Data Protection Law in the UAE: What Businesses Must Do
The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, requires any business that processes the personal data of individuals in the UAE to have a lawful basis for that processing, generally consent, unless an exception applies, honour data subject rights such as access and erasure, keep records of processing activities, notify the UAE Data Office and affected individuals of serious data breaches, and appoint a Data Protection Officer where processing is large-scale or high-risk. The DIFC and ADGM run their own separate, generally stricter data protection laws that take precedence for entities licensed in those zones.
Data protection used to be something only banks and tech companies worried about in the UAE.
Federal Decree-Law No. 45 of 2021, the UAE's first comprehensive Personal Data Protection Law, changed that by giving the country a general privacy framework that reaches ordinary businesses, from a clinic keeping patient records to an e-commerce store with a customer email list.
This guide covers what the law actually requires, in plain terms.
What the PDPL Covers
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, overseen by the UAE Data Office established under a related Decree-Law, sets out a general framework for how businesses, both controllers and processors, collect, use, store and share personal data belonging to individuals.
It reaches beyond companies physically based in the UAE in some respects, since processing the data of individuals located in the UAE can bring an out-of-country business within scope.
The law excludes certain categories, such as government data processed for security or judicial purposes, and it works alongside, rather than instead of, sector-specific rules for health and banking data.

Before the PDPL, UAE businesses generally relied on general contract law and sector-specific rules to handle privacy questions, which left real gaps for an ordinary business collecting customer names, phone numbers and payment details with no dedicated national framework governing that data specifically.
The PDPL closes that gap, and it means a privacy clause buried in generic terms and conditions is no longer enough on its own; a business needs an actual lawful basis and an actual process behind that clause.
The consolidated text and the government's own summary of the UAE Personal Data Protection Law sit on the UAE Government Portal, which is the reference to check when a specific obligation matters.
Controllers, Processors, and Where You Sit
A controller is the business that decides why and how personal data is processed, an online retailer deciding to collect customer addresses for delivery, for example. A processor handles data on the controller's instructions, a cloud hosting provider or a payroll outsourcing firm, for instance.
Most obligations sit primarily with the controller, but processors carry their own responsibilities too, particularly around security and using data only as instructed.
Many businesses are both: a controller for their own customer data, and a processor when they handle data on behalf of a client.
The relationship between a controller and a processor should be documented, typically through a data processing agreement or clause in the main service contract, setting out what the processor is allowed to do with the data, how long it can keep it, and what security measures it must maintain.
A business outsourcing customer data handling to a marketing agency, a call centre, or a software vendor without this kind of agreement in place is exposed if that vendor mishandles the data, since the controller generally remains accountable to the individual regardless of who actually processed it.
Lawful Basis for Processing
Before processing personal data, a business needs a lawful basis. Consent from the data subject is the default and most common basis, and it must be clear, specific, and freely given, not buried in unrelated terms and conditions.
The law also recognises defined exceptions where consent is not required, such as processing necessary to perform a contract with the individual, to comply with a legal obligation, or for the legitimate interests of the controller where those interests do not override the individual's rights and freedoms.
Sensitive categories of data, health, biometric, or data revealing certain protected characteristics, carry a higher bar and generally need explicit consent or a specific legal basis.

A frequent mistake is treating a single, broad consent obtained once, for example at account sign-up, as covering every future use of that customer's data indefinitely, including uses the business had not planned when consent was first collected.
Consent should be specific to the purpose it was given for, and a genuinely new use, selling data to a third-party marketer, for instance, when the original consent only covered order fulfilment, generally needs its own fresh basis rather than relying on the original blanket agreement.
Data Subject Rights
Individuals whose data you hold have a defined set of rights under the PDPL, and a business needs a real process to honour them, not just a policy statement.
A workable process usually means a single point of contact, an email address or a form, where a request can be submitted, a defined internal timeframe for responding, and a clear owner inside the business responsible for actioning it, rather than a request landing in a general inbox and being handled ad hoc whenever someone notices it.

None of these rights are absolute. A right to erasure, for example, does not override a legal obligation to retain certain financial or tax records for a set period, and a right to access can be balanced against genuine confidentiality concerns involving other people's data.
The point is not that every request must be granted exactly as asked, but that every request must be properly considered and answered, rather than ignored, with the reasoning for any refusal documented in case it is later challenged.
- Right to access. Individuals can ask what data you hold on them and how it is used.
- Right to correction. Inaccurate data must be corrected on request.
- Right to erasure. Data can be deleted where there is no legal basis to keep it.
- Right to object and restrict. Individuals can object to certain processing, such as direct marketing.
- Right to data portability. Data can be requested in a usable format to move to another provider, in defined circumstances.
Honouring these rights is not just a legal box to tick, it is also usually the first thing a frustrated customer tests when something has gone wrong, an unwanted marketing email, a data sale they never agreed to, a record they want removed.
A business with a real, working process for these requests turns what could become a complaint or a regulator referral into a routine customer service interaction instead.
Data Protection Officer Requirement
A business must appoint a Data Protection Officer in specific circumstances: where processing carries a high risk due to the use of new technology, where large-scale processing of sensitive data occurs, or where the business engages in large-scale, regular and systematic monitoring of individuals.
Not every business needs a dedicated DPO, but every business should assess whether it meets these triggers, since the assessment itself is expected, not optional.
A DPO can be an employee or an outsourced service, but must have genuine authority and independence to do the role.
We help new companies set up compliant data handling alongside their licence from day one. Price your setup here.
Records, Security and Breach Notification
Controllers and processors are expected to maintain records of their processing activities and to implement appropriate technical and organisational security measures proportionate to the risk, encryption, access controls, staff training, and so on.
If a data breach occurs that is likely to cause serious harm or risk to individuals, the business must notify the UAE Data Office, and in cases of significant risk, notify the affected individuals directly, within the timeframe set by the implementing regulations.
Because the specific notification window and thresholds sit in executive regulations that can be updated, confirm the current requirement with your compliance adviser rather than assuming a fixed number of days.

| Obligation | What it involves |
|---|---|
| Lawful basis | Consent, contract necessity, legal obligation, or legitimate interest |
| Data subject rights | Access, correction, erasure, objection, portability |
| Records of processing | Documented log of what data is processed and why |
| Security measures | Technical and organisational controls proportionate to risk |
| Breach notification | To the UAE Data Office, and to individuals in high-risk cases |
| Cross-border transfer | Requires an adequate level of protection or approved safeguards |
Cross-Border Data Transfers
Transferring personal data outside the UAE is allowed where the receiving country or organisation is assessed to provide an adequate level of protection, or where appropriate safeguards, such as contractual clauses, are in place.
This matters for any UAE business using an overseas cloud provider, a foreign parent company, or an international payment processor.
Check where your data actually sits and flows to, not just where your servers are marketed as being located, since the practical answer is sometimes different from the assumption.
How DIFC and ADGM Differ
The DIFC and ADGM each have their own, separate data protection regimes, the DIFC Data Protection Law and the ADGM Data Protection Regulations, both generally modelled closer to European-style rules and, in several respects, stricter than the federal PDPL.
A company licensed in either financial free zone should comply with that zone's law for its own data processing, rather than the federal PDPL, and should not assume federal compliance automatically satisfies the zone's requirements.
This distinction matters most for group structures that operate both a DIFC entity and a mainland or other free zone entity under the same brand.
Customer data collected through the DIFC entity should be handled under DIFC rules, while data collected through the other entity follows the federal PDPL, even if the two entities share systems, staff, or a single customer database in practice.
Mapping which entity actually collects which data is a necessary first step before deciding which law governs it.
A Practical Starting Checklist
- Map what personal data your business collects, from customers, employees and any third parties.
- Confirm the lawful basis for each type of processing, and fix any that rely on unclear consent.
- Build a simple process to respond to access, correction and deletion requests.
- Assess whether your processing triggers the Data Protection Officer requirement.
- Review where customer and employee data is actually stored and transferred, including third-party tools.
- Confirm whether your entity falls under the federal PDPL or a DIFC or ADGM specific regime.
Data Protection as Ongoing Practice, Not a One-Time Policy
A privacy policy published once and never revisited is not compliance, it is a document.
Real PDPL compliance is an ongoing practice: reviewing new tools and vendors for where they send data, training staff on how to handle a data subject request, and updating your processing records as your business adds new products or markets.
Build this into the same rhythm as your other compliance calendar items, and treat any new customer-facing feature as a privacy question before it is a technical one.
New businesses have an advantage here that established ones often do not: the chance to build data handling correctly from the first customer record rather than retrofitting a privacy programme onto years of accumulated, poorly documented data.
If you are setting up a new UAE company, treating your privacy policy, your consent flows, and your vendor list as part of company setup itself, alongside your licence and registrations, saves a much larger cleanup exercise later, and it signals to customers and partners from day one that data is handled with real care rather than as an afterthought.
Frequently asked questions
Generally yes. The PDPL applies broadly to businesses processing personal data of individuals in the UAE, regardless of size, though the practical obligations, such as whether a Data Protection Officer is required, scale with the volume and sensitivity of the data processed.
The federal PDPL, Federal Decree-Law No. 45 of 2021, applies to mainland and most free zone entities. The DIFC and ADGM each run their own separate, generally stricter data protection laws for entities licensed in those specific financial free zones, and those zone laws take precedence there.
Consent is the default lawful basis under the PDPL and must be clear, specific and freely given. There are recognised exceptions, such as processing necessary to perform a contract or comply with a legal obligation, where consent is not strictly required, but these exceptions are specific, not a general workaround.
A Data Protection Officer is required where processing involves high-risk new technology, large-scale processing of sensitive data, or large-scale, regular and systematic monitoring of individuals. Every business should assess whether it meets these triggers rather than assuming a DPO is unnecessary.
Serious breaches likely to cause harm or risk to individuals must be notified to the UAE Data Office, and to the affected individuals directly where the risk is significant, within the timeframe set by the implementing regulations. Confirm the current notification window with your compliance adviser.
See the number for your setup
The cost calculator runs on Dubai Business Corporation’s real price book. Answer a few questions and get your total, fully itemised, in under a minute.


