Middle East & Africa United Arab Emirates

UAE Federal PDPL: Data Protection Law No. 45 of 2021

The UAE's federal Personal Data Protection Law: scope and free-zone carve-outs, consent and lawful bases, data subject rights, and the pending executive regulations.

Regulation

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data

Max Penalty

Administrative penalties to be specified by Cabinet decision under the executive regulations; sector and penal-code sanctions apply meanwhile

Enforcing Authority

UAE Data Office (Emirates Data Office), established by Federal Decree-Law No. 44 of 2021

Official Source

u.ae

Executive Summary

  • Federal Decree-Law No. 45 of 2021 is the UAE's first comprehensive onshore data protection law, GDPR-influenced, applying across the Emirates except in the financial free zones (DIFC, ADGM) which keep their own regimes.
  • It covers controllers and processors in the UAE and, extraterritorially, those outside it processing UAE data subjects' data.
  • Consent is the default basis with exceptions (contract, legal claims, public interest, and others); processing must satisfy fairness, purpose limitation, minimization, and accuracy principles.
  • The law's operational details, thresholds, DPO triggers, breach timelines, penalty amounts, await the executive regulations, which had not been published as of mid-2026, leaving the framework in force but under-specified.
  • Government data, health data (covered by the separate ICT Health Law), banking-sector rules, and the free zones create a patchwork: UAE compliance is a multi-regime exercise, not one law.

The UAE’s federal PDPL is a GDPR-family law with a distinctive condition: its engine arrived before its dashboard. The statute has been in force since January 2022, but the executive regulations that set breach clocks, DPO triggers, transfer mechanics, and penalty amounts are still pending, so onshore UAE compliance means honoring in-force principles whose enforcement details are unspecified, while the free zones (DIFC, ADGM) run complete, actively enforced regimes next door. Companies that wait for the regulations misread the landscape: sector regulators and the criminal law police data conduct today.

LawFederal Decree-Law No. 45 of 2021
In forceJanuary 2, 2022 (executive regulations pending)
RegulatorUAE Data Office
ExcludedGovernment, health (ICT Health Law), banking data, DIFC/ADGM
Default basisConsent, with Article 4 exceptions; no general legitimate interest

Building UAE-mainland compliance now

Map entities to regimes first. Mainland versus DIFC versus ADGM versus sector laws decides everything downstream; the UAE landscape guide charts the full patchwork.

Run consent-first with documented exceptions. Without a legitimate-interest basis, marketing and analytics lean on consent; evidence and withdrawal mechanics matter from day one.

Adopt GDPR-grade defaults for the unspecified parts. One-month DSR clocks, 72-hour-style internal breach escalation, and DPIA discipline are defensible placeholders the regulations are expected to approximate; transfer planning can similarly track the law’s adequacy/safeguards skeleton.

Watch the sector regulators. Central Bank outsourcing rules, TDRA telecom rules, and health-data law carry live sanctions while the Data Office’s penalty schedule waits on the Cabinet.

Consent and tracker behavior on your UAE-facing pages is enforceable conduct under today’s rules: check it with a free scan.

Frequently Asked Questions

Who does the federal PDPL apply to, and who is carved out?

It applies to processing of personal data of data subjects residing in or having a place of business in the UAE, by controllers or processors inside the country (outside the financial free zones) or abroad. Carved out: government entities and government data, personal data held by security and judicial authorities, health data regulated by its own federal law (No. 2 of 2019, the ICT Health Law), banking and credit data subject to Central Bank rules, and companies in DIFC and ADGM, which apply their own data protection laws with independent commissioners. Scoping a UAE program therefore starts with which regime each entity and dataset sits under.

What lawful bases does the law recognize?

Consent is the anchor: prior, clear, unambiguous, evidenced, and withdrawable. Article 4 lists the exceptions where processing may proceed without it, including: protection of public interest, processing related to legal claims and judicial procedures, protection of the data subject's interests, contract performance or pre-contract steps at the data subject's request, compliance with other UAE laws, and specified employment-related processing. There is no general legitimate-interest basis comparable to GDPR Article 6(1)(f), which is the single biggest structural difference for EU-calibrated programs.

What rights do data subjects have?

A GDPR-recognizable catalogue: the right to receive information about processing, access and obtain a copy, request correction and erasure, restrict or object to processing (including direct marketing and automated processing), portability, and the right not to be subject to fully automated decisions producing legal effects without human review. Response timelines and fee rules are among the details assigned to the executive regulations; pending those, well-advised controllers run the requests on GDPR-style one-month clocks and document their reasoning.

What is the status of the executive regulations and enforcement?

The law took effect January 2, 2022, and states that the executive regulations will specify its operational machinery, breach notification periods, DPO appointment cases, cross-border transfer mechanics, and administrative penalties. As of mid-2026 the regulations remain unpublished, and the UAE Data Office has correspondingly not run a public penalty docket. That is not a compliance holiday: the statutory duties are in force, sector regulators (Central Bank, TDRA, health authorities) enforce their own rules now, and the penal code and cybercrime law criminalize unlawful disclosure. Build now, tune when the regulations land.

How does the federal law interact with DIFC and ADGM?

It does not apply inside them. DIFC runs DP Law No. 5 of 2020 with its own Commissioner of Data Protection, and ADGM its Data Protection Regulations 2021 with an Office of Data Protection, both closer to the GDPR, with active guidance, registration duties, and fines. A UAE group commonly spans all three regimes: mainland entities under the federal PDPL, a DIFC-booked finance arm under DIFC law, and an ADGM vehicle under ADGM regulations. Contracts, notices, and transfer mechanics must be assigned per entity; the free-zone regimes also have their own adequacy lists and SCC forms for transfers.

Regulatory Crosswalk

GDPRDIFC DP LawSaudi PDPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.