Topic Summary
UAE PDPL Applies to Every Business
Federal Decree-Law No. 45 of 2021 covers all companies handling personal data in the UAE, regardless of size, revenue, or country of origin. There is no small-business exemption, so even startups and sole traders must comply.
Fines Reach AED 5,000,000
Cabinet Resolution No. 33 of 2024 set the maximum penalty at AED 5,000,000 for breaching UAE data protection rules. Acting before a regulator investigates is far less costly than paying that fine after the fact.
Know What Counts as Personal Data
Personal data includes names, phone numbers, email addresses, IP addresses, and location data, covering both digital and paper records. Sensitive categories such as health records, biometrics, and financial details attract stricter obligations under the law.
Consent Must Be Specific and Recorded
You need a clear, documented lawful basis before collecting any personal data, and pre-ticked boxes do not satisfy the consent requirement. People can withdraw consent at any time, so your business needs a reliable process to handle those requests.
Report Data Breaches Within 72 Hours
If a breach occurs, you must notify the UAE Ministry of Economy within 72 hours of discovering it. Having a written breach response plan in place before an incident happens is essential to meeting that tight deadline.
Appoint a Data Protection Officer If Required
Businesses that regularly process large volumes of personal data or handle sensitive categories must appoint a Data Protection Officer, who can be an employee or an external specialist. Smaller firms that fall below that threshold should still designate an internal person responsible for data compliance.
Build a Compliance Plan Before Regulators Act
A practical compliance plan covers mapping the data you hold, setting a lawful basis for each use, writing a privacy notice, training staff, and securing your systems. Reviewing these practices at least annually keeps your business aligned as the rules evolve.
In 2026, the UAE Personal Data Protection Law applies to every company that handles personal data inside the country (u.ae, 2024). That covers most businesses. Fines for breaking the rules reach AED 5,000,000 (UAE Cabinet Resolution No. 33 of 2024). The core statute, Federal Decree-Law No. 45 of 2021, has been in force since September 2021. Cabinet Resolution No. 33 of 2024 added the detailed rules that businesses must follow today. Many firms still have no data policy in place. This guide covers the data protection and privacy laws UAE businesses must know so you can act before a regulator does.
What UAE Data Protection Law Means for Your Business
The UAE Personal Data Protection Law sets rules for how companies collect, store, use, and share personal data. It covers all businesses operating in the UAE. The law gives people rights over their data and requires companies to handle it with care, or face fines up to AED 5,000,000. For more detail, see our guide on UAE consumer protection regulations.
UAE Data Protection Law: Key Facts at a Glance
Detail | Information |
|---|---|
Law name | Federal Decree-Law No. 45 of 2021 |
Detailed rules | Cabinet Resolution No. 33 of 2024 |
Maximum fine | AED 5,000,000 |
Who it covers | All firms handling personal data in the UAE, regardless of size or origin |
Oversight body | |
Data subject rights | Access, correction, deletion, and objection |
What Counts as Personal Data
Personal data is any detail that links back to a real person. That includes names, phone numbers, email addresses, IP addresses, and location data. Sensitive data gets extra protection under the law. Sensitive categories include health and medical records, biometric data such as fingerprints or facial scans, financial details, and family status. The PDPL covers both digital and paper records. Staff data and job applicant data fall under it too, not just customer information.
Who the Law Applies To
The PDPL applies to any company that processes personal data in the UAE, regardless of where the company is based. Small firms are not exempt. The law draws no line based on company size or revenue. Free zone companies are generally covered. Some zones such as DIFC and ADGM have their own data rules that sit alongside the federal law (UAE Cabinet, 2024).
Key Rules Every Business Must Follow
UAE data protection rules require businesses to get clear consent before collecting data, use data only for the purpose stated, keep it secure, and delete it when no longer needed. Companies must also appoint a data officer if they process large volumes of personal data regularly.
Consent and Lawful Basis for Data Use
You must have a lawful reason to collect data. The main grounds are clear consent from the person, performance of a contract with that person, or a legal duty the company must meet. Consent must be specific and recorded. Pre-ticked boxes do not count. People can withdraw consent at any time, so you need a process to handle that. Consent for sensitive data must be explicit, not just implied.
Data Security and Storage Rules
You must put technical steps in place to protect data from loss, theft, or unauthorised access. Set a clear retention period for each type of record and delete data once that period ends. If there is a data breach, report it to the Ministry of Economy within 72 hours of finding out. Collect only what you actually need.
Appointing a Data Protection Officer
Some businesses must appoint a Data Protection Officer (DPO). This applies if you process large volumes of data or handle sensitive categories regularly. The DPO can be an employee or an external specialist and must have enough authority to act independently. Smaller firms may not need a formal DPO but should still name someone internally who owns data compliance.
Steps to Build a Data Compliance Plan
To comply with UAE data protection law, map the data you hold, set a lawful basis for each use, write a clear privacy notice, train your team, secure your systems, put a breach response plan in place, and review your practices at least once a year.
Map your data: List every type of personal data you hold, where it comes from, and where it goes.
Set your lawful basis: For each data type, confirm which legal ground justifies its use.
Write a privacy notice: Tell people clearly what data you collect, why, and for how long.
Train your team: Every staff member who touches personal data must know the basic rules.
Secure your systems: Use strong passwords, encrypt sensitive files, and limit access to those who need it.
Build a breach plan: Know who to call, what to log, and how to notify the Ministry within 72 hours. Test the plan, not just write it.
Review every year: Laws change. Your data practices should keep up.
Rights Your Customers Have Under UAE Law
Under UAE data protection law, individuals can ask to see the data you hold on them, request corrections, ask for deletion, and object to certain uses. Businesses must respond within the time limits the law sets, or face penalties. You must have a clear process for logging and responding to requests. Failing to respond is a breach of the PDPL. The person can complain to the Ministry of Economy, which can investigate, issue a warning, or impose a fine. Log every request and every response with a date.
Is there a time limit for responding to data requests?
The PDPL requires businesses to respond to data subject requests within a reasonable period set by the Ministry of Economy. Delays without good reason can trigger a formal complaint. Keep a dated log of every request and response so you can show you acted promptly if a regulator asks.
Sending Data Outside the UAE
UAE law restricts sending personal data to countries outside the UAE unless that country has adequate data protection rules, or the business puts approved safeguards in place. You can send data abroad if the receiving country has rules the UAE recognises as strong enough. If the country does not qualify, you can still transfer data by using approved contractual terms or getting clear consent from the person. Cloud storage location matters as much as who owns the data. Check where your provider stores files, not just who runs the service. Review contracts with vendors who handle data on your behalf, add a data processing clause to every vendor agreement, and keep a record of all cross-border transfers and the legal basis for each (UAE Cabinet, 2024).
Free Zone Data Rules You Need to Know
Companies in UAE free zones generally fall under the federal PDPL. However, the DIFC and ADGM each run their own data protection frameworks. If your business is in one of these zones, you follow the zone's rules. In all other free zones, the federal law applies.
Zone type | Which law applies | Who oversees it |
|---|---|---|
Most free zones (e.g. Dubai South) | Federal PDPL (Decree-Law No. 45 of 2021) | UAE Ministry of Economy |
DIFC | DIFC Data Protection Law (DIFC Law No. 5 of 2020) | DIFC Commissioner of Data Protection |
ADGM | ADGM Data Protection Regulations 2021 | ADGM Registration Authority |
A company that starts a business at Dubai South Business Hub is subject to the federal PDPL and registers any data complaints with the Ministry of Economy. If you deal with EU customers, check whether GDPR also applies. Most PDPL duties overlap with GDPR, but the two are not identical, so do not assume one covers the other. Get legal advice if you operate across more than one zone or across borders.
What Penalties Look Like and How to Avoid Them
UAE data protection fines reach AED 5,000,000 for serious breaches. Criminal penalties can apply for deliberate misuse of data. Regulators look at whether the business had a compliance plan, how quickly it acted after a breach, and whether it cooperated with the investigation.
Breach type | Possible outcome |
|---|---|
No lawful basis for data collection | Warning or fine up to AED 5,000,000 |
Failure to notify a breach within 72 hours | Fine and regulatory review |
Ignoring data subject requests | Complaint, investigation, and fine |
Unlawful cross-border data transfer | Fine and order to stop transfers |
Deliberate misuse of personal data | Criminal penalty in addition to civil fine |
The Ministry of Economy sets fines based on how serious the breach was, how many people were affected, and whether the firm cooperated. Speed of response and cooperation both affect the final outcome. Criminal fines apply where data was misused on purpose and are separate from civil penalties (UAE Ministry of Economy, 2024).
The 3 Most Common Mistakes
No written consent process: Firms collect data with no clear opt-in or explanation of use. Fix it by adding a specific tick box and a plain-language statement of purpose.
No breach response plan: When something goes wrong, the team does not know who to call or what to log. Fix it by writing a one-page response plan and testing it once a year.
Outdated privacy notice: The notice still describes practices the firm changed years ago. Fix it by reviewing the notice every time your data practices change.
Do small businesses need to comply with the UAE PDPL?
Yes. The PDPL applies to all businesses that process personal data in the UAE, with no exemption for size or revenue. A startup collecting email addresses at sign-up is covered from day one. The rules on consent, security, and data subject rights apply in full, regardless of how many staff you have or how much you earn.
The data protection and privacy laws UAE businesses must follow are now firmly in place. The rules cover every firm that touches personal data, from small startups to large enterprises. Get your consent process right, secure your data, train your team, and review your practices every year. If you handle large or sensitive data sets, get expert advice before a regulator does. Dubai South Business Hub can help you set up with a professional license in Dubai and build a compliant operation from day one. The business support services at Dubai South Business Hub can point you toward the right advisers for your industry and license type. For more detail, see our guide on cybersecurity for small businesses in the UAE.
References
u.ae (u.ae)
UAE Cabinet (uaecabinet.ae)
UAE Ministry of Economy (moet.gov.ae)
Frequently Asked Questions





