🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
AE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing13 sources retrieved model claude-sonnet-5 · 2026-07-29

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

United Arab Emirates

AE schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 47 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
47Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The UAE's federal data-protection framework remains anchored in Federal Decree-Law No. 45 of 2021, the omnibus Personal Data Protection Law in effect since 2 January 2022, but this cycle surfaces a genuine dispute over whether the law's supervisory machinery is now operationally live. A 2026 Chambers and Partners practice guide describes the UAE Data Office as not yet fully operational, while a separate 2026 secondary source describes the Data Office as now fully operational and issuing guidance. Neither claim carries a directly retrieved primary statement from the Data Office itself this cycle, so the operational-status question is recorded as genuinely disputed rather than resolved in either direction.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive federal statute is in force, but implementing/executive regulation detail (fines, breach timelines) remained unconfirmed in available secondary sources, and the regime is fragmented across federal, DIFC and ADGM authorities.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberA comprehensive federal statute is in force, but implementing/executive regulation detail (fines, breach timelines) remained unconfirmed in available secondary sources, and the regime is fragmented across federal, DIFC and ADGM authorities.

Sub-modules (5)

Regulator And AuthorityAmber

Federal enforcement sits with the Emirates Data Office; DIFC and ADGM each maintain their own Commissioner/Office of Data Protection for their free zones.

Claims (2):

  • The UAE enacted Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data as part of a sweeping package of legal reforms marking the UAE's 50th anniversary.
  • The PDPL decrees established the Emirates Data Office to monitor and enforce the UAE Personal Data Protection Law countrywide.

Act And InstrumentsAmber

Federal Decree-Law No. 45 of 2021 (PDPL) is the primary federal instrument; DIFC Law No. 5 of 2020 and ADGM Data Protection Regulations 2021 are independent free-zone instruments.

Claims (2):

  • The UAE enacted Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data as part of a sweeping package of legal reforms marking the UAE's 50th anniversary.
  • The DIFC and ADGM financial free zones operate independent data protection regimes (DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021) outside the federal PDPL's civil and commercial jurisdiction.

Material ScopeAmber

The PDPL is described as GDPR-influenced, granting data subjects considerable rights and control over personal data.

Claims (1):

  • Like the EU GDPR, the PDPL gives considerable control and rights to data subjects over their personal data.

Territorial ScopeAmber

The PDPL is reported to apply to virtually all organizations across the seven emirates and to entities elsewhere processing UAE residents' data; DIFC/ADGM regimes apply only within their respective free zones.

Claims (2):

  • Virtually all organizations across all seven emirates that collect or process personal data, and organizations elsewhere processing personal data belonging to UAE residents, fall within the PDPL's compliance scope.
  • The PDPL decrees established the Emirates Data Office to monitor and enforce the UAE Personal Data Protection Law countrywide.

Regulator Registration And FilingAmber

ADGM requires controller registration and processing notification (fee-bearing, exempt for sub-5-employee entities absent high-risk processing); DIFC requires notification within 14 days via its client portal with initial/renewal fees. No federal PDPL-specific registration mechanism was confirmed in available sources.

Claims (2):

  • ADGM requires registration of data controllers and notification of processing activities with the Commissioner of Data Protection, together with data protection fees and renewal fees, except for establishments with fewer than five employees unless they carry out high-risk processing.
  • DIFC entities must notify the Commissioner of processing operations as soon as possible and in any event within 14 days, paying a $1,250 registration fee and $500 annual renewal fee.
Category narrative89 words

The UAE federal regime rests on Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), enforced by the newly established Emirates Data Office (UAE Data Office). Layered on top of the federal statute are two independent financial free-zone regimes — the DIFC Data Protection Law No. 5 of 2020 (Commissioner of Data Protection) and the ADGM Data Protection Regulations 2021 (Office of Data Protection) — each with its own registration, fee, and enforcement architecture, plus sector-specific instruments (health, telecoms) that operate alongside the general regime.

Periodic update · new data 2026-09-28

Regulator & Framework

The UAE's federal omnibus data-protection instrument is Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, in effect since 2 January 2022. Its scope is bounded in specific and material ways: the PDPL does not apply to public entities, to the DIFC and ADGM free zones, each of which maintains its own separate data-protection legislation, or to health and credit data, which remain governed by existing sectoral legislation. Territorially, the PDPL covers the processing of personal data of data subjects located within the UAE regardless of where the controller or processor is itself located, an effects-based rather than establishment-based territorial trigger.

The most material development this cycle concerns the operational status of the UAE Data Office, the PDPL's designated supervisory authority. A 2026 Chambers and Partners practice guide describes the Data Office as not yet fully operational. A separate 2026 secondary source, by contrast, describes the Data Office as now fully operational and issuing guidance. These two accounts are directly contradictory, and neither is corroborated by a directly retrieved primary statement from the Data Office itself this cycle. The honest position is that this is a genuinely disputed fact, not a fact this cycle's evidence resolves, and it is recorded as such rather than averaged or silently resolved in favour of either source.

This disputed operational status matters beyond a bureaucratic technicality: the practical reach of every other PDPL obligation, from data subject rights to controller duties to enforcement powers, depends in part on whether a functioning supervisory authority exists to receive complaints, issue guidance, and take enforcement action. Until the dispute is resolved by a primary Data Office statement, the operational reality of the entire PDPL framework carries this same uncertainty.

Outlook

A direct primary statement from the UAE Data Office, whether a website update, published guidance, or an enforcement action bearing its name, would resolve the current dispute in either direction. Until such a statement is retrieved, the safest reading is that the law is unambiguously in force while its supervisory machinery's operational status remains open.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ProbableIAPP — The UAE enacted Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data as part of a sweeping package of legal reforms marking the UAE's 50th anniversary.observed
  2. ProbableIAPP — The PDPL decrees established the Emirates Data Office to monitor and enforce the UAE Personal Data Protection Law countrywide.observed
  3. ProbableIAPP — The PDPL took effect on January 2, 2022, with enforcement of its provisions beginning in September 2022.observed
  4. ProbableIAPP — Like the EU GDPR, the PDPL gives considerable control and rights to data subjects over their personal data.observed
  5. ProbableIAPP — Virtually all organizations across all seven emirates that collect or process personal data, and organizations elsewhere processing personal data belonging to UAE residents, fall within the PDPL's compliance scope.observed
  6. ProbableOneTrust DataGuidance — The DIFC and ADGM financial free zones operate independent data protection regimes (DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021) outside the federal PDPL's civil and commercial jurisdiction.observed
  7. ProbableOneTrust DataGuidance — ADGM requires registration of data controllers and notification of processing activities with the Commissioner of Data Protection, together with data protection fees and renewal fees, except for establishments with fewer than five employees unless they carry out high-risk processing.observed
  8. ProbableOneTrust DataGuidance — DIFC entities must notify the Commissioner of processing operations as soon as possible and in any event within 14 days, paying a $1,250 registration fee and $500 annual renewal fee.observed

#

Free-zone (DIFC/ADGM) lawful-basis and special-category rules are well-documented and GDPR-aligned; federal PDPL detail on lawful bases beyond consent-plus-exceptions was not confirmed in available sources.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 (PDPL); DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberFree-zone (DIFC/ADGM) lawful-basis and special-category rules are well-documented and GDPR-aligned; federal PDPL detail on lawful bases beyond consent-plus-exceptions was not confirmed in available sources.

Sub-modules (4)

Lawful BasesAmber

PDPL defaults to consent with exceptions for public interest, judicial/security proceedings and public health; ADGM/DIFC mirror GDPR-style bases (consent, contract, legal obligation, public interest), though ADGM omits journalistic/artistic grounds.

Claims (2):

  • Where consent is not an option or not practical, the PDPL permits processing only for protection of the public interest, judicial or security proceedings, protection of public health, or compliance with other laws such as KYC requirements.
  • ADGM Data Protection Regulations provide lawful grounds for processing similar to GDPR — consent, contractual performance, controller obligations and public interest — but do not reference journalistic or artistic purposes as a legal basis.

Special CategoriesGreen

ADGM defines special categories consistently with GDPR while explicitly adding criminal data as a distinct category.

Claims (1):

  • ADGM Regulations remain consistent with GDPR definitions of special categories of data while explicitly extending the category to include criminal data.

Pseudonymisation And AnonymisationAmber

ADGM references pseudonymisation (GDPR-consistent) as a security measure but does not explicitly define anonymisation; DIFC Law 2020 explicitly references both concepts without GDPR-level definitional specificity.

Claims (2):

  • ADGM Regulations do not explicitly define anonymisation, although pseudonymisation is defined consistently with GDPR and referenced as an appropriate security measure.
  • DIFC Law 2020 makes explicit reference to both anonymisation and pseudonymisation but does not define these concepts with GDPR-level specificity.
Category narrative43 words

The federal PDPL centers processing lawfulness on consent, with statutory exceptions; the DIFC and ADGM free-zone laws mirror GDPR-style lawful bases and special-category definitions, with ADGM explicitly extending special categories to criminal data and both regimes referencing pseudonymisation without fully GDPR-equivalent anonymisation definitions.

Sources and claims (5)
  1. ProbableIAPP — Where consent is not an option or not practical, the PDPL permits processing only for protection of the public interest, judicial or security proceedings, protection of public health, or compliance with other laws such as KYC requirements.observed
  2. ProbableOneTrust DataGuidance — ADGM Data Protection Regulations provide lawful grounds for processing similar to GDPR — consent, contractual performance, controller obligations and public interest — but do not reference journalistic or artistic purposes as a legal basis.observed
  3. ProbableOneTrust DataGuidance — ADGM Regulations remain consistent with GDPR definitions of special categories of data while explicitly extending the category to include criminal data.observed
  4. ProbableOneTrust DataGuidance — ADGM Regulations do not explicitly define anonymisation, although pseudonymisation is defined consistently with GDPR and referenced as an appropriate security measure.observed
  5. ProbableOneTrust DataGuidance — DIFC Law 2020 makes explicit reference to both anonymisation and pseudonymisation but does not define these concepts with GDPR-level specificity.observed

#

Rights exist in principle across federal, DIFC and ADGM instruments, but response-window specificity at federal level is unconfirmed.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 (PDPL); ADGM Data Protection Regulations 2021
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberRights exist in principle across federal, DIFC and ADGM instruments, but response-window specificity at federal level is unconfirmed.

Sub-modules (5)

Access RightRed

General characterization of GDPR-comparable rights exists; specific access-right mechanics for the federal PDPL were not located in available sources.

Absence provenance: unavailable. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Claims (1):

  • The PDPL is characterized as giving data subjects considerable control and rights over their personal data, comparable in intent to the EU GDPR.

Rectification And ErasureAmber

ADGM's right to erasure does not apply where processing is necessary for archiving/research and erasure would seriously impair those objectives.

Claims (1):

  • Under ADGM Regulations, the right to erasure does not apply to the extent that processing is necessary for archiving or research purposes where erasure would render impossible or seriously impair those objectives, provided appropriate safeguards are taken.

Restriction And ObjectionRed

No AE-specific restriction/objection mechanics beyond general GDPR-alignment characterization were confirmed.

Absence provenance: unavailable. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Data PortabilityRed

No AE-specific portability provisions were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE Federal Decree Law 45 2021 PDPL fines penalties DPO threshold data subject rights.

Deadlines And Response WindowsRed

Specific statutory response-time deadlines for federal PDPL data-subject requests were not confirmed; secondary commentary noted uncertainty over implementing details shortly after enactment.

Claims (1):

  • Shortly after PDPL enactment it remained uncertain exactly how breach reporting timelines (and, by extension, other statutory response windows) would be specified pending executive regulations.
Category narrative37 words

The PDPL is characterized as granting GDPR-style data subject rights, though specific statutory response deadlines for federal-law subject-access or erasure requests were not confirmed in available sources; ADGM provides a right to erasure subject to archiving/research exceptions.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableIAPP — The PDPL is characterized as giving data subjects considerable control and rights over their personal data, comparable in intent to the EU GDPR.observed
  2. ProbableOneTrust DataGuidance — Under ADGM Regulations, the right to erasure does not apply to the extent that processing is necessary for archiving or research purposes where erasure would render impossible or seriously impair those objectives, provided appropriate safeguards are taken.observed
  3. UncertainIAPP — Shortly after PDPL enactment it remained uncertain exactly how breach reporting timelines (and, by extension, other statutory response windows) would be specified pending executive regulations.observed

#

Free-zone (DIFC/ADGM) controller duties are well documented and GDPR-aligned; federal PDPL implementing detail (fine schedules, precise breach timelines) is not confirmed.

Primary frameworkDIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021; UAE Federal Decree-Law No. 45 of 2021 (PDPL)
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberFree-zone (DIFC/ADGM) controller duties are well documented and GDPR-aligned; federal PDPL implementing detail (fine schedules, precise breach timelines) is not confirmed.

Sub-modules (7)

Accountability And DpiaGreen

DIFC Law 2020 introduced DPIA obligations for high-risk processing (absent from the 2007 predecessor) and requires controllers/processors to maintain a 'Privacy Program' demonstrating accountability.

Claims (2):

  • DIFC Law 2020 establishes Data Protection Impact Assessment (DPIA) requirements not present under the prior DIFC Law 2007.
  • DIFC Law 2020 introduces accountability as a key requirement, stipulating that controllers and processors establish a Privacy Program to demonstrate compliance.

Dpo RequirementsGreen

The PDPL permits but does not universally mandate DPO appointment (employee or outsourced); DIFC requires DPO appointment where necessary, including annual assessments — a requirement more detailed than GDPR's baseline.

Claims (2):

  • The PDPL allows an organization's DPO to be an employee or outsourced to a third party with data-privacy expertise, and not all organizations are required to appoint one.
  • DIFC Law 2020 requires DPOs to conduct annual assessments, a requirement more nuanced than the GDPR's baseline DPO obligations.

Ropa RequirementsGreen

ADGM and DIFC both require maintenance of Records of Processing Activities, including separate records where both regimes apply to the same entity.

Claims (1):

  • ADGM Regulations require controllers and processors to maintain a Record of Processing Activities, including maintaining separate records in both jurisdictions where both ADGM and another regime apply.

Joint Controller ArrangementsRed

No AE-specific joint-controller provisions beyond general controller/processor contract requirements were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Security MeasuresAmber

DIFC and ADGM both require technical/organisational security measures, with pseudonymisation referenced as an ADGM security measure.

Claims (1):

  • DIFC Law 2020 introduces accountability as a key requirement, stipulating that controllers and processors establish a Privacy Program to demonstrate compliance.

Breach NotificationAmber

DIFC requires controller notification to the Commissioner 'as soon as practicable' for confidentiality/security/privacy-compromising breaches, processor-to-controller notification 'without undue delay', and data-subject notification 'as soon as practicable' (or 'promptly' for immediate-risk cases); federal PDPL breach-timeline specifics remained unconfirmed shortly after enactment.

Claims (3):

  • DIFC controllers must notify the Commissioner of a personal data breach compromising confidentiality, security, or privacy 'as soon as practicable in the circumstances', and processors must notify controllers 'without undue delay'.
  • DIFC controllers must communicate a personal data breach to affected data subjects 'as soon as practicable' where high risk exists, and 'promptly' where there is immediate risk of damage.
  • Shortly after PDPL enactment it remained uncertain exactly how breach reporting timelines (and, by extension, other statutory response windows) would be specified pending executive regulations.

Retention And DisposalAmber

No AE-specific statutory retention period was confirmed; PDPL is described only generally as restricting retention to as long as needed for the original purpose.

Claims (1):

  • The PDPL restricts data retention to only as long as needed for the purpose originally captured (data retention principle).
Category narrative49 words

DIFC Law 2020 provides the most detailed accountability, DPIA, DPO, ROPA, breach-notification and privacy-program requirements among the UAE's data protection instruments; ADGM imposes parallel ROPA/registration duties; the federal PDPL permits (but does not universally mandate) DPO appointment, with executive-regulation-level detail on breach timelines and fines unconfirmed as of research.

no periodic updates on record for this sub-brief

Sources and claims (8)
  1. ProbableOneTrust DataGuidance — DIFC Law 2020 establishes Data Protection Impact Assessment (DPIA) requirements not present under the prior DIFC Law 2007.observed
  2. ProbableOneTrust DataGuidance — DIFC Law 2020 introduces accountability as a key requirement, stipulating that controllers and processors establish a Privacy Program to demonstrate compliance.observed
  3. ProbableIAPP — The PDPL allows an organization's DPO to be an employee or outsourced to a third party with data-privacy expertise, and not all organizations are required to appoint one.observed
  4. ProbableOneTrust DataGuidance — DIFC Law 2020 requires DPOs to conduct annual assessments, a requirement more nuanced than the GDPR's baseline DPO obligations.observed
  5. ProbableOneTrust DataGuidance — ADGM Regulations require controllers and processors to maintain a Record of Processing Activities, including maintaining separate records in both jurisdictions where both ADGM and another regime apply.observed
  6. ProbableOneTrust DataGuidance — DIFC controllers must notify the Commissioner of a personal data breach compromising confidentiality, security, or privacy 'as soon as practicable in the circumstances', and processors must notify controllers 'without undue delay'.observed
  7. ProbableOneTrust DataGuidance — DIFC controllers must communicate a personal data breach to affected data subjects 'as soon as practicable' where high risk exists, and 'promptly' where there is immediate risk of damage.observed
  8. ProbableIAPP — The PDPL restricts data retention to only as long as needed for the purpose originally captured (data retention principle).observed

#

Strong DIFC/ADGM evidence on transfer mechanisms and adequacy granted; federal PDPL transfer detail and adequacy received status are unconfirmed/pending.

Primary frameworkDIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberStrong DIFC/ADGM evidence on transfer mechanisms and adequacy granted; federal PDPL transfer detail and adequacy received status are unconfirmed/pending.

Sub-modules (6)

Transfer MechanismsGreen

ADGM Regulations provide transfer mechanisms mirroring GDPR — SCCs, BCRs, derogations, and adequacy assessment criteria.

Claims (1):

  • ADGM Data Protection Regulations provide transfer mechanisms similar to GDPR, including standard contractual clauses, binding corporate rules, derogations, and adequacy assessment criteria, with neither ADGM nor GDPR requiring data localisation or residency.

Adequacy ReceivedRed

The DIFC's 2020 law was explicitly framed to support DIFC's pursuit of adequacy recognition from the European Commission and the UK; the UK DCMS announced an adequacy assessment of DIFC in 2021, but a confirmed outcome was not located in available sources.

Claims (2):

  • The DIFC explicitly stated that enactment of the Data Protection Law and adoption of its Regulations was intended to support DIFC's pursuit of adequacy recognition from the European Commission and the UK.
  • In 2021 the UK's Department for Digital, Culture, Media and Sport announced it would conduct an adequacy assessment of the DIFC; a confirmed final outcome of that assessment was not located in available sources.

Adequacy GrantedGreen

DIFC has declared adequacy toward EU member states, the UK, Canada, Singapore and South Korea, and in August 2023 mutually recognized California, the first US state so recognized.

Claims (2):

  • DIFC has declared adequacy with a number of jurisdictions including EU member states, the UK, Canada, Singapore, and South Korea.
  • On August 9, 2023, the California Privacy Protection Agency and DIFC recognized each other's frameworks, marking the first time DIFC granted this adequacy-type status to a U.S. state.

Sccs And BcrsGreen

The DIFC Commissioner has approved two sets of standard contractual clauses for transfers to non-adequate jurisdictions; ADGM also provides for BCRs and SCCs.

Claims (1):

  • The DIFC Commissioner has approved two sets of standard contractual clauses that may be used for transfers outside the DIFC to a non-adequate jurisdiction.

Transfer Impact AssessmentRed

No AE-specific formal Transfer Impact Assessment requirement (akin to post-Schrems II EU practice) was confirmed for DIFC, ADGM or the federal PDPL in available sources.

Absence provenance: unavailable. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Data LocalisationAmber

Neither the ADGM Regulations nor the GDPR (as comparator) require data localisation or residency; no general federal PDPL localisation mandate was confirmed, though sector-specific health-data storage standards may impose de facto constraints.

Claims (1):

  • Neither the ADGM Regulations nor the GDPR require data localisation or residency for personal data.
Category narrative70 words

Cross-border transfer detail is best documented at the DIFC and ADGM free-zone level: both provide GDPR-style mechanisms (adequacy, SCCs, BCRs, derogations) with no data-localisation mandate, and the DIFC has declared adequacy toward the EU, UK, Canada, Singapore, South Korea and — since August 2023 — California. Federal PDPL-specific transfer-mechanism detail, and confirmation of any reciprocal adequacy determination received by the UAE from the EU/UK, was not located in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ProbableOneTrust DataGuidance — ADGM Data Protection Regulations provide transfer mechanisms similar to GDPR, including standard contractual clauses, binding corporate rules, derogations, and adequacy assessment criteria, with neither ADGM nor GDPR requiring data localisation or residency.observed
  2. ProbableOneTrust DataGuidance — The DIFC explicitly stated that enactment of the Data Protection Law and adoption of its Regulations was intended to support DIFC's pursuit of adequacy recognition from the European Commission and the UK.observed
  3. UncertainOneTrust DataGuidance — In 2021 the UK's Department for Digital, Culture, Media and Sport announced it would conduct an adequacy assessment of the DIFC; a confirmed final outcome of that assessment was not located in available sources.observed
  4. ProbableCPPA — DIFC has declared adequacy with a number of jurisdictions including EU member states, the UK, Canada, Singapore, and South Korea.observed
  5. ProbableCPPA — On August 9, 2023, the California Privacy Protection Agency and DIFC recognized each other's frameworks, marking the first time DIFC granted this adequacy-type status to a U.S. state.observed
  6. ProbableDIFC Authority — The DIFC Commissioner has approved two sets of standard contractual clauses that may be used for transfers outside the DIFC to a non-adequate jurisdiction.observed
  7. ProbableOneTrust DataGuidance — Neither the ADGM Regulations nor the GDPR require data localisation or residency for personal data.observed

#

Telecoms and health overlays are documented; financial-sector overlay evidence is limited to one regulation; credit, education and insurance sub-modules have no confirmed evidence.

Supervisory authorityTelecommunications and Digital Government Regulatory Authority (TRA/TDRA)
Traffic-light rationale — AmberTelecoms and health overlays are documented; financial-sector overlay evidence is limited to one regulation; credit, education and insurance sub-modules have no confirmed evidence.

Sub-modules (7)

Financial Sector OverlayAmber

The UAE Stored Value Facilities Regulation was reportedly the first UAE law to mandate data minimization as a compliance requirement.

Claims (1):

  • The UAE Stored Value Facilities Regulation was the first UAE law to specifically mandate information/data minimization as a compliance requirement.

Health Sector OverlayAmber

The Health Data Law/ICT Health Law governs ICT use in healthcare across mainland and free zones; Abu Dhabi's DOH applies its own 2020 healthcare-data-privacy standards; Dubai Healthcare City is separately governed by Federal Law No. 2 of 2019.

Claims (3):

  • The UAE Health Data Law/ICT Health Law applies to all methods and uses of information and communication technology in the UAE healthcare sector, covering both mainland and free-zone entities.
  • The Department of Health Abu Dhabi's Standards on Healthcare Data Privacy 2020 apply specifically to entities within the Emirate of Abu Dhabi and strictly define how health data may be used, stored, shared and protected.
  • Dubai Healthcare City is governed by Federal Law No. 2 of 2019 (Healthcare Data Protection Law), which regulates protection of individuals' data within DHCC, including restrictions on data disclosures and transfers, superseding the 2013 DHCC Data Protection Regulation.

Telecoms And EprivacyAmber

The Law Regulating the Telecommunications Sector gives the TRA jurisdiction over customer-data-use regulation and criminalizes unauthorized disclosure of call/message content.

Claims (1):

  • The Law Regulating the Telecommunications Sector gives the Telecommunications Regulatory Authority jurisdiction to implement regulations concerning customer data use (Article 14) and criminalizes disclosure of the content of a call or message sent through the network (Article 72).

Employment DataRed

No AE-specific employment-data overlay was confirmed in available sources beyond the general PDPL framework.

Absence provenance: unavailable. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Credit And ScoringRed

No AE-specific credit-scoring data rules were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

EducationRed

No AE-specific education-sector data rules were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

InsuranceRed

No AE-specific insurance-sector data rules were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Category narrative78 words

Telecommunications and healthcare are the most clearly documented sectoral overlays: the TRA derives customer-data jurisdiction from the Law Regulating the Telecommunications Sector, health data is separately governed by the federal ICT Health Law and (within Dubai Healthcare City) Federal Law No. 2 of 2019, and Abu Dhabi's Department of Health imposes its own healthcare-data-privacy standards. A financial-sector data-minimization requirement appears in the Stored Value Facilities Regulation. Credit-scoring, education, and insurance-sector-specific data rules were not confirmed in available sources.

Sources and claims (5)
  1. ProbableOneTrust DataGuidance — The UAE Stored Value Facilities Regulation was the first UAE law to specifically mandate information/data minimization as a compliance requirement.observed
  2. ProbableOneTrust DataGuidance — The UAE Health Data Law/ICT Health Law applies to all methods and uses of information and communication technology in the UAE healthcare sector, covering both mainland and free-zone entities.observed
  3. ProbableOneTrust DataGuidance — The Department of Health Abu Dhabi's Standards on Healthcare Data Privacy 2020 apply specifically to entities within the Emirate of Abu Dhabi and strictly define how health data may be used, stored, shared and protected.observed
  4. ProbableOneTrust DataGuidance — Dubai Healthcare City is governed by Federal Law No. 2 of 2019 (Healthcare Data Protection Law), which regulates protection of individuals' data within DHCC, including restrictions on data disclosures and transfers, superseding the 2013 DHCC Data Protection Regulation.observed
  5. ProbableOneTrust DataGuidance — The Law Regulating the Telecommunications Sector gives the Telecommunications Regulatory Authority jurisdiction to implement regulations concerning customer data use (Article 14) and criminalizes disclosure of the content of a call or message sent through the network (Article 72).observed

#

No comprehensive adtech-specific regime was confirmed for the UAE in available research; only the general PDPL consent framework applies.

Traffic-light rationale — RedNo comprehensive adtech-specific regime was confirmed for the UAE in available research; only the general PDPL consent framework applies.

Sub-modules (6)

Cookies And TrackersRed

No AE-specific cookie/tracker law was confirmed.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office, UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Dark PatternsRed

No AE-specific dark-pattern prohibition was confirmed.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Opt Out SignalsRed

No AE-specific recognition of browser-level opt-out signals (e.g., GPC) was confirmed.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Clean Rooms And DcrRed

No AE-specific clean-room/data-collaboration-room rules were confirmed.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Cross Context AdvertisingRed

No AE-specific cross-context-advertising ('sale'/'share') framework analogous to CPRA was confirmed.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Direct MarketingAmber

The PDPL's general consent requirement covers processing for direct-marketing purposes in principle, but no AE-specific suppression-list or marketing-consent statute was confirmed.

Claims (1):

  • The PDPL requires organizations to create consent forms and disclosures for the processing of all personal data, which in practice would extend to processing for direct-marketing purposes absent a specific statutory exception.
Category narrative27 words

No AE-specific cookie/tracker consent regime, dark-pattern prohibition, Global-Privacy-Control-style opt-out recognition, clean-room rule, or direct-marketing-specific consent/suppression regime was located in available sources beyond the PDPL's general consent-for-processing requirement.

Sources and claims (1)
  1. ProbableIAPP — The PDPL requires organizations to create consent forms and disclosures for the processing of all personal data, which in practice would extend to processing for direct-marketing purposes absent a specific statutory exception.observed

#

AI policy infrastructure and one DIFC-specific binding regulation are documented; federal biometric/genetic/surveillance-carveout specifics are unconfirmed.

Primary frameworkDIFC Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems
Supervisory authorityUAE AI Office / Council for AI and Blockchain
Traffic-light rationale — AmberAI policy infrastructure and one DIFC-specific binding regulation are documented; federal biometric/genetic/surveillance-carveout specifics are unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No AE-specific profiling-restriction statute distinct from general PDPL principles was confirmed.

Absence provenance: unavailable. Searched: UAE artificial intelligence law regulation 2024 2025 AI governance Dubai.

Automated Decision Making TransparencyAmber

DIFC Regulation 10 specifically addresses processing of personal data through autonomous and semi-autonomous systems and is in force.

Claims (1):

  • The DIFC's Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems is in force.

Ai Risk AssessmentsAmber

UAE AI governance relies on strategy documents, ethics guidelines and self-assessment tools (e.g., AI System Ethics Self-Assessment Tool) rather than a binding AI risk-assessment statute.

Claims (2):

  • UAE AI governance is conducted primarily through national strategy, ethical guidelines and sector-specific initiatives — including the UAE National Strategy for Artificial Intelligence 2031 — rather than through dedicated cross-sectoral AI legislation.
  • In October 2024, the UAE Cabinet approved the country's International Stance on Artificial Intelligence Policy, and the UAE has issued non-binding guidance resources including an AI Ethics Principles and Guidelines document and an AI System Ethics Self-Assessment Tool.

Biometric RegimeRed

No AE federal-level biometric-data-specific regime was confirmed; ADGM's GDPR-aligned special-category definition (which would typically capture biometric data) is the closest available proxy.

Absence provenance: unavailable. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Genetic DataRed

No AE-specific genetic-data regime was confirmed in available sources.

Absence provenance: unavailable. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

State Surveillance CarveoutsRed

No AE-specific state-surveillance carve-out provisions were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Category narrative50 words

UAE AI governance is conducted primarily through national strategy, ethical guidelines and sector initiatives rather than dedicated cross-sectoral AI legislation, though the DIFC has an in-force Regulation 10 specifically governing personal data processing through autonomous/semi-autonomous systems. Federal-level biometric- and genetic-data-specific regimes, and state-surveillance carve-outs, were not confirmed in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableIAPP — The DIFC's Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems is in force.observed
  2. ProbableIAPP — UAE AI governance is conducted primarily through national strategy, ethical guidelines and sector-specific initiatives — including the UAE National Strategy for Artificial Intelligence 2031 — rather than through dedicated cross-sectoral AI legislation.observed
  3. ProbableIAPP — In October 2024, the UAE Cabinet approved the country's International Stance on Artificial Intelligence Policy, and the UAE has issued non-binding guidance resources including an AI Ethics Principles and Guidelines document and an AI System Ethics Self-Assessment Tool.observed

#

Coverage of children's/vulnerable-groups' data is thin and inconsistent across the UAE's fragmented regime; no dedicated federal children's-data regime was confirmed.

Traffic-light rationale — RedCoverage of children's/vulnerable-groups' data is thin and inconsistent across the UAE's fragmented regime; no dedicated federal children's-data regime was confirmed.

Sub-modules (5)

Age VerificationAmber

ADGM defines a child as a natural person under 18, but no age-verification mechanism was confirmed.

Claims (1):

  • ADGM Data Protection Regulations define a child as a natural person under the age of 18, in contrast to GDPR's default age of consent of 16 (adjustable by Member States to not younger than 13), but do not explicitly outline requirements for consent to process children's data.

Minor Profiling BansRed

No AE-specific minor-profiling ban was confirmed in available sources.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Education SettingsRed

No AE-specific education-sector children's-data rules were confirmed.

Absence provenance: unavailable. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Dependent AdultsRed

No AE-specific dependent-adult data protections were confirmed in available sources.

Absence provenance: unavailable. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Category narrative59 words

Free-zone instruments provide limited, inconsistent coverage of children's data: ADGM defines a child as under 18 (versus GDPR's 16, adjustable to 13) but does not set explicit parental-consent mechanics, while DIFC Law 2020, like its 2007 predecessor, does not generally address children's data at all. No federal PDPL-specific children's-data provisions, minor-profiling bans, education-setting rules, or dependent-adult protections were confirmed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableOneTrust DataGuidance — ADGM Data Protection Regulations define a child as a natural person under the age of 18, in contrast to GDPR's default age of consent of 16 (adjustable by Member States to not younger than 13), but do not explicitly outline requirements for consent to process children's data.observed
  2. ProbableOneTrust DataGuidance — DIFC Law 2020, consistent with its 2007 predecessor, does not generally refer to children's data or provide specific requirements for collecting personal data from children.observed

#

DIFC enforcement track record and powers are well documented; federal PDPL-specific enforcement activity, funding, and any collective-redress mechanism remain unconfirmed, and no confirmed developments within the last 180 days were located.

Primary frameworkDIFC Law No. 5 of 2020
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberDIFC enforcement track record and powers are well documented; federal PDPL-specific enforcement activity, funding, and any collective-redress mechanism remain unconfirmed, and no confirmed developments within the last 180 days were located.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The DIFC Commissioner may issue proportionate administrative fines for contraventions and compel payment via court order; broader UAE laws carry penalties up to AED 1 million or imprisonment.

Claims (3):

  • The DIFC Commissioner may issue general fines for contraventions of the Data Protection Law by a controller or processor (including sub-processors), in an amount considered appropriate and proportionate to the seriousness of the contravention and risk of harm to data subjects.
  • The DIFC Commissioner may conduct investigations and inspections to verify compliance and may apply to the court for an order compelling payment of unpaid administrative fines, including publishing details of the matter.
  • Violations of UAE constitutional, Penal Code, Cyber Crime Law and sector-specific privacy provisions can carry penalties as high as AED 1 million or potential imprisonment.

Enforcement Activity IndexAmber

By August 2021, DIFC authorities had issued 88 fines since the region's late-2020 data protection regulations became effective.

Claims (1):

  • Authorities in the Dubai International Financial Centre had issued 88 fines since the region's new data protection regulations became effective in late 2020, as of publication in August 2021.

Regulator Funding And CapacityRed

No funding or headcount data for the Emirates Data Office or DIFC Commissioner's office was confirmed in available sources.

Absence provenance: unavailable. Searched: UAE PDPL 2026 update executive regulations status latest.

Collective Redress And Class ActionsRed

No AE-specific collective-redress or class-action mechanism for data protection claims was confirmed; DIFC provides individual complaint/mediation only.

Claims (1):

  • A person may file a complaint with the DIFC Commissioner, who applies mediation practices and procedures aimed at timely, fair and effective resolution, and may issue a binding direction to a controller under Article 60(4) of the DIFC Law if mediation does not resolve the matter.

Private Right Of ActionAmber

Data subjects may lodge complaints directly with the DIFC Commissioner, who may mediate and, if unresolved, issue binding directions to controllers.

Claims (1):

  • A person may file a complaint with the DIFC Commissioner, who applies mediation practices and procedures aimed at timely, fair and effective resolution, and may issue a binding direction to a controller under Article 60(4) of the DIFC Law if mediation does not resolve the matter.

Recent Developments 180DRed

No confirmed UAE data-protection regulatory developments within the 180 days preceding this run (approx. late January 2026 through July 29, 2026) were located in available sources.

Absence provenance: unavailable. Searched: UAE data protection 2026 enforcement fine Emirates Data Office news, UAE PDPL 2026 update executive regulations status latest.

Category narrative61 words

The DIFC Commissioner has clear, exercised administrative-fine, investigation, and complaint/mediation powers, with 88 fines reported issued since late-2020 regulations took effect. Broader UAE privacy-adjacent statutes (constitution, Penal Code, Cyber Crime Law) carry penalties as high as AED 1 million or imprisonment. Federal PDPL-specific penalty schedules, recent (180-day) enforcement developments, regulator funding/capacity data, and collective-redress/class-action mechanisms were not confirmed in available sources.

Periodic update · new data 2026-09-28

Enforcement & Redress

Enforcement intensity under the PDPL is contested across this cycle's sources in a way that mirrors the broader Data Office operational-status dispute. A 2026 secondary source cites administrative fines of up to AED 5 million for processing sensitive personal data without lawful basis or explicit consent, describing these fines as applied in enforcement actions from 2025 onward. This figure is not corroborated by a directly retrieved Data Office enforcement record or primary penalty schedule this cycle, so it should be read as a reported penalty ceiling rather than a confirmed, currently-enforced figure.

A separate 2026 Chambers and Partners practice guide takes a different tack, describing the practical effect of the PDPL's incomplete operationalisation as limited enforcement activity to date, with organisations largely driving compliance internally rather than in response to active regulatory pressure. This account is in tension with the first: one source implies enforcement actions are already occurring at meaningful penalty levels, the other implies enforcement activity has been limited in practice. Both accounts are retained rather than reconciled, consistent with the disputed-state doctrine applied elsewhere in this cycle's UAE record, because averaging or silently preferring one account over the other would manufacture a certainty the evidence does not support.

The practical takeaway for this cycle is that the PDPL's enforcement reality is genuinely unsettled: the statutory penalty architecture may exist on paper, per the AED 5 million figure, while actual enforcement practice may remain limited, per the Chambers account, and both can be true simultaneously without contradiction if the cited fines represent maximum exposure rather than typical outcomes.

Outlook

A directly retrieved Data Office enforcement record, or a confirmed enforcement action naming a specific penalty amount, would meaningfully sharpen this picture in either direction. Until then, the enforcement-and-redress picture should be read as unsettled rather than as either aggressively enforced or dormant.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableOneTrust DataGuidance — The DIFC Commissioner may issue general fines for contraventions of the Data Protection Law by a controller or processor (including sub-processors), in an amount considered appropriate and proportionate to the seriousness of the contravention and risk of harm to data subjects.observed
  2. ProbableDIFC Authority — The DIFC Commissioner may conduct investigations and inspections to verify compliance and may apply to the court for an order compelling payment of unpaid administrative fines, including publishing details of the matter.observed
  3. ProbableIAPP — Violations of UAE constitutional, Penal Code, Cyber Crime Law and sector-specific privacy provisions can carry penalties as high as AED 1 million or potential imprisonment.observed
  4. ProbableIAPP — Authorities in the Dubai International Financial Centre had issued 88 fines since the region's new data protection regulations became effective in late 2020, as of publication in August 2021.observed
  5. ProbableDIFC Authority — A person may file a complaint with the DIFC Commissioner, who applies mediation practices and procedures aimed at timely, fair and effective resolution, and may issue a binding direction to a controller under Article 60(4) of the DIFC Law if mediation does not resolve the matter.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct7.69
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United Arab Emirates
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 47 claim(s) (47 category placement(s)), 27 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: upheld (15 confirmed against the cited source; 9 could not be checked). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (20 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 15Data Subject Rightsaccess right
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-14Data Subject Rightsaccess right
Art. 16-17Data Subject Rightsrectification and erasure
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

T1 primary-text coverage exists for the DIFC (Data Protection Regulations Consolidated Version No. 2 PDF) and ADGM (GDPR-v-ADGM comparison PDF drawing directly on the ADGM Data Protection Regulations 2021 text) free-zone regimes, plus a T1 regulator announcement (CPPA) for the DIFC-California adequacy recognition. The federal PDPL (Federal Decree-Law No. 45 of 2021) is covered only via T2 secondary analysis (IAPP, DataGuidance opinion pieces) — no primary statutory text or Emirates Data Office guidance was retrievable via search, and several DataGuidance jurisdiction-note pages returned only navigation stubs with no substantive content. Sectoral modules (telecoms, health) rely on a single T2 opinion piece; adtech/commercial-privacy, credit/education/insurance sectoral sub-modules, children's-data federal provisions, biometric/genetic regimes, state-surveillance carve-outs, regulator funding/capacity, collective redress, and recent 180-day developments carry no confirmed evidence and are flagged with absent_field_provenance.

Unresolved questions (7):

  • Has the UAE issued executive regulations/implementing rules under Federal Decree-Law No. 45 of 2021 specifying breach-notification timelines and administrative fine amounts, and if so, what is their current status?
  • Did the UK DCMS adequacy assessment of the DIFC (announced 2021) conclude, and with what outcome?
  • Has the EU Commission made any adequacy determination regarding the UAE, DIFC, or ADGM?
  • What is the official URL and precise statutory citation for the Emirates Data Office / UAE Data Office regulator homepage?
  • Are there AE-specific cookie/tracker, dark-pattern, or cross-context-advertising rules distinct from the general PDPL consent framework?
  • What enforcement actions, guidance, or legislative developments occurred in the UAE data-protection space in the 180 days preceding this run (~late January 2026 through July 29, 2026)?
  • Does the federal PDPL provide statutory response-time deadlines for data subject access/erasure/objection requests?

Escalate to primary-source review: yes