If you have been told your UAE business must comply with the data protection law by a particular date,
or that breaches must be reported within 72 hours, or that fines run to a specific number of dirhams —
none of that is currently law.
The UAE data protection law exists and is in force. The regulations that would make
most of it operational have not been issued. That gap is the single most important thing to understand
about compliance here, and it is missing from almost everything written on the subject.
What is actually in force
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — the PDPL — came into force on
2 January 2022. The government describes it as “an integrated framework to ensure the
confidentiality of information and protect the privacy of individuals in the UAE”, and notes it was the
first federal law drafted in partnership with major private-sector technology companies.
Its core provisions are real and do apply:
| Provision | What it does |
|---|---|
| Scope | Applies to processing of personal data, in whole or part, through electronic systems, inside or outside the country — extraterritorial reach |
| Consent | Prohibits processing without the data owner’s consent, except where necessary to protect a public interest or to carry out legal procedures and rights |
| Data subject rights | Includes the right to request correction of inaccurate data and to restrict or stop processing |
| Cross-border transfer | Sets out requirements for transferring and sharing personal data abroad for processing |
Separately, Federal Decree-Law No. 44 of 2021 established the UAE Data Office as the
federal data regulator, affiliated with the Cabinet. Its published responsibilities are preparing
policies and legislation, proposing and approving standards for monitoring the law, preparing complaints
and grievance systems, and issuing guidelines for implementation.
Note that the Data Office is created by a different law from the PDPL. The two decree-laws were issued
together and are constantly merged into one in secondary writing.
The correction: the Executive Regulations have not been issued
Article 28 of the PDPL requires the Cabinet to issue Executive Regulations on the proposal of the
Director General of the Data Office. Article 29 then gives controllers and processors a period to bring
themselves into conformity — a period that runs from the issuance of those Regulations.
They have not been published. The international law-firm tracker maintained by DLA Piper put it plainly
as at 6 January 2025: the executive regulations “were due to be published within six months of the
issuance of the PDPL. However as of 6 January 2025, those have not yet been published.”
The government’s own PDPL page corroborates this by omission. It describes the law, the Data Office and
the Office’s future role in issuing implementing guidance — and makes no mention of any Executive
Regulation at all. A portal describing a fully implemented regime would say so.
Why that matters commercially
Almost every operative detail a compliance team needs sits in the unissued Regulations:
| What businesses ask about | Status |
|---|---|
| When you must appoint a Data Protection Officer | In the Regulations — not yet issued |
| What triggers a data protection impact assessment | In the Regulations — not yet issued |
| The breach notification clock | In the Regulations — not yet issued |
| The cross-border adequacy list and contractual clause templates | In the Regulations — not yet issued |
| The administrative fine schedule | Set by Cabinet decision under Article 26 — not yet published |
| Your compliance deadline | Runs from issuance under Article 29 — the clock has not started |
So when a consultancy quotes you a PDPL fine figure or a 72-hour breach deadline, ask which instrument
it comes from. The “72 hours” figure is an analyst’s inference from market practice and from the DIFC and
ADGM regimes — it is not a UAE federal requirement.
This is not an argument for doing nothing. The consent rule, the extraterritorial scope and the
cross-border requirements are live obligations today. It is an argument for knowing which of your
obligations are law and which are a vendor’s roadmap.
Two claims that are simply false
“Article 44 of the PDPL directed that executive regulations would be issued within six
months.” There is no Article 44. The law contains exactly 31 articles, numbered 1 to 31 with no
gaps. The Executive Regulations article is Article 28; adjustment of status is Article
29; repeals are Article 30; publication and entry into force is Article 31. A citation to Article 44 is a
reliable marker that the text was generated or copied rather than read.
“Cabinet Decision No. 33 of 2024 is the PDPL Executive Regulation.” No government
source supports this. The same document making that claim also asserted the Regulations were issued in
2026 — two contradictory statements in one text, which is its own warning label.
The carve-out that catches Dubai and Abu Dhabi businesses
The PDPL is not the UAE’s only data protection law, and it does not apply in DIFC or
ADGM. Both financial free zones have their own separate regimes, expressly preserved — the
government portal points readers to DIFC Law No. 5 of 2020 alongside the federal law, and the same
carve-out covers Dubai Healthcare City.
The practical consequence: a business in DIFC answers to the DIFC Commissioner of Data Protection, not
the UAE Data Office, and its obligations are already fully specified — because those regimes have their
regulations. Our comparison of
DIFC and ADGM and
our explainer on
ADGM’s separate legal
framework set out why those two jurisdictions run their own rulebooks on almost everything.
So “the UAE data protection law” is a misleading phrase for a large share of businesses in exactly the
two districts where the most data-intensive companies sit.
What to do now
Three things are worth doing regardless of when the Regulations land.
Get consent right. The prohibition on processing without consent is in force now, with
narrow exceptions for public interest and legal procedures.
Map your cross-border flows. The requirement exists; only the mechanics are pending.
Knowing where your data goes is the work that will not change when the adequacy list appears.
Know which regime you are in. Mainland, free zone, DIFC, ADGM and Dubai Healthcare
City are not the same answer. Our guides to
free zone versus mainland
setup and Dubai’s free
zones cover the choice, and businesses handling regulated data should also see our explainer on
Dubai’s crypto regulation under
VARA for a comparable example of a zone-specific regime.
Consumer data has a second, older layer too: Federal Law No. 15 of 2020 on Consumer Protection also
protects consumer data and prohibits suppliers from using it for marketing.
The UAE has moved fast on the technology itself — our overview of the
AI Strategy 2031
covers the ambition. The data-protection scaffolding around it is, for now, a law with its foundations in
place and its operating manual still unwritten. Saying so is more useful than pretending otherwise.
Primary sources: the UAE Government portal on
data
protection laws, and the text of Federal Decree-Law 45 of 2021
as
published on the UAE Government portal, from which the article count and structure above were read
directly. The statement that the Executive Regulations remain unissued is dated to
DLA
Piper’s data protection tracker — a law-firm source, cited as such. This article is general
information, not legal advice.


