UAE · FEDERAL PDPL · DIFC · ADGM

The UAE has three data regimes. You are in one of them.

Establishment decides which one reaches you, and groups routinely span two.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Three instruments, and only one of them is yours
Federal PDPL DIFC ADGM Three regulators One determination

Our promise

“Three regimes, one group. Mapping is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

The UAE, in three chapters

The Laws

Three instruments govern personal data here: the federal law onshore under the UAE Data Office, the Dubai International Financial Centre under its own law and Commissioner, and the Abu Dhabi Global Market under its own regulator. All three are consent-led, and all three of them differ.

The Gap

Most groups run one privacy programme across companies sitting under different instruments. It is nobody’s mistake exactly - the entities share a logo, a helpdesk and a data warehouse. What they do not share is a regulator, transfer conditions or a DPO trigger. None travel.

The Office

Which instrument reaches each entity is the first thing we settle, in writing, before a word of the programme is drafted. Then the duties of that instrument are tested against the estate as it actually runs, and a group spanning the free-zone line gets one review rather than two separate ones.

Which law applies

Three instruments, two boundaries.

Start with where the entity is registered, not with what it does - and take it from the licence, not the office address.

Onshore – the federal law № 01
  • Entities registered outside the free zones
  • Supervised by the UAE Data Office
  • Consent-led, with statutory exceptions
  • Unless a sector rule says otherwise
UAE · iDharma · Presented for review
DIFC and ADGM – their own laws № 02
  • Entities registered in either free zone
  • Each with its own regulator and enforcement
  • Closer to the GDPR in shape than the federal law
  • And not a variation on it, or on each other
UAE · iDharma · Presented for review
Whose duty is it

The duty is yours. Which duty is the question.

Onshore

The federal law of the UAE

The national regime, overseen by the UAE Data Office. It reaches entities established onshore unless a sector rule says otherwise, and it is consent-led with statutory exceptions rather than carrying the full lawful-basis set that a GDPR programme is normally written against and expects.

In the free zones

The DIFC and ADGM regimes

Two financial free zones, each with its own data protection instrument, its own regulator and its own enforcement. Both sit closer to the GDPR in shape than the federal law does - and neither is a variation on it, on the other, or on the federal law that they happen to sit beside. Each is its own programme.

The catch

Establishment decides, not activity

A group with an onshore company and a DIFC entity has two programmes, not one. Build to the highest common standard and apply it everywhere, or run them separately - both are defensible. Assuming one covers all of it because the entities share a logo and a helpdesk is not defensible for long.

What most groups assume

“One programme. It is all the UAE.”

What the laws say

The licence decides, not the letterhead.

It is the first thing we have to correct.

  • Who it is for
  • Banks & DIFC firms
  • ADGM entities
  • Healthcare & insurance
  • Retail & telecoms
  • Cloud & AI vendors
Why this matters
A black archive binder lying closed on a dark desk under a low lamp, a blank brass label plate screwed to its spine and a red wax seal holding the page block shut, with clipped papers, reading glasses and a fountain pen laid out beside it.
01 Three instruments, three regulators, three sets of transfer conditions. A programme built to the wrong one is not a partial programme - it is the wrong programme.
02

Administrative penalties are set per regime, and the amounts are what summaries get wrong most often. This page therefore prints none.

03

Directions and compensation are frequently the real outcome. For a live product an order to stop processing is sharper than a fine would be.

04

Saudi Arabia, Qatar and Bahrain each run their own regime too. Only the UAE and Qatar carry a free-zone law beside the national one.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

UAE personal data -

That is what brings the duties. Which of the three instruments then applies is the next question, and it turns on where the processing entity is established rather than on what it does.

Which instrument -

This is the question the page turns on. Three instruments, three regulators, three sets of transfer conditions - and a programme built to the wrong one is not a partial programme.

Record of processing -

All three regimes turn on it. Being able to show it rather than only to do it is common to every instrument here, and the record is what a regulator opens first.

The calendar

Four clocks, and one starts them all.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Determine

    Before anything

    Which of the three instruments reaches each entity. Nothing else on this page can be scheduled until that is written down.

  2. Notify

    On becoming aware

    The breach duty runs from awareness under each regime, and the window is one of the things that differs between them.

  3. Answer

    On request

    A rights request starts a clock set by whichever instrument reaches the entity holding the data, not by the group standard.

  4. Demonstrate

    Continuously

    Being able to show it rather than only to do it is common to all three. The records have to describe the estate on the day.

The trap

The windows are not the same under the three instruments, so a group standard set to the shortest one is safe and a group standard set to the longest is not. Which clock applies is decided by the entity holding the data, not by the parent.

Requirement & coverage

What the law says, what we ship

12 duties, with the note saying where the three instruments diverge.

Regime determination The first artefact
A written determination for each entity - federal, DIFC or ADGM - taken from the licence rather than from the office address, with the reasoning kept where a shared system serves both sides of a boundary.
Records of processing All three regimes
A record per activity with purpose, categories, recipients, transfers and retention filled in rather than left as headings. The document every regulator here opens first.
Lawful basis Consent-led onshore
A basis recorded per purpose, with the consent position documented where consent is what you rely on and the statutory exception named where it is not.
Purpose limitation Fixed before use
Purposes defined before collection with a compatibility test for any new use - the principle secondary model training most often breaks.
Data minimisation Necessity per field
The least that answers the purpose, assessed at field level and reviewed rather than assumed to still be right two releases later.
Accuracy Scaled to consequence
A higher bar where the data drives a decision about the individual, with a correction route that reaches the downstream copies people forget.
Storage limitation Ceasing is an action
A retention period per category with its justification, and a deletion route named rather than assumed to exist somewhere in the platform.
Integrity and confidentiality Tested, not attested
The measures you actually run, argued against the risk they address, including the processors and vendors holding the data on your behalf.
Individual rights Windows differ
One intake route somebody outside can find, identity verification, and a search that reaches the backups and the ticketing system rather than the primary database alone.
Impact assessments Where risk is high
A screening test that says when an assessment is required under the applicable regime, the methodology, and completed assessments for the processing that triggers it.
Cross-border transfers Differs by regime
A transfer register with the condition relied on per route, under the instrument that reaches the exporting entity - the three sets of conditions are not the same.
Data protection officer Triggers differ
The appointment decision written either way, and where one is appointed, the independence, resource and freedom from conflicting duties the role is meant to carry.
The engagement

Personal data, independently reviewed

From the onshore estate to the free-zone entity.

  1. Determine

    Which of the three regimes reaches each entity, in writing.

  2. Test

    The duties of that regime against the estate as it actually runs.

  3. Sign off and evidence

    You see the draft first. Then the records, notices and drills - dated.

Request a UAE review
An auditor in a rust-brown trouser suit and cream blouse, standing against a warm pale wall and pointing into the open space alongside.
The determination is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their UAE review

The regime, settled first

Which instrument reaches each entity, written down before the programme is drafted.

One scope, three rulebooks

A group that spans the free-zone line gets one review rather than two reviews that disagree.

GDPR work carries over

The free-zone regimes sit close to the GDPR, so existing work maps rather than restarts.

The Gulf in one scope

Saudi, Qatar and Bahrain obligations overlap enough to scope in the same engagement.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

UAE readiness report

The full review: which instrument reaches each entity, what you process under it, and where every duty is evidenced or is not - written duty by duty. Findings carry the regime they arise under, so a group spanning the free-zone line reads one report rather than two, with the transfer and DPO positions stated separately.

Memo

Regime determination

Entity by entity, taken from the licence rather than from custom - with the reasoning recorded where a shared system serves both sides of a boundary.

Workbook

Processing inventory

Every activity with purpose, categories, recipients, transfers and retention - built from the systems inwards rather than from a questionnaire.

Register

Basis and consent register

A basis per purpose with the consent position where consent is relied on, and the statutory exception named where it is not relied on at all.

Runbooks

Rights and breach runbooks

One intake route with identity verification, plus a breach path with the decision-maker named in advance and the clock set by the right regime.

Register

Transfer register

Where the data actually lands and the condition relied on per route, under the instrument reaching the exporting entity rather than the group standard.

Documents

Policy template pack

The core set, the rights and consent set and the security and breach set - written to the regime that reaches you rather than handed over generic.

Format & fee

Real numbers, upfront.

Scope
Set by the instrument
Inputs
Your entities and your records
Re-review
Every twelve months - $10,500 against your known baseline

The instrument fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
UAE · Named engagement $12,500 flat
  • Regime determination per entity
  • Processing inventory and register
  • Transfer register, per instrument
  • 26 policy templates, tailored
Show your hand

Four things you have to be able to produce

None of the three regimes is graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The regime,
decided

A written determination for each entity: federal, DIFC or ADGM. Everything else depends on it, and it is the artefact a group spanning the line most often lacks.

The record,
current

A record of processing that matches what the systems do. It is the first document any of the three regulators opens, and what every other position is argued out of.

The route,
findable

A rights route somebody outside can find without asking you, and a breach path with the decision-maker named before an incident rather than in the middle of one.

The officer,
unconflicted

Appointing a DPO is the easy half. What the regimes expect is independence, direct access to senior management, real resource and no conflicting duties.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Which law reaches you, whether it crosses the border, and where AI lands. Answered straight.

Request this review
What is the UAE Personal Data Protection Law?

The federal personal data protection law, overseen by the UAE Data Office - and it is one of three regimes rather than the only one. The DIFC and ADGM financial free zones each have their own instrument, their own regulator and their own enforcement.

How do we know which law applies to us?

Establishment decides, not activity. An entity registered onshore falls under the federal regime unless a sector rule says otherwise; an entity registered in DIFC or ADGM falls under that zone’s own instrument. Groups spanning both need both.

Does the UAE PDPL apply to companies outside the UAE?

It can. Processing the personal data of individuals in the UAE is what brings the duties, and the question of which instrument then applies turns on where the processing entity is established. An overseas company contracting with a DIFC entity is in a different position from one contracting onshore.

Do prompts and logs count as personal data?

If they identify a person, or can be linked to one with anything else you hold, yes. A prompt carrying customer detail is personal data in transmission; inference logs retained for debugging are a copy of it. Each pulls its host system into whichever regime reaches the entity running it.

What does an iDharma UAE review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the readiness report, the regime determination, the processing inventory, the basis and consent register, the rights and breach runbooks, the transfer register and the policy template pack.

Get started

Request your UAE review

Tell us where the entities sit and we come back with a scoping call in a day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.

  1. Which entities process, and where each is licensed
  2. Which systems hold personal data, and what for
  3. Your record of processing, if one already exists
  4. Which systems are shared across the free-zone line
  5. Where data leaves the country, and on what condition

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a UAE review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The UAE Data Office, on the federal regime
  • The DIFC Commissioner and the ADGM Office of Data Protection
Instruments
Three
Regulators
Three

What it means

  • General information about what each regime requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • No penalty amount appears here. The figures differ across the three regimes and are the detail summaries get wrong most often — for a number, go to the regulator that actually reaches your entity.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us