UAE PDPL: requirements, deadlines and compliance actions
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
What is the UAE PDPL?
The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.
Status note: In force since 2 January 2022. Executive regulations that trigger the compliance period for organisations had not been confirmed as issued at the last check; a reviewer must confirm their status.
Who does it apply to?
Controllers and processors in the UAE (outside the financial free zones) and those outside the UAE processing personal data of individuals in the UAE. Government data, security bodies and health and banking data covered by other laws are excluded or partly excluded.
Organisations processing personal data of individuals in the UAE, including AI developers and deployers using such data.
When do the requirements apply?
Issued 20 September 2021; in force 2 January 2022; compliance period runs from issuance of executive regulations (status to be confirmed).
| Date | Milestone | Source reference | Status |
|---|---|---|---|
| Law in force Entry into force. |
— | Passed | |
| Depends on issuance of executive regulations (to be confirmed) | Compliance period after executive regulations Reviewer to confirm whether executive regulations have been issued. |
— | Tbd confidence: low |
What must organisations do?
Establish a lawful basis for AI data processing, provide rights including objection to automated decisions, conduct impact assessments for high-risk AI processing, secure data and notify breaches to the Data Office.
Legal requirement Respect the right to object to automated decision-making without human intervention Article on data-subject rights relating to automated processing (reviewer to cite article number)
Data subjects may object to decisions based solely on automated processing, including profiling, that produce legal or similarly serious effects, subject to exceptions such as contractual necessity or consent.
Practical action: Provide a human-review route for significant automated decisions affecting UAE residents.
Evidence examples: Automated decision objection procedure
Framework mapping (original, editorial): NIST AI RMF 1.0 GOVERN 5.x, MANAGE 4.x
Obligation page Source-linked
Legal requirement Conduct a data protection impact assessment for high-risk processing using new technologies Article on data protection impact assessment (reviewer to cite article number)
Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, covering the processing, its purposes, risks and safeguards.
Practical action: Run a DPIA for AI systems processing personal data of UAE residents and keep it on file.
Evidence examples: Data protection impact assessment
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment
Obligation page Source-linked
Penalties
Administrative penalties to be set by Cabinet decision (reviewer to confirm current position).
Official sources
-
Data protection — UAE Government portal (Federal Decree-Law No. 45 of 2021)
UAE Government · 20 Sep 2021 · Tier 1 source
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.