Federal Decree-Law No. 45 of 2021 established a general personal data protection framework for the United Arab Emirates. It applies to processing of personal data of data subjects inside the UAE and, in defined circumstances, to controllers and processors outside the UAE processing the data of subjects inside it.
The UAE has a layered privacy landscape. The federal law governs onshore processing, while the Dubai International Financial Centre and Abu Dhabi Global Market operate their own data protection laws with their own regulators. Determining which regime applies is the first step of any UAE programme.
The federal law is built on consent as the default, with a defined list of circumstances in which processing may proceed without it — including performance of a contract, legal obligations, protection of public interest and the controller's legitimate interests where the data subject's rights are not prejudiced.
Several operational details — including timeframes and procedures — are left to executive regulations, so implementation planning should confirm the current published position rather than assume detail from other regimes.
Who and what it applies to
- Onshore federal scope
- Processing of personal data of data subjects residing or having a place of business in the UAE, by controllers or processors inside the UAE, and by those outside the UAE processing such data.
- Free zones
- The DIFC and ADGM have separate data protection laws and regulators; entities established there follow those regimes rather than the federal law.
- Exclusions
- The law contains carve-outs, including government data, health and banking data governed by dedicated legislation, and personal data held for personal purposes.
Core principles
- Fair, transparent and lawful processing.
- Collection for a specific and clear purpose, without processing in a way inconsistent with that purpose.
- Adequacy and limitation to what is necessary for the purpose.
- Accuracy, with correction or erasure of inaccurate data.
- Security measures appropriate to the risk, protecting confidentiality and privacy.
- Retention no longer than necessary for the purpose of processing.
Individual rights
Access and receive data
Request information about processing and obtain personal data in a readable, structured format.
Portability
Request transfer of personal data to another controller where technically feasible and processing is automated and consent- or contract-based.
Correction
Request correction or completion of inaccurate personal data.
Erasure
Request deletion in defined circumstances, subject to exceptions such as public interest and legal claims.
Restrict processing
Request restriction of processing in defined circumstances, for example while accuracy is contested.
Object
Object to processing for direct marketing and to automated decision-making producing legal consequences.
Complain
File a complaint with the UAE Data Office where processing breaches the law.
Organisational obligations
Records of processing
Controllers and processors must maintain records of processing operations with prescribed content.
Processor engagement
Engage processors under terms that provide sufficient guarantees and restrict processing to the controller's instructions.
Security
Apply appropriate technical and organisational measures, taking account of the nature and risk of processing.
Breach notification
Notify the Data Office of breaches that would prejudice privacy, confidentiality or security of personal data, and notify data subjects where the breach would prejudice their privacy or security.
Data protection officer
Appoint a DPO where processing would cause high risk, involves large-scale sensitive data, or involves systematic and comprehensive evaluation of sensitive data.
Impact assessment
Carry out an assessment before processing using new technologies or where processing presents high risk to privacy.
Cross-border considerations
- Personal data may be transferred outside the UAE to jurisdictions with an adequate level of protection as determined by the Data Office, or under an applicable international agreement.
- Where adequacy does not apply, transfers may proceed on the basis of contractual clauses, binding corporate rules, express consent, or other defined exceptions such as necessity for a contract or legal claims.
- Entities in the DIFC or ADGM follow the transfer rules of those regimes instead, which are closer in structure to the GDPR.
Enforcement overview
- The UAE Data Office is responsible for supervision, guidance and handling complaints under the federal law.
- Administrative penalties and procedures are set out in executive regulations and resolutions rather than in the decree-law itself.
- The DIFC Commissioner of Data Protection and the ADGM Office of Data Protection enforce their own regimes independently, including their own fine schedules.
- Because operational detail continues to develop, verify the current published position with the relevant regulator before relying on any specific procedure or timeframe.
Implementation checklist
- 1Determine which regime applies — federal, DIFC or ADGM — for each UAE entity and data flow.
- 2Document consent, or the specific exception relied on, for each processing purpose.
- 3Maintain records of processing with the prescribed content for controllers and processors.
- 4Assess whether a DPO appointment is triggered by risk, scale or sensitive data.
- 5Run impact assessments before deploying new technologies affecting personal data.
- 6Record the transfer basis for each cross-border flow and review it against Data Office determinations.
- 7Build a breach notification process aligned to the applicable regime's expectations.
Frequently asked questions
Does the UAE federal law apply to DIFC and ADGM entities?
No. Those free zones have their own data protection laws and regulators, and entities established in them follow those regimes.
Is consent always needed under the UAE PDPL?
Consent is the default, but the law lists circumstances where processing may proceed without it, including contract performance, legal obligations, public interest and certain legitimate interests.
Official sources
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.