Regulatory · Privacy & Data Protection

UAE Data Protection — federal PDPL, DIFC, ADGM and the sector overlays.

Federal Decree-Law 45 of 2021 (the UAE PDPL), DIFC Data Protection Law 5 of 2020, ADGM Data Protection Regulations 2021 and the sector-specific overlays for banking, health, telecom and securities. Mapping, build-out, breach response, regulator engagement.

Brief our privacy team → Scope of work
FDL 45/2021
Federal PDPL
DIFC L.5/2020
DIFC DP Law
ADGM 2021
ADGM DP Regulations
72hr
Breach notification standard

Scope

What we do for controllers, processors and DPOs.

Compliance build-out

  • Regime mapping — federal PDPL vs DIFC vs ADGM vs sector regulator
  • Controller / processor classification per processing activity
  • Record of Processing Activities (ROPA) preparation
  • Lawful-basis analysis for each processing purpose
  • Privacy policy, notices and consent flow drafting
  • Data Processing Agreement (DPA) template suite
  • Sub-processor governance and approval framework
  • Cross-border transfer architecture — SCCs, BCRs, adequacy

DPO services

  • Outsourced DPO appointment
  • DPO operating model design (in-house, outsourced, hybrid)
  • Reporting line to top management
  • DPO function audit
  • Annual DPO report drafting

Breach response & enforcement

  • 24/7 breach hotline retainer
  • 72-hour regulator notification preparation and submission
  • Affected data-subject communication
  • Internal investigation under privilege
  • Cross-regulator coordination (UAE + DIFC + ADGM + GDPR)
  • Forensic-investigation counsel coordination
  • Insurance claim support — cyber/D&O
  • Regulator follow-up enforcement defence

Specialist matters

  • Data Protection Impact Assessment (DPIA)
  • Marketing consent re-architecture (TDRA + PDPL)
  • Health data — DHA / DOH / MOHAP overlays
  • Banking data — CBUAE confidentiality framework
  • Employee monitoring & HR-data compliance
  • AI / automated decision-making compliance
  • Children's data and edu-tech
Speak to a partner →

Frequently asked questions

Which UAE data protection law applies to my business?

Three regimes parallel: federal PDPL (FDL 45/2021), DIFC DP Law 5/2020, ADGM DP Regulations 2021 — plus sector overlays (CBUAE banks, DHA/DOH/MOHAP health, TDRA telecom, SCA securities). Mapping by establishment + data-subject location + activity context.

Are we a controller or a processor?

Controller determines purposes/means; processor processes on controller's behalf. Real-world ambiguity in SaaS vendors, marketplaces, benefits administrators, cloud infra — misclassification is a common audit finding and changes contracts, breach obligations, transfer mechanisms.

Do we need to appoint a Data Protection Officer?

PDPL Article 10: required for high-risk processing, large-scale systematic monitoring, or large-scale special-category data. DIFC and ADGM similar. DPO need not be UAE resident but needs unimpeded access to top management. We act as outsourced DPO.

What are breach-notification obligations?

72-hour regulator notification standard; data-subject notification where likely to cause harm. PDPL Article 9. DIFC, ADGM aligned. Sector regimes (CBUAE, DHA) may impose shorter windows. We run breach-response retainers with 24/7 cover.

How are cross-border data transfers handled?

Adequacy list, SCCs, BCRs, certification, or specific exceptions (consent, contract, public interest, vital interests, legal claims). DIFC/ADGM aligned to EU GDPR Chapter V. Most MNCs reuse GDPR SCC architecture; Russia/China flows attract heightened scrutiny.

What about marketing and consent?

PDPL Article 6 — consent must be specific, informed, freely given, easy to withdraw. WhatsApp/SMS interacts with TDRA anti-spam regime. Pre-checked boxes, package-deal consents, continuing-relationship assumptions all fail.

What are PDPL fines and enforcement?

AED 50k–5m per breach with aggravation. DIFC up to USD 100k. ADGM similar. Cross-border groups may face parallel UAE/DIFC/ADGM/GDPR action — coordinated counsel material.


Last updated: 1 May 2026. General information only — not legal advice. Contact us for matter-specific advice.

PDPL build-out, breach or regulator action?

Federal PDPL, DIFC, ADGM, sector overlays — same business-day partner response.

Brief our team →