The UAE Personal Data Protection Law,
what it asks and what is still pending.
A plain guide to Federal Decree-Law No. 45 of 2021 for companies selling into the UAE: scope, the free zone carve-outs, the obligations already in the text, and the parts that wait on executive regulations. Not legal advice: check the official Arabic text and current status with UAE counsel.
Last updated Published by TryTrustableNot legal advice
The UAE PDPL is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, in force since 2 January 2022. It applies to processing of personal data of people living or doing business in the UAE, by controllers and processors inside or outside the country, but not to companies in free zones that have their own data protection law (such as DIFC and ADGM), or to government data. It requires consent unless an exception applies, a data protection officer for high-risk processing, breach notice to the UAE Data Office, and safeguards for transfers abroad. As of October 2026 we could not find published Executive Regulations or a penalties decision, so several details, including deadlines and fines, are not yet set.
What is the UAE PDPL?
The UAE Personal Data Protection Law (PDPL) is Federal Decree by Law No. 45 of 2021 Concerning the Protection of Personal Data. It is the UAE's first general federal data protection law, and it borrows much of its structure from the GDPR: controllers and processors, processing principles, data subject rights, impact assessments, a data protection officer and transfer rules. The regulator it refers to as "the Bureau" is the UAE Data Office, set up by Federal Decree-Law No. 44 of 2021.
Personal data means any data relating to an identified or identifiable natural person. Sensitive personal data covers data revealing family, ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, and health, genetic or sexual information.
Has the UAE PDPL come into force? Executive regulations and enforcement
The Decree-Law has been in force since 2 January 2022, but much of its operation depends on Executive Regulations that the Cabinet was to issue within six months. As of early October 2026 we could not find them, or the Cabinet decision on violations and penalties, published on the official UAE legislation portal.
| Item | Status (early October 2026) |
|---|---|
| Decree-Law No. 45 of 2021 | Issued 20 September 2021, published in the Official Gazette on 26 September 2021, in force 2 January 2022 |
| Executive Regulations (Article 28) | Due within six months of promulgation. Not found on the UAE legislation portal; the portal still lists the law's last update as 20 September 2021 |
| Grace period to comply (Article 29) | Six months from the date the Executive Regulations are issued, extendable once by the Cabinet. The clock has not visibly started |
| Violations and penalties (Article 26) | To be set by a Cabinet decision. We could not find one published |
| UAE Data Office | Established by Federal Decree-Law No. 44 of 2021 as the federal data regulator |
We checked uaelegislation.gov.ae and u.ae. If you find a published regulation or decision we missed, treat it as current.
In practice: the obligations in the Decree-Law are law, but the Article 29 window to regularise runs from the regulations, breach deadlines are left to them, and there are no published fine amounts. Build to the text now; the window will be short once the regulations appear.
Who does the PDPL apply to? Scope and free zone carve-outs
Article 2 sets the scope. In practice:
| Situation | Which law |
|---|---|
| Company on the UAE mainland (for example a Dubai or Abu Dhabi DED licence) | Federal PDPL |
| Company outside the UAE processing personal data of people in the UAE | Federal PDPL (Article 2(1)(c)) |
| Company in the DIFC | DIFC Data Protection Law No. 5 of 2020, not the PDPL |
| Company in ADGM | ADGM Data Protection Regulations 2021, not the PDPL |
| Company in another free zone | The PDPL, unless that free zone has its own data protection legislation |
| Health data or banking and credit data covered by their own legislation | That sector legislation (for example Federal Law No. 2 of 2019 on ICT in health fields), outside the PDPL |
| Federal and local government entities, government data | Outside the PDPL |
Article 2 of the Decree-Law. Free zone status turns on where the entity is established and licensed.
Article 3 also lets the Data Office exempt establishments that do not process a large volume of personal data from some or all requirements, under criteria in the Executive Regulations. For DIFC and ADGM, see our guide to DIFC and ADGM data protection.
Lawful processing and consent
The PDPL starts from a prohibition: personal data may not be processed without the data subject's consent (Article 4), unless an exception applies. The exceptions include performing a contract with the data subject, complying with other UAE laws, employment and social security obligations, legal claims, public interest, public health, preventive and occupational medicine, archiving and research, protecting the data subject's interests, and data the data subject has made public. Unlike the GDPR there is no general "legitimate interests" basis.
Where you rely on consent, Article 6 requires that you can prove it, that it is clear, simple, unambiguous and easily accessible, and that the data subject can withdraw it easily at any time. Article 5 adds the familiar principles: fairness and transparency, purpose limitation, data minimisation, accuracy, security and storage limitation.
Data subject rights under the PDPL
| Right | Article |
|---|---|
| Information about processing, including automated decisions and who data is shared with | 13 |
| Receive data and have it transferred to another controller (portability) | 14 |
| Correction, and erasure in the cases the law sets out | 15 |
| Restriction of processing | 16 |
| Object to and stop processing, including for direct marketing and profiling for it | 17 |
| Object to decisions based on automated processing, and ask for human review | 18 |
| Clear ways to contact the controller to exercise these rights | 19 |
Each right has exceptions in the text. Requests to the controller are free of charge under Article 13.
When do you need a data protection officer in the UAE?
Article 10 requires controllers and processors to appoint a DPO with sufficient skills and knowledge where processing would cause a high level of risk because of new technologies or the volume of data, involves a systematic and comprehensive assessment of sensitive personal data including profiling and automated processing, or involves a large volume of sensitive personal data. The DPO may be an employee or an appointed provider, and may be inside or outside the UAE. You must notify the Data Office of the DPO's contact details. The Executive Regulations are meant to define the technologies and volume criteria. Our DPO guide covers the role in more depth.
Breach notification under the UAE PDPL
Under Article 9, once a controller becomes aware of a breach that would prejudice the privacy, confidentiality and security of personal data, it must notify the Data Office, and must notify affected data subjects where the breach would prejudice their privacy, in both cases within the period and following the procedure set by the Executive Regulations. A processor must tell the controller as soon as it becomes aware. The notice to the Data Office must describe the breach, its causes and approximate number of records, give the DPO's details, set out the likely effects and the corrective measures, and attach supporting documents. Until a deadline is published, build a process that can report within days, not weeks.
Cross-border data transfers from the UAE
Article 22 allows transfers to a country with data protection legislation covering the key protections and a regulator able to act, or to a country the UAE has a data protection agreement with, in cases approved by the Data Office. Where that level of protection is not available, Article 23 allows transfers under a contract that binds the recipient to the PDPL's requirements, with the data subject's explicit consent (if it does not conflict with UAE public or security interests), to perform a contract with or in the interest of the data subject, for legal claims, for international judicial cooperation, or to protect the public interest. The Executive Regulations are to set the detailed conditions. In practice, map every vendor that receives UAE personal data, record its country, and put a transfer clause in the contract; see standard contractual clauses and vendor risk management.
Other controller duties: records, DPIA and security
- Records of processing (Articles 7 and 8): controllers and processors each keep a record covering the parties, categories of data, who has access, retention, cross-border movement and security measures, and give it to the Data Office on request.
- Data protection impact assessment (Article 21): before processing that uses new technologies posing a high risk, including systematic profiling with legal or serious effects and large volumes of sensitive data. Our DPIA guide walks through the method.
- Security (Article 20): measures suited to the risk, in line with international best practice, including encryption and pseudonymisation, resilience, timely restoration and regular testing.
- Processors (Article 8): act only on the controller's documented instructions, delete data at the end of the processing period, and be able to prove compliance.
How TryTrustable helps with the UAE PDPL
The UAE PDPL is one of the frameworks modelled in the platform. Its requirements are mapped to controls in a shared library, so work done for GDPR or ISO 27701 counts toward it, and readiness comes from control results.
| PDPL requirement | What TryTrustable does |
|---|---|
| Provable consent and easy withdrawal (Article 6) | A consent banner that records each choice in a tamper-evident ledger against the notice version shown, and relays withdrawals to your processors with delivery logged |
| Rights requests (Articles 13 to 19) | A rights-request queue with a deadline on each request and a public intake endpoint your own form can post to |
| Processor and records duties (Articles 7 and 8) | Vendor and processor registers with contract status, data access and destination country for each recipient |
| Transfers (Articles 22 and 23) | Each processor's country checked against the destinations you restrict |
| DPIA (Article 21) | DPIA as a control in the shared library, a free DPIA guide and template, and the risks it finds kept in the risk register |
| Security and breach notice (Articles 9 and 20) | Security controls with evidence from GitHub, AWS and GCP, and incident tracking from detection to post-mortem |
The UAE PDPL is modelled as a framework, mapped to the same controls as GDPR, SOC 2 and ISO 27001. TryTrustable hosts in Google Cloud Mumbai today (we are expanding to Singapore, the US and the EU), so using it is itself a transfer outside the UAE to cover under Article 23.
The things people ask us
Is the UAE PDPL in force?
Yes, the Decree-Law has been in force since 2 January 2022. As of October 2026 we could not find its Executive Regulations or the Cabinet decision on penalties, and the six-month grace period in Article 29 runs from when the regulations are issued.
Does the UAE PDPL apply to companies in DIFC and ADGM?
No. Article 2 excludes companies in free zones that have their own data protection legislation. DIFC has the Data Protection Law No. 5 of 2020 and ADGM has the Data Protection Regulations 2021.
Does the UAE PDPL apply to foreign companies?
Yes. It covers controllers and processors outside the UAE that process personal data of data subjects in the UAE.
What are the fines under the UAE PDPL?
The Decree-Law leaves violations and administrative penalties to a Cabinet decision under Article 26. We could not find that decision published as of October 2026, so there are no official fine amounts to quote.
Is a DPO mandatory in the UAE?
Only in the cases in Article 10: high-risk processing from new technology or data volume, systematic assessment of sensitive data including profiling, or large volumes of sensitive data. The DPO can be based inside or outside the UAE.
What is the UAE Data Office?
The federal data regulator set up by Federal Decree-Law No. 44 of 2021. The PDPL calls it the Bureau and gives it powers to receive breach notices and complaints, approve transfers and impose penalties.
Does the UAE PDPL require cookie consent?
There is no cookie-specific rule, but tracking data linked to a person is personal data and the PDPL's default basis is consent, so most UAE websites that track visitors ask for it. Our free cookie scanner shows what your site sets.
Map the UAE PDPL to controls you already run.
Thirty minutes on the PDPL alongside GDPR, ISO 27001 or the DIFC and ADGM regimes, with your consent and rights-request records in one place.