Start with the two facts that decide everything else. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data has been in force since 2 January 2022 [4]. And the Executive Regulations that would make its penalties, procedures and thresholds operative have still not been issued [2][3]. The law contemplated them within six months. That window closed in 2022. It is now August 2026.
That is not a footnote. Chambers and Partners, in its Data Protection and Privacy 2026 guide for the UAE, states it plainly: "The Implementing Regulations, intended to clarify key aspects of the law, have yet to be issued" [2]. The UAE Government's own portal still describes the federal data regulator in the future tense [1]. DLA Piper's tracker recorded the same gap, and noted that once the regulations appear, organisations get a further six months to comply [3].
Meanwhile business owners are quoted for "PDPL Executive Regulations compliance packages" citing fines of AED 50,000 to AED 5 million, a 72-hour breach notification window and a numeric DPO threshold. We could not trace any of those to a primary source. Since 2013, our team has run compliance calendars for UAE companies, and this is the fastest-growing item we strike off a quote before a client signs. This is a guide, not legal advice.
Is the UAE PDPL actually enforceable yet?
The Decree-Law is in force and its general principles bind you now. But the machinery that turns principles into enforceable procedure, specified violations and monetary penalties sits in Executive Regulations that have not been published [2][3]. Chambers describes the result as "limited enforcement activity and a cautious regulatory stance" on the mainland [2].
Hold both halves at once, because the two common readings are each wrong. "The PDPL is not in force, ignore it" is false: it took effect on 2 January 2022 and its obligations around lawful basis, consent, data minimisation and data subject rights sit in the instrument itself [4]. "The PDPL is fully operative with a defined penalty schedule" is also false: the law defers the specification of violations and penalties to a Cabinet decision we could not find published [2][3].
What exists is a binding statute with an unfinished delivery mechanism. Chambers puts the PDPL as "still very much a work in progress", with organisations driving compliance through internal risk assessment rather than regulatory action [2].
Real Talk: If a provider says the PDPL is "fully enforced with active fines", ask for one published enforcement decision against a UAE mainland company under Federal Decree-Law No. 45 of 2021. We looked and could not find one, and Chambers characterises enforcement activity as limited [2].
What are the Executive Regulations, and why does their absence matter?
They are the implementing instrument that would define how the PDPL operates: the procedure for exercising each right, the standards for cross-border transfer, the DPO threshold, the controls behind the small-processor exemption, and the mechanics of the Cabinet's penalty decision. Without them, the law states outcomes without stating method. Three independent sources agree on their absence, which matters because the counter-claim is repeated so widely that one source would not be enough.
| Source | What it says | Date checked |
|---|---|---|
| Chambers and Partners, Data Protection and Privacy 2026, UAE | "The Implementing Regulations, intended to clarify key aspects of the law, have yet to be issued" [2] | 2026 guide edition |
| u.ae, the UAE Government portal | Describes the UAE Data Office in the future tense, on a page carrying a December 2025 update stamp [1] | December 2025 stamp |
| DLA Piper, Data Protection Laws of the World | Executive Regulations not published as of 6 January 2025, with a further six months to comply once they are [3] | 6 January 2025 |
The u.ae wording is the one to read closely, because it is the government describing its own regulator. The page states that the UAE Data Office "will act as the federal data regulator in the UAE" and that the office, affiliated with the UAE Cabinet, "will be responsible for" preparing policies and legislations related to data protection, proposing and approving the standards for monitoring the Personal Data Protection Law, and preparing systems for complaints [1].
Every verb there is future tense, on a page updated in December 2025, describing a body established by Federal Decree-Law No. 44 of 2021 alongside the PDPL itself [1]. A government does not describe a working regulator's core functions as things it "will be responsible for" four years on.
Pro Tip: Read [1] yourself before you sign anything. It takes ninety seconds, it is on a government domain, and it settles the argument faster than any consultant's slide deck.
One sourcing note. The primary text of Federal Decree-Law No. 45 of 2021 is hosted in Arabic on assets.u.ae [4], and we found no official English full text on a government domain. Every English version in circulation, including the phrasing here, is a translation, so where exact wording drives a decision, work from the Arabic.
Which Cabinet Decision numbers are being cited, and should you rely on them?
Three different numbers circulate as the Executive Regulations: "Cabinet Decision No. 111 of 2023", "Cabinet Decision No. 33 of 2024", and simply "issued in 2026". They cannot all be right, and we could not verify any of them against a primary government source. Rely on none of them until someone shows you a gazette reference.
We want to be fair. We are not accusing anyone of fabricating anything. Citation errors propagate: one page guesses, a second copies it, a third cites the second, and within a year the number reads as established fact.
| Circulating citation | Where it appears | What we found |
|---|---|---|
| "Cabinet Decision No. 111 of 2023" | Compliance-vendor pages and SEO summaries | No primary government source connecting this number to the PDPL |
| "Cabinet Decision No. 33 of 2024" | Compliance-vendor pages and SEO summaries | A targeted search returns nothing linking it to the PDPL |
| "Executive Regulations issued in 2026" | Recent marketing pages, no decision number given | No publication traceable; contradicted by [1], [2] and [3] |
| All three, side by side | Multiple pages | Mutually contradictory, so at most one could ever be correct |
Take them on their own terms. A page citing a 2023 decision number and one citing a 2024 number cannot both describe the same instrument, and a third claiming publication in 2026 contradicts both.
Common Mistake: Treating a decision number as self-authenticating. A number in a bulleted list is not a citation. A citation points to a gazette entry, an official PDF, or a government page reproducing the instrument. If a provider cannot produce that, the number is unverified however confidently it is stated.
The practical test is one question: "Please send me the gazette reference or the official government link for that decision." Legitimate advisers answer with a link. Everyone else changes the subject to why compliance matters generally. That is the discipline we apply when reviewing quotes against our post-setup services compliance calendar. Talk to a setup expert→
Are the PDPL penalty figures being quoted at you real?
We could not trace them to any primary instrument. Figures in circulation include a range of AED 50,000 to AED 5 million and a standalone "up to AED 1 million". The PDPL provides that the Cabinet will issue a decision specifying the violations and the administrative penalties, and we could not find that decision published [2][3].
Read the structure carefully. The Decree-Law does not set out a schedule for regulations to refine. It defers the specification of violations and penalties to a separate Cabinet decision. Until that decision is published, there is no schedule to enforce against you and no figure anyone can honestly quote as codified law.
| Claim you will hear | Status on the evidence we found |
|---|---|
| "Fines of AED 50,000 to AED 5 million" | Not traceable to a primary instrument |
| "Penalties up to AED 1 million" | Not traceable to a primary instrument |
| "The penalty schedule is in the Executive Regulations" | The Executive Regulations are not published [2][3] |
| "The Cabinet will specify violations and penalties" | This is what the law itself provides for, and we found no such decision published |
| "There is currently no published PDPL penalty schedule" | Consistent with everything we could verify [1][2][3] |
This is not an argument for ignoring the law. It is an argument for refusing to buy protection against a number nobody can source [3].
Based on our experience, a precise-sounding fine range is the strongest single predictor that the rest of a proposal has not been checked. Precision is easy to manufacture. Sourcing is not.
Who does the PDPL apply to, and does it reach outside the UAE?
It applies to processing of personal data wholly or partly by electronic means, by controllers or processors inside or outside the UAE, where the processing relates to data subjects inside the UAE [4]. That last limb is the extraterritorial hook: an overseas processor handling UAE residents' data is in scope with no UAE presence at all.
| Element | What it means | Practical consequence |
|---|---|---|
| Electronic means | Processing wholly or partly by electronic means [4] | Almost every modern business process qualifies |
| Controller or processor | Whoever sets purposes and means, or processes for them [4] | SaaS vendors and outsourced payroll sit inside the chain |
| Inside or outside the UAE | The processor's location is not the gate [4] | Offshore dev teams and overseas cloud vendors are reachable |
| Data subjects inside the UAE | The connecting factor is where the individual is [4] | UAE residents' data is what triggers scope |
For an ordinary Dubai company that means your customer database, employee records, identifiable CCTV footage, CRM, marketing list and website analytics are all in scope, and your vendor stack is in scope through you. If your business builds the software doing that processing, the picture stacks further, which is the theme of our guide to cybersecurity company setup.
Real Talk: The most common scoping mistake we see is a founder assuming that hosting abroad puts them outside the PDPL. The connecting factor is the data subject's location, not the server's [4]. Moving your database to Frankfurt does not move your Dubai customers.
What is exempt from the federal PDPL?
Several categories fall outside it, and the exclusions are broader than people expect. Government data, security and judicial processing, purely personal or family use, health data, banking and credit data, and the financial free zones each sit under a different regime or outside the law entirely [4][8]. The last is the most misunderstood.
| Category | Position under the PDPL | Governing instrument instead |
|---|---|---|
| Government data held by government entities | Exempt [4] | Public sector rules |
| Security, judicial and law-enforcement processing | Exempt [4] | Sector-specific legislation |
| Purely personal or family use | Exempt [4] | Outside the law |
| Health data | Exempt [4][8] | Federal Law No. 2 of 2019 on ICT in health fields |
| Banking and credit data | Exempt [4][8] | Includes Federal Law No. 6 of 2010 on Credit Information |
| DIFC entities | Outside the federal PDPL [8] | DIFC Data Protection Law No. 5 of 2020 [7] |
| ADGM entities | Outside the federal PDPL [8] | ADGM Data Protection Regulations 2021 [5][6] |
| Every other mainland and free zone company | In scope [4] | Federal Decree-Law No. 45 of 2021 |
Read the last three rows together, because they contain the error that costs the most. "Free zones are exempt from the PDPL" is wrong. Only the financial free zones, DIFC and ADGM, run separate regimes [8]. A company in a media, technology, logistics or general trading free zone is governed by the federal PDPL exactly as a mainland company is. That belongs on the comparison sheet next to activity and visa quota, which our free zone company setup page walks through.
The health and banking exclusions are exclusions from the PDPL, not exemptions from data protection. A clinic sits under Federal Law No. 2 of 2019 and a lender under the credit information regime [4][8], and both are operative.
The Article 3 exemption that cannot currently be used
Article 3 carries a power for the Data Office to exempt establishments that do not process large volumes of personal data, exercisable "in accordance with standards and controls set by the Executive Regulations" [4]. Since the Executive Regulations do not exist, neither do those standards, and the exemption route is not currently operable.
This is underreported and sharp. A small Dubai company processing modest volumes is exactly the establishment the legislator contemplated relieving. The grantor would be the UAE Data Office, established under Federal Decree-Law No. 44 of 2021 [1]. But the relief is conditioned on a document that has not been issued, so no standard exists against which an application could be assessed, and no operable route exists to apply.
The effect is counter-intuitive. The unissued regulations do not only delay penalties, they delay relief. A small business is not in a comfortable gap. It is inside the law's general principles with the one door out locked.
Common Mistake: Assuming "we are small, so the PDPL will not apply to us". The threshold that would make that true lives in a document that has not been published, so there is currently no volume below which the law stops applying to you [4].
What does the PDPL actually require of you today?
The Decree-Law's principles bind you now, independently of the missing regulations. Have a lawful basis, obtain consent where required, collect only what you need for a stated purpose, keep it secure, honour data subject requests in good faith, and keep a record of what you hold and why [4]. None of that waits on an unissued instrument.
Consent sits at the centre. Processing personal data without the data subject's consent is prohibited, subject to enumerated exceptions such as protecting a public interest or legal procedures [4]. That is closer to a general prohibition with carve-outs than to a menu of lawful bases.
| Obligation live today | What it looks like in a Dubai SME | Regulation-dependent? |
|---|---|---|
| Lawful basis and consent | Real consent on forms, sign-ups and CCTV notices [4] | No |
| Purpose limitation | Stated purpose, not repurposed silently [4] | No |
| Data minimisation | Stop collecting Emirates ID copies you cannot use [4] | No |
| Security of processing | Access control, encryption in transit, no shared logins | No |
| Record of processing | Written inventory: what, where, why, how long | No |
| Honouring data subject requests | Respond in good faith [4] | Partly. The mechanics are deferred [2][3] |
| Breach notification procedure | An escalation path you can actually run | Yes, for the timelines [3] |
| DPO appointment threshold | A judgement call on your risk profile | Yes, for the trigger [2][3] |
| Cross-border transfer approvals | Contractual safeguards you can defend | Yes, for adequacy and approvals [2][3] |
Work from the right-hand column. Six of these nine are actionable today with no reference to anything unpublished, and they would form the backbone of a credible position under any final version of the regulations. The three that are regulation-dependent are exactly the three compliance packages lead with.
Pro Tip: Build the record of processing first. It costs a few days of internal work, it is immediately useful for contracts, insurance and bank onboarding, and it is the one artefact that survives whatever the Executive Regulations say.
What data subject rights exist, and why are the mechanics missing?
The rights commonly listed are access, correction, erasure, restriction of processing, portability and objection [4][8]. The substantive rights sit in the law. The mechanics for exercising each one, the response deadlines, verification standards, permitted refusal grounds and format requirements, are deferred to the Executive Regulations and are not yet defined [2][3].
| Right | In the law | Procedure defined? |
|---|---|---|
| Access to personal data held | Yes [4][8] | No. Deferred to the Executive Regulations [2][3] |
| Correction of inaccurate data | Yes [4][8] | No |
| Erasure | Yes [4][8] | No, including its limits and exceptions |
| Restriction of processing | Yes [4][8] | No |
| Data portability | Yes [4][8] | No, including the required format |
| Objection to processing | Yes [4][8] | No, including the grounds |
If a customer emails tomorrow asking for a copy of everything you hold, there is no published UAE deadline for responding, no published standard for verifying the requester, and no published list of grounds on which you may decline.
So answer in good faith, on a written internal policy with a self-imposed deadline you can evidence. A company that logged the request, verified identity sensibly, responded inside its stated timeframe and documented it has a defensible file under any standard eventually imposed. A company that ignored it because "the procedure is not defined yet" has nothing. If you adopt a thirty-day working standard, present it as your policy, not as a UAE legal deadline.
What about cross-border transfers of personal data?
The PDPL sets requirements for transferring personal data outside the UAE, but the operative detail sits in the unissued regulations. The adequacy list of approved destinations, the standards for contractual safeguards and the approval procedures are all Executive-Regulation-dependent and unpublished [2][3]. The obligation exists in outline while the compliance route is undefined.
This lands hardest on the Dubai company that never thinks of itself as transferring data internationally. If your CRM is hosted in Ireland, your email in the United States, your accounting platform in Singapore and your bookkeeping team offshore, you move personal data across borders every day.
Build the file you would need under any plausible final rule: know where each dataset sits, hold a written contract with each processor covering confidentiality, security, sub-processors and deletion on exit, and be able to explain why each transfer is necessary. An enterprise customer or a bank will ask for exactly that long before a regulator does. Our post-setup services team folds it into the same annual review as corporate tax and licence renewal.
Quick Math: The Decree-Law came into force on 2 January 2022 and contemplated its Executive Regulations within six months, so mid-2022. As at August 2026 that is over four years past the contemplated date, with a further six-month compliance runway still to come once they are published [3]. Any plan treating the regulations as imminent has now been wrong for four consecutive years.
Where does the "72-hour breach notification" figure come from?
Not from any primary UAE source we could confirm, though it is stated across vendor content as though codified. DLA Piper notes the PDPL does not specify penalties or detailed procedural timelines, deferring them to the unissued regulations [3]. The likeliest explanation is that the figure was imported from the GDPR, where 72 hours is genuinely codified, and transplanted onto the UAE.
We are stating this carefully. The final UAE position may well be 72 hours, since the drafters have clearly looked at European practice. What we are saying is that today there is no confirmed UAE 72-hour requirement you can point to, and any provider presenting one as settled law should be asked which article of which instrument it comes from.
The instruction is the same either way. Build an internal breach response procedure that moves fast: who is told, who decides, who contacts affected individuals, who preserves the logs. If the final rule is 72 hours you are ready. If it is longer you have lost nothing. What you should not do is pay for a package whose central deliverable is a deadline nobody can source, or copy a GDPR breach policy onto UAE letterhead, which creates written evidence of a standard that does not exist in UAE law.
When do you actually need a Data Protection Officer?
There is no published numeric threshold. The PDPL contemplates a DPO requirement, but the trigger is Executive-Regulation-dependent and unpublished [2][3]. Any figure quoted at you, whether a record count, a headcount or a revenue level, is not traceable to a primary source. Treat DPO appointment as a risk judgement, not a compliance box.
| Profile | Sensible position today |
|---|---|
| Small trading company, staff and supplier records only | Name an accountable person. No formal appointment needed yet |
| Consumer app or platform with a large UAE user base | Assume you will be in scope. Appoint someone credible now |
| Business processing sensitive categories at scale | Appoint. Do not wait for a threshold |
| Company doing systematic monitoring or profiling | Appoint. The classic trigger in comparable regimes |
| DIFC or ADGM entity | Work to your zone's own rules, which are operative [5][6][7] |
The last row is the exception that matters, and it leads into the most useful distinction in this whole subject.
DIFC and ADGM: the zones that are not waiting
DIFC and ADGM are not in the same position at all. Both run fully operative regimes with their own independent Commissioners, and both are enforceable today [5][6][7]. If your entity is registered in either, you have a live present-tense obligation while the mainland conversation is still about an unissued instrument.
DIFC Data Protection Law No. 5 of 2020 has been in force since 1 July 2020, administered by an independent Office of the Commissioner of Data Protection [7]. DIFC was the first GCC jurisdiction to enact a data protection law. ADGM's Data Protection Regulations 2021 were issued on 14 February 2021, explicitly benchmarked against the GDPR, with an independent Office of Data Protection headed by a Commissioner publishing its own guidance [5][6].
| Feature | Federal PDPL (mainland and other free zones) | DIFC | ADGM |
|---|---|---|---|
| Instrument | Federal Decree-Law No. 45 of 2021 [4] | Data Protection Law No. 5 of 2020 [7] | Data Protection Regulations 2021 [5] |
| In force since | 2 January 2022 [4] | 1 July 2020 [7] | Issued 14 February 2021 [5] |
| Implementing detail | Not issued [2][3] | In place | In place |
| Regulator | UAE Data Office, future tense on u.ae [1] | Independent Commissioner [7] | Independent Commissioner [5][6] |
| Published guidance | Limited | Yes | Yes [6] |
| Benchmarked to GDPR | Broadly similar | Closely aligned | Explicitly benchmarked [5] |
| Enforceable today | Principles yes, procedure and penalties unclear [2][3] | Yes | Yes |
| What you should do | Principles now, watch for the regulations | Comply now | Comply now |
The asymmetry is the point. A DIFC or ADGM entity waiting for "the UAE data protection law to be finalised" has been in breach of an operative regime for years while watching the wrong jurisdiction. We see it most often in groups that set up a DIFC holding entity for the regulatory profile, then run the group's calendar off mainland assumptions. Our DIFC business setup and ADGM company setup guides cover what each zone expects.
Real Talk: "We are in a free zone so data protection does not apply to us" is the most expensive sentence in this subject. If the free zone is DIFC or ADGM, a stricter and fully operative regime applies. If it is any other free zone, the federal PDPL applies exactly as it does on the mainland [8].
What should a Dubai SME actually do this quarter?
Comply with the PDPL's general principles, because the Decree-Law is in force [4]. Do not buy anything promising specific breach windows, DPO thresholds or penalty-avoidance figures as settled law. Watch for publication of the Executive Regulations, because that date starts a six-month compliance clock [3]. If you are in DIFC or ADGM, comply with your zone's law now.
| # | Action | Why it is worth doing now |
|---|---|---|
| 1 | Build a record of processing | Everything else depends on knowing what you hold. Useful for banks and enterprise customers now |
| 2 | Fix consent at the collection points | Forms, sign-ups, CCTV notices, messaging opt-ins. The consent rule is live [4] |
| 3 | Delete what you cannot justify | Old Emirates ID copies, CVs from 2019, dormant lists. Minimisation is a live principle [4] |
| 4 | List your processors and where data sits | The base of any transfer position, whatever the adequacy rules become |
| 5 | Put processor terms in vendor contracts | Confidentiality, security, sub-processors, deletion on exit. Contract law, not regulation |
| 6 | Write an internal request-handling policy | A defensible answer to an access request today [2][3] |
| 7 | Write an internal breach escalation path | Speed is the deliverable, not the hour count |
| 8 | Name an accountable person | Not a formal DPO appointment. Someone whose job it is |
| 9 | Diary a quarterly check for the regulations | The publication date is the real trigger [3] |
| 10 | If DIFC or ADGM, comply with your zone now | Those obligations are live and enforceable [5][6][7] |
Notice what is not on that list: a certification, a gap assessment against an unpublished instrument, or a penalty-avoidance programme. Steps one to five are business hygiene that pays for itself in vendor negotiations and bank onboarding. Steps six to eight you can write yourself, and step nine is free.
If you are still choosing a structure, this is one more reason to be deliberate about jurisdiction. A mainland company setup and a general free zone licence both put you under the federal PDPL, while DIFC and ADGM put you under a separate operative regime with real obligations and published guidance [5][6][7]. Talk to a setup expert→
What happens when the Executive Regulations finally land?
Publication starts a six-month compliance runway [3], and the deferred items become concrete. Companies that built the record of processing and the consent position early will spend those six months configuring. Companies that did nothing will spend them in a panic.
| What is deferred today | What publication would settle |
|---|---|
| Violations and administrative penalties | The actual schedule, via the Cabinet decision the law provides for [2][3] |
| Breach notification timeline | Whether the imported 72-hour assumption is correct [3] |
| DPO appointment trigger | The threshold, whatever form it takes [2][3] |
| Data subject request procedure | Deadlines, verification standards, refusal grounds [2][3] |
| Cross-border transfer route | Adequacy list, contractual standards, approval procedure [2][3] |
| Article 3 small-processor exemption | The standards and controls that would make it usable [4] |
One consequence is worth planning for. The Article 3 exemption may become usable at the same moment penalties become enforceable, so a small business could find its exposure and its relief crystallising in the same week [4]. A free early-warning signal: when u.ae stops describing the Data Office in the future tense, something has moved [1].
The honest summary
The federal PDPL is in force and its principles bind you today, but its Executive Regulations remain unissued more than four years past the contemplated window [1][2][3]. The Cabinet Decision numbers circulating as proof otherwise contradict one another and none is traceable to a primary source. The penalty figures, the 72-hour breach window and the numeric DPO threshold quoted at you are not verifiable as codified UAE law. DIFC and ADGM are a different story, with operative regimes and active Commissioners [5][6][7].
Since 2013, BusinessDubai.ae has completed 700+ company registrations across the UAE, and data protection now sits on the same compliance calendar as corporate tax, audit and licence renewal. We will tell you which obligations under your structure are live, which quote line items point at an unpublished instrument, and whether your zone puts you under the federal PDPL or a separate operative regime. The ongoing side is what our post-setup services team handles, and the structuring side, whether a free zone company setup or a mainland company setup, is where the position is set before you process a record. See also our guides to economic substance regulations, UAE AML and CFT compliance and corporate tax filing requirements. Talk to a setup expert→
Been quoted for a PDPL Executive Regulations compliance package? Send us the proposal. We will tell you which line items point at a published instrument and which do not, with clear fixed fees.
Get started free→Real Client Stories
Real examples from businesses we have helped, with details changed for privacy.
The e-commerce company quoted AED 24,000 for "PDPL Executive Regulations compliance". A Dubai free zone retailer received a proposal built around a 72-hour breach notification procedure, a DPO appointment to meet a stated threshold, and avoiding fines "up to AED 5 million". We asked for the gazette reference for the Executive Regulations underpinning all three. The reply cited a Cabinet Decision number we could not trace to any primary government source, while the government's own portal still described the Data Office in the future tense [1]. The client kept what was real, the record of processing, the consent fix on its checkout flow and the vendor contract terms, and paid roughly a third of the original figure.
The DIFC advisory firm watching the wrong law. A DIFC-registered corporate advisory business told us it was "waiting for the UAE data protection law to be finalised" before doing anything. It sits in DIFC, where Data Protection Law No. 5 of 2020 has applied since 1 July 2020 with an independent Commissioner throughout [7]. The federal position it had been monitoring was not the law governing it. We reset the work to the DIFC regime, which was real and overdue rather than speculative, and dealt with its mainland service company separately [4].
The clinic sold the wrong regime entirely. A Dubai healthcare group had bought a PDPL readiness assessment covering its patient records. Health data is carved out of the federal PDPL and governed separately under Federal Law No. 2 of 2019 on ICT in health fields [4][8], so it had been built against the wrong instrument. Its staff and supplier records did sit under the PDPL, so narrower work was needed, but the patient-record analysis had to be redone against the health-sector regime.
Frequently Asked Questions
Is the UAE PDPL in force?
Yes. Federal Decree-Law No. 45 of 2021 has been in force since 2 January 2022 [4]. Its general principles bind you today, independently of the missing Executive Regulations.
Have the PDPL Executive Regulations been issued?
No. Chambers and Partners states in its Data Protection and Privacy 2026 UAE guide that "The Implementing Regulations, intended to clarify key aspects of the law, have yet to be issued" [2], and DLA Piper recorded the same [3].
How long have the Executive Regulations been outstanding?
The law contemplated them within six months, so mid-2022. As at August 2026 that is more than four years past the contemplated date [2][3].
What about Cabinet Decision No. 111 of 2023?
It circulates widely as the Executive Regulations. We could not verify it against any primary government source, and it contradicts the other numbers in circulation. Ask anyone citing it for a gazette reference.
What about Cabinet Decision No. 33 of 2024?
The same answer. A targeted search returns nothing connecting that number to the PDPL, and it cannot coexist with the 2023 and 2026 claims also being made.
Someone told me the regulations were issued in 2026. Is that right?
We found no publication traceable to a primary source, and the claim is contradicted by the portal's future-tense description of the Data Office [1] and by the professional-firm trackers [2][3].
Why does the u.ae page matter so much?
Because it is the government describing its own regulator. It states the UAE Data Office "will act" as the federal data regulator and "will be responsible for" preparing policies, standards and complaint systems, on a page stamped December 2025 [1].
What is the UAE Data Office?
The federal data protection regulator, established by Federal Decree-Law No. 44 of 2021 and affiliated with the UAE Cabinet, alongside the PDPL in the same legislative package [1].
Are the AED 50,000 to AED 5 million fines real?
We could not trace them to any primary instrument. The law provides that the Cabinet will issue a decision specifying violations and penalties, and we could not find that decision published [2][3].
So there is no PDPL penalty at all right now?
There is no published penalty schedule we could verify. That is not the same as saying nothing will ever apply. It means no adviser can honestly quote you a codified figure today.
Does the PDPL require breach notification within 72 hours?
Not confirmable. DLA Piper notes the PDPL does not specify detailed procedural timelines, deferring them to the unissued regulations [3]. The figure appears to be imported from the GDPR rather than sourced from UAE law.
When do I need to appoint a Data Protection Officer?
There is no published numeric threshold. The trigger is Executive-Regulation-dependent and unpublished [2][3]. Treat it as a risk judgement based on your volumes, data sensitivity and any monitoring you do.
Does the PDPL apply to companies outside the UAE?
Yes. It reaches controllers and processors inside or outside the UAE where the processing relates to data subjects inside the UAE [4]. An offshore processor handling UAE residents' data is in scope.
Does hosting my data abroad take me outside the PDPL?
No. The connecting factor is where the data subject is, not where the server is [4]. Moving your database overseas does not move your UAE customers.
Are free zone companies exempt from the PDPL?
Only the financial free zones, DIFC and ADGM, sit outside it, because they run their own regimes [8]. Every other free zone company is governed by the federal PDPL exactly as a mainland company is.
What law applies in DIFC?
DIFC Data Protection Law No. 5 of 2020, in force since 1 July 2020, administered by an independent Office of the Commissioner of Data Protection [7]. It was the GCC's first data protection law.
What law applies in ADGM?
The ADGM Data Protection Regulations 2021, issued 14 February 2021, explicitly benchmarked against the GDPR, with an independent Office of Data Protection headed by a Commissioner [5][6].
Is a DIFC or ADGM obligation enforceable today?
Yes. Both regimes are fully operative with published guidance and active Commissioners [5][6][7]. That is the sharpest practical difference from the federal position.
Is health data covered by the PDPL?
No. It is carved out and governed separately, including under Federal Law No. 2 of 2019 on ICT in health fields [4][8]. Being outside the PDPL does not mean being unregulated.
Is banking and credit data covered?
No. It sits under separate regimes including Federal Law No. 6 of 2010 on Credit Information [4][8]. Your staff and supplier records may still fall under the PDPL.
Is there a small business exemption?
Article 3 contemplates one for establishments not processing large volumes, but conditions it on standards set by the Executive Regulations [4]. Since those do not exist, the route is not currently operable and no published volume threshold applies.
What rights do data subjects have?
Access, correction, erasure, restriction, portability and objection are commonly listed [4][8]. The mechanics for exercising each are deferred to the Executive Regulations and not yet defined [2][3].
How quickly must I answer a data access request?
No UAE deadline is published [2][3]. Set your own written policy, meet it consistently, and describe it internally as your policy rather than a legal deadline.
What are the rules on transferring personal data out of the UAE?
The law sets requirements, but the adequacy list, contractual safeguard standards and approval procedures are Executive-Regulation-dependent and unpublished [2][3]. Build the vendor inventory and contract terms you would need under any plausible rule.
Is there an official English text of the PDPL?
We found none on a government domain. The primary text is hosted in Arabic on assets.u.ae [4], so every English version in circulation, including the phrasing here, is a translation.
What should I do before the regulations are published?
Build a record of processing, fix consent at collection, delete what you cannot justify, list your processors, put processor terms in vendor contracts, and write internal request and breach procedures [4].
What happens once the Executive Regulations are published?
Organisations get a further six months to comply [3]. That date is the real trigger, which is why it is worth a recurring calendar check rather than a package bought in advance.
How do I check whether a provider's PDPL claims are sound?
Ask one question: "Please send me the gazette reference or official government link for that decision." If they cannot produce it for the Executive Regulations, the penalty figures or the breach timeline, treat those deliverables as unsourced.
References
[1] UAE Government portal. Data protection laws. Describes the UAE Data Office in the future tense: it "will act as the federal data regulator in the UAE" and "will be responsible for" preparing policies and legislations, standards for monitoring the Personal Data Protection Law, and systems for complaints and grievances. Carries a December 2025 update stamp, and is also the source for Federal Decree-Law No. 44 of 2021. u.ae, data protection laws
[2] Chambers and Partners. Data Protection and Privacy 2026, UAE trends and developments. States that "The Implementing Regulations, intended to clarify key aspects of the law, have yet to be issued", that the PDPL "is still very much a work in progress", and that their absence has produced limited enforcement on the mainland. Chambers, Data Protection and Privacy 2026, UAE
[3] DLA Piper. Data Protection Laws of the World, United Arab Emirates. Records as of 6 January 2025 that the Executive Regulations had not been published, that the PDPL does not itself specify penalties or procedural timelines, and that once published, organisations get six months to comply. DLA Piper, Data Protection Laws of the World, UAE
[4] Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Primary text hosted in Arabic on the UAE Government assets domain, and the source for the 2 January 2022 commencement, the scope provisions on processing by electronic means inside or outside the UAE relating to data subjects inside the UAE, the exemptions, the Article 3 exemption power, the consent rule and the listed rights. No official English full text was found on a government domain. Federal Decree-Law No. 45 of 2021, Arabic primary text
[5] Abu Dhabi Global Market. Data Protection Regulations 2021, updated consolidated text. Issued 14 February 2021, explicitly benchmarked against the GDPR, establishing an independent Office of Data Protection under a Commissioner. ADGM Data Protection Regulations 2021
[6] Abu Dhabi Global Market. Office of Data Protection guidance. Guidance for controllers and processors in ADGM, evidencing an operative regime rather than one awaiting implementing rules. ADGM Office of Data Protection guidance
[7] DIFC Data Protection Law No. 5 of 2020, consolidated text. In force since 1 July 2020, administered by an independent Office of the Commissioner of Data Protection. DIFC was the first GCC jurisdiction to enact a data protection law. DIFC Data Protection Law No. 5 of 2020
[8] Pinsent Masons. Business in the UAE and the data protection regime. Practitioner overview of how the federal PDPL sits alongside the separate DIFC and ADGM regimes, and the carve-outs for health data under Federal Law No. 2 of 2019 and credit data under Federal Law No. 6 of 2010. Pinsent Masons, business in the UAE and the data protection regime









