All frameworks
UAEFederal Decree-Law 45/2021 · in force 2 Jan 2022 · Executive Regulations pending

UAE PDPL compliance

The UAE's onshore personal-data law.

The UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), in force since 2 January 2022, is the country's first comprehensive, onshore personal-data law, regulated by the UAE Data Office. It is a consent-first regime: you process personal data on the data subject's consent unless one of the law's specific exceptions applies, and it does not recognise the GDPR-style legitimate-interests basis. It covers the processing principles, a full set of individual rights, records of processing, security, breach notification, a Data Protection Officer where risk is high, impact assessments, and rules for moving data across borders. Its operational detail (breach deadlines, consent mechanics, transfer safeguards, penalties) is set by Executive Regulations that are still to be issued, so a compliance programme should be built ready to switch those specifics on the moment they land.

Start from the basics

The standard

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)

Who needs it

Any business established in mainland UAE that handles personal data, and any business anywhere that processes the personal data of people in the UAE. Organisations inside the DIFC or ADGM free zones follow those zones' own laws instead, and health and credit data follow their sector regimes.

31

Articles, fully mapped

The basics

What is UAE PDPL?

The PDPL applies to organisations in the UAE that process personal data, and to organisations outside the UAE that process the personal data of people inside the UAE, so its reach extends beyond the country's borders. It turns on consent (Article 6) backed by a defined list of situations where you may process without consent (Article 4), the processing principles in Article 5, a bill of data-subject rights in Articles 13 to 19, and obligations on controllers and processors for records, security, breach reporting, the DPO, impact assessments and cross-border transfers.

Three things set it apart from GDPR and from the UAE's financial free zones. It is consent-first with a closed exception list rather than six balanced lawful bases. It carves out whole categories of data that have their own regimes, namely government data, health data, credit data, and anything regulated inside the DIFC and ADGM free zones. And much of its machinery waits on Executive Regulations that, as of now, have not been published, so the firm numbers (such as a breach deadline) are provisional until they are.

Why it matters

What UAE PDPL does for your business

It is the law of the land

Mainland UAE operations need a lawful basis, privacy notices, security and breach readiness under the PDPL, with a federal regulator, the UAE Data Office, standing behind it.

It reaches outside the UAE

Process the data of people in the UAE from abroad and you are in scope, just as with GDPR's extraterritorial reach.

Consent is the default

Without a legitimate-interests fallback, getting consent and the Article 4 exceptions right is the core of compliance, not an afterthought.

Be ready for the Regulations

The Executive Regulations will set the hard deadlines and penalties. A programme that is already structured switches them on in days, not months.

What it covers

Principles & lawful basis

The Article 5 principles, consent under Article 6, and the Article 4 exceptions for processing without consent.

Transparency & records

Privacy notices under Articles 7 and 13, and the Record of Processing you provide to the UAE Data Office on request.

Individual rights

Information, portability, correction and erasure, restriction, stop-processing, and objection to automated decisions (Articles 13 to 19).

Security & breach

Appropriate technical and organisational measures (Articles 7 and 20) and breach notification to the Data Office and affected individuals (Article 9).

DPO & impact assessments

A Data Protection Officer where processing is high risk or large-scale sensitive (Articles 10 to 12), and DPIAs for high-risk processing (Article 21).

Cross-border transfers

Adequacy (Article 22) or safeguards and derogations (Article 23), pending the Data Office's adequacy list.

The hard way

Teams try to reuse their GDPR programme wholesale, then trip over the differences: there is no legitimate-interests basis, several obligations are carved out to other regimes, and the firm numbers are still pending Executive Regulations. Mapping it by hand across spreadsheets, and keeping it aligned with the free-zone and sector rules a group also faces, is slow and error-prone.

The easier way, with Compliance One

  • A ready control library covering all 31 Articles across 15 domains, consent-first and tagged where the Executive Regulations still apply, so you implement the law as it stands and switch on the deferred specifics when they issue.
  • The shared privacy registers, records of processing, consent, rights requests, DPIAs, breach, transfers, retention, configured for the PDPL's vocabulary and the UAE Data Office.
  • Cross-mapping to GDPR so a single evidence set counts across both, with the free-zone regimes (DIFC and ADGM) on the same UAE track for groups that span onshore and the free zones.
  • Breach workflow, DPO and DPIA triggers, and a cross-border transfer assessment, with an alert that prompts a re-check the moment the Executive Regulations are published.

Do it once, reuse it everywhere. Evidence you collect for UAE PDPL is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is the PDPL in force?
Yes, since 2 January 2022. But its Executive Regulations, which set the operational detail like the breach deadline and penalty amounts, have not yet been issued, and the compliance grace period runs from their issuance.
Does the PDPL apply to DIFC or ADGM companies?
No. The DIFC and ADGM financial free zones have their own data-protection laws, and the federal PDPL carves them out. We cover all three on one UAE track.
Can I rely on legitimate interests like under GDPR?
No. The PDPL is consent-first and does not recognise a legitimate-interests basis. You process on consent unless a specific Article 4 exception applies.
Who enforces it?
The UAE Data Office (the Bureau), established by Federal Decree-Law No. 44 of 2021, with administrative penalties set by Cabinet resolution once the Executive Regulations are in place.

Ready to tackle UAE PDPL?

See exactly how Compliance One maps UAE PDPL to your environment in a 30-minute walkthrough — and how much of it we handle for you.