UAE · FEDERAL PDPL · DIFC · ADGM

UAE data protection is three regimes, not one.

The federal law, the DIFC regime and the ADGM regime are separate instruments with separate regulators. The first question is never what the rules require — it is which set of rules reaches the entity you are actually talking about, and groups routinely span more than one.


A black legal binder with a brass plate and a red wax seal on a dark desk, beside a stamp bearing a set of scales Illustrative materials
Which regime, before which rule
Federal PDPL DIFC ADGM DPO Transfers

What is the UAE PDPL?

The UAE federal personal data protection law, sitting alongside the separate regimes of the DIFC and ADGM financial free zones. All three are consent-led and broadly GDPR-influenced; they differ enough in detail that a programme built for one does not satisfy another.

  • Federal law Applies onshore The national regime, overseen by the UAE Data Office.
  • DIFC Separate regime Its own data protection law and its own commissioner.
  • ADGM Separate regime Its own regulations and its own regulator.
  • First question Which one applies Establishment decides the regime, and groups frequently span more than one.

Who needs UAE PDPL compliance?

Anyone processing personal data of individuals in the UAE — and the answer to "under which law" depends on where the processing entity sits.

  • Onshore entities The federal regime, unless a sector rule says otherwise.
  • DIFC and ADGM entities Their own regimes, closer to GDPR in shape and enforced by their own regulators.
  • Groups spanning both The common case, and the one where a single privacy programme quietly fails to satisfy two of the three regimes.
  • Anyone running automated decisions The free-zone regimes carry provisions closer to GDPR's treatment of automated decision-making. Check the position under the regime that reaches you.
  • AI vendors serving UAE customers Your customers will ask which regime you have built to. Having an answer shortens the review considerably.
How we help

How iDharma supports UAE PDPL compliance

Regime first, then the duties. Doing it the other way round is the single most common false start we see.

Duty area What the assessment does
Regime determinationWhich of the three instruments reaches each entity in the group, and where a single programme currently assumes one answer for all of them. This is the mapping everything else depends on.
Data inventory and mappingEvery personal data flow reaching a model — training corpora, prompts, retrieval indexes, logs and vendor endpoints. Prompts and logs are where personal data is usually found unexpectedly.
Lawful basis and consentFor each purpose, the basis relied on and whether the record of it would survive a regulator asking. Including whether withdrawal actually propagates.
Data subject rightsAccess, correction, erasure, restriction, portability, objection and withdrawal, tested from the outside in rather than described from the inside out.
Cross-border transfersWhere the data physically lands, the condition relied on under the applicable regime, and whether that matches what your privacy notice says.
DPO and governanceWhether an appointment is required under the regime that reaches you, and whether the role has the independence and access the law expects.
Breach readinessA written assessment procedure, a named decision-maker, a notification path per regulator, and a rehearsal against the clock.
AI-specific exposureAutomated decisions, model memorisation, prompt logging and processor arrangements — the four places a statute written before generative AI still bites.

Establish the regime first. Almost every UAE engagement we see begins with a programme designed against one instrument and an entity sitting under another. That mapping costs far less to do deliberately than to discover during diligence.

Capabilities

What the assessment produces

Six areas, each delivering an artefact rather than an opinion.

Personal data mapping and inventory

Everything else is derived from this

Every category held, its source, purpose, recipients and location — including the prompts, logs and retrieval indexes created after the last inventory was written.

Data subject rights management

Tested from the outside

A request route a member of the public can find, identity checks that are proportionate, and responses that meet the timeframe of the applicable regime.

Cross-border transfer compliance

Per regime, not in general

Where the data actually lands, the condition relied on, and whether your notice describes it. The conditions differ between federal, DIFC and ADGM.

Consent and legal basis tracking

Recorded, not implied

Consent captured with what was shown at the time, withdrawal honoured downstream, and every exception relied on documented rather than assumed.

Breach detection and notification

Deciding is the slow part

A written assessment procedure, a named decision-maker, per-regulator notification templates, and a rehearsal against the clock before you need one.

Privacy impact assessments

Before the project, not the launch

Structured assessment where processing is likely to present high risk, with findings that change the design rather than describe it after the fact.

Coverage

Complete UAE PDPL requirements coverage

The processing principles, the data subject rights, and the duties that sit alongside them — assessed under the regime that applies to each entity.

3
Separate regimes assessed
7
Processing principles
8
Data subject rights
01 Regime determination Which instrument reaches each entity
Covered by the assessment
02 Processing principles Each with the evidence it should produce
Covered by the assessment
03 Lawful basis and consent Including withdrawal that works downstream
Covered by the assessment
04 Data subject rights Request routes tested from outside
Covered by the assessment
05 Automated decisions Where the free-zone regimes go furthest
Covered by the assessment
06 Cross-border transfers Conditions that differ by regime
Covered by the assessment
07 DPO requirements Whether an appointment is triggered
Covered by the assessment
08 Breach duties Assessment, decision-maker, notification path
Covered by the assessment
09 Privacy impact assessments Where high-risk processing is involved
Covered by the assessment
10 Records and accountability What a regulator asks for before anything else
Covered by the assessment

All three in one review

Federal, DIFC and ADGM assessed together, because a group spanning them needs three answers rather than an average of three.

Cross-border transfer logic

Conditions resolved per regime rather than assumed uniform, because they are not.

Automated decisions

Assessed under the regime that actually reaches the entity, which is where the free zones go furthest.

Entity-level mapping

A record of which instrument applies where — the artefact diligence asks for first.

The principles

Seven key data protection principles

Broadly common across all three regimes, and close to GDPR in the free zones. Each is stated here as something that produces evidence rather than something to agree with.

Lawful basis

Consent-led, with statutory exceptions

  • A basis identified and recorded per purpose
  • Consent informed and specific where relied on
  • Exceptions relied on explicitly, not by default
  • Withdrawal that works downstream

Purpose limitation

Fixed before collection

  • Purposes stated at the point of collection
  • Secondary use assessed rather than assumed
  • Training a model is usually a new purpose
  • Changes notified, not absorbed

Data minimisation

The least that answers the purpose

  • Fields collected because they are needed
  • Training sets scoped rather than maximised
  • Prompt context trimmed at the edge
  • The judgement recorded

Accuracy

Proportionate to the consequence

  • Higher bar where a decision affects the person
  • Source and currency recorded
  • Correction reaching downstream copies
  • Model output is not a source of truth

Storage limitation

Ceasing retention is an action

  • A schedule with named owners
  • Disposal that actually runs
  • Backups, archives and logs in scope
  • Prompt and response logs included

Integrity and confidentiality

Tested, not attested

  • Access control over data and model artefacts
  • Encryption in transit and at rest
  • Processor controls that were verified
  • Output treated as an egress path

Accountability

Able to show it, not only do it

  • Records of processing kept current
  • A named contact for data protection
  • Policies communicated and evidenced
  • Decisions documented at the time
Individual rights

Data subject rights under UAE PDPL

Eight rights, each needing a route a member of the public can find and use. Timeframes and exact scope vary by regime, which is another reason the regime question comes first.

Right to know

Information and transparency

What is collected, why, who receives it and where it goes — owed before or at the point of collection rather than on request.

Right of access

Access to their data

Confirmation of processing and a copy of what is held, through a route a member of the public can find without help.

Right to rectify

Correction

Inaccurate or incomplete data corrected, with the correction reaching processors and downstream copies rather than the primary record alone.

Right to erase

Erasure

Deletion where the conditions are met, and a written position on what deletion means for a model already trained on the data.

Right to restrict

Restriction of processing

Processing paused rather than deleted while a dispute is resolved — which requires a technical state most systems were not built to hold.

Right to portability

Data portability

A structured, machine-readable copy, and where feasible transmission to another controller. The engineering is the long pole.

Right to object

Objection

Including objection to direct marketing, which carries its own consent regime separate from the basis for processing.

Right to withdraw

Withdrawal of consent

As easy to withdraw as it was to give, and effective downstream — a withdrawal that stops the front door and not the pipeline is not a withdrawal.

Restriction and portability are the two that need engineering. Restriction requires a state most systems were never built to hold, and portability requires an export nobody specified. Both are cheaper to design in than to retrofit under a live request.

The free zones

DIFC and ADGM data protection frameworks

Two financial free zones, each with its own data protection law, its own regulator and its own enforcement. Neither is a variation on the federal regime — they are separate instruments.

Dubai International Financial Centre

DIFC Data Protection Law

Its own law, its own Commissioner of Data Protection

  • Structurally closer to GDPR than the federal regime
  • Its own lawful bases, including a legitimate-interests route
  • Data protection officer appointment triggered in defined cases
  • Its own notification duties and its own regulator to notify
  • Transfer conditions set by the DIFC regime, not the federal one
  • Provisions on automated decision-making with GDPR lineage
Abu Dhabi Global Market

ADGM Data Protection Regulations

Its own regulations, its own regulator

  • Also GDPR-influenced in structure and vocabulary
  • Its own basis set and its own definitions
  • Officer appointment obligations on its own terms
  • Its own breach notification path and thresholds
  • Transfer conditions distinct from federal and DIFC
  • Rights set that is close to, but not identical with, DIFC

A group with an onshore company and a DIFC entity has two programmes, not one. You can build to the highest common standard and apply it everywhere, or run them separately — both are defensible. What is not defensible is a single programme that assumed one answer applied across the group.

Getting there

16-week implementation roadmap

A practical path with clear milestones. The weeks are elapsed position, not effort — and phase one here starts with a question the other Gulf jurisdictions do not have to ask.

  1. Weeks 1–4

    Data mapping

    Regime first, then the data

    • Determine which regime reaches each entity
    • Map collection points and stated purposes
    • Include prompts, logs and retrieval stores
    • List processors and where they process
    • Gap-assess against the applicable regime
  2. Weeks 5–8

    Rights and governance

    Make the duties operable

    • Rights request workflow stood up
    • Consent capture and withdrawal that works
    • DPO appointment where triggered
    • Privacy notices revised to match reality
    • Records of processing brought current
  3. Weeks 9–12

    Security and transfers

    The technical half

    • Access control over data and artefacts
    • Transfer assessments per regime
    • Processor terms updated
    • Retention schedule with named owners
    • Erasure reaching every store
  4. Weeks 13–16

    Documentation and training

    Evidence that it keeps working

    • Breach procedure rehearsed against the clock
    • Privacy impact assessments where required
    • Staff training with attendance recorded
    • Internal audit of the obligations
    • Review cadence fixed and owned
Enforcement

Penalties and enforcement

Three regimes, three enforcement regimes. Your exposure depends on which instrument reaches the entity — the same question everything else on this page turns on.

Administrative penalties

Set per regime

Each of the three instruments carries its own penalty provisions, with the band reflecting the seriousness of the contravention. Confirm the figures for the regime that applies to your entity before relying on any number.

The UAE Data Office

The federal supervisor

The federal authority for data protection, alongside the DIFC Commissioner and the ADGM regulator. Three supervisors, operating independently, with their own guidance and their own expectations.

Directions and compensation

Often the real outcome

Regulators can require an organisation to change or stop what it is doing, and the free-zone regimes contemplate routes for individuals to seek compensation. A direction to remediate arrives more often than a headline penalty.

No figure is printed on this page deliberately. Penalty amounts differ across the three regimes and are the most-quoted and most-often-wrong detail in UAE privacy summaries. The bands are described; the numbers belong here once someone has checked them against each enacted text.

Governance

Data Protection Officer requirements

When an appointment is triggered, and what the role has to be able to do once it exists. The triggers differ between the federal law and the two free-zone regimes.

Public authorities

Generally in scope

Bodies carrying out public functions are among the clearest cases for an appointment, and the expectations attached to the role are correspondingly firm.

Large-scale processing

Volume and systematic monitoring

Processing at scale, or systematic monitoring of individuals, is a common trigger. AI systems that score or rank people at volume fall squarely inside this description.

Sensitive data flows

Category over quantity

Processing sensitive categories can trigger an appointment regardless of volume — and those categories appear in training sets more often than in inventories.

DIFC and ADGM entities

Their own triggers

The free-zone regimes set their own appointment obligations on their own terms. An assessment against the federal position does not answer the question for a free-zone entity.

The appointment is the easy half. What the regimes actually expect is independence, direct access to senior management, sufficient resource, and no conflict with other duties the person holds. A named officer with none of those is a title rather than a control.

In context

How UAE PDPL compares

The three UAE regimes against GDPR and the wider Gulf. The UAE is the outlier in one respect that matters more than any other: it is three instruments rather than one.

UAE federal DIFC ADGM GDPR Other Gulf
Instrument Federal PDPL DIFC Data Protection Law ADGM DP Regulations Regulation (EU) 2016/679 National statutes
Regulator UAE Data Office DIFC Commissioner ADGM regulator National DPAs National authorities
Primary basis Consent-led Basis set incl. legitimate interests Own basis set Six lawful bases Consent-led
Structure Its own Close to GDPR Close to GDPR The reference Varies by state
Transfers Conditioned Own conditions Own conditions Adequacy and safeguards Conditioned
DPO Triggered in cases Triggered in cases Triggered in cases Article 37 triggers Varies by state
Automated decisions Not a standalone regime GDPR-lineage provisions GDPR-lineage provisions Article 22 Rarely standalone

The free-zone regimes are closer to GDPR in structure, which for a team with GDPR experience often makes them more familiar rather than harder. What matters is not which is stricter but that all three are genuinely different instruments with different regulators.

Policy templates

Complete privacy governance policy repository

Ready-to-use templates covering the principles, the rights, the DPO role, the breach path and the AI-specific questions — with the regime mapping that decides which version applies.

Data protection

  • Personal Data Protection Policy
  • Regime Determination Record
  • Lawful Basis & Consent Standard
  • Privacy Notice Templates
  • Records of Processing
  • Retention Schedule

+ 4 more policies

Data subject rights

  • Rights Request Procedure
  • Identity Verification Standard
  • Erasure & Model Position Note
  • Restriction Handling Standard
  • Portability Export Specification
  • Objection & Marketing Opt-Out

+ 3 more policies

Security & compliance

  • Breach Assessment Procedure
  • Per-Regulator Notification Templates
  • Privacy Impact Assessment Template
  • DPO Terms of Reference
  • Cross-Border Transfer Assessment
  • Processor & Vendor Terms

+ 4 more policies

Questions

Frequently asked questions

What comes up in every UAE scoping call, starting with the one that decides the rest.

1 Which regime applies
What is the UAE Personal Data Protection Law?

The federal statute governing the processing of personal data onshore, overseen by the UAE Data Office. It sits alongside — not above — the separate data protection regimes of the DIFC and ADGM financial free zones, each of which has its own law and its own regulator.

How do we know which law applies to us?

By where the processing entity is established. An onshore company falls under the federal regime; a DIFC or ADGM entity falls under its free-zone regime. Groups often span more than one, which means more than one programme rather than an averaged one.

Does the UAE PDPL apply to companies outside the UAE?

Processing the personal data of individuals in the UAE generally brings you in, wherever you are established. As always in this region, the law follows the data rather than the head office.

Are the free-zone regimes stricter?

They are closer to GDPR in structure, which for a team with GDPR experience often makes them more familiar rather than harder. What matters is not which is stricter but that they are genuinely different instruments enforced by different regulators.

2 Duties and governance
When do we need a Data Protection Officer?

Appointment is triggered in defined circumstances — commonly public authorities, large-scale or systematic processing, and processing of sensitive categories. The triggers differ between the federal law and the two free-zone regimes, so confirm the position under the instrument that reaches your entity. And the appointment is the easy half: independence, access to senior management and freedom from conflict are what the role actually needs.

What are the data subject rights?

Broadly information, access, correction, erasure, restriction, portability, objection and withdrawal of consent. The exact scope and the response timeframes vary by regime, which is one more reason the regime question comes first.

Do we need privacy impact assessments?

Where processing is likely to present high risk to individuals, yes — and an AI system that scores or ranks people at scale is a strong candidate. The value is in doing it before the architecture is fixed; an assessment written after the design is frozen changes nothing.

When do we have to report a breach?

Each regime sets its own notification duties and thresholds, and each has its own regulator to notify. The practical preparation is a written assessment procedure and a named decision-maker, because most of the window gets spent deciding whether it is notifiable rather than reporting it.

3 AI, transfers and running it
Does using an overseas model provider trigger the transfer rules?

Under all three regimes, yes, if personal data reaches the provider. The conditions differ between them, which is another reason the regime question comes first rather than last.

Do any of the regimes regulate automated decisions?

The free-zone regimes carry provisions with GDPR lineage on automated decision-making. Check the position under the specific regime that reaches your entity rather than assuming the country behaves as one jurisdiction.

Do prompts and logs count as personal data?

If a prompt contains personal data then sending it is processing, and the log holding it is personal data at rest in a system that was almost certainly never classified. It is the first place we look, under any of the three regimes.

Can we train a model on data collected in the UAE?

Only with a basis that covers training as a purpose. Data collected to deliver a service and reused to train a model is generally a new purpose, and the notice and consent you already hold almost certainly do not reach it.

How long does a readiness review take?

Typically five to nine weeks — a little longer than single-regime jurisdictions because the mapping comes first. Where the personal data inventory does not yet exist, building it is the work and everything else derives from it. Scope is agreed with you before anything is charged.

Get started

Ready to achieve UAE PDPL compliance?

Regime first, then inventory, basis, rights, transfers and the DPO question — built against the instrument that actually reaches you.

This page is guidance on how we scope an assessment, not legal advice. UAE counsel should confirm which regime applies and anything you intend to rely on.