UAE Personal Data Protection Law (PDPL) for Free Zone Companies 2026
UAE’s Federal Personal Data Protection Law (Federal Decree-Law No. 45/2021 — PDPL) is the UAE’s comprehensive data protection regulation, broadly equivalent to GDPR in Europe. In force since 2023, PDPL applies to all UAE entities that process personal data. This guide covers PDPL implications for UAE free zone companies in 2026.
Does PDPL Apply to UAE Free Zone Companies?
Yes — UAE PDPL applies to all UAE-based data controllers and processors, including free zone companies, with the exception of DIFC and ADGM (which have their own separate data protection laws: DIFC Law No. 5/2020 and ADGM Data Protection Regulations). For DIFC/ADGM companies: comply with the respective free zone data protection law rather than federal PDPL.
Key PDPL Obligations for Free Zone Companies
- Lawful basis for processing: personal data must only be processed if a legal basis exists (consent, contractual necessity, legal obligation, legitimate interest, vital interest, public interest)
- Data subject rights: individuals must be informed of their data rights (access, correction, deletion, portability, objection)
- Privacy notice: a written privacy policy must be provided to data subjects
- Data minimisation: only collect data necessary for the stated purpose
- Retention periods: establish and document data retention schedules
- Cross-border transfers: data transfers outside UAE require adequate protection (adequacy decision or standard contractual clauses)
UAE Data Protection Officer (DPO)
Under UAE PDPL, controllers that conduct large-scale systematic processing of personal data, or process sensitive data, must appoint a Data Protection Officer (DPO). For most SME free zone companies with limited personal data processing: a DPO may not be mandatory. For companies handling health data, financial data of many individuals, or large-scale marketing databases: a DPO is likely required. The DPO must be registered with UAE’s data protection authority (TDRA).
Sensitive Personal Data Under UAE PDPL
UAE PDPL defines sensitive data as: health and genetic data, biometric data, criminal records data, data related to ethnic or racial origin, political opinions, religious beliefs, financial data. Sensitive data requires stronger protection and specific legal bases for processing (explicit consent or specific exemptions).
PDPL Penalties
- General violations: fines up to AED 5 million
- Sensitive data violations: up to AED 20 million
- Criminal liability: individuals (directors, officers) can face personal liability for intentional violations
UAE PDPL enforcement is administered by the UAE Telecommunications and Digital Government Regulatory Authority (TDRA). Enforcement action has increased significantly since 2024.