UAE PDPL Compliance Checklist
Before any checklist is useful, one question has to be answered: which UAE data protection regime applies to you. The federal law, the DIFC regime and the ADGM regime are separate, with separate regulators and separate obligations. This page sets out the position for each and the work each one requires.
Three regimes, not one
The United Arab Emirates does not have a single data protection regime. There are three that matter to most organisations:
- The federal Personal Data Protection Law. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, issued on 26 September 2021 and in force from 2 January 2022. This is the law commonly meant by UAE PDPL.
- The Dubai International Financial Centre. DIFC operates under its own Data Protection Law, DIFC Law No. 5 of 2020, enforced by the DIFC Commissioner of Data Protection.
- Abu Dhabi Global Market. ADGM operates under its Data Protection Regulations 2021, which came into effect on 11 February 2021, enforced by the ADGM Commissioner of Data Protection.
The federal law does not apply to entities established in a free zone that has its own data protection legislation, so an entity licensed in DIFC or ADGM looks to its own regime. Sectoral carve-outs also exist at federal level, including for government data and for health and credit data governed by separate legislation.
The federal PDPL and its regulator
The federal PDPL sets out the familiar structure of a modern data protection law: lawful bases for processing, obligations of controllers and processors, rights for data subjects including access, rectification, erasure, restriction, portability and objection to automated decision making, security obligations, breach notification, and conditions on transfers of personal data outside the UAE.
Two facts are usually glossed over. First, the executive regulations under the federal PDPL have not been issued. Several operative details, including notification timelines and the penalty regime, were left to those regulations, so the practical detail of federal compliance remains incomplete.
Second, the supervisory position has been in flux. The Emirates Data Office was created to oversee the law but did not become fully operational. On 14 June 2026 the UAE established a Federal Authority for Artificial Intelligence and Data, consolidating the Artificial Intelligence Office, the digital government functions previously held by the Telecommunications and Digital Government Regulatory Authority, and the Emirates Data Office.
None of that defers compliance. The law itself is in force, so the sensible approach is to build to the requirements in the decree-law and to the more developed DIFC and ADGM standards, so the arrangement holds when the regulations arrive.
The DIFC and ADGM regimes
The two financial free zone regimes are more developed than the federal position and are actively supervised.
- DIFC. DIFC Law No. 5 of 2020 is enforced by the Commissioner of Data Protection, whose office handles notifications, supervision, complaints and the authorisation of data exports. DIFC has continued to develop the regime, including a regulation on personal data processing in autonomous and artificial intelligence systems, and 2025 amendments allowing data subjects to bring claims directly before the DIFC courts.
- ADGM. The Data Protection Regulations 2021 are enforced by the ADGM Commissioner of Data Protection. Controllers must complete an annual notification to the Commissioner and pay the annual data protection fee. Rules made in 2025 refined the conditions for processing special categories of personal data in defined public interest situations.
Both regimes require lawful bases, transparency, security measures, records of processing, written contracts with processors, impact assessments where processing is high risk, breach notification to the Commissioner and, where the risk is significant, to affected individuals.
The compliance checklist
The steps below apply in substance across all three regimes, with the regulator, the notification duties and the transfer mechanisms differing according to which one you fall under.
- Establish which regime applies. Check the licensing authority of each entity in the group. A group can have entities under the federal law, in DIFC and in ADGM at the same time, in which case each entity is assessed separately.
- Determine the role of each entity for each processing activity: controller, processor, or both.
- Build a record of processing activities. Purpose, categories of data and data subjects, recipients, retention, transfers and security measures for each activity.
- Assign a lawful basis to every processing activity, and where consent is relied on, confirm that it is freely given, specific, informed and capable of being withdrawn, and that a record of it exists.
- Review privacy notices so that they state what is collected, why, on what basis, who it is shared with, how long it is kept and how rights are exercised.
- Establish a data subject rights procedure covering access, rectification, erasure, restriction, portability and objection, with a defined route for receiving, verifying and answering requests.
- Assess whether a Data Protection Officer must be appointed. The trigger is risk based: large scale processing of sensitive data, systematic evaluation of individuals, or processing likely to present a high risk. Where a DPO is appointed, record the appointment and the reporting line.
- Complete the annual notification and fee where the regime requires it. This applies in DIFC and ADGM.
- Put written data processing agreements in place with every processor and sub-processor, covering purpose limitation, security, sub-processing, assistance with rights requests, breach notification and deletion or return at the end of the engagement.
- Carry out impact assessments for high risk processing, including large scale processing of sensitive data, systematic monitoring and new technologies including automated decision making.
- Document the security measures in place. Access control, encryption, logging, backup, secure disposal and supplier security. An information security management system built to ISO/IEC 27001 supplies most of this evidence directly.
- Establish a breach response procedure that identifies who assesses the breach, on what criteria the regulator is notified, when data subjects are informed and how the incident is recorded.
- Confirm the mechanism for every transfer of personal data outside the jurisdiction, and record it in the transfer inventory.
- Set retention periods against each category of data, with disposal actually carried out rather than merely documented.
- Train staff who handle personal data, and keep the training record.
- Review annually, and on any material change to processing, systems or group structure, and when the federal executive regulations are issued.
How Univate supports UAE data protection work
- Determining which regime each entity in a group falls under, and where obligations overlap.
- Data mapping, records of processing and transfer inventories.
- Gap assessment against the applicable regime and a prioritised remediation plan.
- Drafting privacy notices, consent mechanisms, rights procedures, retention schedules and processor agreements.
- Impact assessment methodology and facilitation for high risk processing.
- DIFC and ADGM annual notification support.
- Alignment with ISO/IEC 27001 and ISO/IEC 27701 where the organisation wants certified evidence of its arrangements.
Frequently asked questions
What is the UAE PDPL?
The UAE PDPL is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It was issued on 26 September 2021 and came into force on 2 January 2022, and it is the federal data protection law of the United Arab Emirates.
Have the executive regulations under the federal PDPL been issued?
No. The executive regulations have not been issued. Several operative details, including notification timelines and the penalty regime, were left to them, so the practical detail of federal compliance remains incomplete while the law itself is in force.
Who is the federal regulator?
The Emirates Data Office was created to supervise the federal law but did not become fully operational. On 14 June 2026 the UAE established a Federal Authority for Artificial Intelligence and Data, which consolidated the Artificial Intelligence Office, the information and digital government functions previously with the Telecommunications and Digital Government Regulatory Authority, and the Emirates Data Office.
Does the federal PDPL apply to companies in DIFC or ADGM?
No. The federal law does not apply to entities established in a free zone that has its own data protection legislation. DIFC entities are subject to DIFC Law No. 5 of 2020 and the DIFC Commissioner of Data Protection. ADGM entities are subject to the ADGM Data Protection Regulations 2021 and the ADGM Commissioner of Data Protection.
Is an annual data protection notification required in the UAE?
In DIFC and in ADGM, yes. Controllers must complete an annual notification to the relevant Commissioner and pay the annual data protection fee. There is no equivalent federal notification and fee in operation.
Does ISO/IEC 27001 or ISO/IEC 27701 make an organisation PDPL compliant?
No certification proves compliance with a statute. ISO/IEC 27001 supplies the security control evidence and ISO/IEC 27701 supplies the privacy management evidence that a regulator would expect to see, but the legal analysis of whether a given processing activity is lawful still has to be done separately.
Univate Solutions supports organisations across India, the GCC, South East Asia, Africa and the United States. Speak to a consultant about your scope.
Related Services & Resources
Univate Global delivers ISO certifications, data privacy compliance and cybersecurity frameworks across its international markets.








