Home › Law library › UAE PDPL
AE
UAE PDPL
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
Sourced. Last verified 9 October 2026
United Arab Emirates (onshore; excludes DIFC and ADGM free zones) Privacy
- Status
- In force since 2 January 2022, but Executive Regulations still not issued as of July 2026, so many operational details are pending.
- Who it applies to
- Processing of data of people living or doing business in the UAE; UAE-based controllers/processors whatever the data subject's location; and foreign controllers/processors handling data of people in the UAE (extraterritorial). Leaves DIFC and ADGM laws intact.
- Size thresholds
- No size or volume threshold; applies to any covered organisation. DPO duty is triggered by high-risk or large-scale sensitive data processing.
- Regulator
- UAE Data Office (nominal regulator, not fully operational); consolidated into the UAE Artificial Intelligence and Data Authority, established 14 June 2026.
- Breach or incident reporting
- Notify the Data Office immediately on becoming aware of a breach that harms privacy (Art. 9); exact deadline and procedure await the Executive Regulations.
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- Required for high-risk processing using new technologies, systematic assessment/profiling of sensitive data, or large volumes of sensitive data (Art. 10). Can be staff or contractor; need not be UAE-based.
- Local representative
- Being verified
- Sending data abroad
- Restricted. Allowed to jurisdictions approved as adequate by the Data Office or under listed exceptions (e.g., consent, contract); details await Executive Regulations.
- Cookies and consent
- Consent is the default legal basis, with exceptions (contract, legal claims, public interest, health). No cookie-specific rules. People can object to direct marketing and related profiling (Art. 17).
- Maximum penalty
- PDPL itself sets no fines; a Cabinet decision on violations and penalties is pending. The Cybercrime Law (Decree-Law 34/2021) may apply: detention and/or AED 50,000–500,000.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Map processing of UAE residents' data, including offshore processing of it.
- Get clear consent or document another permitted legal basis before processing.
- Appoint a DPO if you run high-risk or large-scale sensitive data processing.
- Set up a breach process to notify the Data Office immediately once a breach is known.
- Restrict transfers outside the UAE to approved countries or listed exceptions.
- Honour access, correction, erasure and objection requests, including opt-outs from direct marketing.
- Monitor for the Executive Regulations; a 6-month adjustment window is expected after they are issued.
Recent changes
Executive Regulations still pending (July 2026). UAE AI and Data Authority established 14 June 2026, absorbing the Data Office. New Child Digital Safety Law bans collecting under-13s' data without verified parental consent.
Sources
- Primary source: https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
- Second source: https://www.ashurstperkinscoie.com/en/insights/data-bytes-67-your-emea-data-privacy-update-for-july-2026/
- Regulator: UAE Data Office (nominal regulator, not fully operational); consolidated into the UAE Artificial Intelligence and Data Authority, established 14 June 2026.
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].