Nothing about UAE privacy law makes sense until you stop looking for “the UAE law.” There are at least five: a federal PDPL awaiting its executive regulations, two complete GDPR-grade free-zone regimes with active commissioners and fining powers, a health-data law with hard localization, and banking rules from the Central Bank. Enforcement gravity currently sits in DIFC and ADGM, where the rules are complete and the regulators publish decisions, which is precisely where multinationals tend to book their regulated entities.
| Regime | Applies to | Status |
|---|---|---|
| Federal PDPL | Mainland UAE | In force; regulations pending |
| DIFC DP Law 5/2020 | DIFC entities | Active enforcement |
| ADGM DP Regs 2021 | ADGM entities | Active; fines to USD 28M |
| ICT Health Law | UAE health data | Localization; approvals for export |
| Central Bank / TDRA | Banking / telecom | Sector enforcement |
Scoping a multi-regime UAE program
Build the entity-regime matrix first. Every legal entity and dataset gets a regime assignment; ambiguity here poisons notices, DPAs, and transfer paper downstream. The federal PDPL guide and DIFC guides cover the two biggest cells.
Comply upward. Where a group spans regimes, standardizing on the strictest applicable standard (usually DIFC/ADGM practice) minimizes per-entity divergence, with regime-specific paper on top; the DIFC implementation guide details the free-zone build.
Respect the hard edges. Health-data localization and Central Bank rules are not harmonizable by contract; architect data flows around them, alongside the UAE transfer analysis.
Regional consistency. The Gulf neighbors made different choices, Saudi Arabia’s PDPL and Bahrain’s law each need their own module, not a UAE clone.
Your public web properties answer the first scoping question themselves, what you collect and who you send it to: see the evidence with a free scan.