Discover your OT Blind spots today! Get your free Executive Readiness Heatmap.

Contact Us
Close
Chat
Get In Touch

Get Immediate Help

Get in Touch!

Tell us what you need and we’ll connect you with the right specialist within 10 minutes.

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

We appreciate your interest in our cybersecurity services! Our team will review your submission and reach out to you soon to discuss next steps.

UK: +44 (0)20 3336 7200
UAE: +971 454 01252
KSA: +966 1351 81844

4.9 Microminder Cybersecurity

310 reviews on

Trusted by 2600+ Enterprises & Governments

Trusted by 2600+ Enterprises & Governments

Contact the Microminder Team

Need a quote or have a question? Fill out the form below, and our team will respond to you as soon as we can.

What are you looking for today?

Managed security Services

Managed security Services

Cyber Risk Management

Cyber Risk Management

Compliance & Consulting Services

Compliance & Consulting Services

Cyber Technology Solutions

Cyber Technology Solutions

Selected Services:

Request for

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

In the meantime, please help our team scope your requirement better and to get the right expert on the call by completing the below section. It should take 30 seconds!

30 seconds!

Untick the solutions you don’t need

  • Untick All
  • Untick All
  • Untick All
  • Untick All
Thank You

What happens next?

Thanks for considering us for your cybersecurity needs! Our team will review your submission and contact you shortly to discuss how we can assist you.

01

Our cyber technology team team will contact you after analysing your requirements

02

We sign NDAs for complete confidentiality during engagements if required

03

Post a scoping call, a detailed proposal is shared which consists of scope of work, costs, timelines and methodology

04

Once signed off and pre-requisites provided, the assembled team can commence the delivery within 48 hours

05

Post delivery, A management presentation is offered to discuss project findings and remediation advice

Home  Resources  Blogs  UAE PDPL Compliance: What Federal Decree-Law 45 Requires of Enterprises

UAE PDPL Compliance: What Federal Decree-Law 45 Requires of Enterprises

 
Sanjiv Cherian

Sanjiv Cherian, Chief Commercial Officer
Sep 16, 2026

  • LinkedIn

Federal Decree-Law No. 45 of 2021, the UAE's Personal Data Protection Law, took effect on 2 January 2022 and governs how mainland UAE enterprises collect, process, and secure personal data. It requires consent as the default lawful basis, notification to the UAE Data Office within 72 hours of a qualifying breach, and a Data Protection Officer in specific high-risk scenarios. This guide translates those legal obligations into the technical and organisational controls a security team actually needs to build.

Key Takeaways

Before mapping PDPL obligations to controls, these points set the scope correctly.

  • The PDPL applies to mainland UAE entities and to any entity processing UAE residents' data, regardless of where that entity is located.
  • Consent is the default lawful basis for processing, with ten enumerated exceptions where consent is not required.
  • A qualifying data breach must be notified to the UAE Data Office within 72 hours, the working standard confirmed through the law's implementing regulations.
  • A Data Protection Officer is mandatory under three specific conditions, not as a general requirement for every organisation.
  • DIFC and ADGM operate entirely separate data protection regimes; the PDPL does not apply within either free zone.


Understanding these boundaries first prevents the most common PDPL misreading, treating it as a single uniform obligation rather than a scoped one.

What Federal Decree-Law 45 Requires of UAE Enterprises

The UAE Personal Data Protection Law has been in force since January 2022, and by now most enterprises have read a legal summary of what it says. Far fewer have translated that summary into the technical and organisational controls a security team actually needs to operate day-to-day, which is the gap this guide addresses.

Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data was issued alongside a companion law, Federal Decree-Law No. 44 of 2021, which established the UAE Data Office as the law's supervisory authority. Cabinet Decision No. 111 of 2023 later detailed compliance timelines and several operational specifics as the law's implementing regulation. Our ISO 27001 certification guide covers a related certification path that overlaps substantially with what PDPL compliance requires in practice.

The businesses that translate PDPL obligations into working controls most efficiently are the ones that start from the law's actual article structure rather than a generic privacy checklist, since several of its requirements- breach notification timing and DPO triggers specifically- are stated with real precision rather than left to interpretation.

Who the PDPL Applies To

The law's territorial scope is broader than many enterprises initially assume, extending well beyond entities physically located in the UAE.

  • Any controller or processor located in the UAE that processes personal data of subjects inside or outside the country.
  • Any controller or processor located outside the UAE, processing personal data of subjects inside the country.
  • The law excludes government data, data held by security and judicial authorities, personal health data (regulated separately under Federal Law No. 2 of 2019), and personal financial data.
  • DIFC and ADGM maintain their own separate data protection regimes, DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 respectively, and the federal PDPL does not apply within either free zone.


An enterprise operating a mainland entity alongside a DIFC entity falls under two separate regimes simultaneously, each with its own supervisory authority and its own notification and penalty structure. Our zero trust network access page covers one technical control that typically applies consistently across both regimes, regardless of which law governs a given processing activity.

Core Obligations and the Controls That Satisfy Them

Translating legal duty into operational control is where most PDPL compliance work actually happens, and it is the piece missing from most legal summaries of the law.


PDPL obligationWhat it means in practiceTechnical or organisational control
Lawful basis for processingConsent is required by default, with ten enumerated exceptions under Article 4Consent capture and management system with an audit trail
Consent managementConsent must be informed, specific, and freely given, and withdrawableConsent records showing what was agreed, when, and by whom
Data subject access rightsIndividuals can request confirmation, access, and details of their processingA documented process for handling and timing subject access requests
Right to erasure and correctionIndividuals can request deletion or correction of inaccurate dataTechnical capability to locate and remove or correct a specific individual's data
Data minimisation and retention limitsOnly necessary data is collected, retained only as long as neededData retention schedules enforced through automated deletion where feasible
Security of processingTechnical and organisational measures proportionate to data sensitivityEncryption, access control, and logging proportionate to data classification
Records of processing activitiesControllers and processors must maintain records of processingA maintained ROPA (Record of Processing Activities) document
Breach notificationNotification to the Data Office and affected subjects where risk existsAn incident response process with a defined notification workflow and timeline
Cross-border transfer conditionsTransfers outside the UAE require appropriate safeguardsTransfer impact assessments and contractual safeguards with recipients
Processor and supplier obligationsProcessors act only on documented controller instructionsData processing agreements specifying scope, security, and breach obligations

This table maps the obligation a legal reading surfaces to the control a security team actually has to build and evidence, which is the translation most PDPL guidance skips entirely.

Meeting Breach Notification Duties in Practice

The PDPL requires the controller to notify the UAE Data Office without undue delay after becoming aware of a breach that might result in a risk to a data subject's privacy, confidentiality, or security, with 72 hours confirmed as the working notification standard through the law's implementing regulations and consistent regulatory guidance since. A processor discovering a breach must immediately notify the controller, who then carries the notification obligation onward to the Data Office and, where the risk warrants it, to affected individuals directly.

Meeting this window operationally requires several things in place before an incident occurs, not assembled during one. Detection capability that can actually surface a breach quickly matters more than the notification process itself, since a 72-hour clock is meaningless if an entity does not discover a breach until weeks later. A defined severity threshold helps a team decide quickly whether a given incident rises to notifiable risk rather than debating it during the response itself. Evidence preservation, an escalation path with named owners, and a drafted notification template covering the nature, scope, and effect of the breach round out the operational requirement. Our incident response guide covers this detection-to-notification pipeline in more technical depth, including how UAE-specific regulatory windows compare across different frameworks.

When You Need a Data Protection Officer

The PDPL does not require every organisation to appoint a Data Protection Officer, and treating it as a universal requirement creates unnecessary overhead for enterprises that do not meet the triggers. Article 10 requires a DPO in three specific circumstances: where processing carries a high risk to privacy and confidentiality due to new technologies or the volume of data involved, where processing involves a systematic and comprehensive assessment of sensitive personal data including profiling and automated decision-making, or where processing involves a large volume of sensitive personal data.

The appointed individual can be an employee or an external appointee, and can be based inside or outside the UAE, provided they hold adequate data protection skills and knowledge and their contact details are shared with the Data Office. A related obligation under Article 21 requires a Data Protection Impact Assessment before deploying new technologies likely to create high risk to data subjects, which is a separate but closely connected trigger many enterprises assessing DPO need should evaluate at the same time.

PDPL and GDPR Compared

Most UAE enterprises approach PDPL compliance having already done GDPR work, and understanding where the two align saves real duplicated effort.


AreaGDPR positionPDPL position
Territorial scopeEU residents' data, regardless of processor locationUAE residents' data, regardless of processor location
Lawful basesSix lawful bases including legitimate interestsConsent-first, with no general legitimate interests basis
Data subject rightsAccess, erasure, portability, objection, and moreSimilar core rights: access, correction, erasure
Breach notification window72 hours to the supervisory authority72 hours, confirmed as the working standard
DPO requirementMandatory for public authorities and large-scale monitoringMandatory under three specific high-risk triggers (Article 10)
Cross-border transfersAdequacy decisions, SCCs, and other safeguard mechanismsAppropriate safeguards required; mechanism details set in implementing regulations
PenaltiesUp to €20 million or 4% of global turnoverAED 50,000 to AED 5 million in administrative fines

The absence of a general legitimate-interests basis is the single biggest practical difference for enterprises arriving from a GDPR programme, since processing activities that relied on legitimate interests under GDPR need a different lawful basis, most often consent, to satisfy the PDPL.

Where to Start if You Have Done Nothing Yet

Building PDPL compliance from a standing start follows a reasonably predictable sequence, regardless of enterprise size or sector.

  1. Data mapping and inventory: establishing what personal data exists, where it sits, and who processes it.
  2. Lawful basis review, confirming every processing activity has a valid basis under Article 4.
  3. Privacy notice update, ensuring data subjects are properly informed of how their data is used.
  4. Retention schedule, defining how long each category of data is kept and how it is disposed of.
  5. Access control review, confirming technical measures are proportionate to data sensitivity.
  6. Processor contract review, ensuring data processing agreements meet the standard's requirements.
  7. Breach response process, building the detection-to-notification pipeline covered above.
  8. Staff training, since most PDPL failures trace back to a process nobody followed rather than a process that did not exist.


Sequencing realistically, rather than attempting all eight simultaneously, tends to produce a more durable compliance programme than a rushed, parallel effort. Our cyber risk assessment guide covers how to prioritise this kind of sequenced remediation work more broadly. This article provides general guidance on the technical and organisational controls PDPL compliance typically requires and does not constitute legal advice; the published law and its implementing regulations remain the authoritative source for any specific compliance decision.

Don’t Let Cyber Attacks Ruin Your Business

  • Certified Security Experts: Our CREST and ISO27001 accredited experts have a proven track record of implementing modern security solutions
  • 41 years of experience: We have served 2600+ customers across 20 countries to secure 7M+ users
  • One Stop Security Shop: You name the service, we’ve got it — a comprehensive suite of security solutions designed to keep your organization safe

FAQs

What is the UAE PDPL?

Federal Decree-Law No. 45 of 2021, the UAE's federal personal data protection law, in force since January 2022.

Does the PDPL apply to companies outside the UAE?

Yes, if they process personal data of individuals inside the UAE, regardless of where the company itself is located.

Do DIFC and ADGM companies follow the PDPL?

No. Both operate separate regimes: DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021.

Does the PDPL require a data protection officer?

Only under three specific triggers in Article 10: high-risk processing, systematic sensitive-data assessment, or large-scale sensitive data.

How does the PDPL differ from GDPR?

Most notably, PDPL has no general legitimate-interests basis; consent is the default lawful basis for processing.

What are the penalties for PDPL non-compliance?

Administrative fines ranging from AED 50,000 to AED 5 million, set by Cabinet Resolution under Article 26.

Does the PDPL require encryption?

Yes, as part of security measures proportionate to data sensitivity, though the law does not mandate a specific method. See our NESA compliance page.

How do we report a data breach in the UAE?

Notify the UAE Data Office within 72 hours of becoming aware, per the law's implementing regulations. See our incident response guide.
Federal Decree-Law No. 45 of 2021, the UAE's federal personal data protection law, in force since January 2022.
Yes, if they process personal data of individuals inside the UAE, regardless of where the company itself is located.
No. Both operate separate regimes: DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021.
Only under three specific triggers in Article 10: high-risk processing, systematic sensitive-data assessment, or large-scale sensitive data.
Most notably, PDPL has no general legitimate-interests basis; consent is the default lawful basis for processing.
Administrative fines ranging from AED 50,000 to AED 5 million, set by Cabinet Resolution under Article 26.
Yes, as part of security measures proportionate to data sensitivity, though the law does not mandate a specific method. See our NESA compliance page.
Notify the UAE Data Office within 72 hours of becoming aware, per the law's implementing regulations. See our incident response guide.