
The UAE has no single data protection law. Onshore processing is governed by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, while the Dubai International Financial Centre and Abu Dhabi Global Market each run their own regimes with their own regulators, their own registration duties and their own enforcement powers.
That distinction is the first thing to establish, because the answer changes what a business has to do. A company in DIFC is not subject to the federal law for its DIFC activity. A company in a non-financial free zone such as JAFZA or DMCC generally is. A group with entities in more than one of these will be running parallel compliance positions, not one.
A second point matters throughout. The federal law’s executive regulations, which were to supply the operational detail, had still not been issued as at September 2026. The law is in force, but several of its most important mechanisms are incomplete.
Which data protection law applies to your business in the UAE?
Work through it in this order:
- DIFC entities are subject to DIFC Data Protection Law No. 5 of 2020 and its regulations, overseen by the DIFC Commissioner of Data Protection.
- ADGM entities are subject to the ADGM Data Protection Regulations 2021, overseen by the ADGM Office of Data Protection.
- Everyone else in the UAE, including onshore companies and companies in non-financial free zones, falls under the federal PDPL, subject to the carve-outs below.
- Sector rules sit on top. Health data is also governed by Federal Law No. 2 of 2019 on the use of information and communication technology in health fields, which contains its own restrictions on moving health data abroad. Central Bank regulations affect payment and financial data. Dubai Healthcare City has its own framework.
What does the federal PDPL cover, and what falls outside it?
The federal law applies to the processing of personal data of data subjects inside the UAE, to controllers and processors established in the UAE, and to controllers and processors outside the UAE that process the personal data of people inside the UAE. It is a broad reach, comparable in structure to the European model it draws on.
Several things sit outside it. Government entities are treated separately, as is personal data held by security and judicial authorities. Health data and credit data already regulated by their own legislation are carved out to that extent. Processing by an individual for purely personal purposes is not caught. And the law preserves the separate regimes in the financial free zones.
Sensitive personal data, which includes data revealing health, biometric and genetic data, racial or ethnic origin, religious or political beliefs and criminal records, attracts stricter treatment. Biometric processing is the one most businesses underestimate, because attendance systems and building access controls collect it routinely.
When can you process personal data without consent?
Consent is the default under the federal law, and must be clear, specific and withdrawable. But consent is not required where one of the stated alternatives applies. Those include:
- Performance of a contract with the data subject, or steps taken at their request before entering one.
- Obligations under employment, social security or social protection law.
- Protecting the data subject’s interests, or public health and preventive or occupational medicine.
- Where the data has been made public by the data subject.
- Establishing, exercising or defending legal claims, or judicial and security procedures.
- Archiving, scientific, historical or statistical purposes.
- Compliance with other obligations imposed by UAE law, or protection of the public interest.
Note what is not on that list in the same terms as the European regime: a broad, free-standing legitimate interests basis. Businesses that built their marketing or analytics on legitimate interests elsewhere should not assume the reasoning transfers onshore.
What rights do individuals have under the federal law?
The PDPL gives data subjects the familiar set: to be informed about processing, to obtain access to their data, to have it corrected or erased, to restrict or stop processing, to receive their data in a structured machine-readable form and have it ported, and to object to decisions made solely by automated processing where those decisions have legal effects.
The response deadlines and the form of the response were left to the executive regulations. Until those are published, a business should adopt a defensible internal service standard and document it rather than wait. Regulators tend to look unfavourably on an organisation that had no process at all because the detail was pending.
What do controllers and processors have to do?
The core duties track international practice. Controllers must process lawfully and fairly, limit collection to what is needed, keep data accurate, apply appropriate security, keep records of processing, and use only processors that give sufficient guarantees under a written arrangement. Processors must act on the controller’s instructions, secure the data and keep their own records.
Two duties need specific attention. A data protection officer must be appointed where processing is likely to create a high risk, including where new technologies are used, where there is systematic and extensive evaluation of sensitive data including profiling and automated processing, or where large volumes of sensitive data are processed. The DPO does not have to be resident in the UAE. Separately, a data protection impact assessment is expected for high-risk processing.
Breach notification is where the gap bites hardest. The law requires notification to the regulator, and to data subjects where the breach would prejudice their privacy or security, but the procedure and the timing were to come from the executive regulations. Sector rules do not wait: financial institutions have their own Central Bank reporting expectations. A sensible incident response plan assumes prompt reporting and works backwards from that.
Can personal data leave the UAE?
Yes, subject to conditions. The federal law permits transfers to jurisdictions that have adequate protection, with the assessment of adequacy left to the regulator. Where there is no adequacy finding, transfers can still be made on the basis of a contract or binding arrangement containing appropriate safeguards, with the data subject’s explicit consent, or where the transfer is necessary for a contract, for legal claims, or to protect the data subject’s interests.
Adequacy decisions had not been published as at September 2026, so most businesses rely on contractual safeguards and consent. Health data is the exception: the health ICT law restricts moving health data generated in the UAE outside the country except in defined circumstances.
How do the DIFC and ADGM regimes differ, and what should you do now?
Both financial free zone regimes are closer in structure and in enforcement maturity to the European model than the federal law currently is. DIFC Law No. 5 of 2020 requires controllers and processors to notify the Commissioner and file annually, sets out accountability duties, and imposes defined breach notification obligations. The DIFC has been the most active regulator of the three, adding a specific regulation on processing through autonomous and semi-autonomous systems in 2023 and strengthening its enforcement framework in 2025, including giving data subjects a direct route to the DIFC Courts. ADGM’s 2021 Regulations are administered by its Office of Data Protection, with its own registration regime, and were refined in 2025 with narrow exceptions for processing special category data in insurance and safeguarding contexts.
The federal position is different. The UAE Data Office was established by Federal Decree-Law No. 44 of 2021 but has not been fully operational, with the Telecommunications and Digital Government Regulatory Authority providing the practical point of contact. Enforcement activity onshore has consequently been limited. That is a reason to prepare, not a reason to relax, because the law is already in force and the regulations may arrive with a compliance window attached.
The practical starting point is a data map: what personal data the business holds, where it sits, who it goes to, and which of the three regimes each activity falls under. Notices, processor contracts, retention schedules and incident response all depend on getting that right first. Businesses most often get caught out by HR and biometric data, by marketing databases assembled before the law, and by intra-group transfers that nobody has papered.
This article is general information about UAE law as at September 2026 and is not legal advice. The position varies by emirate and by free zone, and it changes often. Take advice on your own facts before acting.
Frequently asked questions
Does the UAE federal data protection law apply in DIFC and ADGM?
No. Federal Decree-Law No. 45 of 2021 preserves the separate regimes in the financial free zones. A DIFC entity is subject to DIFC Data Protection Law No. 5 of 2020 and the DIFC Commissioner of Data Protection, and an ADGM entity to the ADGM Data Protection Regulations 2021 and its Office of Data Protection. Companies in non-financial free zones generally fall under the federal law.
Have the UAE PDPL executive regulations been issued?
As at September 2026 they had not been published. The law itself is in force, but the detail on breach notification procedure, response deadlines for data subject requests and the mechanics of cross-border transfers was left to those regulations. Businesses are expected to comply with the law as written in the meantime, and commentary suggests a compliance window may follow publication.
Do UAE companies need to appoint a data protection officer?
Only where the processing triggers the threshold. A DPO is required where processing is likely to create a high risk, including the use of new technologies, systematic and extensive evaluation of sensitive personal data involving profiling or automated processing, or processing large volumes of sensitive data. The DPO does not have to be based in the UAE. DIFC and ADGM apply their own separate tests.
Can personal data be transferred out of the UAE?
Yes, under conditions. Transfers are permitted to jurisdictions assessed as having adequate protection, and otherwise on the basis of appropriate contractual safeguards, explicit consent, contractual necessity or legal claims. Adequacy decisions had not been published as at September 2026, so contractual safeguards and consent carry most of the weight. Health data is restricted separately under the health ICT law.
More from the UAE desk
Power of Attorney in the UAE: How It Works Rental Disputes in Dubai: How the Process Works The full UAE hubLegal Desire has published legal industry news and analysis since 2012. This article is part of our UAE desk, which tracks the laws, courts and regulators of the Emirates for lawyers and in-house teams.
Where the legal industry reads first.
Enjoyed this article? Get the biggest legal industry updates, deals, appointments, insights and expert interviews in your inbox, free.
No spam. Unsubscribe anytime.From Legal Desire
Is your firm the one being cited, or the one being skipped?
We ran the test. On several everyday legal questions, software companies are answering and law firms are not. We help firms fix that, and we build the technology behind the practice.