The UAE Has a Data Protection Law — and Most Businesses Aren't Ready For It
For years, the UAE had no comprehensive federal data protection law. That changed with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — the PDPL — overseen by the newly created UAE Data Office. If your business collects, stores, or processes personal data of individuals in the UAE — customers, employees, patients, website visitors — the PDPL applies to you.
Most UAE businesses are not ready, for two reasons. First, they assume "we're GDPR-aligned, so we're fine" — but the PDPL is its own law with its own requirements, not a copy of GDPR. Second, they don't know where their personal data actually lives, which makes every other obligation impossible to meet. This is a practical walkthrough of what the law expects and how to get compliant — from running the engagements, not reciting the statute.
First: Which Law Actually Applies to You
This trips up almost everyone, and getting it wrong wastes months.
The UAE has multiple data protection regimes:
- The federal PDPL (Decree-Law 45 of 2021) applies onshore and across most of the country.
- The DIFC (Dubai International Financial Centre) has its own DIFC Data Protection Law — separate, GDPR-style, with its own Commissioner.
- The ADGM (Abu Dhabi Global Market) has its own Data Protection Regulations — also separate.
If you're a company in DIFC or ADGM, your primary obligation is to that free zone's law, not the federal PDPL. If you're onshore, it's the PDPL. Many businesses operate across both and need to satisfy more than one. Confirm which regime(s) govern you before you do anything else — it determines the entire programme.
A note on specifics: the PDPL's Executive Regulations and the UAE Data Office's guidance govern the precise procedures and timelines (breach-notification windows, transfer mechanisms, registration details). Always work from the current published regulations, not from memory — including this article.
What the PDPL Requires
The PDPL is built on obligations that will feel familiar if you know GDPR — but the details differ, so don't assume.
- A lawful basis for processing. You need a legitimate reason to process personal data — consent being the most visible, but not the only one. Consent must be properly obtained and withdrawable.
- Data subject rights. Individuals can request access to their data, correction, erasure, restriction of processing, portability, and can object to certain processing. You need an operational process to handle these requests within the statutory window.
- Record of Processing Activities (RoPA). A documented inventory of what personal data you process, why, where it goes, and how long you keep it. This is the foundation — you cannot comply with anything else if you don't know what you hold.
- Data Protection Impact Assessments (DPIA). For high-risk processing, a documented assessment of the risk and how you mitigate it.
- Breach notification. Personal-data breaches must be reported to the Data Office (and affected individuals in certain cases) within the timelines the regulations set.
- Cross-border transfer controls. Moving personal data outside the UAE is restricted — permitted to jurisdictions with adequate protection, or under specified safeguards. Your cloud providers, SaaS tools, and group entities abroad all count.
- Data Protection Officer (DPO). Required in defined circumstances (large-scale or sensitive processing). You decide whether to appoint internally or outsource.
The Implementation Journey — What Good Looks Like
- Confirm your regime. PDPL, DIFC, ADGM, or a combination (see above).
- Data mapping. Interview the business and technical teams and map every personal-data flow: collection point, purpose, lawful basis, recipients, storage location, retention. Everything else depends on this.
- Build the RoPA from the data map — a living register, owner-tagged, with a quarterly maintenance process your team can actually run.
- DPIAs for the high-risk processing the data map surfaces.
- Policies. External (website privacy notice, app) and internal (employee data, retention, breach response). Specific to the PDPL — not GDPR copies.
- Data subject rights workflow. A runnable process — in your ticketing or CRM — to handle access, deletion, correction, and objection requests inside the statutory window. A policy alone isn't enough; it has to work.
- Cross-border transfer assessment. Map every transfer out of the UAE (cloud, SaaS, group entities) and document the lawful basis for each.
- Breach-readiness. An incident-response process aligned to the notification timelines, so a breach doesn't become a second crisis.
- DPO decision + appointment where required.
- Awareness training for everyone who handles personal data.
The Mistakes We See Most Often
- "We're GDPR-compliant, so we're fine." The PDPL is its own law. GDPR work is a strong head start, not a free pass — the lawful bases, transfer rules, and procedures differ.
- Not knowing where the data is. Without a data map and RoPA, every other obligation is guesswork. This is always the first real piece of work.
- Ignoring the free-zone distinction. A DIFC company chasing federal PDPL compliance (or vice versa) wastes effort on the wrong regime.
- Forgetting cross-border transfers. Your data is already leaving the UAE — every overseas cloud region and SaaS vendor. Most businesses have never documented the lawful basis.
- A privacy policy with no operational backing. A polished notice on the website means nothing if you can't actually fulfil a deletion request when one arrives.
- Treating it as a one-off project. Personal data flows change constantly. Compliance is a maintained state, not a certificate on the wall.
Timeline and How to Start
A PDPL implementation typically runs 8–12 weeks for a mid-size organisation — data mapping, RoPA, DPIAs, the policy stack, the rights workflow, transfer assessment, and training. The single best first step is the data-mapping and RoPA exercise: it's the foundation everything else builds on, and it immediately tells you your biggest exposures.
Healthcare organisations in Abu Dhabi often run PDPL alongside ADHICS — the two overlap, and doing them together is more efficient than sequentially.
Working With Underwings
We deliver PDPL as a hands-on implementation — data mapping, a populated RoPA, DPIAs, the policy stack, a runnable data-subject-rights workflow, cross-border transfer documentation, and staff training — led by a senior practitioner, not a junior. Transparent AED pricing, fixed written quotes within 48 hours, and a limited number of founding-client places at preferential rates while we build our public track record.
If the PDPL is on your radar — or you've realised you don't actually know where your personal data lives — a free 30-minute scoping call will tell you where you stand. Book at book.underwings.org, email [email protected], or call +971 50 567 0394.
Manoj Prabhakaran is an ISO 27001 Lead Auditor (CPTS, Azure Security) and leads GRC and compliance at Underwings Cybersecurity Solutions, Abu Dhabi.