The UAE’s federal PDPL is a GDPR-family law with a distinctive condition: its engine arrived before its dashboard. The statute has been in force since January 2022, but the executive regulations that set breach clocks, DPO triggers, transfer mechanics, and penalty amounts are still pending, so onshore UAE compliance means honoring in-force principles whose enforcement details are unspecified, while the free zones (DIFC, ADGM) run complete, actively enforced regimes next door. Companies that wait for the regulations misread the landscape: sector regulators and the criminal law police data conduct today.
| Law | Federal Decree-Law No. 45 of 2021 |
|---|---|
| In force | January 2, 2022 (executive regulations pending) |
| Regulator | UAE Data Office |
| Excluded | Government, health (ICT Health Law), banking data, DIFC/ADGM |
| Default basis | Consent, with Article 4 exceptions; no general legitimate interest |
Building UAE-mainland compliance now
Map entities to regimes first. Mainland versus DIFC versus ADGM versus sector laws decides everything downstream; the UAE landscape guide charts the full patchwork.
Run consent-first with documented exceptions. Without a legitimate-interest basis, marketing and analytics lean on consent; evidence and withdrawal mechanics matter from day one.
Adopt GDPR-grade defaults for the unspecified parts. One-month DSR clocks, 72-hour-style internal breach escalation, and DPIA discipline are defensible placeholders the regulations are expected to approximate; transfer planning can similarly track the law’s adequacy/safeguards skeleton.
Watch the sector regulators. Central Bank outsourcing rules, TDRA telecom rules, and health-data law carry live sanctions while the Data Office’s penalty schedule waits on the Cabinet.
Consent and tracker behavior on your UAE-facing pages is enforceable conduct under today’s rules: check it with a free scan.