data Privacy Policy (the "Policy") establishes the framework for how the Firm collects, processes, stores, and protects Personal Data in the course of its Virtual Asset activities.
This Policy is designed to ensure strict compliance with:
- VARA Technology and Information Rulebook, specifically Rule II.B (Compliance Programme).
- UAE Federal Decree-Law No. (45) of 2021 on the Protection of Personal Data (the "PDPL").
- Applicable international data protection standards where the Firm operates globally.
2. Scope and Applicability
This Policy applies to all "Personal Data" processed by ARP Digital FZCO regarding:
- Clients: Individuals and institutional representatives using the Firm’s services.
- Employees: All full-time, part-time, and temporary staff.
- Associated Persons: Agents, consultants, and third-party intermediaries.
3. Governance and DPO Appointment
In accordance with Rule II.B of the VARA Technology and Information Rulebook, ARP Digital FZCO has established a formal Data Protection Compliance Programme:
3.1 Data Protection Officer (DPO)
The Firm has appointed a Data Protection Officer (DPO) who possesses the requisite competencies and experience to perform statutory duties under Article 11 of the UAE PDPL.
- Role: The DPO acts as the primary point of contact for VARA and data subjects regarding data privacy matters.
- Independence: The DPO reports directly to Senior Management to ensure independence in monitoring compliance.
- As permitted by VARA, this role may be held by the Chief Information Security Officer (CISO) if appropriate.
3.2 Data Protection Function
The Firm has established a dedicated function responsible for the management and protection of Personal Data. This function is integrated into the Firm's broader Risk and Compliance framework and is responsible for:
- Implementing technical and organizational measures to protect data.
- Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
- Maintaining the Record of Processing Activities (ROPA).
4. Data Collection and Processing
The Firm collects and processes Personal Data only for specified, clear, and legitimate purposes, including:
- Client Onboarding (KYC/KYB): Collecting identity documents (passports, IDs), biometric data, and corporate affiliations to comply with AML/CFT laws.
- Service Provision: Processing wallet addresses, transaction history, and settlement details to execute Virtual Asset transfers.
- Regulatory Compliance: Retaining records to satisfy VARA, UAE Financial Intelligence Unit (FIU), and other regulatory reporting obligations.
5. Data Security and Storage
To comply with VARA Rule I.L regarding client data privacy, the Firm employs a "defense-in-depth" approach to security:
- Encryption: All Personal Data is encrypted both in transit (using TLS 1.2+) and at rest (using AES-256 standard).
- Access Control: Access to Personal Data is restricted on a "need-to-know" basis, managed via strict Role-Based Access Controls (RBAC) and Multi-Factor Authentication (MFA).
- Data Localization: Personal Data is stored on secure servers adhering to UAE data sovereignty requirements where applicable.
6. Data Sharing and Transfers
The Firm does not sell Personal Data. Data is only shared with:
- Service Providers: Third-party processors (e.g., eKYC providers, cloud hosts) who are contractually bound to equivalent data protection standards.
- Regulatory Authorities: VARA, Law Enforcement, and other competent authorities upon lawful request.
- Cross-Border Transfers: Transfers of data outside the UAE are only conducted to jurisdictions with an adequate level of protection or under standard contractual clauses (SCCs) ensuring safeguards equivalent to the UAE PDPL.
7. Data Subject Rights
Under the UAE PDPL, individuals have the following rights regarding their Personal Data:
- Right to Access: Request a copy of the Personal Data held by the Firm.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of data ("Right to be Forgotten"), subject to the Firm’s regulatory record-keeping obligations (e.g., 8-year retention for AML/VARA records).
- Right to Restriction: Request the limitation of processing in certain disputes.
8. Data Breach Notification
In the event of a Personal Data breach (accidental or unlawful destruction, loss, alteration, or unauthorized disclosure), the Firm adheres to strict reporting timelines:
- Internal Escalation: Any employee who suspects a breach must immediately report it to the DPO.
- VARA Notification: The DPO shall notify VARA within 24 hours of becoming aware of any incident affecting Personal Data.
- Regulator Notification: The UAE Data Office will be notified as required under the PDPL.
- Client Notification: Affected clients will be notified without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
9. Contact Information
For any inquiries regarding this Policy or to exercise data subject rights, please contact:
Data Protection Officer (DPO)
Name: Pratik Mohite
Email: pratik@arpdigital.io
Address: Al Furjan, Dubai, UAE