The United Arab Emirates now has its first comprehensive federal data-protection law: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, commonly known as the PDPL. It came into legal force in early 2022 and establishes a federal regime for how organisations collect, use and safeguard personal data. For any business operating in the UAE, or handling the personal data of individuals there, the PDPL sets a clear direction of travel. The practical challenge is that some of the detailed rules are still to come, so the sensible course is to prepare on the fundamentals now and refine as the specifics are confirmed.
Who the law applies to
Broadly, the PDPL applies to organisations that process the personal data of individuals inside the UAE, whether they are established in the country or not. It is designed to reach beyond national borders where the data relates to people in the UAE, in line with the approach taken by other modern data-protection frameworks. There are some exemptions, and certain sectors and free zones may operate under their own established data regimes. If you are unsure whether the federal law, a free-zone framework, or both apply to your operations, that question is worth resolving early, because it shapes every obligation that follows.
The key obligations in plain English
At its core, the PDPL requires organisations to have a lawful basis for every act of processing. Consent is central to the regime, and where you rely on it, that consent must be given through a clear, positive action rather than assumed from silence or inactivity. Consent is not the only route, though: processing may also rest on other lawful bases, such as the necessity of a contract or a legal obligation.
Beyond a lawful basis, the law builds in familiar principles. Purpose limitation means personal data should be collected for specified, legitimate purposes and not used in ways incompatible with them. Data minimisation means collecting only what you genuinely need. The PDPL also grants individuals a set of data-subject rights, including access to their data, correction of inaccuracies, erasure, restriction of or objection to processing, and portability of their data. Organisations are expected to notify the regulator of personal-data breaches, and there are controls and safeguards governing cross-border transfers of personal data out of the UAE. Oversight of the regime sits with the UAE Data Office, the federal regulator.
The Executive Regulations are still pending
This is the single most important point of context. Much of the detailed procedural and timing detail under the PDPL, the mechanics that turn principles into precise operational requirements, is expected to be set out in the law’s Executive Regulations. At the time of writing, those Executive Regulations had not yet been published, and the timeline for them was not known. In practice this means the fundamentals of the law are in force, but some specifics, such as exact procedures and timeframes, remain to be finalised. The right response is not to wait. Businesses should act now on the principles that are already clear and watch closely for the Executive Regulations to confirm the finer detail.
It is also worth noting that the protection of the personal data of minors and children is an area of growing regulatory attention in the UAE, and organisations that handle such data should treat it as a priority.
Practical steps to prepare now
You do not need the final regulations to make meaningful progress. A sound compliance foundation rests on a handful of practical activities:
- Map your data. Build an inventory of the personal data you hold, where it comes from, why you process it, where it is stored and who it is shared with. You cannot protect or account for what you have not mapped.
- Review your lawful bases and consent mechanisms. Confirm you have a valid basis for each processing activity, and where you rely on consent, make sure it is captured through a clear, positive action.
- Establish data-subject-request and breach-response processes. Put a repeatable procedure in place for handling access, correction, erasure and similar requests, and a defined route for detecting, assessing and notifying breaches.
- Assign clear governance and ownership. Someone should be accountable for data protection, with defined responsibilities rather than diffuse, informal duties.
- Review cross-border transfers and vendor contracts. Understand where personal data leaves the UAE, and make sure your contracts with processors and suppliers reflect appropriate safeguards.
These steps align closely with recognised good practice in standards compliance, and they will hold their value whatever detail the Executive Regulations ultimately add.
Prepare on principles, finalise on the detail
The most balanced stance is to treat the PDPL’s principles as your working brief today, while keeping a watching eye on the regulations that will pin down the specifics. Organisations that map their data, tidy up their lawful bases, stand up their processes and assign clear ownership now will be in a strong position to adapt quickly once the detailed rules land, rather than starting from a standing position. Structured cyber advisory support can help you prioritise these steps and avoid over-engineering ahead of the confirmed detail. This article is general information and not legal advice; for your specific circumstances you should take professional advice.
How Baknet can help
Baknet helps businesses operating in, or handling data from, the UAE turn the PDPL from a source of uncertainty into a clear, manageable programme of work. We support data mapping and inventory exercises, review of lawful bases and consent, the design of data-subject-request and breach-response processes, governance and ownership models, and assessment of cross-border transfers and vendor arrangements, all framed to prepare on the fundamentals now and adapt smoothly when the Executive Regulations are published. To discuss where your organisation stands and the practical next steps, book a consultation with our team.
