Enquire Us

GDPR vs UAE PDPL

This comparison is between the GDPR, Regulation (EU) 2016/679, and the federal UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, which came into effect on 2 January 2022. It is worth being precise about which UAE regime is meant, because the country has three. The federal PDPL applies onshore and is overseen by the UAE Data Office, established by Federal Decree-Law No. 44 of 2021. The Dubai International Financial Centre and the Abu Dhabi Global Market are financial free zones with their own data protection laws and their own commissioners, and entities within them are outside the federal law. The GDPR, by contrast, is enforced by the national supervisory authority of each EU and EEA member state, coordinated by the European Data Protection Board.

What is the UAE federal PDPL?

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the United Arab Emirates’ first general federal data protection law. The UAE Government describes it as an integrated framework to ensure the confidentiality of information and protect the privacy of individuals in the UAE.

  • Regulator. The UAE Data Office, created by Federal Decree-Law No. 44 of 2021, is the federal body responsible for data protection policy, standards, guidance and complaint mechanisms, and it receives breach notifications.
  • Scope. It covers the processing of personal data by electronic means, inside the UAE and in some circumstances outside it, where the data relates to individuals in the UAE.
  • Consent and rights. Processing generally requires consent, with defined exceptions such as public interest or a legal obligation. Individuals have rights including access, correction, erasure and restriction of processing, and rights in relation to automated processing.
  • Free zone carve out. Entities in free zones that have their own personal data protection legislation, currently DIFC and ADGM, are outside the federal law.
  • Executive regulations. The executive regulations that will settle several operational details had not been published at the time of writing, so organisations should track the UAE Data Office for the current position rather than assume final procedural rules.

What is the GDPR?

The General Data Protection Regulation, Regulation (EU) 2016/679, was adopted on 27 April 2016 and has applied since 25 May 2018. It applies directly in every EU member state and, through the EEA Agreement, in Iceland, Liechtenstein and Norway.

  • Enforcement. An independent supervisory authority in each member state supervises and enforces. The European Data Protection Board issues guidelines and binding decisions so that the regulation is applied consistently, and cross border cases run through a lead supervisory authority.
  • Legal bases. Six lawful bases are available, so consent is one option among several rather than the default.
  • Accountability. Controllers keep a record of processing activities, run data protection impact assessments for high risk processing, appoint a data protection officer in defined cases, and must be able to demonstrate compliance.
  • Breach notification. Notification to the supervisory authority within 72 hours where the breach is likely to result in a risk, and to individuals where the risk is high.
  • Transfers. Transfers outside the EEA rely on an adequacy decision or on safeguards such as standard contractual clauses or binding corporate rules.

GDPR vs UAE PDPL compared

AttributeGDPRUAE federal PDPL
InstrumentRegulation (EU) 2016/679Federal Decree-Law No. 45 of 2021
RegulatorNational supervisory authority in each EU and EEA state, coordinated by the European Data Protection BoardUAE Data Office, established by Federal Decree-Law No. 44 of 2021
Key datesAdopted 27 April 2016, applicable from 25 May 2018In effect from 2 January 2022
TerritoryThe EU and EEA, plus controllers and processors outside who target or monitor people thereOnshore UAE, and processing outside the UAE relating to individuals in the UAE
Free zone positionNot applicableDoes not apply to DIFC or ADGM entities, which have their own laws and commissioners
Legal basesSix lawful bases, consent being one of themConsent is the general requirement, with defined exceptions such as public interest or legal obligation
Implementing rulesSupplemented by EDPB guidelines and national lawExecutive regulations not yet published at the time of writing
Breach notificationTo the supervisory authority within 72 hours where a risk is likely, and to individuals where the risk is highTo the UAE Data Office, which assesses the causes and the security measures in place
TransfersAdequacy decision, or safeguards such as standard contractual clauses or binding corporate rulesPermitted to jurisdictions with adequate protection, or under conditions set out in the law
EU adequacyNot applicableThe UAE is not the subject of an EU adequacy decision

The three UAE regimes, and why the distinction matters

Getting the regime right is the first compliance decision, not a detail.

  • Onshore UAE. Federal Decree-Law No. 45 of 2021 applies, supervised by the UAE Data Office.
  • DIFC. The Data Protection Law, DIFC Law No. 5 of 2020, applies, supervised by the DIFC Commissioner of Data Protection. DIFC has been recognised by the United Kingdom as a Data Bridge priority partner.
  • ADGM. The Data Protection Regulations 2021, enacted on 14 February 2021, apply, supervised by the ADGM Office of Data Protection under its Commissioner of Data Protection. ADGM benchmarked the regulations against the GDPR.

A group with an onshore trading company, a DIFC entity and an ADGM entity is dealing with three regulators and three sets of procedural rules, even where the substantive principles line up. Contracts, privacy notices and breach playbooks need to name the correct law and the correct regulator for each entity.

Which law applies to you?

  • The federal UAE PDPL if you process personal data onshore in the UAE, or process the data of individuals in the UAE from outside, and you are not established in DIFC or ADGM.
  • DIFC Law No. 5 of 2020 or the ADGM Data Protection Regulations 2021 if your entity is registered in that financial free zone. The federal law does not apply to you in that case.
  • The GDPR if you are established in the EU or EEA, or if you offer goods or services to people there or monitor their behaviour.
  • More than one at once is common. A UAE group selling into Europe will be inside both the relevant UAE regime and the GDPR, and should build one programme to the stricter requirement in each area rather than run two.

Frequently Asked Questions

Which UAE law does this page compare with the GDPR?

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the federal UAE PDPL, which came into effect on 2 January 2022. The Dubai International Financial Centre and the Abu Dhabi Global Market have separate data protection laws and separate commissioners, and entities inside those free zones are outside the federal law.

Who regulates the federal UAE PDPL?

The UAE Data Office, established by Federal Decree-Law No. 44 of 2021. It is responsible for data protection policy and legislation, monitoring standards, complaint mechanisms and implementation guidance, and it receives breach notifications.

Have the executive regulations to the UAE PDPL been issued?

They had not been published at the time of writing. Several operational details therefore remain to be settled, and organisations should follow announcements from the UAE Data Office rather than assume final procedural rules.

Is the UAE covered by an EU adequacy decision?

No. Transfers of personal data from the EEA to the UAE therefore require an appropriate safeguard under the GDPR, such as standard contractual clauses or binding corporate rules, together with a transfer risk assessment.

How does consent differ between the two laws?

Under the GDPR, consent is one of six lawful bases and is often not the most appropriate one for business processing. Under the federal UAE PDPL, processing generally requires the consent of the data subject, with defined exceptions such as public interest or compliance with a legal obligation. That difference usually shows up first in marketing and HR processing.

If we comply with the GDPR, do we comply with the UAE PDPL?

Not automatically. A mature GDPR programme covers most of the principles, but the UAE framework differs on the consent model, on which regulator you deal with, and on which of the three UAE regimes applies to each of your entities. A mapping exercise per entity is the sensible first step.

Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.

Related Services & Resources

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.