UAE data protection explained: the PDPL, DIFC and ADGM
Most countries give you one data-protection law to worry about. The UAE gives you three, and they are genuinely different regimes, not three copies of the same text. Pick the wrong one and you build a programme against rules that do not apply to you. So before anything else, the useful question is not what does the UAE require, it is which UAE applies to me.
Three regimes, decided by geography
The federal Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021, is the onshore law. It covers the mainland and reaches organisations outside the UAE that process the data of people inside it. It is regulated by the UAE Data Office.
The DIFC Data Protection Law (DIFC Law No. 5 of 2020) governs the Dubai International Financial Centre, a financial free zone with its own courts and its own Commissioner of Data Protection.
The ADGM Data Protection Regulations 2021 govern Abu Dhabi Global Market, a separate common-law free zone with its own Office of Data Protection.
The two free zones are expressly carved out of the federal PDPL. If your entity is registered in the DIFC, you follow the DIFC law, not the federal one, and the same logic applies to the ADGM. A group that spans the mainland and one or both free zones is genuinely subject to more than one at once.
The one that is different: the federal PDPL
The headline difference is that the PDPL is consent-first. You process personal data on the data subject's consent unless one of the law's specific exceptions applies, and it does not recognise the GDPR-style legitimate-interests basis that the two free zones do. If your instinct is to reach for legitimate interests, that instinct is wrong onshore.
The other thing to know is that the PDPL's Executive Regulations have not yet been issued. The firm numbers, the breach deadline, the penalty amounts, the DPO thresholds, are set by those Regulations, so a sensible onshore programme is built ready to switch those specifics on the day they land.
The two that look like GDPR: DIFC and ADGM
Both free-zone regimes are GDPR-grade. They give you the six lawful bases including legitimate interests, the full set of individual rights, records of processing, breach notification, a Data Protection Officer and impact assessments. If you already run a GDPR programme, most of it carries across.
The catches are in the detail, and the detail differs between the two zones. Both require you to register with the regulator and pay an annual fee, which GDPR abolished. The DIFC runs a one-month rights clock and an as-soon-as-practicable breach standard, and it has a dedicated regime for autonomous and AI systems. The ADGM runs a two-month rights clock and a seventy-two-hour breach clock, and its impact assessments are notified to the regulator rather than consulted on. Reusing a GDPR programme wholesale, without reading those differences, is the classic free-zone mistake.
Running all three without running three programmes
The practical trap is treating each regime as a separate project with its own spreadsheets. Most of the underlying work, the records of processing, the rights workflow, the breach plan, the security controls, is shared. What changes is the vocabulary, the deadlines and a handful of local duties.
In Compliance One the three UAE frameworks live on one United Arab Emirates track, each with its own control library and native language, and they are cross-mapped to GDPR so a single evidence set counts across all of them. You switch on the regime your entity actually falls under, or more than one for a group, and the shared evidence does the heavy lifting.
The UAE is not one data-protection question, it is three. The good news is that the answer to all three is mostly the same evidence, pointed at three slightly different sets of rules.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.