Privacy Policy
Abu Dhabi National Takaful Company (“ADNTC”, “we”, “us”, “our”) is committed to protecting your privacy.
Privacy and Protection of Personal Information:
At Abu Dhabi National Takaful Company (ADNTC), we respect your privacy and are committed to protecting your personal information. We only collect and use personal data when necessary – to provide our services, meet our legal and regulatory requirements, improve your experience, or for other legitimate business purposes.
We always ensure that we have a valid legal basis for collecting and using your personal information. When we process personal information on behalf of our customers or business partners, we ensure that they have the appropriate legal basis for sharing your information with us. We also make sure that you are informed about how your personal information will be collected, used, and protected.
Any personal information or health information that we collect or receive is processed in accordance with the applicable laws and regulations of the United Arab Emirates, including, where applicable:
- Federal Decree-Law No. 14 of 2024 concerning Modern Technology in Healthcare;
- Applicable regulations and standards issued by the Central Bank of the UAE;
- Applicable regulations and standards issued by Department of Health – Abu Dhabi; and
- Applicable regulations and standards issued by Dubai Health Authority; and
- Any other applicable laws governing the protection and processing of personal data.
Health information required for underwriting, policy administration, claims handling, reinsurance, fraud prevention, or compliance with legal and regulatory requirements is processed only where necessary, treated as confidential, and protected by appropriate technical and organizational safeguards.
Your personal information is used only for the purposes for which it was collected, or as otherwise permitted or required by law. Reasonable steps are taken to keep your information accurate, secure, and up to date, and you are encouraged to inform us if your personal information changes.
Protecting your personal information is a priority for us. We have appropriate technical and organizational security measures in place to safeguard your information against unauthorized access, disclosure, alteration, loss, or misuse. Access to personal information is limited to authorized employees and service providers who need it to do their jobs.
Principles of Data Processing:
We process personal information in line with the following principles:
- Lawfulness, Fairness, and Transparency – Personal information is processed in a lawful, fair, and transparent manner, and individuals are kept informed about how their data is being processed.
- Intended Use Only – Personal information is collected only for specific, explicit, and legitimate purposes, and is not used or processed for any other unrelated reasons.
- Data Minimization – Only the minimum amount of personal information required for the intended purpose is collected and processed.
- Accuracy – Reasonable steps are taken to keep personal information accurate, with any inaccuracies promptly corrected.
- Storage Limitation – Personal information is retained only for as long as necessary for the purpose it was collected, and in line with applicable legal and regulatory requirements.
- Integrity and Confidentiality – Appropriate technical and organizational measures are implemented to keep personal information secure, accurate, and confidential.
- Accountability – Responsibility is taken for complying with this policy and with all applicable privacy laws, with designated personnel overseeing and managing privacy matters.
Data Collection and Processing:
We only collect your personal information when necessary and with your informed consent. It is processed fairly, transparently, and strictly in line with the purpose it was collected for.
You have the right to be informed about how your data is used, including your right to access, correct, and request the erasure of your personal information.
Access to your personal information within ADNTC is limited to authorized personnel who require it to perform their job functions, based on the principle of least privilege.
Encryption and strong access controls are applied to protect your personal information, both in storage and during transmission, with regular security assessments and audits carried out to identify and address any vulnerabilities.
The data held is also reviewed regularly to ensure it remains relevant, accurate, and up to date.
To provide our insurance services or to comply with legal and regulatory obligations, we may share your personal information with reinsurers, healthcare providers, third-party administrators, loss adjusters, professional advisers, auditors, regulatory authorities, government entities, or other service providers, strictly on a need-to-know basis and subject to appropriate confidentiality and security measures.
If it becomes necessary to transfer your personal information outside the United Arab Emirates, we take reasonable steps to ensure that such transfers are carried out in accordance with applicable legal requirements and that appropriate safeguards are in place to protect your personal information.
We may use automated systems and technologies, where appropriate, to support underwriting, fraud prevention, sanctions screening, claims assessment, customer service, and other insurance-related processes. Such processing will always be carried out in accordance with applicable legal and regulatory requirements.
Use of Cookies:
A cookie is a small file placed on your device when you visit our website. Cookies help us recognize your browser, remember your preferences, and understand how our website is used.
We use the following types of cookies:
- Necessary/Essential Cookies – Session-based cookies required to provide core website functionality and to authenticate users securely. Without these, certain services on our website cannot be delivered.
- Cookies Policy/Notice Acceptance Cookies – Persistent cookies that record whether you have accepted our use of cookies on the website.
- Functionality Cookies – Persistent cookies that remember your preferences, such as login details or language settings, to give you a more personalized experience.
You can choose to accept or refuse cookies through your browser settings. Please note that refusing cookies may affect your ability to use certain features of our website.
Data Security Measures:
To protect your personal information from unauthorized access, loss, destruction, or alteration, we:
- Implement appropriate technical and organizational security measures
- Encrypt personal information during both transmission and storage
- Conduct regular security assessments and audits to identify and address vulnerabilities
- Ensures that all third-party vendors and contractors adhere to our security standards
Your Rights as a Data Subject:
You have the right to access, correct, erase, and restrict the processing of your personal information. Any requests you make regarding your personal information will be addressed promptly.
You also have the right to withdraw your consent at any time and to request the portability of your data.
Data Retention and Disposal:
We define retention periods for different categories of personal information based on legal requirements and business needs. Once the applicable retention period has expired, your personal information is securely disposed of.
Third-Party Relationships:
Any third-party vendors and partners who handle personal information on our behalf are selected based on their ability to meet ISO 27001 and other applicable regulatory requirements.
Our contracts with third parties clearly outline their responsibilities in relation to the protection of personal data.
Disclosure of Your Personal Data:
Your personal information may be disclosed under the following circumstances:
- Business Transactions – If ADNTC is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
- Law Enforcement – Disclosure of your personal information may be required by law or in response to valid requests from public authorities, such as a court or government agency, and/or reinsurers, healthcare providers, third-party administrators, loss adjusters, professional advisers and auditors.
- Other Legal Requirements – Your personal information may be disclosed where it is believed in good faith that such action is necessary to comply with a legal obligation, protect and defend ADNTC’s rights or property, prevent or investigate wrongdoing related to its services, protect the personal safety of users or the public, or protect against legal liability.
Data Breach Notification:
In the event of a data breach or potential security incident, we follow incident response plan to mitigate the risk, notify affected individuals and the relevant authorities as required, and take the necessary steps to prevent similar incidents in the future.
Protection of Records:
We take appropriate steps to ensure that important organizational records are protected from loss, destruction, falsification, unauthorized access, and unauthorized release. Records are stored in locations that are backed up on a regular basis.
To ensure this level of protection, we:
- Account for the possibility of deterioration of storage media to prevent loss of information
- Distinguish between different types of data and adheres to the legislative, regulatory, contractual, and business requirements applicable to each
- Ensure that, where electronic storage media is used, records remain accessible throughout the required retention period and are safeguarded against changes in technology
- Maintain a document retention policy that clearly defines and enforces the retention, storage, handling, and disposal of records, along with a retention schedule detailing the retention period for different types of records
- Implements appropriate controls to protect records and information from loss
Contact Us:
If you have any questions about above Privacy Policy or Data Subject Rights (DSR) Requests or how we handle your personal information, please contact us at:
We may update this Privacy Policy from time to time to reflect changes in applicable laws, regulations, technology, or our business practices. The latest version will always be available on our website.

