Three instruments govern personal data here: the federal law onshore under the UAE Data Office, the Dubai International Financial Centre under its own law and Commissioner, and the Abu Dhabi Global Market under its own regulator. All three are consent-led, and all three of them differ.
The UAE has three data regimes. You are in one of them.
Establishment decides which one reaches you, and groups routinely span two.
Our promise
“Three regimes, one group. Mapping is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe UAE, in three chapters
Most groups run one privacy programme across companies sitting under different instruments. It is nobody’s mistake exactly - the entities share a logo, a helpdesk and a data warehouse. What they do not share is a regulator, transfer conditions or a DPO trigger. None travel.
Which instrument reaches each entity is the first thing we settle, in writing, before a word of the programme is drafted. Then the duties of that instrument are tested against the estate as it actually runs, and a group spanning the free-zone line gets one review rather than two separate ones.
Three instruments, two boundaries.
Start with where the entity is registered, not with what it does - and take it from the licence, not the office address.
- Entities registered outside the free zones
- Supervised by the UAE Data Office
- Consent-led, with statutory exceptions
- Unless a sector rule says otherwise
- Entities registered in either free zone
- Each with its own regulator and enforcement
- Closer to the GDPR in shape than the federal law
- And not a variation on it, or on each other
The duty is yours. Which duty is the question.
The federal law of the UAE
The national regime, overseen by the UAE Data Office. It reaches entities established onshore unless a sector rule says otherwise, and it is consent-led with statutory exceptions rather than carrying the full lawful-basis set that a GDPR programme is normally written against and expects.
The DIFC and ADGM regimes
Two financial free zones, each with its own data protection instrument, its own regulator and its own enforcement. Both sit closer to the GDPR in shape than the federal law does - and neither is a variation on it, on the other, or on the federal law that they happen to sit beside. Each is its own programme.
Establishment decides, not activity
A group with an onshore company and a DIFC entity has two programmes, not one. Build to the highest common standard and apply it everywhere, or run them separately - both are defensible. Assuming one covers all of it because the entities share a logo and a helpdesk is not defensible for long.
“One programme. It is all the UAE.”
The licence decides, not the letterhead.
It is the first thing we have to correct.
- Who it is for
- Banks & DIFC firms
- ADGM entities
- Healthcare & insurance
- Retail & telecoms
- Cloud & AI vendors
Administrative penalties are set per regime, and the amounts are what summaries get wrong most often. This page therefore prints none.
Directions and compensation are frequently the real outcome. For a live product an order to stop processing is sharper than a fine would be.
Saudi Arabia, Qatar and Bahrain each run their own regime too. Only the UAE and Qatar carry a free-zone law beside the national one.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and one starts them all.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Determine
Before anythingWhich of the three instruments reaches each entity. Nothing else on this page can be scheduled until that is written down.
-
Notify
On becoming awareThe breach duty runs from awareness under each regime, and the window is one of the things that differs between them.
-
Answer
On requestA rights request starts a clock set by whichever instrument reaches the entity holding the data, not by the group standard.
-
Demonstrate
ContinuouslyBeing able to show it rather than only to do it is common to all three. The records have to describe the estate on the day.
The windows are not the same under the three instruments, so a group standard set to the shortest one is safe and a group standard set to the longest is not. Which clock applies is decided by the entity holding the data, not by the parent.
What the law says, what we ship
12 duties, with the note saying where the three instruments diverge.
- Regime determination The first artefact
- A written determination for each entity - federal, DIFC or ADGM - taken from the licence rather than from the office address, with the reasoning kept where a shared system serves both sides of a boundary.
- Records of processing All three regimes
- A record per activity with purpose, categories, recipients, transfers and retention filled in rather than left as headings. The document every regulator here opens first.
- Lawful basis Consent-led onshore
- A basis recorded per purpose, with the consent position documented where consent is what you rely on and the statutory exception named where it is not.
- Purpose limitation Fixed before use
- Purposes defined before collection with a compatibility test for any new use - the principle secondary model training most often breaks.
- Data minimisation Necessity per field
- The least that answers the purpose, assessed at field level and reviewed rather than assumed to still be right two releases later.
- Accuracy Scaled to consequence
- A higher bar where the data drives a decision about the individual, with a correction route that reaches the downstream copies people forget.
- Storage limitation Ceasing is an action
- A retention period per category with its justification, and a deletion route named rather than assumed to exist somewhere in the platform.
- Integrity and confidentiality Tested, not attested
- The measures you actually run, argued against the risk they address, including the processors and vendors holding the data on your behalf.
- Individual rights Windows differ
- One intake route somebody outside can find, identity verification, and a search that reaches the backups and the ticketing system rather than the primary database alone.
- Impact assessments Where risk is high
- A screening test that says when an assessment is required under the applicable regime, the methodology, and completed assessments for the processing that triggers it.
- Cross-border transfers Differs by regime
- A transfer register with the condition relied on per route, under the instrument that reaches the exporting entity - the three sets of conditions are not the same.
- Data protection officer Triggers differ
- The appointment decision written either way, and where one is appointed, the independence, resource and freedom from conflicting duties the role is meant to carry.
Personal data, independently reviewed
From the onshore estate to the free-zone entity.
-
Determine
Which of the three regimes reaches each entity, in writing.
-
Test
The duties of that regime against the estate as it actually runs.
-
Sign off and evidence
You see the draft first. Then the records, notices and drills - dated.
Why teams choose iDharma for their UAE review
The regime, settled first
Which instrument reaches each entity, written down before the programme is drafted.
One scope, three rulebooks
A group that spans the free-zone line gets one review rather than two reviews that disagree.
GDPR work carries over
The free-zone regimes sit close to the GDPR, so existing work maps rather than restarts.
The Gulf in one scope
Saudi, Qatar and Bahrain obligations overlap enough to scope in the same engagement.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
UAE readiness report
The full review: which instrument reaches each entity, what you process under it, and where every duty is evidenced or is not - written duty by duty. Findings carry the regime they arise under, so a group spanning the free-zone line reads one report rather than two, with the transfer and DPO positions stated separately.
Regime determination
Entity by entity, taken from the licence rather than from custom - with the reasoning recorded where a shared system serves both sides of a boundary.
Processing inventory
Every activity with purpose, categories, recipients, transfers and retention - built from the systems inwards rather than from a questionnaire.
Basis and consent register
A basis per purpose with the consent position where consent is relied on, and the statutory exception named where it is not relied on at all.
Rights and breach runbooks
One intake route with identity verification, plus a breach path with the decision-maker named in advance and the clock set by the right regime.
Transfer register
Where the data actually lands and the condition relied on per route, under the instrument reaching the exporting entity rather than the group standard.
Policy template pack
The core set, the rights and consent set and the security and breach set - written to the regime that reaches you rather than handed over generic.
Real numbers, upfront.
- Scope
- Set by the instrument
- Inputs
- Your entities and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The instrument fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Regime determination per entity
- Processing inventory and register
- Transfer register, per instrument
- 26 policy templates, tailored
Four things you have to be able to produce
None of the three regimes is graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The regime,
decided
A written determination for each entity: federal, DIFC or ADGM. Everything else depends on it, and it is the artefact a group spanning the line most often lacks.
The record,
current
A record of processing that matches what the systems do. It is the first document any of the three regulators opens, and what every other position is argued out of.
The route,
findable
A rights route somebody outside can find without asking you, and a breach path with the decision-maker named before an incident rather than in the middle of one.
The officer,
unconflicted
Appointing a DPO is the easy half. What the regimes expect is independence, direct access to senior management, real resource and no conflicting duties.
Four cards, and the date on each one is part of the card.
Plain answers
Which law reaches you, whether it crosses the border, and where AI lands. Answered straight.
Request this reviewWhat is the UAE Personal Data Protection Law?
The federal personal data protection law, overseen by the UAE Data Office - and it is one of three regimes rather than the only one. The DIFC and ADGM financial free zones each have their own instrument, their own regulator and their own enforcement.
How do we know which law applies to us?
Establishment decides, not activity. An entity registered onshore falls under the federal regime unless a sector rule says otherwise; an entity registered in DIFC or ADGM falls under that zone’s own instrument. Groups spanning both need both.
Does the UAE PDPL apply to companies outside the UAE?
It can. Processing the personal data of individuals in the UAE is what brings the duties, and the question of which instrument then applies turns on where the processing entity is established. An overseas company contracting with a DIFC entity is in a different position from one contracting onshore.
Do prompts and logs count as personal data?
If they identify a person, or can be linked to one with anything else you hold, yes. A prompt carrying customer detail is personal data in transmission; inference logs retained for debugging are a copy of it. Each pulls its host system into whichever regime reaches the entity running it.
What does an iDharma UAE review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the readiness report, the regime determination, the processing inventory, the basis and consent register, the rights and breach runbooks, the transfer register and the policy template pack.
Request your UAE review
Tell us where the entities sit and we come back with a scoping call in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.
- Which entities process, and where each is licensed
- Which systems hold personal data, and what for
- Your record of processing, if one already exists
- Which systems are shared across the free-zone line
- Where data leaves the country, and on what condition
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The UAE Data Office, on the federal regime
- The DIFC Commissioner and the ADGM Office of Data Protection
- Instruments
- Three
- Regulators
- Three
What it means
- General information about what each regime requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- No penalty amount appears here. The figures differ across the three regimes and are the detail summaries get wrong most often — for a number, go to the regulator that actually reaches your entity.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom