signzy

API Marketplace

downArrow
Logo
Responsive
Decorative line

PDPL Data Protection Law UAE

United Arab Emirates

United Arab Emirates

2021

Privacy

Overview

The PDPL is the UAE’s first comprehensive federal law on personal data protection, issued in 2021. It regulates how organizations collect, process, store, and transfer personal data while ensuring individual privacy rights. The law aligns with global standards (similar to GDPR) and is supervised by the UAE Data Office.
The regulation applies broadly to public and private sector entities, including banks, insurers, healthcare providers, telecom operators, tech companies, e-commerce platforms, and government entities operating in or targeting the UAE.

Key Obligations

  • Obtain clear consent before collecting or processing personal data
  • Process data only for legitimate, declared purposes
  • Grant individuals rights to access, correct, erase, or restrict their data
  • Restrict cross-border data transfers unless the recipient jurisdiction ensures adequate protection
  • Appoint a Data Protection Officer (DPO) in certain high-risk cases
  • Notify the UAE Data Office and affected individuals of data breaches
  • Maintain records of processing activities and implement security safeguards

FAQ

Who regulates the PDPL in the UAE?

The UAE Data Office is the national supervisory authority.

Does the law apply to companies outside the UAE?

Yes, if they process personal data of individuals in the UAE.

Are data transfers outside the UAE allowed?

Yes, but only to countries deemed to provide adequate protection, or with approved safeguards.

What are the penalties for non-compliance?

Administrative fines, business restrictions, and potential criminal liability depending on severity.