Law · Privacy · United Arab Emirates

UAE PDPL compliance: the federal data protection law explained

UAE PDPL compliance means meeting Federal Decree-Law No. 45 of 2021, the UAE's federal personal data protection law, in force since 2 January 2022. It requires a lawful basis, transparency, security, breach notification to the UAE Data Office and data subject rights, while free zones such as DIFC and ADGM keep their own laws.

Key takeaways

What you need to know about UAE PDPL

Federal onlyDIFC and ADGM free zones apply their own data protection laws.
Carve-outsGovernment data and some sector data fall outside it.
GDPR-likePrinciples, rights and DPIAs mirror GDPR closely.
Breach noticeNotify the UAE Data Office of breaches affecting privacy or security.
Watch the regulationsDetailed rules and penalties depend on the Executive Regulations.

Who must comply with the UAE PDPL?

Controllers and processors handling personal data of people in the UAE, outside the free zones and carve-outs.

UAE businessesMainland companies processing personal data.
Foreign companiesProcessing personal data of people in the UAE.
Processors and SaaS providersActing for UAE controllers.
Group companiesWith both mainland and free-zone entities.
Not coveredGovernment data, and data under sector laws or free-zone laws.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the law requires

What does the UAE PDPL require?

The UAE PDPL requires a lawful basis for processing, transparency, security measures, records of processing, breach notification to the UAE Data Office, DPIAs for high-risk processing, and respect for data subject rights.

Art. 4–6 Basis

Lawful processing

Consent or listed exceptions.

In QULDEX: Basis per purpose
Art. 7–8 Duties

Controllers and processors

Measures, records, instructions.

In QULDEX: Record of processing
Art. 9 Breach

Breach notification

To the UAE Data Office.

In QULDEX: Breach register
Art. 10 DPO

Data protection officer

Where processing is high risk.

In QULDEX: Appointment record
Art. 13–18 Rights

Data subject rights

Access, portability, erasure, objection.

In QULDEX: Request log
Art. 22–23 Transfer

Cross-border transfers

Adequacy or listed conditions.

In QULDEX: Transfer register
Article explorer

Which UAE PDPL articles matter most?

These 16 articles carry the obligations most organisations work on. Select any article to see what it requires, typical evidence and the matching GDPR article.

Sep 2021law issued
Jan 2022in force
DIFC/ADGMown laws
Data Officeregulator

Showing up to 6 per group. Search, filter, or open a group to see all 16.

Scope 2

  1. Art. 2Scope

    Applies to processing of personal data of people in the UAE, and to controllers and processors in the UAE, including those processing abroad.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 3

  2. Art. 2(2)ExclusionsScope check

    Excludes government data, personal data processed for personal purposes, and health, banking and credit data covered by their own laws; free zones with their own laws (DIFC, ADGM) apply those instead.

    In QULDEXEach data set records which law applies.

    Typical evidence
    Applicable-law map

Lawful processing 3

  1. Art. 4Lawful processing and consent

    Process personal data with consent, or under listed exceptions such as contract performance or legal obligation.

    In QULDEXEach purpose records its basis.

    Typical evidence
    Purpose register
    Maps to
    GDPR Art. 6

  2. Art. 5Processing principles

    Fair, transparent, purpose-limited, minimal, accurate, secure and time-limited processing.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 5

  3. Art. 6Conditions for consent

    Consent must be specific, clear and unambiguous, and can be withdrawn.

    In QULDEXConsent and withdrawal records are logged.

    Typical evidence
    Consent logs
    Maps to
    GDPR Art. 7

Obligations 6

  1. Art. 7Controller obligations

    Take technical and organisational measures, and keep a record of processing.

    In QULDEXThe record of processing is kept per activity.

    Typical evidence
    Record of processing
    Maps to
    GDPR Art. 24, 30

  2. Art. 8Processor obligations

    Process only on the controller's instructions, with appropriate security.

    In QULDEXEach processor is linked to its instructions and contract.

    Typical evidence
    Processor contracts
    Maps to
    GDPR Art. 28

  3. Art. 9Breach notification

    Notify the UAE Data Office of a breach that affects privacy, confidentiality or security, and notify the data subject in some cases.

    In QULDEXBreaches are logged with notification decisions.

    Typical evidence
    Breach register
    Maps to
    GDPR Art. 33–34

  4. Art. 10Data protection officer

    Appoint a DPO where processing involves high risk, large-scale sensitive data or systematic monitoring.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    DPO appointment
    Maps to
    GDPR Art. 37

  5. Art. 20Security of processing

    Apply appropriate technical and organisational security measures.

    In QULDEXSecurity controls are reused from ISO 27001.

    Typical evidence
    Security evidence
    Maps to
    GDPR Art. 32ISO 27001

  6. Art. 21Impact assessment

    Assess the impact of processing that is likely to pose a high risk.

    In QULDEXDPIAs run as assessments with sign-off.

    Typical evidence
    DPIAs
    Maps to
    GDPR Art. 35

Data subject rights 4

  1. Art. 13Right to information

    Data subjects can obtain information about the processing of their data.

    In QULDEXRequests are logged with deadlines.

    Typical evidence
    Request log
    Maps to
    GDPR Art. 15

  2. Art. 14Right to data portability

    Receive data in a structured, machine-readable format.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 20

  3. Art. 15Rectification and erasure

    Correct inaccurate data and erase data in listed cases.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 16–17

  4. Art. 16–18Restriction, objection and automated processing

    Restrict or object to processing, and object to decisions based solely on automated processing.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 18, 21, 22

Transfers 1

  1. Art. 22–23Cross-border transfers

    Transfer data abroad to countries with adequate protection, or under listed conditions such as contracts or consent.

    In QULDEXTransfers record destination and basis.

    Typical evidence
    Transfer register
    Maps to
    GDPR Art. 44–49

Article numbers follow Federal Decree-Law No. 45 of 2021. Summaries are QULDEX paraphrases, not legal advice.

Compliance path

How do you comply with the UAE PDPL?

Confirm which law applies to each entity and data set, map your processing, fix notices and consent, and set up breach and rights processes. Most organisations need 3 to 6 months, less with a GDPR programme.

  1. Confirm the applicable law

    Mainland PDPL, DIFC or ADGM law, or a sector law, per entity and data set.

  2. Map processing

    Record purposes, data, bases, processors and transfers.

  3. Notices, consent and DPIAs

    Update notices, capture consent, assess high-risk processing.

  4. Breach and rights processes

    Notify the Data Office, answer requests on time.

  5. Processors and transfers

    Contracts with processors and a basis for every transfer.

  6. Track the Executive Regulations

    On issueRead the Executive Regulations
    ThenUse the grace period to close gaps
    YearlyReview the programme

Durations are QULDEX planning ranges.

Records to keep

Which records does the UAE PDPL need?

The law asks for a record of processing; these records cover the rest.

RecordArticleWhere it lives in QULDEX
Applicable-law map per entityArt. 2Risk register
Record of processingArt. 7Risk register
Notices and consent logsArt. 4–6Evidence vault
Processor contractsArt. 8Vendor register
Breach registerArt. 9CAPA automation
DPO appointmentArt. 10Policy library
DPIAsArt. 21Audit workspace
Rights request logArt. 13–18Evidence vault
Transfer registerArt. 22–23Vendor register

Record names are QULDEX recommendations based on the Decree-Law.

Time and cost

How long does UAE PDPL compliance take and what drives the effort?

Most organisations need 3 to 6 months. Group structure across mainland and free zones, processors and transfers drive the effort.

Where the time goes

Applicable law1–3 wk
Processing map3–6 wk
Notices and DPIAs1–2 mo
Breach and rights3–6 wk
Processors and transfers1–2 mo

Bars show the upper end of each range on one scale (6 months = full width).

What changes the effort

  • Group structure: mainland and free-zone entities follow different laws
  • Sector data: health and banking data follow sector laws
  • Processors: every processor needs a contract
  • Transfers: each needs a basis
  • Existing GDPR programme: much carries over
Readiness check · 2 minutes

How ready are you for the UAE PDPL?

Check these eight things first. Nothing you enter leaves this page.

Art. 2Do you know which law applies to each entity and data set?
Art. 7Do you keep a record of processing?
Art. 4Is there a lawful basis for every purpose?
Art. 8Do processors act under contract?
Art. 9Can you notify the UAE Data Office of a breach?
Art. 13Can you answer access requests on time?
Art. 21Do you assess high-risk processing?
Art. 22Does every transfer abroad have a basis?
Crosswalk

How the UAE PDPL maps to GDPR, the Saudi PDPL and ISO 27701

The UAE PDPL follows GDPR closely, so a GDPR programme covers most of it. The Saudi PDPL differs on transfers and registration.

UAE PDPL vs GDPR at a glance

UAE PDPLGDPR
ScopeMainland UAE; free zones and some sectors excludedEU and EEA, extraterritorial
Lawful basesConsent plus listed exceptionsSix lawful bases
RegulatorUAE Data OfficeNational supervisory authorities
Breach noticeTo the Data Office; timing per regulations72 hours if reportable
PenaltiesSet by the Executive RegulationsUp to €20m or 4%
In QULDEXQULDEX maps each process to both laws, so one privacy programme serves the UAE and the EU.

Privacy crosswalk

UAE PDPLGDPRSaudi PDPLISO 27701:2025Shared evidence
Art. 4 BasisArt. 6Art. 6Lawful basisPurpose register
Art. 7 RecordsArt. 30Art. 31Records of processingRecord of processing
Art. 8 ProcessorsArt. 28Art. 8Processor contractsContracts
Art. 9 BreachArt. 33–34Art. 20Breach notificationBreach register
Art. 21 DPIAArt. 35Art. 22Impact assessmentDPIAs
Art. 22 TransfersArt. 44–49Art. 29TransfersTransfer register

Indicative mapping for planning, not legal advice.

Where QULDEX fits

How QULDEX runs UAE PDPL compliance from data map to audit

QULDEX is UAE PDPL compliance and audit management software built from EGV Group's audit delivery, used by controllers, their DPOs and privacy auditors. Pick your role to see who does what.

For organisations processing personal data in the UAE.

  1. ScopeConfirm the lawApplicable-law map
  2. MapRecord processingRecord of processing
  3. NoticesFix notices and consentNotice versions and consent logs
  4. BreachesNotify the Data OfficeBreach log with decisions
  5. TransfersDocument transfersTransfer register
  6. AuditProve complianceControlled evidence sharing
Without one systemWith QULDEX
Free-zone and mainland data mixedApplicable law per entity and data set
Processing records out of dateA live record of processing
GDPR and PDPL run separatelyOne programme mapped to both
Transfers undocumentedA basis for every transfer
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

UAE PDPL questions people ask

Does the UAE PDPL apply in DIFC and ADGM?

No. DIFC and ADGM have their own data protection laws, which apply to entities established there. The federal PDPL covers the mainland and other free zones without their own law.

When did the UAE PDPL come into force?

Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022. Detailed obligations and penalties depend on its Executive Regulations, followed by a grace period to comply.

Who regulates the UAE PDPL?

The UAE Data Office, which issues guidance, receives breach notifications and handles complaints.

What data is excluded from the UAE PDPL?

Government data, personal data processed for personal purposes, and health, banking and credit data governed by their own laws.

How is the UAE PDPL different from GDPR?

It is close to GDPR on principles and rights, but uses consent plus listed exceptions instead of six lawful bases, excludes free zones and some sectors, and leaves penalties to the Executive Regulations.

Sources

References

  1. UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. u.ae / uaelegislation.gov.ae
  2. UAE Data Office. u.ae
  3. DIFC Data Protection Law No. 5 of 2020. difc.ae
  4. ADGM Data Protection Regulations 2021. adgm.com

Reviewed by

Abhishek Yadav

Lead Auditor · QULDEX

Reviewed this page against UAE Federal Decree-Law No. 45 of 2021: scope, obligations, rights and transfers.

Page history
  • : Page first built: article explorer, scope and carve-outs, readiness check and GDPR comparison

Know which data the UAE PDPL covers

Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.

Schedule
Book a Demo