The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, has been in force since 2 January 2022. It applies to any business processing the personal data of people in the UAE, including businesses based outside the country, and it requires consent as the default basis for processing, a documented data record, breach notification, and a Data Protection Officer in three defined situations.

There is a complication that most guidance on this law skips over, and it changes what you should actually do. Article 28 required the Cabinet to issue Executive Regulations within six months of the decree-law being promulgated, and Article 29 gives controllers and processors six months from the issue of those regulations to bring themselves into compliance. At the time of writing we could not locate the Executive Regulations on any official UAE source, and the UAE Legislation portal’s entry for the decree-law lists no related legislation. This guide sets out what the law itself requires, and is explicit about which obligations are complete on the face of the statute and which are waiting on regulations that we could not confirm exist.

Who the PDPL Applies To

Article 2 extends the law to three groups: data subjects residing or having a place of business in the UAE, controllers and processors resident in the UAE processing data of people inside or outside the country, and controllers and processors resident outside the UAE processing data of people inside the country. The last of those makes the law extraterritorial.

A company with no UAE presence that sells to UAE customers and holds their names, addresses and payment details is within scope. There is no revenue threshold and no establishment test.

The seven exclusions, and why they matter more than the inclusions

Article 2(2) carves out a great deal, and for a large share of UAE businesses one of these carve-outs decides the answer.

Excluded What that means in practice
Government data Data held as government data is outside the federal law entirely
Government entities that control or process personal data Federal and local government bodies are excluded as processors and controllers in their own right
Personal data held by security and judicial authorities Police, prosecution and court holdings are outside scope
A data subject processing their own data for personal purposes The household exemption
Personal health data with its own protective legislation Clinics, hospitals and health insurers are governed by Federal Law No. 2 of 2019 on ICT in health fields instead
Personal banking and credit data with its own protective legislation Banks and credit bureaux fall under the Central Bank framework and Federal Law No. 6 of 2010 on Credit Information
Companies in free zones with their own special data protection legislation DIFC and ADGM entities apply their own regimes, not the federal law

That free zone exclusion is narrower than it sounds. It applies to free zones that have special legislation regarding personal data protection, which in practice means the financial free zones. A company in a commercial free zone with no data protection law of its own is inside the federal regime. If you are weighing jurisdictions, the data regime belongs in the same comparison as everything else in the DIFC and ADGM financial free zone comparison.

The exemption power in Article 3

The UAE Data Office may exempt establishments that do not process a large volume of personal data from part or all of the requirements. The standards and controls for that exemption are left to the Executive Regulations, so the small-business relief exists in principle and has no published criteria. Do not plan around it.

Article 4 opens with a flat prohibition: it is prohibited to process personal data without the consent of its owner. Ten exceptions follow, and two of them cover most ordinary commercial processing.

The exceptions are: protecting public interest; data the subject has themselves made public; legal claims, defence of rights, or judicial and security procedures; occupational or preventive medicine including fitness to work, diagnosis, care, treatment and health insurance administration; public health protection; archival, scientific, historical and statistical purposes; protecting the data subject’s interests; carrying out obligations and rights in employment, social security and social protection law; performing a contract to which the data subject is a party, or taking steps at their request to conclude, amend or terminate one; and fulfilling specific obligations imposed on the controller by other UAE laws.

Those last two do the heavy lifting. Processing a customer’s address to deliver what they bought sits under the contract exception. Retaining identification documents because AML law requires it sits under the legal obligation exception. Neither needs a consent checkbox, and treating them as if they do creates a worse problem: if the lawful basis is consent, the subject can withdraw it, and Article 6(2) says they may do so at any time.

What valid consent requires

Article 6(1) sets three conditions. The controller must be able to prove consent where processing relies on it. The consent must be clear, simple, unambiguous and easily accessible, in writing or electronically. And it must include the data subject’s right to withdraw it easily. Withdrawal does not retroactively invalidate processing already carried out.

The Eight Processing Controls

Article 5 lists the principles every processing operation must satisfy: fairness, transparency and lawfulness; a specific and clear purpose; data minimization; accuracy; correction or deletion of incorrect data; security; and deletion once the purpose is exhausted, unless the data is anonymized.

Two of these have sharp practical edges. The purpose rule allows later processing only where the new purpose is the same, similar or close to the original, which is narrower than a general legitimate interests test. And the storage rule requires deletion once the purpose is exhausted, with anonymization offered as the alternative to deletion rather than as a separate retention basis.

That last principle collides with retention duties elsewhere. UAE anti-money laundering law requires five-year retention of customer due diligence records, and corporate tax law imposes its own retention periods. Where another law compels retention, Article 4(10) supplies the basis for continuing to hold the data. What it does not do is licence you to keep everything else in the same file.

What Controllers and Processors Must Actually Have in Place

Article 7 imposes five concrete obligations on controllers, and the most operationally demanding is a special record of personal data with nine specified contents, producible to the UAE Data Office on request.

The record must contain the controller’s and Data Protection Officer’s details, a description of the categories of personal data, details of the persons authorized to access it, processing times, limitations and scope, the mechanism for erasing, modifying or processing the data, the purpose of processing, any data relating to cross-border movement, and the technical and organizational information security measures.

Article 8 imposes eleven obligations on processors, including processing only on the controller’s instructions under a contract specifying scope, subject, purpose, nature and data types; erasing data at the end of the processing period or handing it to the controller; maintaining an equivalent record of its own; and proving compliance to the controller or the Bureau on request. Article 8(10) adds a rule worth writing into contracts: where several processors are involved and no written agreement clearly defines their roles, they are jointly responsible for the obligations under the law.

When You Must Appoint a Data Protection Officer

Article 10 requires a Data Protection Officer in three situations: where processing would cause high-level risk to confidentiality and privacy through new technologies or the volume of data, where it involves systematic and comprehensive assessment of sensitive personal data including profiling and automated processing, or where it is carried out on a large volume of sensitive personal data.

Three features of the UAE approach differ from what companies coming from other regimes expect.

  • The obligation falls on both controllers and processors, not only controllers
  • The officer may be an employee or an authorized external appointee, and may be based inside or outside the UAE, so an outsourced or group DPO is expressly permitted
  • The contact details must be notified to the UAE Data Office

Article 12(1)(c) then protects the role directly: the controller and processor may not terminate the DPO’s services or impose any disciplinary penalty for a reason related to performing those duties, and may not assign duties that conflict with them. Article 12(2) lets data subjects communicate with the DPO directly.

Article 10(4) leaves the definitions of “new technologies” and “large volume” to the Executive Regulations. Until those exist, the trigger is a judgment call, and the sensible approach is to document the reasoning for whichever conclusion you reach.

The Seven Data Subject Rights

The law gives individuals rights to information, portability, correction and erasure, restriction of processing, objection to processing, objection to automated decisions, and a clear channel to contact the controller. Each right carries its own exceptions.

Right Article Key limit
Receive information about processing, free of charge 13 May be refused if excessively repetitive, if it conflicts with judicial procedures or investigations, if it would harm information security efforts, or if it affects third parties’ privacy
Receive data in an orderly, machine-readable form and have it transferred to another controller 14 Only where processing is based on consent or contractual necessity and is carried out by automated means; transfer only where technically feasible
Correction and erasure 15 No erasure where the request concerns public health data in private facilities, affects investigations or the claiming and defence of rights, or contradicts other legislation binding the controller
Restrict and stop processing 16 Controller may still proceed where processing is limited to storage, is needed for claims, rights or judicial proceedings, protects third parties’ rights, or protects the public interest
Object to processing 17 Available for direct marketing including related profiling, for statistical surveys unless the public interest requires them, and where processing breaches Article 5
Object to automated decisions and profiling 18 Not available where the automated processing is agreed in the contract, required by other legislation, or consented to in advance
A clear and appropriate way to contact the controller 19 No stated exception

The direct marketing right is the one customers use

Article 17(1) gives an unqualified right to object to processing for direct marketing, including profiling connected to it. There is no balancing test and no exception attached to that limb. In practice this means an opt-out mechanism on marketing communications is not optional, and it is the request type a consumer-facing UAE business should expect most often.

The human review requirement

Article 18(4) states plainly that the controller shall include the human element in reviewing automated processing decisions at the data subject’s request. Even where an objection is barred because the automated processing was contractually agreed, Article 18(3) still requires appropriate protective measures and prohibits prejudice to the subject’s rights. Anyone running automated credit, pricing or screening decisions needs a documented human review path. That applies to tenant screening as much as to lending, which is why a landlord running a credit check on a prospective tenant needs a consent trail rather than an assumption.

Breach Notification and Security

Article 9 requires the controller to notify the UAE Data Office when it becomes aware of a breach that would prejudice the privacy, confidentiality or security of personal data, and to notify affected individuals where the breach would prejudice their data. The notification period and procedure are left to the Executive Regulations.

The notification must include a description of the breach’s nature, form, causes, approximate number and records; the appointed DPO’s details; the potential and expected effects; the corrective measures taken or proposed; documentation of the violation and the corrective actions; and anything else the Bureau requires. Article 9(3) puts the processor in the chain: it notifies the controller as soon as it becomes aware, and the controller notifies the Bureau.

Because there is no published deadline, the practical standard is the statutory language itself. The duty arises “at the time it becomes aware,” which is closer to immediate than to a fixed window.

Article 20 requires technical and organizational measures meeting the highest standard of information security appropriate to the risk, and names four specifically: encryption and pseudonymization, measures ensuring continuous confidentiality, safety, accuracy and flexibility of processing systems, measures ensuring timely retrieval and access after an actual or technical failure, and measures ensuring testing and evaluation of the effectiveness of those measures. Encryption is named in the statute, not left to guidance.

When you must run a data protection impact assessment

Article 21 requires an assessment before processing where modern technologies pose a high risk, and mandatory in two cases: systematic and comprehensive assessment of personal aspects using automated processing including profiling, with legal consequences or serious impact; and processing on a large volume of sensitive personal data. The assessment has four minimum contents, must be prepared in coordination with the DPO, may cover a group of similar operations in one document, and must be reviewed regularly where risk levels change.

Sending Data Outside the UAE

Articles 22 and 23 create two routes. Where the destination has adequate protection, transfer is permitted with the Bureau’s approval. Where it does not, transfer is still permitted through a contract imposing the decree-law’s protections, or on one of five other grounds including explicit consent.

Article 22 treats a destination as adequate where it has data protection legislation covering the significant provisions, controls and rules, along with a judicial or regulatory authority able to impose appropriate measures on the controller or processor, or where the UAE has joined a bilateral or multilateral data protection agreement with that country.

Article 23 then lists the fallbacks: a contract or agreement obliging companies in the destination country to adopt the measures, controls and requirements set out in the decree-law, plus provisions requiring appropriate measures imposed by a judicial or regulatory authority there; explicit consent from the data subject, provided the transfer does not contradict the public or security interest of the State; necessity for obligations and rights before judicial entities; necessity to sign or implement a contract between the controller and the data subject, or between the controller and a third party in the data subject’s interest; necessity for international judicial cooperation; and necessity to protect the public interest.

The controls governing all of this sit in the Executive Regulations under Article 23(2). Since those were not locatable, the honest position is that the contractual route in Article 23(1)(a) is the one drafted to work without further rules, because its content is defined by reference to the decree-law itself.

Complaints, Penalties and the Regulations Gap

Data subjects complain to the UAE Data Office under Article 24. Any stakeholder may file a written grievance against a Bureau decision within 30 days, and the Bureau must decide within 30 days. Administrative penalties themselves are left to a Cabinet decision under Article 26 that we could not locate.

Article 26 does not set any fine. It says the Council of Ministers, on the General Director’s proposal, “shall issue a decision to limit the actions which constitute a violation of this Decree by Law and its Executive Regulations, including administrative penalties to be imposed.” The schedule of violations and fines is therefore a separate instrument, not part of the decree-law.

Article 25 adds a procedural bar that mirrors several other UAE regimes: no decision of the Bureau may be challenged before a grievance has first been submitted against it.

What we could and could not verify

Article 28 required the Executive Regulations within six months of the decree-law’s promulgation on 20 September 2021. Article 29 then gives controllers and processors up to six months from the issue of those regulations to regularize their position, extendable by the Cabinet for one further period.

We could not find the Executive Regulations on the UAE Legislation portal, whose entry for Federal Decree-Law No. 45 of 2021 shows a last update of 20 September 2021 and lists no related legislation, nor on the UAE Government portal’s data protection page, which was last updated in December 2025, describes the Data Office in the future tense and links only to the decree-law itself. Several commercial compliance sites cite specific Cabinet decision numbers as the implementing regulations; we could not verify any of those citations against an official source and are not repeating them.

Two consequences follow, and they point in opposite directions. There is no published penalty schedule and the Article 29 transition period has not demonstrably started. But the decree-law has been in force since 2 January 2022, and the obligations that are complete on its face, including the lawful basis rules, the processing controls, the data subject rights, the security duty and the record, do not depend on regulations to be legally binding.

What to Do Now

The practical priority is the work that is unambiguous today and would be needed under any version of the regulations.

  • Build the Article 7(4) record of personal data with all nine contents. Nothing about it is contingent on further rules
  • Identify a lawful basis for each processing activity and stop treating consent as the universal answer where contract or legal obligation applies
  • Fix the marketing opt-out, because Article 17(1) is unqualified
  • Put a written contract in place with every processor that defines scope, subject, purpose, nature, data types and subject categories, and clarifies roles where several processors are involved
  • Decide and document whether you need a DPO, and notify the Bureau of the contact details if you appoint one
  • Write a breach response procedure that can produce the six items Article 9 requires quickly, since no notification deadline is published
  • Map cross-border flows and, where the destination is not clearly adequate, use the Article 23(1)(a) contractual route

None of this is unusual for a business already handling regulated data. If you are setting up a company in Dubai that will hold customer data, the record and the processor contracts are cheaper to build at the start than to retrofit.

Other UAE Laws That Touch Personal Data

The PDPL is not the whole picture, and the exclusions in Article 2 push several sectors into other regimes.

  • Federal Law No. 15 of 2020 on Consumer Protection protects consumer data and prohibits suppliers from using it for marketing, which runs alongside the PDPL for consumer-facing businesses and underpins the consumer rights framework on returns and refunds
  • Federal Law No. 2 of 2019 governs the use of information and communication technology in health fields, including in the free zones
  • Federal Law No. 6 of 2010 on Credit Information governs credit data, which is why an AECB credit report sits under its own regime rather than the PDPL
  • Federal Decree-Law No. 34 of 2021 on Combatting Rumours and Cybercrimes criminalizes misuse of online technologies and is the instrument behind most UAE enforcement around online content and social media offences
  • Article 31 of the UAE Constitution guarantees freedom and confidentiality of communication by post, telegraph and other means
  • DIFC Law No. 5 of 2020 and the ADGM Data Protection Regulations operate independently inside those financial free zones

Frequently Asked Questions

Does the UAE PDPL apply to my company if it is registered abroad?

Yes, if you process the personal data of people inside the UAE. Article 2(1)(c) applies the decree-law to any controller or processor residing outside the State that carries out processing activities on the personal data of data subjects inside the State. There is no revenue threshold and no requirement to have a UAE establishment.

Do free zone companies have to comply with the UAE PDPL?

It depends on the free zone. Article 2(2)(g) excludes companies and establishments located in free zones that have special legislation regarding personal data protection, which in practice means DIFC and ADGM, each of which has its own data protection law. A company in a commercial free zone with no data protection legislation of its own is inside the federal regime.

Do I always need consent to process personal data in the UAE?

No. Article 4 prohibits processing without consent but then lists ten exceptions. The two that cover most ordinary business processing are performing a contract to which the data subject is a party, or taking steps at their request to conclude, amend or terminate one, and fulfilling specific obligations imposed on the controller by other UAE laws. Relying on consent where one of these applies is a mistake, because consent can be withdrawn at any time.

When does a UAE business need a Data Protection Officer?

In three cases under Article 10: where processing would cause a high-level risk to confidentiality and privacy because of new technologies or the volume of data, where it involves systematic and comprehensive assessment of sensitive personal data including profiling and automated processing, or where it is carried out on a large volume of sensitive personal data. The obligation applies to processors as well as controllers, and the officer may sit inside or outside the UAE.

How quickly must a data breach be reported in the UAE?

Article 9(1) requires the controller to notify the UAE Data Office at the time it becomes aware of a breach that would prejudice the privacy, confidentiality or security of the data, but the specific period and procedure are left to the Executive Regulations. Since no published deadline could be located, the operative standard is the statutory wording, which is closer to immediate notification than to a fixed number of days.

What are the fines for breaching the UAE PDPL?

The decree-law sets none. Article 26 leaves the list of violations and the administrative penalties to a Cabinet decision issued on the proposal of the UAE Data Office’s General Director. We could not locate that decision on any official source, so no fine figure is quoted here. Treat any specific penalty amount you see elsewhere as unverified until it appears on an official UAE source.

Have the UAE PDPL Executive Regulations been issued?

We could not confirm that they have. Article 28 required them within six months of the decree-law’s promulgation on 20 September 2021, but the UAE Legislation portal’s entry for the law shows a last update of 20 September 2021 and lists no related legislation, and the UAE Government portal’s data protection page makes no reference to them. Several commercial compliance sites cite Cabinet decision numbers that we could not verify against any official source.

Can I transfer personal data out of the UAE?

Yes, by two routes. Article 22 permits transfer, subject to Bureau approval, where the destination has adequate data protection legislation and a judicial or regulatory authority able to enforce it, or where the UAE has a data protection agreement with that country. Article 23 permits transfer to countries without such laws under a contract imposing the decree-law’s measures, or on explicit consent, judicial necessity, contractual necessity, international judicial cooperation, or public interest grounds.

Does the PDPL give a right to be forgotten?

A limited one. Article 15(2) gives a right to request erasure where the data is no longer necessary for its purpose, where consent has been withdrawn, where the subject objects and the controller has no legitimate reason to continue, or where processing breached the law. Article 15(3) then blocks erasure where the request concerns public health data in private facilities, affects investigations or the claiming and defence of rights, or contradicts other legislation binding on the controller.

Can UAE customers stop me sending marketing?

Yes, and this is the strongest right in the law. Article 17(1) gives a right to object to processing intended for direct marketing, including profiling related to direct marketing, with no balancing test and no exception attached to that limb. A working opt-out mechanism is a legal requirement, not a courtesy.

Official Sources

Information is current as of August 2026. Every article number, right, obligation and exception above was read from the official English text of Federal Decree-Law No. 45 of 2021 as published on the UAE Legislation portal. Three limitations are stated rather than smoothed over, and they are unusually important for this law. First, the Executive Regulations required by Article 28 could not be located on any official UAE source at the time of writing: the Legislation portal entry for the decree-law shows a last update of 20 September 2021 and lists no related legislation, and the Government portal’s data protection page, last updated 4 December 2025, does not mention them. Their absence from those sources is not proof that none exists, and readers should check with the UAE Data Office before concluding that any obligation is dormant. Second, and following from the first, no administrative fine is quoted anywhere in this guide, because Article 26 leaves the penalty schedule to a Cabinet decision that we could not retrieve; specific penalty figures circulating on commercial compliance sites are not sourced here. Third, the Government portal states that the decree-law itself is published in Arabic only, and the English text used here is the translation carried on the Legislation portal, which notes that the Arabic prevails in case of conflict. This is general information, not legal advice. Confirm your own obligations with the UAE Data Office or a licensed UAE legal adviser.