Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
United Arab Emirates
In force since 2 January 2022
The PDPL delegates significant operational detail to Executive Regulations, which current specialist legal trackers report have not yet been published.
Asia & Africa
Federal Decree-Law No. 45 of 2021
UAE Personal Data Protection Law / UAE PDPL
2 January 2022
United Arab Emirates, subject to statutory scope and exemptions
Controllers and Processors
Important lawful basis; not the only permitted basis
Additional requirements apply
Access, correction, deletion, restriction, objection and other rights
Required in specified circumstances
Required for specified high-risk processing
Regulated
Appropriate technical and organisational measures required
Regulated; detailed operational requirements depend partly on implementing rules
Specific safeguards and rights apply
Separate regimes
United Arab Emirates
The federal PDPL applies to processing of personal data through electronic systems and other means in the circumstances established by Article 2. The law covers Data Subjects residing in the UAE or having a place of business in the UAE; Controllers or Processors established in the UAE processing personal data of Data Subjects inside or outside the UAE; and Controllers or Processors established outside the UAE processing personal data of Data Subjects inside the UAE. This means that an organisation does not necessarily escape the UAE PDPL simply because its headquarters, servers or processing infrastructure are located outside the UAE.
The PDPL establishes a framework for administrative penalties but does not itself provide one universal headline fine for every violation. Article 26 provides that the Council of Ministers is to issue a decision specifying violations and administrative penalties based on the recommendation of the relevant authority. Because the detailed penalty framework depends on implementing decisions, businesses should avoid publishing a single generic UAE PDPL fine amount without verifying the applicable current instrument. The law also contains criminal provisions for specified conduct. Organisations should therefore assess the nature of the violation, whether it involves personal or sensitive data, whether the conduct was intentional or negligent, whether security obligations were breached, whether regulatory notification was required, and whether another sector-specific law applies.
A key implementation point is that the PDPL itself delegates significant operational detail to Executive Regulations. Current public legal trackers report that the federal Executive Regulations have not yet been published, meaning businesses should distinguish obligations stated directly in the Decree-Law from requirements whose detailed implementation remains dependent on subsequent regulations.
The federal law contains important exclusions.
The PDPL does not apply to certain categories, including:
Businesses should therefore identify which UAE privacy regime applies before designing their compliance programme.
The UAE does not operate one single privacy regime for every organisation.
The federal PDPL is separate from the data-protection frameworks of the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM), which are distinct regimes.
An organisation with entities in mainland UAE, DIFC and ADGM should therefore map processing activities and compliance obligations separately for each entity.
The PDPL defines personal data broadly as information relating to an identified natural person or a natural person who can be identified directly or indirectly.
Examples can include:
The law therefore covers significantly more than traditional identity documents.
Processing covers activities performed on personal data, including activities such as:
Website owners should therefore treat analytics, advertising, customer-management, personalisation and other digital activities as potentially relevant processing activities where personal data is involved.
The UAE PDPL establishes consent as an important basis for processing but also identifies circumstances where processing may take place without consent.
The law allows processing in specified situations, including circumstances involving:
Therefore, a business should not automatically treat consent as the legal basis for every processing operation. The correct approach is to identify the purpose of processing and determine the applicable legal basis.
Where consent is required, the law defines consent as a clear, specific and unambiguous indication that the Data Subject accepts processing through a clear positive statement or action.
A compliant consent mechanism should therefore avoid:
A practical consent record should establish:
Consent should be sufficiently specific to the processing activity.
For example, a business may separately process data for:
Where consent is relied upon, the organisation should determine whether separate choices are appropriate rather than placing unrelated purposes under one generic permission.
The PDPL provides individuals with rights concerning their personal data and establishes controls around consent.
Where processing relies on consent, organisations should provide a practical mechanism through which a Data Subject can withdraw that consent.
A withdrawal mechanism should be:
ConsentX can support this website-level preference-management layer.
Organisations should provide Data Subjects with appropriate information about their processing activities.
A privacy notice should explain relevant information such as:
The notice should be presented in a manner that allows individuals to understand the processing before making relevant choices.
The UAE PDPL gives Data Subjects a range of rights concerning their personal data.
Depending on the circumstances, these include rights relating to:
Organisations should therefore maintain a formal Data Subject Request process.
A Data Subject can request access to personal information processed about them, subject to the applicable legal conditions and exceptions.
A robust access-request workflow should allow an organisation to:
Data Subjects can request correction or completion of inaccurate or incomplete personal data where the statutory conditions are met.
Businesses should ensure that corrections can propagate to relevant systems and processors.
This is particularly important where the same customer information is stored in:
The PDPL recognises circumstances in which a Data Subject can request deletion of personal data.
Deletion should not be treated as an unconditional requirement to erase every record immediately.
Organisations should consider:
The PDPL provides for restrictions on processing in specified circumstances.
Restriction workflows should allow organisations to distinguish between:
This distinction is important for compliance operations because not every privacy request necessarily results in immediate deletion.
Data Subjects have rights to object to certain forms of processing.
Businesses should provide a process for receiving and assessing objections, particularly where processing involves:
The UAE PDPL provides rights relating to the transfer of personal data.
Organisations should maintain technical capabilities that allow relevant personal information to be identified and exported in an appropriate format where the statutory requirements for transfer apply.
This can require coordination across:
The PDPL provides additional safeguards for sensitive personal data.
Sensitive information may include categories of information that could reveal particularly private characteristics or circumstances of an individual.
Businesses should apply stronger controls where sensitive information is processed, including:
The PDPL provides for the appointment of a Data Protection Officer (DPO) in specified circumstances.
A DPO may be required where processing activities involve circumstances such as:
The DPO function may include:
The precise operational requirements should be reviewed against the applicable implementing framework.
The UAE PDPL requires impact assessments for certain processing activities that are likely to result in a high risk to the privacy and confidentiality of Data Subjects.
A DPIA should assess matters such as:
DPIAs are particularly relevant for processing involving:
Organisations should incorporate privacy considerations into systems and product development.
A privacy-by-design programme can include:
For digital businesses, privacy should be addressed when a website, application or analytics architecture is designed rather than after deployment.
Controllers and Processors are expected to implement appropriate technical and organisational measures to protect personal data.
Security measures should reflect:
Controls can include:
The UAE PDPL establishes obligations concerning personal-data breaches.
A breach-response programme should enable organisations to:
The detailed operational requirements, including notification procedures and timing, are among the areas that depend on the implementing framework. The PDPL itself requires further rules concerning its implementation.
The UAE PDPL regulates transfers and sharing of personal data outside the UAE.
International transfers should be assessed before data is:
The PDPL provides mechanisms for international transfers, including transfers based on adequacy, applicable agreements, contractual safeguards and other conditions established by the law.
Businesses should therefore maintain an international-transfer inventory identifying:
The UAE PDPL is relevant to cookies and tracking technologies where they involve personal data.
Businesses should assess:
Common technologies requiring review include:
Where consent is the applicable basis, organisations should prevent the relevant processing from starting before the required choice is obtained.
Marketing activities involving personal data should be assessed against the PDPL and other applicable UAE rules.
Businesses should review:
The UAE also has separate telemarketing rules. Cabinet Resolution No. 56 of 2024 regulates telemarketing calls, while Cabinet Resolution No. 57 of 2024 provides administrative penalties for violations of those telemarketing rules. These requirements should be assessed separately from the federal PDPL.
The UAE PDPL addresses automated processing and provides protections relating to decisions based on automated processing.
Businesses using AI systems, profiling, behavioural scoring, automated eligibility decisions, personalised advertising, recommendation systems, fraud detection, credit assessment or other automated decision technologies should assess:
AI systems that process personal data should be assessed as part of the organisation's wider privacy governance programme.
Organisations should collect personal data for legitimate and clearly defined purposes and avoid collecting information that is unnecessary for those purposes.
For example, a website requesting the following should be able to explain why each category is needed:
Data minimisation should also be considered when configuring analytics, advertising and customer-data platforms.
Businesses should establish retention schedules for personal data.
A retention programme should address:
Retention should be based on legal, contractual, operational and privacy requirements rather than indefinite storage.
The PDPL distinguishes between two roles.
Controller. The entity that determines the method, criteria and purpose of processing personal data.
Processor. The entity that processes personal data on behalf of and under the instructions of a Controller.
Examples of processors may include:
Controller-Processor arrangements should clearly establish:
Using a third-party provider does not eliminate the need for privacy governance.
Before onboarding a processor, organisations should evaluate:
A processor inventory should be maintained throughout the relationship.
A mature UAE PDPL programme should include:
Consent management is one component of this broader governance framework.
One of the most important points to understand about the UAE PDPL is the status of its Executive Regulations.
Article 28 of Federal Decree-Law No. 45 of 2021 provides for Executive Regulations to be issued by the Council of Ministers. Article 29 then provides a regularisation period for Controllers and Processors beginning from issuance of those regulations.
Current specialist legal trackers continue to report that the federal PDPL Executive Regulations have not been published, meaning detailed implementation requirements remain an important area to monitor.
Accordingly, businesses should not present an unverified regulation number or invented implementation deadline as the UAE PDPL's Executive Regulations.
The core obligations contained directly in Federal Decree-Law No. 45 of 2021 remain the foundation of the federal framework.
The federal PDPL does not operate in isolation.
Certain sectors have their own privacy and data-governance requirements, including areas such as:
The PDPL itself excludes certain health and banking or credit information where separate legislation regulates its protection and processing.
Businesses should therefore perform a sector-specific legal assessment before assuming that the federal PDPL is the only applicable framework.
Use this checklist to review your privacy programme.
ConsentX can identify cookies, analytics scripts, advertising trackers, pixels, tags, third-party scripts and other website technologies.
Where consent is the applicable legal basis, ConsentX can provide configurable consent experiences that allow visitors to make informed choices.
ConsentX can help prevent selected non-essential scripts and trackers from executing before the required consent decision.
ConsentX can maintain records of consent choices and provide evidence concerning the timestamp, consent status, selected purposes, consent configuration, user preference changes and withdrawal.
Users can manage applicable privacy preferences rather than relying solely on an initial consent interaction.
ConsentX's region rule engine can help organisations deliver different privacy experiences based on applicable jurisdictional requirements.
ConsentX can support website-level workflows for applicable privacy requests, including access, deletion and preference-related requests.
Regular website scans can identify newly deployed trackers or third-party technologies that may introduce new processing activities.
The UAE PDPL requires more than a cookie banner. ConsentX supports the website, cookie and consent-management layer of a UAE privacy programme through cookie and tracker discovery, consent management, prior-script blocking, consent evidence, preference management, regional privacy rules and data-subject request workflows. Build a transparent and audit-ready privacy experience for users in the United Arab Emirates with ConsentX.
This page provides a general, plain-English overview of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). It is not legal advice and does not cover every exemption, sector-specific law, free-zone regime, implementing decision or individual compliance circumstance. No single consent-management platform replaces a complete privacy programme: broader compliance also requires legal assessment, governance, security, DPO processes, DPIAs, vendor management and breach response. Organisations should review the current UAE legislation, including developments to the Executive Regulations, and obtain qualified UAE legal advice where necessary.
Run a ConsentX scan to identify cookies, scripts, pixels and third-party tracking technologies.
Determine what personal information each technology collects and where that information is sent.
Determine whether processing relies on consent or another lawful basis recognised by the PDPL.
Explain the purposes, categories of data, recipients, retention, rights and other relevant information.
Where consent is required, configure a clear and specific opt-in experience.
Prevent selected trackers from executing before the applicable consent decision.
Maintain auditable consent evidence showing the user's decision and the context in which it was obtained.
Give users a practical mechanism to change applicable choices.
Identify every analytics, advertising, cloud, CRM and marketing vendor receiving personal data.
Identify whether website technologies transmit data outside the UAE and assess the applicable transfer mechanism.
Review whether profiling, AI, large-scale monitoring or sensitive-data processing triggers DPIA or DPO considerations.
Coordinate ConsentX with: