UAE Federal Decree-Law No. 45 of 2021: What Is It and Who Does It Apply To?
The UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (UAE PDPL) is the first comprehensive federal data protection legislation in the UAE, effective from January 2, 2022. Enacted as part of the UAE's broader digital economy strategy under UAE Vision 2030, the law establishes a unified federal framework for personal data protection applicable to the private sector across all Emirates — with carve-outs for government entities, which are subject to a separate regime.
The UAE PDPL has extraterritorial reach: it applies not only to organisations established in the UAE but also to any foreign organisation processing personal data of UAE residents in connection with offering goods or services to, or monitoring the behaviour of, individuals in the UAE. This mirrors the GDPR's extraterritorial approach and is particularly significant for global SaaS companies, e-commerce platforms, and digital service providers with UAE resident customers.
The law is administered by the UAE Data Office, established under Cabinet Resolution No. 44 of 2023 as an independent regulatory authority operating under the supervision of the Telecommunications and Digital Government Regulatory Authority (TDRA). The UAE Data Office is responsible for enforcement, issuing guidance, and receiving breach notifications and complaints.
Key Definitions
- Personal data: Any data relating to an identified or identifiable natural person — directly or indirectly — through identifiers such as name, ID number, location data, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
- Sensitive personal data: Data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, criminal records, financial data, health data, biometric data, genetic data, and data of children.
- Controller: A natural or legal person that determines the purposes and means of processing personal data.
- Processor: A natural or legal person that processes personal data on behalf of a controller.
Lawful Basis for Processing
Article 5 of the UAE PDPL establishes six lawful bases for processing personal data — closely paralleling GDPR Article 6:
- Consent: The data subject has given freely given, specific, informed, and unambiguous consent.
- Contract: Processing is necessary for the performance of a contract to which the data subject is party, or to take pre-contractual steps at their request.
- Legal obligation: Processing is necessary to comply with a legal obligation.
- Vital interests: Processing is necessary to protect the vital interests of the data subject or another person.
- Public task: Processing is necessary for the performance of a task carried out in the public interest.
- Legitimate interests: Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where overridden by the interests or fundamental rights of the data subject.
For sensitive personal data, Article 8 requires explicit consent unless processing falls under specific exceptions (vital interests where consent cannot be given; legal claims; manifestly made public data; public health; archiving/scientific/research purposes).
Consent Requirements
UAE PDPL consent must be:
- Freely given: No coercion or conditionality beyond what is necessary for the service.
- Specific: Tied to a specific, defined purpose — not bundled with other purposes.
- Informed: Data subjects must understand what they are consenting to before giving consent.
- Unambiguous: Clear affirmative action required — pre-ticked boxes and silence do not constitute consent.
For children (under 18 in the UAE): guardian or parental consent is required. Age verification mechanisms must be implemented. Children's data must not be processed for direct marketing or profiling.
Withdrawal of consent must be as easy as giving it. Processing must stop within a reasonable timeframe upon withdrawal. Data subjects cannot be penalised for withdrawing consent. Consent records — including timestamp, scope, and withdrawal history — must be maintained.
Data Subject Rights (Articles 13–21)
The UAE PDPL confers seven key rights on data subjects:
- Right to access (Art. 13): Data subjects can request a copy of their personal data and information about how it is used. Controllers must respond within 30 days. Identity verification is permitted but must not create an unreasonable barrier.
- Right to rectification (Art. 14): Inaccurate or incomplete personal data must be corrected promptly upon request. Third parties to whom the data was disclosed must be notified.
- Right to erasure (Art. 15): Personal data must be deleted upon request when: no longer necessary for the original purpose; consent is withdrawn and no other legal basis applies; processing is unlawful; or a legal obligation requires deletion. Retention on a legitimate legal basis (legal claims, legal obligation, vital interests) must be documented.
- Right to restriction (Art. 16): Data subjects can request processing be restricted pending resolution of an accuracy challenge or objection — data may be stored but not further processed during this period.
- Right to data portability (Art. 17): Personal data must be provided in a structured, commonly used, machine-readable format upon request. Transfer to another controller must be facilitated where technically feasible.
- Right to object (Art. 18): Data subjects can object to processing based on legitimate interests. The objection must be honoured unless compelling legitimate grounds override it. Objection to direct marketing must be honoured immediately and unconditionally.
- Rights request channel: An accessible, documented channel must be maintained for submitting rights requests. Escalation to the UAE Data Office for unresolved complaints must be available.
Controller Obligations and Privacy Notice
Controllers must provide a privacy notice at or before the point of data collection (Art. 22–29). The notice must include:
- Identity of the controller and contact details
- Purposes and legal basis for processing
- Data categories collected
- Retention periods
- Data subject rights and how to exercise them
- Cross-border transfer information (destination country, safeguards)
- DPO/Privacy Officer contact details
The notice must be in clear, plain language. An Arabic language version is strongly recommended for operations targeting UAE resident consumers. The notice must be updated when processing activities change materially.
Additional obligations include: data minimisation; purpose limitation; accuracy maintenance; data retention schedule with automated deletion or anonymisation at end of retention; data processing register (RoPA equivalent); privacy by design and by default; written processor contracts with required clauses.
Security Obligations and 72-Hour Breach Notification
Controllers must implement technical and organisational security measures appropriate to the risk posed by their processing activities (Art. 30). These measures should include:
- Encryption at rest and in transit
- Access controls and multi-factor authentication
- Logging, monitoring, and audit trails
- Regular security testing and vulnerability management
- Staff training on security practices
Upon becoming aware of a personal data breach likely to result in risk to the rights and freedoms of data subjects, controllers must (Art. 32–33):
- Notify the UAE Data Office within 72 hours — including the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed.
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to individuals — notification must be in clear, plain language and include what individuals can do to protect themselves.
A breach incident register must be maintained documenting all breaches regardless of the notification threshold. Processors must notify controllers without undue delay upon becoming aware of a breach.
Cross-Border Data Transfers
Personal data may be transferred outside the UAE only where one of the following safeguards is in place (Arts. 34–38):
- Adequacy decision: Transfer to a country that the UAE Data Office has determined provides an adequate level of personal data protection. The UAE Data Office is expected to publish and maintain an adequacy list; EU/EEA countries and UK are expected to receive adequacy recognition given their own data protection frameworks.
- Contractual safeguards: Data Transfer Agreements (DTAs) or equivalent contractual clauses providing personal data protection equivalent to the UAE PDPL — similar to GDPR Standard Contractual Clauses.
- Binding Corporate Rules: For intra-group transfers, approved BCRs providing equivalent protection.
- Explicit consent: As a fallback, explicit consent of the data subject — but reliance solely on consent for regular operational transfers is high-risk.
A cross-border transfer inventory should be maintained documenting all personal data flows outside the UAE, including destination country, recipient, transfer mechanism, data categories, and legal basis.
DIFC and ADGM Free Zone Regimes
The UAE has two major financial free zones — the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM) — each with its own distinct data protection regime that applies independently of the federal PDPL:
- DIFC Data Protection Law No. 5 of 2020 (DPL 2020): Broadly GDPR-aligned. Applies to all entities established in the DIFC (licensed and registered in the DIFC). Enforced by the DIFC Commissioner of Data Protection. Obligations include: 8 data subject rights; lawful basis (6 bases); DPIA for high-risk processing; DPO appointment (mandatory for certain processing); 72-hour breach notification to DIFC Commissioner; cross-border transfer safeguards (adequacy, appropriate safeguards, derogations); administrative fines up to USD 100,000 per violation.
- ADGM Data Protection Regulations 2021: Also GDPR-aligned. Applies to entities established in the ADGM. Enforced by the ADGM Registration Authority. Similar obligations to DIFC DPL and GDPR.
Entities operating in DIFC or ADGM must ensure compliance with the applicable free zone data protection regime in addition to any obligations under the federal PDPL for processing data of UAE mainland residents.
Enforcement and Penalties
The UAE Data Office has authority to investigate complaints, conduct audits, and issue administrative penalties. Under Cabinet Resolution No. 44 of 2023:
- Administrative penalties: Up to AED 20 million for serious violations of the PDPL.
- Criminal sanctions: Possible for the most serious violations, including unlawful disclosure of sensitive personal data — Criminal Code provisions apply.
The UAE Data Office has been building its enforcement capacity since its establishment in 2023. Given the UAE's position as a global business hub — with over 3 million businesses, significant financial services, technology, and logistics sectors — enforcement activity is expected to intensify as the Data Office matures.
UAE PDPL Compliance Programme
A pragmatic UAE PDPL compliance programme should include:
- Personal data audit and data inventory (mapping all processing activities, data categories, purposes, recipients)
- Lawful basis documentation for every processing activity
- Privacy notice review and update (including Arabic translation)
- Consent mechanism audit (checking for bundled consent, pre-ticked boxes, withdrawal mechanisms)
- Processor contract review (ensuring DTA/equivalent safeguards for cross-border transfers)
- 72-hour breach response plan and incident register
- Data subject rights intake process (30-day response tracking)
- DIFC/ADGM compliance assessment where applicable
- Staff training programme
- UAE Data Office registration where required
Assess Your UAE PDPL Compliance
Use the UAE PDPL Compliance Checker to assess your organisation across 42 key controls, generate a tailored AI compliance report, and build a prioritised remediation roadmap aligned to UAE Federal Decree-Law No. 45/2021 and UAE Data Office requirements.