Data Security & Breach Notification
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — personal data breach notification
United Arab Emirates · January 2, 2022 (statutory duty); operative deadline deferred to Executive Regulations
Verify detailsArt. 9 requires the controller to notify the UAE Data Office immediately upon becoming aware of a breach that would prejudice the privacy, confidentiality, or security of a data subject's data, and to notify the data subject where the breach would prejudice their privacy or confidentiality — with the notification content specified (nature, cause, approximate numbers and records, DPO details, likely effects, and remedial measures). A processor must notify its controller as soon as it becomes aware. The critical caveat: the Decree-Law defers the actual notification PERIOD to the Executive Regulations, and as set out in the UAE comprehensive-law entry, whether and when those Regulations were issued could not be confirmed against a primary UAE government source. Widely repeated '72 hours' figures for the federal PDPL should be treated as unverified. Note also that DIFC and ADGM entities are governed by their free-zone regimes instead, which have their own, separately drafted breach rules.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.