Skip to content
Protect24x7
Esc

Try XDR, DLP, CrowdStrike or PDPL. Arrow keys to move, Enter to open.

Talk to our SOC

UAE framework guide · UAE Data Office

UAE PDPL compliance, with a checklist

Federal Decree-Law No. 45 of 2021, in force since 2 January 2022. Every controller and processor outside the exemptions has duties under it, and the security half of those duties is what this page maps.

Who PDPL applies to

  • The processing of personal data, in whole or in part through electronic systems, inside or outside the country: the law’s own scope, as the UAE Government portal states it.
  • Not government data or government entities, not personal data held by security and judicial authorities, not processing for personal purposes, and not health or credit data governed by their own legislation.
  • Not entities established in free zones that have their own data protection law. DIFC and ADGM each have one, with their own regulator.

What PDPL asks for

The UAE Personal Data Protection Law, as the regulator publishes it, by theme rather than clause number.

A lawful basis, and consent by default
The law prohibits processing personal data without the consent of its owner, except in the cases it sets out, such as processing necessary to protect a public interest or to carry out legal procedures and rights.
Security of processing
Controllers and processors must secure personal data and maintain its confidentiality and privacy. This is the duty the mapping below turns into named controls.
Rights of the data subject
Access, correction, erasure, restriction, portability and objection, each with a process to answer it, which means knowing where the data is first.
Breach notification
Notify the UAE Data Office of a breach that would prejudice the privacy, confidentiality or security of personal data, and the affected individuals where the breach would harm them. The time limit and the content sit in the Executive Regulations.
Cross-border transfer and accountability
Transfers outside the country under the conditions the law and regulations set, records of processing, and a data protection officer in the cases the law defines.

From requirement to what we run

Each theme, and the service, the technology guide and the portfolio vendors that support it. A mapping, not a compliance claim: the service is what makes the control demonstrable.

Portfolio capabilities that support alignment14

Each row is published on the matching vendor page and reproduced here from the same source. This is a capability map, not compliance advice: it is not a certification, an audit result or a guarantee of coverage, and it does not interpret the regulation. Confirm applicability and scope with the vendor and a qualified compliance advisor before relying on it.

The checklist

Thirteen actions, each with an owner. Reviewed by the Protect24x7 GRC team on 14 September 2026.

  1. 01Confirm the law applies: you are not a government entity, not in a free zone with its own data law, and not processing only health or credit data under their own legislation.
  2. 02Inventory the personal data you hold: what, where, why, for how long, and who can reach it. Every other item depends on this one.
  3. 03Record a lawful basis for each processing purpose, and where it is consent, record how it was given and how it is withdrawn.
  4. 04Write the privacy notice people actually see at the point of collection, in plain language, covering purpose, retention and their rights.
  5. 05Build the process that answers a data subject request within a defined internal deadline: access, correction, erasure, restriction, portability, objection.
  6. 06Classify the data and apply controls proportionate to its sensitivity: encryption where it travels, access limited to a need, privileged access recorded.
  7. 07Put a leak control on the channels data leaves by: email, browser, cloud storage, removable media.
  8. 08Decide who your data protection officer is, or document why the law does not require one for you.
  9. 09Contract every processor: what they may do with the data, their security obligations, and their duty to tell you about a breach without delay.
  10. 10Map every cross-border transfer and the condition it relies on.
  11. 11Write the breach plan: how a breach is detected, who assesses it, who notifies the Data Office and the individuals, and how the timeline is evidenced. Read the Executive Regulations for the deadline before you write a number into it.
  12. 12Test recovery. Integrity and availability are obligations too, and a backup that will not restore is a breach waiting to be discovered.
  13. 13Keep the records that show all of the above happened: processing records, request logs, training, tests.

Questions buyers ask

Does PDPL apply to us?
Federal Decree-Law No. 45 of 2021 has applied since 2 January 2022 to the processing of personal data, in whole or in part through electronic systems, inside or outside the country. It does not apply to government data and government entities, to personal data held by security and judicial authorities, to processing for personal purposes, to health and credit data governed by their own laws, or to entities established in free zones with their own data protection law, DIFC and ADGM among them. If none of those exemptions is yours, it applies.
What does the law require of a controller?
A lawful basis for processing, with consent as the default and defined exceptions; safeguards that secure the data and keep it confidential; a process to honour the rights of the people it describes; conditions on transferring it outside the country; records that show how it is handled; and a data protection officer in the cases the law sets out.
What happens when there is a breach?
The controller must notify the UAE Data Office of a breach that would prejudice the privacy, confidentiality or security of personal data, and notify the affected individuals where the breach would harm them. The time limit and the contents of a notification sit in the Executive Regulations rather than in the decree-law, so check the UAE Data Office for their current text before you write a number into your incident plan. What the plan can fix now is the evidence: a forensic timeline turns a notification from an estimate into a statement of fact.
Who enforces it?
The UAE Data Office, the federal data regulator. The UAE Government portal describes its role as preparing data-protection policy and legislation, proposing and approving standards, handling complaints, and issuing guidelines and instructions for implementing the law.
Which security controls does the law actually mean?
It does not name products, and it should not. Read the duties as controls: know what you hold and where (data security posture management), stop it leaving (data loss prevention, browser and email controls), limit who reaches it (privileged access, zero trust), detect and investigate a breach on the clock (detection and response, forensics), and keep it recoverable (tested backups). The mapping above names the service, the guide and the portfolio product for each.
Does PDPL replace the DIFC and ADGM data protection laws?
No. Entities established in a free zone with its own data protection law follow that law and its regulator; the federal law excludes them. An organisation with entities on both sides of that line has two regimes to satisfy, and the inventory in the checklist is where the split becomes visible.

Sources

Every regulatory statement on this page comes from one of these documents. Where they are silent, so is the page.

Being assessed against PDPL?
A gap assessment against the current edition, controls mapped to it, and the evidence collected before the review, not during it.
Talk to the GRC team