Privacy Challenges of Digital Transformation in Critical Government Organizations Handling Sensitive Data in the United Arab Emirates: A Systematic Literature Review and Documentary Analysis
Abstract
Purpose: The purpose of this study was to understand the privacy concerns surrounding the digital transformation of critical government organizations handling sensitive data in the United Arab Emirates (UAE). It examined privacy risks arising from technologies, organizational practices, legislation, and third-party involvement during public-sector digital transformation. Methodology: This study adopted a qualitative systematic literature review and documentary analysis. Scholarly sources were retrieved from Scopus, ScienceDirect and Emerald Insight journals by applying specific search terms for digital transformation, privacy, data protection, security, governance and regulation. The literature search was carried out in English-language sources from 2022 to 2026. Grey literature was collected from official UAE government sources, UAE regulatory and legislative platforms, Digital Dubai sources, and recognized international organizations. A final evidence base of 20 scholarly sources and 12 grey-literature documents was collected. Findings: The findings demonstrate that privacy risks do not stem from technology alone. They are produced as a result of interactions among digital systems, organizational routines, interpretation of regulations, and external providers. Issues include linkage of data, re-identification, loss of anonymity, opaque artificial intelligence (AI) inferences, excessive access privileges, poor consent models, fragmented governance, cloud vulnerabilities, third-party processing, and reduced public trust. The evidence also reveals that technical measures such as encryption, anonymization, access control, differential privacy, homomorphic encryption, and federated learning are significant but are not enough on their own to ensure privacy. Unique Contribution to Theory, Practice and Policy: The study demonstrates that risks to privacy are a result of interactions between technologies, people, institutions, rules, and external actors, and thus contributes to Socio-Technical Systems Theory. It also demonstrates the extension of Privacy by Design, highlighting that purely technical measures to store and manage embedded privacy cannot be sufficient without organizational and regulatory support. The four-layer privacy-governance framework it offers is practical and includes technical safeguards, organizational governance, regulatory accountability, and third-party oversight. For policy, it calls for stronger coherence across UAE digital-government, AI, cloud, cybersecurity, and data-protection policies.