UAE flag

UAE

UAE Data Privacy Laws: Federal PDPL, DIFC & ADGM Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202626 min read
UAE Data Privacy Laws: Federal PDPL, DIFC & ADGM Guide (2026)

Frequently Asked Questions

Which UAE data protection law applies to my business?

The answer depends on where your entity is registered. Companies incorporated in mainland UAE fall under the federal PDPL (Federal Decree-Law No. 45 of 2021). Companies registered in the Dubai International Financial Centre follow the DIFC Data Protection Law No. 5 of 2020. Companies in the Abu Dhabi Global Market follow the ADGM Data Protection Regulations 2021. Foreign organizations that process personal data of individuals in the UAE must comply with the federal PDPL regardless of their own location.

Have the UAE PDPL executive regulations been published?

No. As of mid-2026, the formal executive regulations for Federal Decree-Law No. 45 of 2021 have not been published in the UAE Official Gazette as a discrete instrument, despite being originally due approximately six months after the law's passage in 2021. The PDPL itself remains fully in force and enforceable. The UAE Data Office has issued operational guidance in their absence, including a de facto 72-hour breach notification standard. When the regulations are published, organizations will have a further six months to achieve full procedural compliance.

What are the penalties for violating UAE data protection laws?

Penalties vary across the three regimes. The federal PDPL imposes administrative fines of AED 50,000 to AED 5 million (approximately USD 13,600 to USD 1.36 million). The DIFC Data Protection Law imposes violation-specific fines up to USD 100,000 per violation, and data subjects can now sue directly in DIFC Courts under the 2025 amendments. The ADGM Data Protection Regulations carry the region's heaviest fines at up to USD 28 million per offense. Criminal penalties under Federal Decree-Law No. 34 of 2021 on Cybercrime may also apply to unlawful data disclosure.

Can I transfer personal data from a DIFC entity to my mainland UAE office?

Not without safeguards. Mainland UAE does not appear on the DIFC adequacy list. Transferring personal data from a DIFC entity to a mainland UAE entity requires standard contractual clauses (SCCs) published by the DIFC Commissioner, binding corporate rules for intragroup transfers, or another Commissioner-approved mechanism. Since the July 2025 amendments, organizations must also document a formal adequacy assessment before relying on these safeguards. The same applies to ADGM-to-mainland transfers.

What does DIFC Regulation 10 require for AI systems?

Regulation 10, enacted September 2023, requires organizations using autonomous or semi-autonomous AI systems commercially for high-risk processing in the DIFC to: appoint an Autonomous Systems Officer (ASO) with competencies equivalent to a Data Protection Officer; obtain certification under a scheme established by the DIFC Commissioner of Data Protection; ensure the system processes personal data solely for human-defined or human-approved purposes; and conduct regular DPIAs for AI processing activities. The DIFC launched the Regulation 10 Accelerator program as a regulatory sandbox for testing AI systems before commercial deployment.

What does the UAE Child Digital Safety Law require for data protection?

Federal Decree-Law No. 26 of 2025, in force from January 1, 2026, with full enforcement from January 2027, prohibits digital platforms from collecting, processing, publishing, or sharing personal data of children under 13 without explicit, documented, and verifiable parental consent. Platforms must apply default high-privacy settings for child users, implement proportionate age verification, restrict access to children's data to authorized personnel, and prohibit behavioral profiling and targeted advertising directed at children. The law applies to both UAE-based platforms and foreign platforms directed at UAE users.

Does UAE health data follow the PDPL or a separate law?

A separate sector-specific law applies to electronic health data on the mainland. Federal Law No. 2 of 2019 on the Use of ICT in Health Fields requires health information to be stored on servers physically in the UAE. Cross-border transfers are prohibited except in ten categories set out in Ministerial Resolution No. 51 of 2021, including overseas treatment, pharmacovigilance, and clinical research. Non-compliance carries fines of AED 500,000 to AED 700,000. The PDPL expressly carves out health data already governed by Federal Law No. 2 of 2019.

What did the ADGM Substantial Public Interest Conditions Rules 2025 change?

The Rules, enacted September 9, 2025, introduce two new conditions for processing special-category personal data without consent under the substantial public interest ground in the ADGM. First, processing for insurance and reinsurance purposes, including advice, underwriting, claims handling, and fraud investigation. Second, processing for safeguarding children under 18 and vulnerable adults who are at risk of harm and unable to protect themselves. Both conditions require the processing to be of special-category personal data and to be necessary for substantial public interest reasons.

What is the data breach notification deadline in the UAE?

The DIFC Data Protection Law and the ADGM Data Protection Regulations both require notification to the relevant regulator within 72 hours of becoming aware of a personal data breach. The federal PDPL requires notification without undue delay; the UAE Data Office has communicated that 72 hours is the operative standard, though the formal executive regulations specifying this deadline have not yet been published. Organizations should apply 72 hours as the working standard across all three regimes.

Updates

Full expansion and refresh: added DIFC Regulation 10 (AI/autonomous systems), ADGM Substantial Public Interest Conditions Rules 2025, Federal Decree-Law No. 26/2025 on Child Digital Safety, updated PDPL executive regulations status, expanded cross-border transfer analysis, healthcare data localization, and recent developments section.

Initial publication covering federal PDPL, DIFC Law No. 5/2020, and ADGM Data Protection Regulations 2021.

Sources and References

  1. Federal Decree-Law No. 45 of 2021 on Protection of Personal Data — UAE Legislation Portal(uaelegislation.gov.ae).gov
  2. Data Protection Laws — Official UAE Government Platform(u.ae).gov
  3. DIFC Data Protection Law No. 5 of 2020 — Dubai International Financial Centre(difc.com).gov
  4. Regulation 10 — Processing Personal Data through Autonomous and Semi-Autonomous Systems — DIFC(difc.com).gov
  5. Data Export and Sharing — DIFC Commissioner of Data Protection(difc.com).gov
  6. ADGM Office of Data Protection — Guidance and Regulations(adgm.com).gov
  7. ADGM Data Protection Regulations 2021 — Full Text(assets.adgm.com).gov
  8. ADGM Consultation Paper No. 6 of 2025 — Substantial Public Interest Conditions Rules(assets.adgm.com).gov
  9. Federal Law No. 2 of 2019 on Use of ICT in Health Fields — UAE Legislation Portal(uaelegislation.gov.ae).gov
  10. Federal Decree-Law No. 26 of 2025 on Child Digital Safety — UAE Legislation Portal(uaelegislation.gov.ae).gov
  11. United Arab Emirates Cross-Border Data Flows — U.S. International Trade Administration(trade.gov).gov
  12. DIFC Enacts Amendments to Data Protection Law — Bird & Bird(twobirds.com)
  13. UAE Issues Landmark Child Digital Safety Law — Clyde & Co(clydeco.com)
  14. ADGM Implements New Substantial Public Interest Rules 2025 — Clyde & Co(clydeco.com)
  15. AI Regulation in the DIFC: Autonomous and Semi-Autonomous Systems — Mayer Brown(mayerbrown.com)
  16. Data Protection and Privacy 2026: UAE — Chambers Global Practice Guides(practiceguides.chambers.com)
  17. DIFC Data Protection Law Update Increases Claims Risk — Pinsent Masons(pinsentmasons.com)
  18. Data Protection and Privacy Landscape in the Middle East — Clyde & Co(clydeco.com)
Share: