UAE PDPA Compliance Guide
Everything you need to know about the UAE's Personal Data Protection Act and how to comply with its requirements.
Jan 2022
Effective Date
AED 10M
Maximum Penalty
All Sectors
Applies To
Overview
The UAE Personal Data Protection Act (Federal Decree-Law No. 45 of 2021) is the UAE's first comprehensive federal data protection law, taking effect in January 2022 with an 18-month grace period for compliance. The law establishes requirements for the processing of personal data by both public and private entities operating within the UAE, with certain exemptions for free zone authorities that have their own data protection frameworks such as the DIFC and ADGM. The UAE Data Office, established under the law, serves as the supervisory authority responsible for enforcement and guidance. The PDPA defines personal data as any information that relates to an identified or identifiable natural person, including names, identification numbers, online identifiers, location data, and factors specific to physical, psychological, economic, or social identity. The law requires organizations to have a lawful basis for processing personal data, with consent being the primary basis. Consent must be clear, specific, informed, and unambiguous. Data subjects have rights including access to their data, rectification, erasure, restriction of processing, data portability, and the right to object to processing including automated decision-making and profiling. The PDPA imposes obligations on data controllers including maintaining records of processing activities, conducting data protection impact assessments for high-risk processing, implementing appropriate technical and organizational security measures, and notifying the UAE Data Office and affected individuals in the event of a personal data breach. Cross-border data transfers are permitted to countries with adequate data protection, or with appropriate safeguards such as standard contractual clauses. Penalties for non-compliance include administrative fines up to AED 10,000,000 and other sanctions determined by the UAE Data Office.
Key Requirements
Lawful Basis for Processing
Establish a lawful basis (consent, contract, legal obligation, vital interest, or legitimate interest) before processing personal data.
Consent Standards
Obtain clear, specific, informed, and unambiguous consent. Consent must be freely given and withdrawable at any time.
Data Subject Rights
Provide access, rectification, erasure, portability, restriction of processing, and right to object to automated decisions.
Breach Notification
Notify the UAE Data Office and affected data subjects of personal data breaches without undue delay.
Records of Processing
Maintain detailed records of all data processing activities, including purposes, categories of data, and retention periods.
Security Measures
Implement appropriate technical and organizational measures to protect personal data against unauthorized access and breaches.
Penalties for Non-Compliance
The UAE Data Office enforces penalties for organizations that violate the PDPA.
Administrative Fines
Fines up to AED 10,000,000 (approximately $2.7M USD) for violations of data protection obligations.
Additional Sanctions
The UAE Data Office may impose additional sanctions including suspension of data processing activities and corrective orders.
Compensation Claims
Data subjects can claim compensation for damages resulting from unlawful processing of their personal data.
Reputational Impact
The UAE Data Office may publish enforcement decisions, leading to reputational damage for non-compliant organizations.
How Arqam360 Helps
Consent Collection
Arqam360 banner collects UAE PDPA-compliant consent with clear purpose specification, withdrawal mechanisms, and full audit trails.
DSAR Handling
Automated data subject request processing with multi-platform data retrieval and compliant response generation.
Compliance Audit Trail
Every consent action, data processing activity, and policy change logged with timestamps for regulatory audits.
Arabic Support
Native Arabic and English consent banner with RTL layout. Serve both Arabic-speaking and English-speaking visitors in the UAE.
Enforcement Timeline
PDPA Enacted
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued, establishing the UAE's first comprehensive federal data protection law.
Law Takes Effect
The PDPA officially takes effect with an 18-month grace period for organizations to achieve compliance.
Executive Regulations
Cabinet Decision No. 33 of 2023 issued the Executive Regulations providing detailed implementation guidance.
Grace Period Ends
The 18-month compliance grace period expires. Full enforcement of the PDPA begins for all entities in scope.
Check Your UAE PDPA Compliance
Run a free compliance scan to assess your UAE PDPA compliance status and identify areas that need attention.
Check Your UAE PDPA ComplianceLast updated:
Sources
- 1.UAE Government — data protection laws
- 2.DLA Piper, Data Protection Laws of the World — United Arab Emirates
- 3.DataGuidance — UAE data protection overview
- 4.Cooperation Council for the Arab States of the Gulf — official portal
- 5.Albesher, Alsaad & Alhussain (2026) — cookie consent usability and privacy compliance in Saudi Arabia, PeerJ Computer Science 12:e3701
Regulations
Compliance guides for GDPR, PDPL, and moreSaudi PDPL Compliance Guide
Qatar PDPPL Compliance Guide
Bahrain PDPL Compliance Guide
Jordan PDPL Compliance Guide
Kuwait Data Protection Compliance Guide
GCC Privacy Laws Overview
GDPR Compliance Guide
CCPA Compliance Guide
UAE PDPA FAQ
Common questions about the UAE Personal Data Protection Act.
The UAE PDPA was enacted in January 2022 with an 18-month compliance grace period. Full enforcement is now active.
Get UAE PDPA Compliant Today
Start your free trial and meet UAE data protection requirements in minutes. Multi-language support for the UAE market.