Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
Federal Decree-Law No. 45 of 2021, the UAE's Personal Data Protection Law, took effect on 2 January 2022 and governs how mainland UAE enterprises collect, process, and secure personal data. It requires consent as the default lawful basis, notification to the UAE Data Office within 72 hours of a qualifying breach, and a Data Protection Officer in specific high-risk scenarios. This guide translates those legal obligations into the technical and organisational controls a security team actually needs to build.
Understanding these boundaries first prevents the most common PDPL misreading, treating it as a single uniform obligation rather than a scoped one.
Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data was issued alongside a companion law, Federal Decree-Law No. 44 of 2021, which established the UAE Data Office as the law's supervisory authority. Cabinet Decision No. 111 of 2023 later detailed compliance timelines and several operational specifics as the law's implementing regulation. Our ISO 27001 certification guide covers a related certification path that overlaps substantially with what PDPL compliance requires in practice.
The businesses that translate PDPL obligations into working controls most efficiently are the ones that start from the law's actual article structure rather than a generic privacy checklist, since several of its requirements- breach notification timing and DPO triggers specifically- are stated with real precision rather than left to interpretation.
An enterprise operating a mainland entity alongside a DIFC entity falls under two separate regimes simultaneously, each with its own supervisory authority and its own notification and penalty structure. Our zero trust network access page covers one technical control that typically applies consistently across both regimes, regardless of which law governs a given processing activity.
| PDPL obligation | What it means in practice | Technical or organisational control |
| Lawful basis for processing | Consent is required by default, with ten enumerated exceptions under Article 4 | Consent capture and management system with an audit trail |
| Consent management | Consent must be informed, specific, and freely given, and withdrawable | Consent records showing what was agreed, when, and by whom |
| Data subject access rights | Individuals can request confirmation, access, and details of their processing | A documented process for handling and timing subject access requests |
| Right to erasure and correction | Individuals can request deletion or correction of inaccurate data | Technical capability to locate and remove or correct a specific individual's data |
| Data minimisation and retention limits | Only necessary data is collected, retained only as long as needed | Data retention schedules enforced through automated deletion where feasible |
| Security of processing | Technical and organisational measures proportionate to data sensitivity | Encryption, access control, and logging proportionate to data classification |
| Records of processing activities | Controllers and processors must maintain records of processing | A maintained ROPA (Record of Processing Activities) document |
| Breach notification | Notification to the Data Office and affected subjects where risk exists | An incident response process with a defined notification workflow and timeline |
| Cross-border transfer conditions | Transfers outside the UAE require appropriate safeguards | Transfer impact assessments and contractual safeguards with recipients |
| Processor and supplier obligations | Processors act only on documented controller instructions | Data processing agreements specifying scope, security, and breach obligations |
This table maps the obligation a legal reading surfaces to the control a security team actually has to build and evidence, which is the translation most PDPL guidance skips entirely.
Meeting this window operationally requires several things in place before an incident occurs, not assembled during one. Detection capability that can actually surface a breach quickly matters more than the notification process itself, since a 72-hour clock is meaningless if an entity does not discover a breach until weeks later. A defined severity threshold helps a team decide quickly whether a given incident rises to notifiable risk rather than debating it during the response itself. Evidence preservation, an escalation path with named owners, and a drafted notification template covering the nature, scope, and effect of the breach round out the operational requirement. Our incident response guide covers this detection-to-notification pipeline in more technical depth, including how UAE-specific regulatory windows compare across different frameworks.
The appointed individual can be an employee or an external appointee, and can be based inside or outside the UAE, provided they hold adequate data protection skills and knowledge and their contact details are shared with the Data Office. A related obligation under Article 21 requires a Data Protection Impact Assessment before deploying new technologies likely to create high risk to data subjects, which is a separate but closely connected trigger many enterprises assessing DPO need should evaluate at the same time.
| Area | GDPR position | PDPL position |
| Territorial scope | EU residents' data, regardless of processor location | UAE residents' data, regardless of processor location |
| Lawful bases | Six lawful bases including legitimate interests | Consent-first, with no general legitimate interests basis |
| Data subject rights | Access, erasure, portability, objection, and more | Similar core rights: access, correction, erasure |
| Breach notification window | 72 hours to the supervisory authority | 72 hours, confirmed as the working standard |
| DPO requirement | Mandatory for public authorities and large-scale monitoring | Mandatory under three specific high-risk triggers (Article 10) |
| Cross-border transfers | Adequacy decisions, SCCs, and other safeguard mechanisms | Appropriate safeguards required; mechanism details set in implementing regulations |
| Penalties | Up to €20 million or 4% of global turnover | AED 50,000 to AED 5 million in administrative fines |
The absence of a general legitimate-interests basis is the single biggest practical difference for enterprises arriving from a GDPR programme, since processing activities that relied on legitimate interests under GDPR need a different lawful basis, most often consent, to satisfy the PDPL.
Sequencing realistically, rather than attempting all eight simultaneously, tends to produce a more durable compliance programme than a rushed, parallel effort. Our cyber risk assessment guide covers how to prioritise this kind of sequenced remediation work more broadly. This article provides general guidance on the technical and organisational controls PDPL compliance typically requires and does not constitute legal advice; the published law and its implementing regulations remain the authoritative source for any specific compliance decision.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
What is the UAE PDPL?
Federal Decree-Law No. 45 of 2021, the UAE's federal personal data protection law, in force since January 2022.Does the PDPL apply to companies outside the UAE?
Yes, if they process personal data of individuals inside the UAE, regardless of where the company itself is located.Do DIFC and ADGM companies follow the PDPL?
No. Both operate separate regimes: DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021.Does the PDPL require a data protection officer?
Only under three specific triggers in Article 10: high-risk processing, systematic sensitive-data assessment, or large-scale sensitive data.How does the PDPL differ from GDPR?
Most notably, PDPL has no general legitimate-interests basis; consent is the default lawful basis for processing.What are the penalties for PDPL non-compliance?
Administrative fines ranging from AED 50,000 to AED 5 million, set by Cabinet Resolution under Article 26.Does the PDPL require encryption?
Yes, as part of security measures proportionate to data sensitivity, though the law does not mandate a specific method. See our NESA compliance page.How do we report a data breach in the UAE?
Notify the UAE Data Office within 72 hours of becoming aware, per the law's implementing regulations. See our incident response guide.