It is the law of the land
Mainland UAE operations need a lawful basis, privacy notices, security and breach readiness under the PDPL, with a federal regulator, the UAE Data Office, standing behind it.
The UAE's onshore personal-data law.
The UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), in force since 2 January 2022, is the country's first comprehensive, onshore personal-data law, regulated by the UAE Data Office. It is a consent-first regime: you process personal data on the data subject's consent unless one of the law's specific exceptions applies, and it does not recognise the GDPR-style legitimate-interests basis. It covers the processing principles, a full set of individual rights, records of processing, security, breach notification, a Data Protection Officer where risk is high, impact assessments, and rules for moving data across borders. Its operational detail (breach deadlines, consent mechanics, transfer safeguards, penalties) is set by Executive Regulations that are still to be issued, so a compliance programme should be built ready to switch those specifics on the moment they land.
The standard
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Who needs it
Any business established in mainland UAE that handles personal data, and any business anywhere that processes the personal data of people in the UAE. Organisations inside the DIFC or ADGM free zones follow those zones' own laws instead, and health and credit data follow their sector regimes.
31
Articles, fully mapped
The basics
The PDPL applies to organisations in the UAE that process personal data, and to organisations outside the UAE that process the personal data of people inside the UAE, so its reach extends beyond the country's borders. It turns on consent (Article 6) backed by a defined list of situations where you may process without consent (Article 4), the processing principles in Article 5, a bill of data-subject rights in Articles 13 to 19, and obligations on controllers and processors for records, security, breach reporting, the DPO, impact assessments and cross-border transfers.
Three things set it apart from GDPR and from the UAE's financial free zones. It is consent-first with a closed exception list rather than six balanced lawful bases. It carves out whole categories of data that have their own regimes, namely government data, health data, credit data, and anything regulated inside the DIFC and ADGM free zones. And much of its machinery waits on Executive Regulations that, as of now, have not been published, so the firm numbers (such as a breach deadline) are provisional until they are.
Why it matters
Mainland UAE operations need a lawful basis, privacy notices, security and breach readiness under the PDPL, with a federal regulator, the UAE Data Office, standing behind it.
Process the data of people in the UAE from abroad and you are in scope, just as with GDPR's extraterritorial reach.
Without a legitimate-interests fallback, getting consent and the Article 4 exceptions right is the core of compliance, not an afterthought.
The Executive Regulations will set the hard deadlines and penalties. A programme that is already structured switches them on in days, not months.
The Article 5 principles, consent under Article 6, and the Article 4 exceptions for processing without consent.
Privacy notices under Articles 7 and 13, and the Record of Processing you provide to the UAE Data Office on request.
Information, portability, correction and erasure, restriction, stop-processing, and objection to automated decisions (Articles 13 to 19).
Appropriate technical and organisational measures (Articles 7 and 20) and breach notification to the Data Office and affected individuals (Article 9).
A Data Protection Officer where processing is high risk or large-scale sensitive (Articles 10 to 12), and DPIAs for high-risk processing (Article 21).
Adequacy (Article 22) or safeguards and derogations (Article 23), pending the Data Office's adequacy list.
Teams try to reuse their GDPR programme wholesale, then trip over the differences: there is no legitimate-interests basis, several obligations are carved out to other regimes, and the firm numbers are still pending Executive Regulations. Mapping it by hand across spreadsheets, and keeping it aligned with the free-zone and sector rules a group also faces, is slow and error-prone.
Do it once, reuse it everywhere. Evidence you collect for UAE PDPL is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps UAE PDPL to your environment in a 30-minute walkthrough — and how much of it we handle for you.