Jurisdiction Guides / Middle East
United Arab Emirates Privacy & Data Protection Laws
Every regime below can apply to a business handling United Arab Emirates residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to entities established in the UAE (regardless of where data subjects are located) and, extraterritorially, to entities outside the UAE that process personal data of individuals inside the UAE, including in connection with offering goods/services or monitoring behavior. Excludes government data/public entities, personal/household-use processing, and health or credit/banking data already governed by its own sector legislation; the data-protection authority (the Bureau) also has discretionary power to exempt entities that don't process large volumes of personal data. Important open question: the Executive Regulations that were to be issued within six months of the Decree-Law — and which most operative compliance detail depends on, including the start of the grace period for compliance — had not been confirmed as published against a primary UAE government source at the time of writing. Secondary sources conflict on whether and when they were issued. Treat any claim that federal PDPL enforcement has been 'activated' as unverified until confirmed against the Official Gazette or the UAE Data Office directly.
Sector-Specific Law · 1
This is a hard localisation rule, not a transfer-mechanism regime, and it is the single most operationally disruptive provision in the UAE for a health or health-adjacent business. Art. 13 prohibits storing, processing, generating or transferring health data relating to health services provided in the UAE outside the UAE, and separately prohibits GENERATING such data outside the UAE — so an offshore analytics pipeline or a foreign cloud region is not cured by contractual safeguards. The only route out is an express approval from the relevant health authority or the Minister, and it remains unclear whether those are granted case by case or by category. Penalties run from AED 500,000 to AED 700,000. Note the scope: the law applies across the whole UAE INCLUDING the free zones, so a DIFC or ADGM entity cannot rely on its free-zone data regime to displace this, and health data is separately carved out of the federal PDPL as sector-regulated. Marked 'check': the primary texts are Arabic-language originals and the approval practice is not publicly documented.
Cross-Border Data Transfer · 1
Art. 22 permits transfer outside the UAE to states the UAE Data Office has approved as providing an adequate level of protection, or where a bilateral or multilateral agreement covering personal data protection applies. Art. 23 supplies the routes where no adequacy applies: a contract or agreement binding the recipient to the Decree-Law's requirements, the data subject's explicit consent, necessity for performing a contract between the controller and the data subject or a related contract in their interest, necessity for international judicial cooperation, or necessity to protect the public interest. The operative reality is that the adequacy route is unavailable: no list of adequate countries had been published, so in practice Art. 23 contract clauses or explicit consent carry every transfer. Marked 'check' and read alongside the caveat in the UAE comprehensive-law entry — the Executive Regulations that most operative detail depends on could not be confirmed as issued against a primary UAE government source. Entities licensed in DIFC or ADGM follow those free zones' own transfer rules instead.
Data Security & Breach Notification · 1
Art. 9 requires the controller to notify the UAE Data Office immediately upon becoming aware of a breach that would prejudice the privacy, confidentiality, or security of a data subject's data, and to notify the data subject where the breach would prejudice their privacy or confidentiality — with the notification content specified (nature, cause, approximate numbers and records, DPO details, likely effects, and remedial measures). A processor must notify its controller as soon as it becomes aware. The critical caveat: the Decree-Law defers the actual notification PERIOD to the Executive Regulations, and as set out in the UAE comprehensive-law entry, whether and when those Regulations were issued could not be confirmed against a primary UAE government source. Widely repeated '72 hours' figures for the federal PDPL should be treated as unverified. Note also that DIFC and ADGM entities are governed by their free-zone regimes instead, which have their own, separately drafted breach rules.
Other Middle East jurisdictions