We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Knowledge Center / UAE PDPL
UAE Federal Government / UAE Data Office · United Arab Emirates

UAE Personal Data Protection Law (PDPL)

Federal Decree-Law 45/2021 — the UAE’s federal data protection law.

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the UAE’s federal data protection law. It was issued on 20 September 2021, published in Official Gazette No. 712 (supplement) on 26 September 2021, and came into effect on 2 January 2022; the UAE legislation portal lists it as Active. Official UAE summaries describe it as applying to the processing of personal data, in full or in part through electronic systems, inside or outside the country.

What the law requires

  • General obligations on controllers and processors (Articles 7–8), including processing controls and consent terms (Articles 5–6).
  • Personal data breach reporting (Article 9).
  • A Data Protection Officer with defined roles, in the cases the law sets out (Articles 10–12).
  • Data-subject rights: information, portability, correction and erasure, restriction, and objection to processing including automated processing (Articles 13–18).
  • Personal data security (Article 20) and data protection impact assessment (Article 21).
  • Controls on cross-border transfer and sharing of personal data (Articles 22–23).

Who it applies to — and who it does not

The law reaches controllers and processors handling personal data connected to the UAE. The DIFC and ADGM financial free zones operate their own data protection regimes in place of the federal law — a company with entities both onshore and in a financial free zone answers to more than one regime at once.

Executive Regulations — an honestly open question
Secondary sources conflict on whether the Executive Regulations to Decree-Law 45/2021 — which activate detailed enforcement — have been issued, and none we have checked cites an instrument number against a primary UAE source. We track this in our open compliance registry as unresolved rather than asserting a date. Verify against the Official Gazette or the UAE Data Office before relying on an enforcement position.

Compliance approach

  1. Map processing activities and legal bases, and check whether any entity sits in DIFC/ADGM (different regime).
  2. Stand up the accountability layer: DPO assessment and appointment where required, records, breach-reporting procedure.
  3. Engineer data-subject rights end-to-end — a right promised in policy but unexecutable in systems is the gap regulators test.
  4. Assess cross-border flows against Articles 22–23 before signing processors outside the UAE.
How CyberSigma helps
From our UAE office we run PDPL gap assessments and data privacy audits, and align PDPL obligations with ISO 27001 and India’s DPDP Act for groups operating across both markets — one privacy programme, mapped twice, evidenced once.

Note: the legislation portal’s own disclaimer states that the Arabic text prevails for interpretation — clause-level positions should be checked against the Arabic original.

Free 1-minute check
DPDP Readiness Checker
Check your readiness for India’s DPDP Act and see your priority gaps — free.
Try it free →

Frequently asked questions

When did the UAE PDPL come into force?
Federal Decree-Law 45/2021 was issued on 20 September 2021, published in Official Gazette No. 712 (supplement) on 26 September 2021, and took effect on 2 January 2022 — dates verified against the official UAE legislation portal.
Does PDPL apply to companies in DIFC or ADGM?
The DIFC and ADGM financial free zones run their own data protection regimes in place of the federal PDPL. A group with both onshore and free-zone entities has to satisfy each regime for the data each entity processes.
Do we need a Data Protection Officer under PDPL?
The law dedicates three articles (10–12) to the DPO — appointment in defined cases, the officer’s roles, and the controller’s and processor’s duties towards them. Whether your organisation must appoint one depends on the nature of its processing; that assessment is the usual starting point of a PDPL programme.
How does PDPL compare with India’s DPDP Act?
Both are recent national data-protection laws with consent-centred processing, breach reporting and cross-border transfer controls. Groups operating in both markets can run one privacy programme mapped to both laws — the inventories, rights machinery and breach procedures overlap heavily, while legal bases and regulator interfaces differ.
Are the Executive Regulations to PDPL in force?
This is genuinely unsettled in public sources — reports conflict and we have not found an instrument number confirmed against a primary UAE source. We track it as an open question in our compliance registry rather than asserting a date; check with the UAE Data Office for a current enforcement position.

Need help with UAE PDPL?

CERT-In empanelled, PCI QSA senior auditors can take you from reading about it to compliant — with a scoped, guided programme.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Lawful processing and consent (Articles 4-6)Effective 2 January 2022

    Federal Decree-Law 45/2021 makes consent the default basis for processing personal data, and Article 4 sets out the cases where personal data may be processed WITHOUT the owner's consent (including where necessary to protect the public interest, for legal proceedings, to protect the data subject's interests, or for the controller's legitimate purposes without prejudice to the data subject's rights). Article 5 fixes the personal-data processing controls (fair, transparent and lawful processing; specified purpose; accuracy; minimisation; and secure retention), and Article 6 sets the terms a valid consent must meet.

    Article structure read from the official portal index 11 August 2026; the portal states the Arabic text prevails for interpretation, so clause-level conditions should be checked against the Arabic.

  • Complaints, penalties and Executive Regulation (Articles 24-28)Effective 2 January 2022

    The law provides an enforcement structure: data subjects may file complaints with the UAE Data Office (Article 24), grievances against the Office's decisions are provided for (Article 25), and administrative penalties for violations are established (Article 26). Article 28 provides for an Executive Regulation to be issued to detail the law's implementation. The Decree-Law thus contemplates its own detailed regulations - whether that Executive Regulation has yet been issued is tracked separately and remains unresolved in public sources.

    Article index read from the official portal 11 August 2026. This entry records that Article 28 PROVIDES FOR an Executive Regulation; it does NOT assert that the Regulation has been issued - that is the open question tracked on the uae-pdpl entry.

  • Obligations and rights - article mapEffective 2 January 2022

    Federal Decree-Law 45/2021 requires controllers and processors to meet general obligations (Articles 7-8), report personal data breaches (Article 9), appoint a Data Protection Officer with defined roles (Articles 10-12), honour data-subject rights to information, portability, correction/erasure, restriction and objection (Articles 13-18), secure personal data (Article 20), run data protection impact assessments (Article 21) and control cross-border transfer and sharing (Articles 22-23).

    Article map read from the official portal's English index on 11 August 2026. The portal's own disclaimer states the Arabic text prevails for interpretation; clause-level wording should be checked against the Arabic original.

  • Enactment and effectEffective 2 January 2022

    UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued on 20 September 2021, published in Official Gazette No. 712 (supplement) on 26 September 2021, and came into effect on 2 January 2022; the legislation portal lists it as Active. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.

    OPEN QUESTION - do not treat as settled. Multiple secondary sources report that the Executive Regulations to Federal Decree-Law 45/2021 have been issued, which would activate full enforcement, but they conflict on the instrument and date (one cites Cabinet Decision No. 33 of 2024, others simply say 2026) and none cite a Cabinet Decision number against a primary UAE government source. Not recorded as fact until confirmed from the official gazette or the UAE Data Office.

Ask about UAE PDPL

Answered from CyberSigma’s verified compliance registry — with sources. Not legal advice.