UAE Personal Data Protection Law (PDPL)
Federal Decree-Law No. 45 of 2021 governs the processing of personal data of individuals in the UAE, including by controllers and processors outside the country. It grants data subject rights comparable to the GDPR, requires breach notification, and mandates a data protection officer for high-risk or large-scale sensitive processing.
The PDPL is the federal baseline for personal data in the UAE. The most common mistake we see is a group applying it to an entity that actually sits inside DIFC or ADGM, where a separate data protection law applies instead.
Who Falls Under the PDPL
The law applies to the processing of personal data of data subjects inside the UAE, whether the controller or processor is located in the country or outside it. That extraterritorial reach means a group processing UAE customer data from Europe or Asia is in scope.
The financial free zones are carved out. Entities established in the Dubai International Financial Centre and the Abu Dhabi Global Market apply their own data protection laws and answer to their own commissioners, not to the federal regime. Determining which law binds each entity in a group is the first step of any UAE privacy programme, and it is where most of the avoidable errors happen.
What the Law Requires
Bereit, Ihre
Unternehmensinfrastruktur abzusichern?
Vereinbaren Sie ein technisches Briefing. Kein Sales-Pitch, nur Architekten und Ihr Team.
Processing needs a lawful basis. Where consent is relied on, it must be clear, specific, and withdrawable, and you must be able to demonstrate it was given.
Access, correction, erasure, restriction of processing, portability, and objection, including to automated decision-making. Requests need a documented process and a defined response time.
Controllers must notify the UAE Data Office, and affected individuals where the breach threatens their privacy or the security of their data, with a description of the breach and its likely effects.
Required where processing is high risk, involves systematic profiling or automated decisions, or handles sensitive data at scale. The appointment must be notified to the Data Office.
Permitted to jurisdictions with adequate protection, or on the basis of contractual safeguards, explicit consent, or the other conditions the law sets out.
Controllers and processors keep records of processing activities and must be able to demonstrate compliance rather than merely assert it.
Check the current status of the Executive Regulations before relying on a specific deadline. Several operational details, including the breach notification window, are set by regulations issued under the law rather than by the law itself, and public summaries of their status contradict each other.
UAE PDPL questions
Does the UAE PDPL apply to companies outside the UAE?
Yes, where they process the personal data of data subjects inside the UAE. The law reaches controllers and processors located outside the country, so a group handling UAE customer or employee data from another jurisdiction is in scope and needs to be able to demonstrate compliance.
How does the PDPL compare to the GDPR?
Structurally similar and operationally different. Both are consent and rights based, both require records, breach handling and accountability, and both reach beyond their borders. The differences that matter in practice are the supervisory authority, the specific transfer conditions, the thresholds for appointing a data protection officer, and the notification timelines. A mature GDPR programme is a strong starting point but not a substitute.
We are a DIFC entity. Does the federal PDPL apply to us?
No. Entities established in DIFC apply the DIFC Data Protection Law and answer to the DIFC Commissioner of Data Protection. ADGM works the same way with its own regime. A group with entities inside and outside the free zones ends up running one programme against two regimes, which is workable provided the mapping is explicit.
Do we need a data protection officer in the UAE?
Only where the processing warrants it: high-risk processing, systematic profiling or automated decision-making, or sensitive personal data at scale. Where the obligation applies, the officer’s contact details go to the UAE Data Office and must be available to data subjects. Many organisations appoint one regardless, because it gives customer assurance questionnaires a clear answer.
When can we transfer personal data out of the UAE?
To a jurisdiction the UAE treats as offering adequate protection, or on the basis of one of the alternative conditions the law provides, principally contractual safeguards binding the recipient, or the explicit consent of the data subject where that is genuinely free and informed. Two practical points: the adequacy position and the approved contractual wording are set through regulations issued under the law rather than by the law itself, so verify the current text, and an intra-group transfer is a transfer, which is the exemption groups most often assume incorrectly.
How quickly must we report a personal data breach?
Controllers notify the UAE Data Office, and affected individuals where the breach threatens their privacy or the security of their data, with a description of the breach and its likely effects. The specific notification window is fixed by the Executive Regulations rather than by the decree-law, and published summaries of that timing contradict each other, so confirm the current requirement before writing it into a playbook. Build the process to detect, assess and escalate within hours regardless, because the reporting clock is never the binding constraint in practice.
Does the PDPL cover employee data?
Yes. Employees are data subjects, and HR processing tends to be the highest-risk personal data an organisation holds: health information, disciplinary records, background screening, payroll and, increasingly, monitoring data. Consent is a weak basis in an employment relationship because it is rarely freely given, so employment processing usually needs to rest on contractual necessity or legal obligation instead.
What records of processing do we have to keep?
Enough to demonstrate compliance rather than assert it: what personal data you hold, why, on what lawful basis, who it is shared with, where it goes, how long it is kept, and what protects it. Controllers and processors both carry record-keeping duties. The record is also the artefact every other obligation depends on, since you cannot answer an access request, scope a breach, or assess a transfer against data you have not inventoried.
Working with the PDPL
Two of our entities sit in a financial free zone and were being run against the federal law. Fixing the scoping removed a set of obligations we had been budgeting for.
Our GDPR programme covered more than we expected. The work concentrated on transfer conditions, the notification path and the records, not on starting again.
Where We Do This Work
One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.
Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.
Control-by-control gap assessment against this framework, evidenced finding by finding. Information security audit in Dubai.