We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

UAE Data Office

UAE Data Office (PDPL)

Federal personal data protection under the PDPL (Federal Decree-Law 45 of 2021): consent, processing, breach duties, and cross-border transfer for nearly every business.

Last verified: September 2026Official site

Who is in scope

Nearly every UAE business processing personal data, plus foreign businesses processing data of people in the UAE. Government entities and the DIFC and ADGM free zones operate under their own regimes.

Notification window

Notify the Data Office immediately on becoming aware of a breach that threatens privacy; the law does not set a fixed hour count. (The 72-hour window often quoted online is the ADGM rule, not the federal one.)

Current instrument

Federal Decree-Law 45 of 2021 on the Protection of Personal Data (PDPL).

The duties, in plain language

  • A lawful basis and clear purpose for every processing activity, with records kept.
  • Security measures proportionate to the data, and a rehearsed breach procedure.
  • Cross-border transfers only under the conditions the law allows, documented.

Where this stands

Verified September 2026: the Implementing Regulations had not yet been issued and the Data Office was not yet fully operational. The law applies; detailed procedures follow. We update this line the month that changes.

Dates on this regulator's calendar

Watch · watching

PDPL Implementing Regulations

Not yet issued as of September 2026, with the Data Office not yet fully operational. The law applies now; the detailed procedures follow. This entry updates the month they are published.

Source: Chambers Data Protection 2026 (March 2026); DLA Piper

Questions we get

Do we need a data protection officer?

When processing is high-risk, large-scale or involves sensitive data, yes. Many mid-size firms appoint one anyway because clients and auditors ask.

How does PDPL relate to DIFC and ADGM data protection?

Each financial free zone has its own data protection law and commissioner. A group with entities on the mainland and in a free zone runs both, which is exactly the kind of overlap one mapped control set removes.

Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Book a demo

See your obligations as one program.

Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.

The team replies within one business day, in English or Arabic.