Skip to content

UAE PDPL

UAE PDPL illustration

The Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the PDPL) is the United Arab Emirates' federal data protection law. It was issued on 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, and has been in force since 2 January 2022. Across 31 articles it sets out a consent-first processing regime with enumerated exceptions, processing controls, controller and processor obligations, breach reporting, a Data Protection Officer regime, data subject rights, security and impact-assessment duties, and cross-border transfer rules. Supervision sits with the UAE Data Office, established under Federal Decree-Law No. 44 of 2021 and referred to as the Bureau in the law's official English translation.

Many of the law's operational parameters are deferred to an Executive Regulation, which has not been issued as of this framework release (Modulos templates 1.0.23). Modulos models the law as two paired framework templates, OFF-24 for organization-level obligations and MFF-24 for per-application execution, with each deferral marked in the requirement text. This page orients you on what the law covers, how the templates are structured, and where to go next.

Quick decision — is this framework for you?

  • You process personal data of people residing or doing business in the UAE, or you operate as a controller or processor in the onshore UAE → this is your framework. Start with Scope, enforcement, and the Executive Regulation to confirm the perimeter.
  • You are established in the DIFC or ADGM free zone → the law excludes free-zone companies and establishments that have special personal-data-protection legislation, and both zones run their own regimes with their own regulators. See the exclusions in Scope, enforcement, and the Executive Regulation.
  • You already run a GDPR or ISO/IEC 27701 program → treat the PDPL as an additional legal branch on the privacy estate you already operate. Most of the PDPL control substance in Modulos reuses that estate; what is new is the UAE-specific perimeter, readiness, and Bureau-facing content.
  • You run AI systems on personal data → the PDPL reaches them directly: Article 18 gives data subjects an objection right against automated decisions including profiling, with human review on request, and Article 21 requires an impact assessment for high-risk processing with modern technologies. Lawful processing and data subject rights covers the mechanics.
  • You are waiting for the Executive Regulation before acting → the law's substantive obligations are already in force, and Article 29's regularisation period runs from the Regulation's issuance. ORF-464 exists to make that wait a managed readiness posture rather than a pause.

TL;DR

  • The PDPL (Federal Decree-Law No. 45 of 2021) is the UAE's federal data protection law, in force since 2 January 2022. It applies onshore; free zones with their own data protection legislation are excluded (DIFC and ADGM are the established examples), as are government data, security and judicial data, and health and banking data where sectoral legislation regulates their protection and processing.
  • The regime is consent-first: Article 4 prohibits processing without the data subject's consent, subject to ten enumerated exceptions. There is no general legitimate-interests basis.
  • Supervision sits with the UAE Data Office (the Bureau, Federal Decree-Law No. 44 of 2021): breach notifications, records on request, complaints (Article 24), grievances (Article 25), and administrative penalties once a Cabinet decision defines them (Article 26). The templates model readiness toward the Data Office rather than an active supervision workflow.
  • The Executive Regulation has not yet been issued. It will supply the breach notification period, DPO appointment criteria, transfer controls, and other parameters; Article 29 gives a regularisation period of up to six months from its issuance.
  • Modulos models the law as two templates with the Regulation label: OFF-24 (org, 9 requirements, ORF-456ORF-464) and MFF-24 (app, 9 requirements, MRF-431MRF-439), 18 requirements in total, mapped to 65 distinct controls (59 reused, 6 new).

Primary source

Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, Official Gazette No. 712, 26 September 2021. Official English translation: uaelegislation.gov.ae. The translation is provided for reference; in case of conflict, the Arabic original prevails. Always verify claims against the current published text.

Key facts
Legislator
UAE Federal Government
Instrument
Federal Decree-Law No. 45 of 2021 (Regulation label in Modulos)
Issued
20 September 2021 (Official Gazette No. 712, 26 September 2021)
In force
2 January 2022
Structure
31 articles; Executive Regulation not yet issued
Modulos templates
OFF-24 (organization) + MFF-24 (application): 18 requirements, 65 controls

What the law covers

The PDPL runs to 31 articles in a single sequence, from definitions through publication. The table groups them the way the Modulos templates do.

ArticlesWhat they hold
Article 1 — DefinitionsThe defined terms the rest of the law depends on: Personal Data, Sensitive Personal Data, Biometric Data, Controller, Processor, Processing, Automated Processing, Profiling, Pseudonymization, Anonymization, Data Breach, Consent, and the Bureau.
Articles 2–3 — Scope and exemption powerWho the law reaches (residence and targeting), the seven exclusions (government data, governmental entities, security and judicial data, personal use, sectoral health and banking regimes, free zones with their own laws), and the Bureau's power to exempt establishments that do not process a large volume of personal data, per standards the Executive Regulation will set.
Articles 4–6 — Consent and processing controlsThe consent-first rule with ten enumerated consent-free cases, the processing controls (fairness, transparency and lawfulness, purpose limitation, data minimization, accuracy, security, storage limitation with anonymization), and the terms that make consent valid: provable, clear, easily accessible, and withdrawable at any time.
Articles 7–8 — Controller and processor obligationsTechnical and organizational measures, data protection by design and by default, the record of processing each role must maintain and submit to the Bureau on request, processor appointment guarantees, processing on the controller's instructions under the contracts concluded between them, and joint-processor arrangements.
Article 9 — Breach reportingNotification to the Bureau upon becoming aware of a breach that would prejudice privacy, confidentiality, and security, with prescribed content; notification of the data subject; processor-to-controller notification. The period and procedures are deferred to the Executive Regulation.
Articles 10–12 — The Data Protection OfficerMandatory appointment in three trigger cases (high-risk processing through new technologies or data volume, systematic and comprehensive assessment of sensitive personal data including profiling, large-volume sensitive data processing), the DPO's tasks, and the controller's and processor's duties to enable and protect the role.
Articles 13–19 — Data subject rightsThe right to receive information, portability, correction and erasure, restriction, the right to stop processing (including for direct marketing), the right to object to automated decisions including profiling with human review on request, and the duty to provide clear channels to contact the controller.
Article 20 — Personal data securityTechnical and organizational measures to the highest standard suitable to the risks, naming encryption and pseudonymization, resilience and recovery measures, and testing and evaluation of effectiveness, with a risk-based evaluation of the security level.
Article 21 — Impact assessmentA pre-processing assessment when modern technologies would pose a high risk, with two mandatory trigger cases, minimum content, grouping of similar operations, DPO coordination, and periodic review. The Bureau's list of exempt processing operations has not been published.
Articles 22–23 — Cross-border transfersTransfer where a proper protection level is available, in cases approved by the Bureau, and the alternative bases where a proper protection level is not available: binding contractual measures, explicit consent, and enumerated necessity grounds.
Articles 24–26 — Complaints, grievances, penaltiesData subject complaints to the Bureau, the written grievance route against Bureau decisions (30 days to file, 30 days to decide, grievance before judicial challenge), and administrative penalties to be defined by a Cabinet decision.
Articles 27–29 — Delegation, the Executive Regulation, regularisationAuthorization of local government authorities to exercise Bureau powers, the Council of Ministers' issuance of the Executive Regulation, and the regularisation period of up to six months from the Regulation's issuance, extendable for a similar period.
Articles 30–31 — Repeals and entry into forceRepeal of conflicting provisions; publication and entry into force on 2 January 2022.

The consent-first structure is the law's most consequential design choice. Article 4 opens: "It is prohibited to process Personal Data without the consent of its owner." The ten exceptions that follow cover public interest, data made public by the data subject, legal claims, occupational and preventive medicine, public health, archival and research purposes, protection of the data subject's interests, employment and social protection obligations, contract performance, and other legal obligations of the controller. A general legitimate-interests basis of the kind found in other privacy regimes is not among them.

How Modulos models it

Modulos splits the law into organization-level obligations (OFF-24) and per-application execution (MFF-24). Both templates carry the Regulation label.

TemplateProject typeHoldsRequirements
OFF-24 — UAE PDPLOrganizationApplicability and scope determination, controller accountability and records of processing, processor obligations and agreements, breach reporting, DPO appointment and enablement, cross-border transfer governance, complaints and enforcement readiness, and Executive Regulation readiness9 (ORF-456ORF-464)
MFF-24 — UAE PDPLAI applicationLawful basis and consent, processing controls, data protection by design and by default, transparency, data subject rights handling, automated decision-making and human review, personal data security, impact assessment, and application-level transfers9 (MRF-431MRF-439)

There is no scoping questionnaire, no project settings, and no framework tags. Applicability is handled inside the requirement text: ORF-456 establishes the perimeter (Articles 2–3), records the exclusions that apply, and documents that no descoping relies on the Bureau's Article 3 exemption power, which depends on standards the Executive Regulation will set. The framework will be updated when the Executive Regulation is issued; until then, every deferral is marked in the requirement text with the standardized note "The Executive Regulation will specify [X]; it has not yet been issued."

The 18 requirements group into four coverage domains, each with its own topic page.

1. Scope, enforcement, and the Executive Regulation

The perimeter and exclusions including the free-zone carve-out (ORF-456, Articles 2–3), complaints, grievances, and enforcement readiness toward the Bureau (ORF-463, Articles 24–26), and the regulatory watch that manages the pending Executive Regulation and the Article 29 regularisation window (ORF-464, Articles 28–29).

→ Deep dive: Scope, enforcement, and the Executive Regulation.

2. Lawful processing and data subject rights

The consent-first regime and valid-consent terms (MRF-431, Articles 4 and 6), the Article 5 processing controls (MRF-432), proactive transparency and contact channels (MRF-434, Articles 13(2) and 19), the rights-handling machinery for information, portability, correction, erasure, restriction, and objection (MRF-435, Articles 13–17), and automated decision-making with human review on request (MRF-436, Article 18).

→ Deep dive: Lawful processing and data subject rights.

3. Controllers, processors, and the DPO

Controller accountability and the record of processing (ORF-457, Article 7), processor obligations, instructions, and joint-processor agreements (ORF-458, Article 8), data protection by design and by default on the application side (MRF-433, Articles 7(1)–(3) and 8(2)), the DPO appointment triggers (ORF-460, Article 10), and the DPO's roles and enablement (ORF-461, Articles 11–12).

→ Deep dive: Controllers, processors, and the DPO.

4. Security, breaches, DPIA, and cross-border transfers

Personal data security measures and their risk-based evaluation (MRF-437, Article 20), breach reporting to the Bureau and data subjects (ORF-459, Article 9), the impact assessment triggers, content, and review cycle (MRF-438, Article 21), and cross-border transfers at both levels: organization-wide transfer governance (ORF-462) and per-application transfer execution (MRF-439), Articles 22–23.

→ Deep dive: Security, breaches, DPIA, and cross-border transfers.

How Modulos operationalizes the UAE PDPL

The two templates are designed to run together: OFF-24 establishes the organization-wide perimeter, records, DPO, transfer governance, and Bureau-facing readiness once, and each MFF-24 project produces the per-application evidence that a given AI application processes personal data lawfully.

  • OFF-24 — UAE PDPL — one organization project. 9 requirements (ORF-456ORF-464), mapped to 23 distinct controls: 6 new UAE PDPL controls (OCF-363OCF-368) and 17 reused.
  • MFF-24 — UAE PDPL — one AI-application project per in-scope application. 9 requirements (MRF-431MRF-439), mapped to 42 distinct controls, all reused from the existing estate.

Across both templates that is 65 distinct controls: 59 reused and 6 new. The six new controls carry the UAE-specific organizational duties: OCF-363 (Regulatory Instrument Watch and Readiness), OCF-364 (Breach Notification Readiness), OCF-365 (DPO Appointment Trigger Assessment), OCF-366 (Privacy-Law Applicability Determination), OCF-367 (Processor Instruction, Duration and Co-processor Governance), and OCF-368 (Regulatory Decision Grievance Management).

The reused estate comes mostly from the platform's GDPR and ISO/IEC 27701 control sets, plus security controls shared with the ISO estate. Where reused controls hard-coded GDPR parameters, such as the 72-hour breach notification window, they were generalized rather than duplicated: 34 of the 59 reused controls now carry those figures as GDPR-branch specifics, while the PDPL branch reflects the parameters the Executive Regulation will supply, and the other 25 were reused unchanged. The GDPR and 27701 branches of every generalized control remain fully correct, and the reuse is a control-layer economy, not an assertion of clause-level equivalence between the PDPL and any other instrument.

Each requirement is evidenced through a readiness signal plus owner-attested fulfillment; reviews are reserved for control status changes. All binding legal language stays anchored in the requirement text, with short verbatim quotes from the official English translation and a source line noting that the Arabic original prevails.

→ Full rollout: Operationalizing the UAE PDPL in Modulos: project structure, the requirement-to-article mapping table, the control split, the rollout sequence, and the evidence model.

Where to go next

Frequently asked questions about the UAE PDPL

What is the UAE PDPL?

The UAE PDPL is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, the United Arab Emirates' federal data protection law. It was issued on 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, and has been in force since 2 January 2022. Across 31 articles it regulates the processing of personal data: consent and the enumerated consent-free cases, processing controls, controller and processor obligations, breach reporting, the Data Protection Officer, data subject rights, personal data security, impact assessment, cross-border transfers, and complaints and grievances. Many operational parameters are deferred to an Executive Regulation, which has not been issued as of this framework release (Modulos templates 1.0.23).

Who is in scope for the UAE PDPL, and are DIFC and ADGM covered?

Under Article 2, the law applies to data subjects residing or having a place of business in the UAE, to controllers and processors in the UAE (including where they process data of data subjects outside it), and to controllers and processors outside the UAE that process personal data of data subjects inside it. Excluded are government data, governmental entities, personal data held by security and judicial authorities, purely personal use, health data and banking and credit data that have their own sectoral protection legislation, and companies in free zones with their own data protection laws. The free-zone exclusion is stated in general terms; the DIFC and ADGM financial free zones, which run their own data protection regimes, are the two established examples. Modulos records the perimeter decision through ORF-456.

What is the status of the Executive Regulation, and what does it mean practically?

As of this framework release, the PDPL's Executive Regulation has not been issued. The law's substantive obligations are in force, but several parameters are deferred to the Regulation: the breach notification period and procedures (Article 9), the technology types and data-volume criteria for DPO appointment (Article 10), additional consent-free cases and processing controls (Articles 4 and 5), cross-border transfer controls (Article 23(2)), and grievance procedures (Article 25). Administrative penalties under Article 26 await a separate Cabinet decision, and the Article 21(6) list of processing operations exempt from impact assessment has not been published. Article 29 gives controllers and processors a regularisation period of no more than six months from the date the Executive Regulation is issued, extendable by the Council of Ministers. In the Modulos templates each deferral is marked in the requirement text with a standardized note stating what the Executive Regulation will specify and that it has not yet been issued.

How does Modulos model the UAE PDPL?

As two paired templates carrying the Regulation label. OFF-24 holds the organization-level obligations as 9 requirements, ORF-456 through ORF-464; MFF-24 holds the per-application obligations as 9 requirements, MRF-431 through MRF-439, 18 requirements in total. They map to 65 distinct controls: 59 reused from the platform's existing estates and 6 new organization controls (OCF-363OCF-368). There is no scoping questionnaire and no framework tags; applicability is handled inside the requirement text, with ORF-456 establishing the perimeter.

How does the UAE PDPL relate to the GDPR?

The two laws share concepts (controller and processor roles, records of processing, breach notification, a DPO regime, data subject rights, impact assessment, transfer rules), and in Modulos most of the PDPL control estate is reused from the platform's GDPR and ISO 27701 control sets. That reuse happens at the control layer and is not an assertion of clause-level equivalence. The regimes differ in substance: Article 4 of the PDPL prohibits processing without consent subject to ten enumerated exceptions and has no general legitimate-interests basis; the breach notification period is deferred to the Executive Regulation rather than fixed at 72 hours; cross-border transfers rest on Article 22 transfers in cases approved by the Bureau, with no approvals published as of this framework release, and on the Article 23 alternatives of contractual measures, explicit consent, and enumerated necessity grounds rather than a GDPR-style adequacy list; and penalty amounts await a Cabinet decision. Where reused controls carried GDPR-specific parameters, they were generalized so those parameters remain correct on the GDPR branch while the PDPL branch reflects the deferred parameters.

What does the regulatory-watch requirement do?

ORF-464 (Executive Regulation Readiness and Regulatory Watch) turns the pending Executive Regulation into a managed obligation. It requires the organization to monitor for the issuance of the Executive Regulation, the Article 26 Cabinet decision on administrative penalties, and Bureau publications such as the Article 21(6) exempt-processing list, and to maintain a readiness plan for closing the deferred items (breach notification timeline, DPO appointment criteria, transfer controls, penalty exposure) within the Article 29 regularisation window. It is backed by the new control OCF-363 (Regulatory Instrument Watch and Readiness).

Who enforces the UAE PDPL?

Supervision sits with the UAE Data Office, established under Federal Decree-Law No. 44 of 2021 and referred to as the Bureau throughout the PDPL's official English translation. Under the law, the Bureau receives breach notifications (Article 9), can request the records of processing (Articles 7 and 8), receives and examines complaints from data subjects (Article 24), decides grievances against its decisions within 30 days (Article 25), and imposes the administrative penalties to be defined by a Cabinet decision (Article 26). As of the framework's release (Modulos templates 1.0.23), the Data Office's supervisory processes are still being stood up, so the Modulos templates build cooperation and notification readiness rather than assuming an active supervision workflow.

Source attribution

This page summarizes Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021 and published in Official Gazette No. 712 on 26 September 2021 (official English translation: uaelegislation.gov.ae). The English translation is provided for reference; in case of conflict, the Arabic original prevails, and quotes on this page and in the Modulos templates are taken from the official English translation on that basis. Requirement and control codes (OFF-24, MFF-24, ORF-, MRF-, OCF-, MCF-) are Modulos template identifiers, not references used by the law.

Disclaimer

This page is for general informational purposes and does not constitute legal advice. The PDPL's Executive Regulation has not yet been issued; parameters deferred to it, to the Article 26 Cabinet decision, and to Bureau publications are stated here as pending, not estimated. Always verify against the current published text and consult qualified advisers.