Law · Privacy · United Arab Emirates
UAE PDPL compliance means meeting Federal Decree-Law No. 45 of 2021, the UAE's federal personal data protection law, in force since 2 January 2022. It requires a lawful basis, transparency, security, breach notification to the UAE Data Office and data subject rights, while free zones such as DIFC and ADGM keep their own laws.
Controllers and processors handling personal data of people in the UAE, outside the free zones and carve-outs.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The UAE PDPL requires a lawful basis for processing, transparency, security measures, records of processing, breach notification to the UAE Data Office, DPIAs for high-risk processing, and respect for data subject rights.
Consent or listed exceptions.
In QULDEX: Basis per purposeMeasures, records, instructions.
In QULDEX: Record of processingTo the UAE Data Office.
In QULDEX: Breach registerWhere processing is high risk.
In QULDEX: Appointment recordAccess, portability, erasure, objection.
In QULDEX: Request logAdequacy or listed conditions.
In QULDEX: Transfer registerThese 16 articles carry the obligations most organisations work on. Select any article to see what it requires, typical evidence and the matching GDPR article.
Showing up to 6 per group. Search, filter, or open a group to see all 16.
Art. 2ScopeApplies to processing of personal data of people in the UAE, and to controllers and processors in the UAE, including those processing abroad.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 2(2)ExclusionsScope checkExcludes government data, personal data processed for personal purposes, and health, banking and credit data covered by their own laws; free zones with their own laws (DIFC, ADGM) apply those instead.
In QULDEXEach data set records which law applies.
Art. 4Lawful processing and consentProcess personal data with consent, or under listed exceptions such as contract performance or legal obligation.
In QULDEXEach purpose records its basis.
Art. 5Processing principlesFair, transparent, purpose-limited, minimal, accurate, secure and time-limited processing.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 6Conditions for consentConsent must be specific, clear and unambiguous, and can be withdrawn.
In QULDEXConsent and withdrawal records are logged.
Art. 7Controller obligationsTake technical and organisational measures, and keep a record of processing.
In QULDEXThe record of processing is kept per activity.
Art. 8Processor obligationsProcess only on the controller's instructions, with appropriate security.
In QULDEXEach processor is linked to its instructions and contract.
Art. 9Breach notificationNotify the UAE Data Office of a breach that affects privacy, confidentiality or security, and notify the data subject in some cases.
In QULDEXBreaches are logged with notification decisions.
Art. 10Data protection officerAppoint a DPO where processing involves high risk, large-scale sensitive data or systematic monitoring.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 20Security of processingApply appropriate technical and organisational security measures.
In QULDEXSecurity controls are reused from ISO 27001.
Art. 21Impact assessmentAssess the impact of processing that is likely to pose a high risk.
In QULDEXDPIAs run as assessments with sign-off.
Art. 13Right to informationData subjects can obtain information about the processing of their data.
In QULDEXRequests are logged with deadlines.
Art. 14Right to data portabilityReceive data in a structured, machine-readable format.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 15Rectification and erasureCorrect inaccurate data and erase data in listed cases.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 16–18Restriction, objection and automated processingRestrict or object to processing, and object to decisions based solely on automated processing.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 22–23Cross-border transfersTransfer data abroad to countries with adequate protection, or under listed conditions such as contracts or consent.
In QULDEXTransfers record destination and basis.
Nothing matches that search.
Article numbers follow Federal Decree-Law No. 45 of 2021. Summaries are QULDEX paraphrases, not legal advice.
Confirm which law applies to each entity and data set, map your processing, fix notices and consent, and set up breach and rights processes. Most organisations need 3 to 6 months, less with a GDPR programme.
Mainland PDPL, DIFC or ADGM law, or a sector law, per entity and data set.
Record purposes, data, bases, processors and transfers.
Update notices, capture consent, assess high-risk processing.
Notify the Data Office, answer requests on time.
Contracts with processors and a basis for every transfer.
Durations are QULDEX planning ranges.
The law asks for a record of processing; these records cover the rest.
| Record | Article | Where it lives in QULDEX |
|---|---|---|
| Applicable-law map per entity | Art. 2 | Risk register |
| Record of processing | Art. 7 | Risk register |
| Notices and consent logs | Art. 4–6 | Evidence vault |
| Processor contracts | Art. 8 | Vendor register |
| Breach register | Art. 9 | CAPA automation |
| DPO appointment | Art. 10 | Policy library |
| DPIAs | Art. 21 | Audit workspace |
| Rights request log | Art. 13–18 | Evidence vault |
| Transfer register | Art. 22–23 | Vendor register |
Record names are QULDEX recommendations based on the Decree-Law.
Most organisations need 3 to 6 months. Group structure across mainland and free zones, processors and transfers drive the effort.
Bars show the upper end of each range on one scale (6 months = full width).
Check these eight things first. Nothing you enter leaves this page.
The UAE PDPL follows GDPR closely, so a GDPR programme covers most of it. The Saudi PDPL differs on transfers and registration.
| UAE PDPL | GDPR | |
|---|---|---|
| Scope | Mainland UAE; free zones and some sectors excluded | EU and EEA, extraterritorial |
| Lawful bases | Consent plus listed exceptions | Six lawful bases |
| Regulator | UAE Data Office | National supervisory authorities |
| Breach notice | To the Data Office; timing per regulations | 72 hours if reportable |
| Penalties | Set by the Executive Regulations | Up to €20m or 4% |
| In QULDEX | QULDEX maps each process to both laws, so one privacy programme serves the UAE and the EU. | |
| UAE PDPL | GDPR | Saudi PDPL | ISO 27701:2025 | Shared evidence |
|---|---|---|---|---|
| Art. 4 Basis | Art. 6 | Art. 6 | Lawful basis | Purpose register |
| Art. 7 Records | Art. 30 | Art. 31 | Records of processing | Record of processing |
| Art. 8 Processors | Art. 28 | Art. 8 | Processor contracts | Contracts |
| Art. 9 Breach | Art. 33–34 | Art. 20 | Breach notification | Breach register |
| Art. 21 DPIA | Art. 35 | Art. 22 | Impact assessment | DPIAs |
| Art. 22 Transfers | Art. 44–49 | Art. 29 | Transfers | Transfer register |
Indicative mapping for planning, not legal advice.
QULDEX is UAE PDPL compliance and audit management software built from EGV Group's audit delivery, used by controllers, their DPOs and privacy auditors. Pick your role to see who does what.
For organisations processing personal data in the UAE.
For DPOs and privacy consultants.
For independent privacy auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →No. DIFC and ADGM have their own data protection laws, which apply to entities established there. The federal PDPL covers the mainland and other free zones without their own law.
Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022. Detailed obligations and penalties depend on its Executive Regulations, followed by a grace period to comply.
The UAE Data Office, which issues guidance, receives breach notifications and handles complaints.
Government data, personal data processed for personal purposes, and health, banking and credit data governed by their own laws.
It is close to GDPR on principles and rights, but uses consent plus listed exceptions instead of six lawful bases, excludes free zones and some sectors, and leaves penalties to the Executive Regulations.
NCA ECC, SAMA CSF, UAE IAS and Gulf data protection laws.
blog.quldex.comGDPR, ISO 27701 and privacy-law comparisons.
blog.quldex.comHow another new privacy law phases in its rules.
blog.quldex.comA file-naming scheme auditors can follow.
Reviewed by
Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.