UAE Personal Data Protection Law (PDPL)
Federal Decree-Law No. 45 of 2021 governs the processing of personal data of individuals in the UAE, including by controllers and processors outside the country. It grants data subject rights comparable to the GDPR, requires breach notification, and mandates a data protection officer for high-risk or large-scale sensitive processing.
The PDPL is the federal baseline for personal data in the UAE. The most common mistake we see is a group applying it to an entity that actually sits inside DIFC or ADGM, where a separate data protection law applies instead.
Who Falls Under the PDPL
The law applies to the processing of personal data of data subjects inside the UAE, whether the controller or processor is located in the country or outside it. That extraterritorial reach means a group processing UAE customer data from Europe or Asia is in scope.
The financial free zones are carved out. Entities established in the Dubai International Financial Centre and the Abu Dhabi Global Market apply their own data protection laws and answer to their own commissioners, not to the federal regime. Determining which law binds each entity in a group is the first step of any UAE privacy programme, and it is where most of the avoidable errors happen.
What the Law Requires
enterprise infrastructure?
Schedule a technical briefing. No sales pitch, just architects and your team.
Processing needs a lawful basis. Where consent is relied on, it must be clear, specific, and withdrawable, and you must be able to demonstrate it was given.
Access, correction, erasure, restriction of processing, portability, and objection, including to automated decision-making. Requests need a documented process and a defined response time.
Controllers must notify the UAE Data Office, and affected individuals where the breach threatens their privacy or the security of their data, with a description of the breach and its likely effects.
Required where processing is high risk, involves systematic profiling or automated decisions, or handles sensitive data at scale. The appointment must be notified to the Data Office.
Permitted to jurisdictions with adequate protection, or on the basis of contractual safeguards, explicit consent, or the other conditions the law sets out.
Controllers and processors keep records of processing activities and must be able to demonstrate compliance rather than merely assert it.
Check the current status of the Executive Regulations before relying on a specific deadline. Several operational details, including the breach notification window, are set by regulations issued under the law rather than by the law itself, and public summaries of their status contradict each other.
What Is Still Pending, and What Is Not
Federal Decree-Law No. 45 of 2021 was issued with a number of its operational details left to Executive Regulations to be issued by the Cabinet on the UAE Data Office's recommendation. As at the review date at the foot of this page those regulations were still pending publication in force, and dates announced for them have moved more than once. We do not restate a date here for that reason: a page that names one is wrong the moment it slips, and this is precisely the detail readers arrive checking.
The practical question is not when they land. It is which obligations are already binding and which are genuinely waiting, because the first group is most of the work and none of it depends on the second.
Lawful basis for every processing activity, data subject rights with a documented response process, records of processing activities, security measures proportionate to risk, processor contracts, and the accountability principle that requires you to demonstrate all of it rather than assert it. None of this changes when the regulations arrive.
Procedural specifics: the exact breach notification window and format, the mechanics of registering a data protection officer, the detailed conditions and instruments for cross-border transfer, and the shape of the complaint and grievance process. Build the capability to notify quickly and to evidence a transfer basis; do not hard-code a deadline you cannot yet cite.
DIFC and ADGM entities apply their own data protection laws under their own commissioners, both of which are in force and have their own guidance. A group with entities on both sides runs one control set with a view per regime, not two programmes.
Health, finance and telecommunications carry sector obligations on data handling that are already in force and in several cases stricter than the federal baseline. For entities in those sectors the Executive Regulations are rarely the binding constraint.
A programme that waits for the regulations before starting arrives late holding nothing. A programme that builds the accountability layer first, the records of processing, the rights process, the transfer register and the breach runbook, absorbs whatever the regulations specify as a configuration change rather than as a rebuild. The one thing worth keeping deliberately loose is the breach notification timing, since that is the number most likely to be set narrower than the assumption a programme was built on.
UAE PDPL questions
Does the UAE PDPL apply to companies outside the UAE?
Yes, where they process the personal data of data subjects inside the UAE. The law reaches controllers and processors located outside the country, so a group handling UAE customer or employee data from another jurisdiction is in scope and needs to be able to demonstrate compliance.
How does the PDPL compare to the GDPR?
Structurally similar and operationally different. Both are consent and rights based, both require records, breach handling and accountability, and both reach beyond their borders. The differences that matter in practice are the supervisory authority, the specific transfer conditions, the thresholds for appointing a data protection officer, and the notification timelines. A mature GDPR programme is a strong starting point but not a substitute.
We are a DIFC entity. Does the federal PDPL apply to us?
No. Entities established in DIFC apply the DIFC Data Protection Law and answer to the DIFC Commissioner of Data Protection. ADGM works the same way with its own regime. A group with entities inside and outside the free zones ends up running one programme against two regimes, which is workable provided the mapping is explicit.
Do we need a data protection officer in the UAE?
Only where the processing warrants it: high-risk processing, systematic profiling or automated decision-making, or sensitive personal data at scale. Where the obligation applies, the officer’s contact details go to the UAE Data Office and must be available to data subjects. Many organisations appoint one regardless, because it gives customer assurance questionnaires a clear answer.
When can we transfer personal data out of the UAE?
To a jurisdiction the UAE treats as offering adequate protection, or on the basis of one of the alternative conditions the law provides, principally contractual safeguards binding the recipient, or the explicit consent of the data subject where that is genuinely free and informed. Two practical points: the adequacy position and the approved contractual wording are set through regulations issued under the law rather than by the law itself, so verify the current text, and an intra-group transfer is a transfer, which is the exemption groups most often assume incorrectly.
How quickly must we report a personal data breach?
Controllers notify the UAE Data Office, and affected individuals where the breach threatens their privacy or the security of their data, with a description of the breach and its likely effects. The specific notification window is fixed by the Executive Regulations rather than by the decree-law, and published summaries of that timing contradict each other, so confirm the current requirement before writing it into a playbook. Build the process to detect, assess and escalate within hours regardless, because the reporting clock is never the binding constraint in practice.
Does the PDPL cover employee data?
Yes. Employees are data subjects, and HR processing tends to be the highest-risk personal data an organisation holds: health information, disciplinary records, background screening, payroll and, increasingly, monitoring data. Consent is a weak basis in an employment relationship because it is rarely freely given, so employment processing usually needs to rest on contractual necessity or legal obligation instead.
What is the status of the PDPL Executive Regulations?
As at the review date shown at the foot of this page they were still pending, and announced timelines for them have slipped more than once. We deliberately do not print a date here, because a page that names one becomes wrong silently and this is the exact detail people arrive checking. Verify with the UAE Data Office before you rely on it.
What the delay does not excuse: lawful basis, data subject rights, records of processing, processor contracts and proportionate security are in force under the Decree-Law itself. What is genuinely waiting is procedural, principally the precise breach notification window and format, DPO registration mechanics, and the detailed instruments for cross-border transfer. Build the accountability layer now and treat the pending items as configuration, not as a reason to wait.
What records of processing do we have to keep?
Enough to demonstrate compliance rather than assert it: what personal data you hold, why, on what lawful basis, who it is shared with, where it goes, how long it is kept, and what protects it. Controllers and processors both carry record-keeping duties. The record is also the artefact every other obligation depends on, since you cannot answer an access request, scope a breach, or assess a transfer against data you have not inventoried.
Where We Do This Work
One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.
Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.
Control-by-control gap assessment against this framework, evidenced finding by finding. Information security assessment in Dubai.