Before the list: does the law apply to you
Federal Decree-Law No. 45 of 2021 applies to the processing of personal data inside or outside the country. It does not apply to government data and government entities, to personal data held by security and judicial authorities, to processing for personal purposes, to health and credit data governed by their own laws, or to entities in a free zone with its own data protection law. Owner: legal. Done when: a one-page memo says which entities are in scope and why, and names the free-zone entities that answer to a different regulator.
Items one to three: know the data, and why you hold it
Inventory what personal data you hold, where, why, for how long, and who can reach it. Record a lawful basis for each purpose; where it is consent, record how it was given and how it is withdrawn. Write the privacy notice people actually see at the point of collection. Owner: the data protection lead, with IT for the inventory. Done when: the inventory exists as a maintained register, not a spreadsheet from a workshop, and every purpose in it has a basis beside it. This is the item the rest depend on, and it is where data security posture management earns its place: a tool that finds the data across the stores you actually use turns a quarter of guesswork into a week of confirmation.
Items four and five: the rights, and the process behind them
Access, correction, erasure, restriction, portability, objection. Each is a request someone can make, and each needs a process that answers it within a defined internal deadline. Owner: the data protection lead, with whoever runs the systems. Done when: a request can be traced from receipt to answer, and a test request has been run end to end. A request you cannot answer is the same failure as one you refused.
Items six and seven: security of processing
Classify the data and apply controls proportionate to its sensitivity: encryption where it travels, access limited to a need, privileged access recorded. Put a leak control on the channels data leaves by: email, browser, cloud storage, removable media. Owner: security. Done when: the controls map to the classification, and the leak control is in blocking mode rather than switched to monitor-only after it interrupted someone. These two items are where the law meets the technologies on the data security page: loss prevention, privileged access, browser controls.
Items eight to ten: the people and the contracts
Decide who your data protection officer is, or document why the law does not require one for you. Contract every processor for what they may do with the data, their security obligations, and their duty to tell you about a breach without delay. Map every cross-border transfer and the condition it relies on. Owner: legal, with procurement for the contracts. Done when: every supplier that touches personal data has the clause, and the transfer map has no rows marked unknown.
Item eleven: the breach plan
How a breach is detected, who assesses it, who notifies the UAE Data Office and the individuals, and how the timeline is evidenced. The decree-law leaves the notification period and contents to the Executive Regulations, so read those before writing a number into the plan. Owner: security, with legal for the notification itself. Done when: a tabletop exercise has run the plan end to end and produced the artefact a regulator would ask for: a timeline of what was known when. Detection and forensics are what make that timeline a statement of fact rather than an estimate.
Items twelve and thirteen: recovery and records
Test recovery: integrity and availability are obligations too, and a backup that will not restore is a breach waiting to be discovered. Keep the records that show all of the above happened: processing records, request logs, training, tests. Owner: IT for recovery, the data protection lead for the record. Done when: a restore has been run against a real backup this quarter, and the record can answer "show me" for any item on this list without a search.
What this is not
Legal advice, or a statement of any deadline. The regulator is the UAE Data Office; the Executive Regulations carry the detail this article deliberately does not. Protect24x7 holds no accreditation under the law. What the GRC service does is the inventory, the gap assessment and the evidence; what the managed services do is the detection, response and recovery the security items depend on.
Written by the Protect24x7 GRC team. Published 15 September 2026, last reviewed 15 September 2026. Indicative guidance, not legal advice or a certification claim.
