The UAE PDPL vs GDPR: why consent-first changes your programme
The UAE Federal Personal Data Protection Law, Decree-Law No. 45 of 2021, reads like GDPR at a glance. Same principles, a familiar set of rights, records of processing, breach notification, a DPO, impact assessments. That surface similarity is exactly what gets teams into trouble, because the places it diverges are the places compliance programmes are actually built.
Consent-first, with no legitimate interests
Under GDPR you have six balanced lawful bases, and legitimate interests is the workhorse for a lot of ordinary processing. The PDPL does not work that way. It is consent-first: you process on the data subject's consent unless one of the law's specific exceptions (Article 4) applies, and there is no legitimate-interests basis to fall back on.
This is not a cosmetic difference. A GDPR programme that leans on legitimate interests for analytics, marketing or fraud prevention has to re-ground all of that onshore, either on consent or on a specific Article 4 exception. Getting consent and the exceptions right is the core of PDPL compliance, not an afterthought.
Whole categories are carved out
The PDPL hands several categories of data to their own regimes and steps back: government data, health data, credit data, and anything regulated inside the DIFC and ADGM free zones (Article 2). If your processing is mostly in one of those buckets, the law that governs you may not be the PDPL at all. Mapping scope first saves you from building against the wrong rulebook.
The numbers are not final yet
Much of the PDPL's operational machinery, the breach-notification deadline, the penalty amounts, the DPO thresholds, the transfer safeguards, is set by Executive Regulations that have not been issued. So any firm figure you see quoted today is provisional. The right move is to build the programme structured and ready, so when the Regulations land you switch the specifics on in days rather than starting a project.
Reusing your GDPR programme for the UAE mainland is a good start and a bad finish. The bones carry across; the lawful basis, the carve-outs and the pending numbers do not.
How Compliance One handles it
The PDPL control library in Compliance One is consent-first by design, with the legitimate-interests basis deliberately absent, and the obligations that depend on the Executive Regulations are flagged so you can see what is provisional. It cross-maps to GDPR so the evidence you already hold carries across, and it sits on the same UAE track as the DIFC and ADGM regimes for groups that span onshore and the free zones.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.