PrivacyCache
enactedAEEffective January 2, 2022

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)

Complete compliance guide for companies with <200 employees. Everything you need to know about PDPL requirements, deadlines, and penalties.

DSAR Deadline

30 calendar days

Max Penalty

AED 5,000,000/violation

Administrative fines up to AED 5 million for violations. Higher penalties may apply for repeat offenders. Note: the DIFC and ADGM free zones have separate data protection frameworks with their own penalty structures.

Threshold

No threshold

Est. Cost

$8,000 – $25,000

8-18 weeks

Mid-Market Compliance Guide

The federal PDPL provides a baseline for data protection across the UAE. Companies operating in the DIFC or ADGM free zones should comply with the respective free zone data protection laws in addition. Executive regulations issued in 2023 provide detailed implementation guidance. Full enforcement began in 2025.

Key Requirements

  • Obtain explicit consent for processing personal data
  • Purpose limitation and data minimization
  • Implement appropriate technical and organizational measures
  • Data breach notification to UAE Data Office
  • Cross-border transfer requires adequate protection in recipient country
  • Data Protection Impact Assessment for high-risk processing
Enforced by: UAE Data OfficeOfficial site

Consumer Rights

Right of Access (Art. 14)
Right to Correction (Art. 15)
Right to Erasure (Art. 16)
Right to Restrict Processing (Art. 17)
Right to Data Portability (Art. 18)
Right to Object to Automated Decision-Making

Business Obligations

Exemptions

  • Government data for national security purposes
  • Data processed by security and judicial authorities
  • Personal or family use
  • Health data for public health emergencies (limited scope)

Related Privacy Laws

Recommended Compliance Tools

No vendors have been reviewed for PDPL coverage yet.

Browse all compliance tools

Get a mid-market compliance checklist for PDPL

We'll send you a practical, step-by-step checklist tailored for companies with <200 employees. No spam, unsubscribe anytime.

See how DPAs enforce PDPL in practice

Real fines, real violations, real lessons. Browse our enforcement database to understand what gets penalized under PDPL.

Disclaimer: This is general information, not legal advice. Consult a qualified attorney for your specific situation. Laws and regulations may change. Last reviewed: 3/27/2026.

Read the official text of PDPL