UAE Data Protection Law (PDPL) — Business Compliance Guide 2026
UAE enacted Federal Decree-Law No. 45 of 2021 (UAE Personal Data Protection Law, PDPL), which came into force in 2022. The UAE PDPL establishes data protection rights for individuals and obligations for businesses handling personal data in UAE. This guide covers UAE PDPL compliance for businesses in 2026.
UAE PDPL Overview
- Full name: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
- Enforced by: UAE Data Office (UDO); established under the law
- Scope: applies to any entity processing personal data of UAE residents; includes businesses inside UAE AND businesses outside UAE that process UAE residents’ data
- Exemptions: DIFC and ADGM have their own data protection regimes (DP Law 2020 and ADGM DPR 2021); entities regulated by those regimes may be exempt from UAE PDPL in some cases
Key UAE PDPL Obligations for Businesses
- Lawful basis: must have a lawful basis for processing personal data; consent is the primary basis; contract performance; legitimate interest (with balancing test); legal obligation
- Privacy notice: must inform individuals what data you collect, why, how long you keep it, and with whom you share it; transparent privacy policy required
- Data subject rights: UAE residents have right to access their data; right to correction; right to deletion (right to be forgotten); right to restrict processing; right to data portability
- Data breach notification: must notify UAE Data Office and affected individuals of a data breach if the breach is likely to result in significant harm; notification within 72 hours of becoming aware
- Data Processing Agreement (DPA): when sharing personal data with third-party processors (cloud providers, analytics tools, CRM), a DPA is required
UAE PDPL and International Data Transfers
- Adequate countries: UAE Data Office maintains list of countries with adequate protection; data can flow freely to these countries
- Non-adequate countries: transferring UAE residents’ data to non-adequate countries requires appropriate safeguards (contractual clauses equivalent to standard contractual clauses)
- Cloud services: if your UAE business uses cloud services (AWS, Google Cloud, Microsoft Azure) with servers outside UAE, this may constitute international data transfer; ensure DPA with your cloud provider addresses UAE PDPL requirements
UAE PDPL Penalties
- Processing without lawful basis: fine up to AED 5,000,000
- Failure to notify data breach: fine up to AED 500,000
- Processing sensitive personal data without consent: fine up to AED 20,000,000
- Sensitive personal data: health data, biometric data, genetic data, financial data, religious beliefs, political opinions — higher standard of protection required
Practical UAE PDPL Compliance Steps
- Map your data: what personal data do you collect? Where does it come from? Where does it go?
- Update privacy policy: ensure it meets UAE PDPL disclosure requirements; publish on your website
- Review consent mechanisms: are you collecting consent properly? Is it freely given, specific, informed?
- Audit your vendors: are your cloud providers, CRM, email marketing tools PDPL-compliant? Do you have DPAs?
- Train staff: anyone handling personal data should understand basic UAE PDPL obligations