GCC Data-Protection & Cybersecurity Laws 2026: Country Guide for Businesses

Date:

Every GCC state except Kuwait now has a standalone personal data protection law, and each is enforced by a dedicated authority. The UAE runs Federal Decree-Law No. 45 of 2021, Saudi Arabia’s PDPL is fully enforced through SDAIA, and Oman’s law took full effect on 5 February 2026. On top of these sit cybersecurity rules such as Saudi Arabia’s NCA Essential Cybersecurity Controls, now expanded to cover all private companies.

What data-protection laws apply across the GCC in 2026?

Data protection in the Gulf is regulated country by country, not by a single bloc-wide statute. Each of the six states has moved to a modern, consent-based framework modelled loosely on Europe’s GDPR, with breach-notification duties and penalties. The table below sets out the core law and regulator in each jurisdiction.

CountryMain data-protection lawRegulator
United Arab EmiratesFederal Decree-Law No. 45 of 2021 (PDPL), in force since 2 January 2022UAE Data Office (plus separate DIFC and ADGM regimes)
Saudi ArabiaPersonal Data Protection Law (PDPL), full enforcement from September 2024SDAIA (Saudi Data & AI Authority)
QatarLaw No. 13 of 2016 on Personal Data Privacy ProtectionNational Cyber Security Agency (NCSA)
BahrainLaw No. 30 of 2018 (PDPL), in force since 2019Personal Data Protection Authority
OmanPersonal Data Protection Law (Royal Decree 6/2022), full effect 5 February 2026Ministry of Transport, Communications & IT (MTCIT)
KuwaitNo comprehensive law yet; CITRA Data Privacy Protection Regulation for telecom sectorCITRA

How does the UAE Personal Data Protection Law work?

In the United Arab Emirates, Federal Decree-Law No. 45 of 2021 (the PDPL) has been in force since 2 January 2022 and applies to organisations processing the personal data of UAE residents. It requires a lawful basis for processing, gives individuals rights of access, correction and erasure, and obliges controllers to report significant breaches. The two financial free zones run their own mature regimes — the DIFC’s Data Protection Law No. 5 of 2020 and the ADGM’s data protection regulations — so a firm’s obligations depend on where it is licensed. Our guide to the UAE digital economy law covers the related rules on AI content and data brokers.

What are Saudi Arabia’s PDPL and NCA cybersecurity controls?

Saudi Arabia’s Personal Data Protection Law is fully enforced, with the grace period ending in September 2024. It is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA) and carries penalties of up to SAR 5 million for the most serious violations. Running alongside it is the National Cybersecurity Authority’s Essential Cybersecurity Controls, updated to the ECC-2:2024 edition. That revision raised the number of controls from 59 to 110, sharpened requirements against ransomware and phishing, and — importantly for the private sector — extended baseline obligations to all companies rather than only operators of critical national infrastructure. For the wider policy picture, see our overview of GCC cybersecurity governance and the Saudi NCA.

Which cyber threats hit GCC businesses hardest?

The Gulf’s wealth, connectivity and rapid digitalisation make it a magnet for attackers. The dominant threats in 2026 are:

  • Ransomware — encryption-plus-extortion attacks aimed at large enterprises, hospitals and government suppliers.
  • Phishing and business email compromise — still the most common entry point, increasingly AI-assisted and highly localised.
  • Supply-chain and cloud misconfiguration — third-party vendors and exposed cloud storage as a route in.
  • DDoS and hacktivism — high-volume disruption campaigns against public-facing services.

Attack volumes are enormous: the UAE alone fends off vast numbers of daily intrusion attempts, as we reported in our coverage of GCC cyber threats in 2026.

How do businesses stay compliant and secure?

Compliance and security overlap but are not the same thing. Practical, no-regret steps for any GCC-based company include:

  • Map where personal data is collected, stored and transferred, and confirm a lawful basis for each use.
  • Appoint a data protection officer or responsible owner, and register with the relevant authority where required.
  • Put a breach-notification playbook in place so regulators and affected people are told within the legal window.
  • Enforce multi-factor authentication, patching, encrypted backups and network segmentation to blunt ransomware.
  • Run staff phishing training — the human layer remains the most exploited.
  • Vet vendors’ security and check cross-border data-transfer rules before moving data outside the country.

FAQ

Is there one GCC-wide data protection law?

No. Each GCC country has its own law and regulator. There is no single Gulf-wide statute, so a business operating across borders must comply with each jurisdiction, and with the separate DIFC and ADGM regimes in the UAE.

Does Kuwait have a data protection law?

Kuwait does not yet have a comprehensive personal data protection law. It has a CITRA Data Privacy Protection Regulation aimed mainly at telecom and internet service providers, and a full national law is anticipated.

What are the penalties for breaking these laws?

Penalties vary by country. Saudi Arabia’s PDPL allows fines up to SAR 5 million for serious violations, and other states impose administrative fines and, in some cases, criminal liability for unlawful disclosure of personal data.

When did Oman’s law take full effect?

Oman’s Personal Data Protection Law, issued under Royal Decree 6/2022, took full effect on 5 February 2026 after a two-year grace period for organisations to comply.

Bottom line: By 2026 five of the six GCC states enforce a dedicated data-protection law — the UAE, Saudi Arabia, Qatar, Bahrain and Oman — each with its own regulator, while Kuwait relies on sector rules pending a full statute. Layered on top are cybersecurity mandates such as Saudi Arabia’s NCA ECC-2:2024. For Gulf businesses, staying safe means treating compliance and ransomware defence as one programme: know your data, secure your systems and be ready to report a breach fast.

Ahmed Al Farsi
Ahmed Al Farsi
Ahmed Al Farsi writes the Gulf Briefing, our coverage of all six GCC states — the UAE, Saudi Arabia, Qatar, Kuwait, Oman and Bahrain. He follows policy, regulation and the decisions taken in the region that readers feel later, and reports each country on its own terms rather than through a single capital.

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

Abu Dhabi Judicial Department: Wills, Courts and Non-Muslim Inheritance

Abu Dhabi has its own wills registry, and on eligibility it is broader than DIFC — plus the intestacy default your heirs can still apply to displace.

How the UAE Left the FATF Grey List — and What Did Not Change

The UAE came off FATF monitoring on 23 February 2024 with three other countries — and was never blacklisted. What delisting did not change for businesses.

Al Wathba Wetland Reserve: Abu Dhabi’s Flamingo Sanctuary

The flamingo figure everyone quotes is a seasonal peak. The real story is 1,000 nests — and the GCC’s first IUCN Green List site almost nobody mentions.

UAE Commercial Agency Law: What Federal Law 3 of 2022 Changed

The 2022 agency law did not open agencies to foreign ownership, and the transition is not two years. What the Ministry’s own text actually says.