Commercial Law

UAE Personal Data Protection Law Compliance Guide

05 October 2026 · 10 min read

The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, requires businesses to have a valid reason for using personal data, protect it, respect individual rights, manage breaches, and control overseas transfers. If your business handles personal data of people in the UAE, these duties can apply even if the processing happens outside the UAE.

Who must comply with the UAE PDPL

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the main UAE federal law for personal data protection. It applies to businesses that process personal data of individuals in the UAE. The rule is not limited to companies incorporated in the UAE.

A UAE shop, clinic, app, delivery company, hotel, broker, school, or online platform will usually be within scope if it collects or uses customer, employee, supplier, or user data. A foreign company can also be caught if it handles personal data of people in the UAE. For example, an overseas software company that stores user profiles for UAE residents, sends marketing to UAE customers, or supports a UAE client’s HR system may need to comply.

“Processing” is broad in practice. It can include collecting, recording, storing, changing, sharing, deleting, viewing, or otherwise using personal data. Personal data includes information that identifies a person, or can identify them when combined with other data. This can include names, mobile numbers, Emirates ID details, email addresses, location data, photos, CCTV images, health information, payment details, account IDs, and device data.

The PDPL matters for small businesses too. A small salon with client booking records, a gym using biometric access, or a real estate agency holding tenant passports may all process personal data. The size of the business does not remove the need to handle personal data lawfully and securely.

Business situation Likely PDPL issue Practical action
UAE e-commerce site stores customer names, addresses, and payment records Personal data processing in the UAE Use clear privacy notices, secure systems, and valid consent or another legal basis
Overseas app targets UAE users PDPL may apply because users are in the UAE Review UAE data handling, consent, support, and transfer controls
Clinic keeps patient files Sensitive data risk, including health data Use stricter access controls and consider appointing a DPO
Employer keeps staff records Employee personal data processing Limit access, keep records accurate, and allow rights requests
Marketing agency sends campaigns for clients Shared processing and consent risk Check contracts, consent records, and data sharing rules

The PDPL requires a proper legal basis before a business processes personal data. In many cases, this means getting explicit consent from the individual. Consent should be clear, specific, informed, and capable of being withdrawn. A vague line hidden in general terms is risky. A pre-ticked box is also risky because it may not show a real choice.

A good consent request should say what data you collect, why you need it, who will use it, whether it will be shared, and how the person can withdraw consent. If you collect data for more than one purpose, separate the choices where possible. For example, a customer may need to give data to receive delivery updates, but they should not be forced to accept marketing messages unless marketing is truly part of the service they requested.

The research confirms that there are exceptions where consent may not be needed, such as processing needed to protect public interest or comply with a legal obligation. Businesses should not treat these exceptions as a shortcut. If you rely on a non-consent basis, record the reason and keep evidence. For example, if you keep invoice records because the law requires business records, your file should show that purpose.

Consent must also be easy to withdraw. If a customer can sign up online, they should normally be able to withdraw marketing consent without calling several departments. Withdrawal does not always mean the business must delete every record at once. Some records may still need to be kept for legal, accounting, dispute, or security reasons. The key point is that the business must stop using the data for the purpose covered by the withdrawn consent, unless another valid basis applies.

Individual rights your business must support

The PDPL gives individuals rights over their personal data. The research identifies rights to access, correct, delete, and restrict processing of personal data. Businesses must have a working process to receive and handle these requests. It is not enough to write these rights in a privacy notice if staff do not know what to do when a request arrives.

An access request means the person asks what personal data you hold about them. A correction request means they want wrong or outdated data fixed. A deletion request means they want data erased. A restriction request means they want the business to limit how the data is used, for example while a complaint is being reviewed.

The research says businesses must respond within specified timeframes, but it does not give the number of days. Because of that, a business should set an internal deadline that is short enough to avoid delay, and should check the current UAE regulatory guidance or legal advice for the exact period that applies to its case. As a practical control, many businesses route all privacy requests to one mailbox or ticket queue so they are not missed.

Businesses also need identity checks. If someone asks for a copy of personal data, you should make sure the requester is the actual person or a properly authorised representative. Otherwise, a rights request can itself become a data breach.

A worked example helps. A UAE gym member asks for deletion of their account. The gym should check what data it holds, such as membership records, payment records, CCTV records, biometric access data, and emails. It may be able to delete marketing preferences and inactive profile data. It may need to keep invoices or dispute-related records if another legal duty applies. The response should explain what was deleted, what was kept, and why.

DPO, security measures, and breach notification

The PDPL expects businesses to protect personal data using appropriate technical and organisational measures. Technical measures include passwords, multi-factor authentication, encryption, access logs, backups, device controls, secure cloud settings, and patching. Organisational measures include staff training, written policies, approval workflows, contracts with suppliers, internal audits, and limits on who can access data.

Some businesses should appoint a Data Protection Officer, often called a DPO. The research points to this especially where an organisation processes large volumes of personal data or handles sensitive categories such as health data or biometric data. The DPO monitors compliance and acts as a point of contact with the UAE Data Office. Even where a full-time DPO is not needed, a business should still appoint someone senior enough to own data protection tasks.

A DPO should not be a figurehead. They should understand where data comes from, where it is stored, who can access it, which vendors use it, and what happens if there is a complaint or breach. For a small company, this may be a trained compliance manager or operations manager, supported by external legal and IT help. For a larger company, it may require a dedicated role.

Breach notification is also a major duty. If a personal data breach happens, the business must notify the UAE Data Office and affected individuals without undue delay. The notification should explain the nature of the breach and the measures taken to address it. A breach can include a hacked customer database, a laptop lost without encryption, a staff member sending payroll data to the wrong recipient, or accidental online exposure of files.

Businesses should prepare before a breach happens. A simple breach plan should list who investigates, who decides whether notification is needed, who contacts affected people, and who deals with system recovery. Delay often happens because no one knows who is in charge.

Sending personal data outside the UAE

Cross-border data transfers are a key PDPL risk. Many UAE businesses use overseas cloud hosting, foreign payroll providers, global CRM tools, international payment platforms, offshore call centres, or regional group companies. These arrangements can involve transferring personal data outside the UAE, even if the customer never sees it.

The research states that transfers outside the UAE are restricted unless the receiving country provides adequate protection, appropriate safeguards are in place, or explicit consent is obtained from the data subject. This means a business should not assume that using a famous global vendor is automatically compliant. You need to understand where the vendor stores and accesses the data, what security measures it uses, and what contractual promises it gives.

Appropriate safeguards may include strong data processing terms, security duties, breach reporting duties, limits on onward transfers, audit rights, confidentiality duties, and deletion or return of data when the service ends. The exact safeguards should match the sensitivity of the data. Customer email addresses for a newsletter are not the same risk as health records, biometric scans, or passport copies.

Explicit consent can help in some cases, but it is not always the best operational solution. Consent must be clear and withdrawable. If your whole service depends on an overseas processor, a withdrawn consent can create a practical problem. Businesses should therefore build transfer compliance into supplier contracts and system design, not rely only on consent wording.

An edge case is remote support. A UAE business may store data in the UAE, but an overseas IT team may log in to fix errors. That can still involve access from outside the UAE. Treat it as a transfer or overseas access issue and control it through permissions, logs, confidentiality, and contract terms.

What to do next

Start with a data map. List what personal data your business collects, where it comes from, why you use it, where it is stored, who can access it, who you share it with, and when you delete it. Do this for customers, employees, suppliers, website users, app users, CCTV footage, and marketing contacts. A basic spreadsheet is better than no record at all.

Next, check your legal basis. For each use of personal data, write down whether you rely on explicit consent, a legal obligation, public interest, or another permitted basis. Do not use one broad consent statement for every purpose. Separate core service use from optional marketing, profiling, surveys, or sharing with partners.

Then update your customer-facing documents. Your privacy notice should be easy to find and easy to read. It should explain what data you collect, why you collect it, who receives it, whether it may go outside the UAE, what rights people have, and how they can contact you. Your consent wording should be specific. Keep evidence of when and how consent was given.

Review supplier contracts. Focus on cloud providers, software vendors, payment processors, outsourced HR providers, call centres, marketing agencies, delivery partners, and IT support companies. Contracts should cover confidentiality, security, breach reporting, use limits, deletion, subcontracting, and cross-border transfers.

Put rights request and breach procedures in writing. Train front-line staff to recognise a data request or breach. A receptionist, sales employee, or customer service agent may be the first person to receive one. They should know where to send it.

Finally, decide whether you need a DPO or a named data protection lead. If you process large volumes of personal data, or sensitive data such as health or biometric data, treat this as a priority. Budget for legal review, IT security checks, staff training, and contract updates. The exact cost depends on the size and complexity of the business, but the cost of fixing a breach after the event is often far higher than building controls early.

This article is general information about UAE law, not legal advice. Laws change and every situation is different. For advice on your own case, speak to a licensed UAE lawyer.

Have a question about your own case? Ask LocalLaw AI and get a clear answer with the law behind it. Start for free

Common questions

Who must comply with the UAE Personal Data Protection Law?

The UAE PDPL applies to businesses that process personal data of individuals in the UAE. It can also apply to foreign companies if they handle data of people in the UAE, such as UAE users, customers, or employees.

What counts as personal data under the UAE PDPL?

Personal data is information that identifies a person or can identify them when combined with other data. Examples include names, Emirates ID details, mobile numbers, email addresses, CCTV images, health data, payment details, and location data.

Does a business always need consent to process personal data?

The PDPL requires a valid legal basis for processing personal data, and explicit consent is often used. However, consent may not be needed in some cases, such as legal obligations or public interest, but the business should record and evidence the basis relied on.

What rights do individuals have under the UAE PDPL?

Individuals may have rights to access, correct, delete, and restrict the processing of their personal data. Businesses should have a clear process for receiving requests, checking identity, and responding within the required timeframe.

When must a business report a personal data breach?

If a personal data breach occurs, the business must notify the UAE Data Office and affected individuals without undue delay. The notice should explain the breach, its nature, and the steps taken to address it.

Sources

Have a question about your own situation?

LocalLaw AI answers in plain English and shows you the law behind it, in English or Arabic.

Start for free