WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Middle East

United Arab Emirates Privacy & Data Protection Laws

Every regime below can apply to a business handling United Arab Emirates residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 2, 2022 (federal law only — the DIFC and ADGM free zones run their own separate, self-contained data-protection regimes that apply only to entities registered within those specific zones, displacing rather than supplementing the federal law for them)
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
UAE PDPL
Verify details

Applies to entities established in the UAE (regardless of where data subjects are located) and, extraterritorially, to entities outside the UAE that process personal data of individuals inside the UAE, including in connection with offering goods/services or monitoring behavior. Excludes government data/public entities, personal/household-use processing, and health or credit/banking data already governed by its own sector legislation; the data-protection authority (the Bureau) also has discretionary power to exempt entities that don't process large volumes of personal data. Important open question: the Executive Regulations that were to be issued within six months of the Decree-Law — and which most operative compliance detail depends on, including the start of the grace period for compliance — had not been confirmed as published against a primary UAE government source at the time of writing. Secondary sources conflict on whether and when they were issued. Treat any claim that federal PDPL enforcement has been 'activated' as unverified until confirmed against the Official Gazette or the UAE Data Office directly.

Federal Decree-Law No. 45 of 2021, Arts. 2-3 (scope, exclusions, Bureau exemption power)Read regulation →

Sector-Specific Law · 1

This is a hard localisation rule, not a transfer-mechanism regime, and it is the single most operationally disruptive provision in the UAE for a health or health-adjacent business. Art. 13 prohibits storing, processing, generating or transferring health data relating to health services provided in the UAE outside the UAE, and separately prohibits GENERATING such data outside the UAE — so an offshore analytics pipeline or a foreign cloud region is not cured by contractual safeguards. The only route out is an express approval from the relevant health authority or the Minister, and it remains unclear whether those are granted case by case or by category. Penalties run from AED 500,000 to AED 700,000. Note the scope: the law applies across the whole UAE INCLUDING the free zones, so a DIFC or ADGM entity cannot rely on its free-zone data regime to displace this, and health data is separately carved out of the federal PDPL as sector-regulated. Marked 'check': the primary texts are Arabic-language originals and the approval practice is not publicly documented.

Federal Law No. 2 of 2019, esp. Art. 13; Cabinet Decision No. 32 of 2020 (Implementing Regulation)Read regulation →

Cross-Border Data Transfer · 1

January 2, 2022 (federal law only — DIFC and ADGM run separate regimes)
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — cross-border transfer and sharing of personal data
UAE PDPL Arts. 22-23
Verify details

Art. 22 permits transfer outside the UAE to states the UAE Data Office has approved as providing an adequate level of protection, or where a bilateral or multilateral agreement covering personal data protection applies. Art. 23 supplies the routes where no adequacy applies: a contract or agreement binding the recipient to the Decree-Law's requirements, the data subject's explicit consent, necessity for performing a contract between the controller and the data subject or a related contract in their interest, necessity for international judicial cooperation, or necessity to protect the public interest. The operative reality is that the adequacy route is unavailable: no list of adequate countries had been published, so in practice Art. 23 contract clauses or explicit consent carry every transfer. Marked 'check' and read alongside the caveat in the UAE comprehensive-law entry — the Executive Regulations that most operative detail depends on could not be confirmed as issued against a primary UAE government source. Entities licensed in DIFC or ADGM follow those free zones' own transfer rules instead.

Federal Decree-Law No. 45 of 2021, Arts. 22-23Read regulation →

Data Security & Breach Notification · 1

January 2, 2022 (statutory duty); operative deadline deferred to Executive Regulations
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — personal data breach notification
UAE PDPL Art. 9
Verify details

Art. 9 requires the controller to notify the UAE Data Office immediately upon becoming aware of a breach that would prejudice the privacy, confidentiality, or security of a data subject's data, and to notify the data subject where the breach would prejudice their privacy or confidentiality — with the notification content specified (nature, cause, approximate numbers and records, DPO details, likely effects, and remedial measures). A processor must notify its controller as soon as it becomes aware. The critical caveat: the Decree-Law defers the actual notification PERIOD to the Executive Regulations, and as set out in the UAE comprehensive-law entry, whether and when those Regulations were issued could not be confirmed against a primary UAE government source. Widely repeated '72 hours' figures for the federal PDPL should be treated as unverified. Note also that DIFC and ADGM entities are governed by their free-zone regimes instead, which have their own, separately drafted breach rules.

Federal Decree-Law No. 45 of 2021, Art. 9Read regulation →

Other Middle East jurisdictions