What Could a Cyberattack Actually Cost Your Business?
The cybersecurity risks UAE businesses may be carrying — and five questions that reveal how prepared you really are.
The UAE PDPL Executive Regulations remain outstanding, while the UAE’s federal data governance structure changed in 2026. Here’s what businesses need to know and the cybersecurity measures they should be taking now.
The UAE data protection landscape changed in 2026. The PDPL Executive Regulations remain outstanding, while the UAE Data Office has been brought into the new Artificial Intelligence and Data Authority. Here’s what businesses need to know and what they should be doing now.
The UAE data protection law continues to evolve.
Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data — commonly known as the UAE PDPL — established the federal framework for protecting personal data and came into force on 2 January 2022.
But two developments are particularly important for businesses in 2026.
First, the Executive Regulations contemplated by the UAE PDPL remain outstanding. Second, on 14 June 2026, the UAE approved the establishment of the Artificial Intelligence and Data Authority, bringing together functions previously held by the UAE Data Office, the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, and the Digital Government Sector of the TDRA. The new Authority reports directly to the Cabinet.
That raises an important question for organizations:
With the regulatory structure changing but the PDPL Executive Regulations still outstanding, what applies today — and what should businesses be doing now?
The UAE PDPL is the country's federal framework governing the processing and protection of personal data.
For businesses, personal data can exist across almost every part of the technology environment, including:
This makes data protection more than a legal or policy issue.
Every application, account, database, API or third-party platform processing personal information can also become part of an organization's cybersecurity attack surface.
No. As of 24 September 2026, the Executive Regulations remain outstanding.
Article 28 of Federal Decree-Law No. 45 of 2021 provides for the Council of Ministers to issue the Executive Regulations.
Article 29 is particularly important for businesses because it provides for controllers and processors to regularise their status within six months from the date the Executive Regulations are issued, subject to the possibility of an extension.
The UAE PDPL itself is in force, but the outstanding Executive Regulations are intended to provide important implementation detail.
Businesses should therefore distinguish between the existence of the federal law and the detailed regulatory framework that remains outstanding.
The regulatory landscape itself has also changed.
On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum approved the establishment of the Artificial Intelligence and Data Authority.
The official announcement describes it as the single national body responsible for data, artificial intelligence and digital government in the UAE, reporting directly to the Cabinet.
Importantly for the UAE data protection law, the new Authority brings together functions previously held by three bodies:
The UAE Data Office is therefore no longer operating in its previous standalone institutional structure; its functions have been brought under the new Authority.
The Authority's announced responsibilities include proposing national policies, legislation and strategies, managing and integrating government data, setting standards and guidelines for data and AI management, supporting cybersecurity efforts and government information-security management, and ensuring compliance across federal entities within its mandate.
For businesses following PDPL UAE developments, this is significant because the institutional framework surrounding federal data governance has changed while the PDPL Executive Regulations remain outstanding.
However, the June announcement does not itself issue the PDPL Executive Regulations or establish a new PDPL compliance deadline. Those are separate issues.
The current position can be understood through two developments:
1. The UAE PDPL remains the federal personal data protection law.
Federal Decree-Law No. 45 of 2021 remains in force.
2. The Executive Regulations remain outstanding.
The detailed implementation framework contemplated by Articles 28 and 29 has not yet been issued.
3. The federal data-governance structure has changed.
Functions previously held by the UAE Data Office have been consolidated into the new Artificial Intelligence and Data Authority.
For organizations assessing PDPL UAE requirements, this means regulatory developments should be monitored closely.
It does not, however, mean businesses need to wait before assessing whether the personal data they already hold is adequately protected.
Personal data rarely exists in isolation.
It sits inside applications, databases, cloud environments, endpoints, APIs and third-party platforms.
A weakness in any of those environments can therefore become a data-protection risk.
Consider an organization with documented privacy policies and data-handling procedures.
Its customer portal contains an exploitable vulnerability.
An API exposes more information than intended.
A cloud environment is misconfigured.
Privileged accounts have excessive permissions.
An employee's credentials are compromised.
Or a third-party provider with access to customer information suffers a breach.
In each scenario, the organization may have policies explaining how personal data should be protected while the underlying technical environment leaves that data exposed.
That is why compliance with the UAE data protection law should not be approached as documentation alone.
Policies establish how data should be handled. Cybersecurity controls help determine whether that data is actually protected.
You cannot effectively protect data you cannot identify.
Businesses should understand what personal data enters the organization, why it is collected, where it is stored and how it moves between systems.
That includes information held in primary databases as well as backups, cloud storage, SaaS platforms, employee devices and systems operated by third parties.
The objective is to understand the organization's actual data exposure.
Having security controls does not automatically mean those controls are effective.
Applications, APIs, networks, cloud infrastructure and other systems processing personal information should be assessed for vulnerabilities.
Vulnerability Assessment and Penetration Testing (VAPT) can help identify security weaknesses and determine whether they could be exploited in practice.
Testing should also lead to action.
Critical findings should be prioritised, remediated and retested to verify that the exposure has actually been addressed.
One compromised account should not provide unrestricted access to sensitive information.
Organizations should review authentication controls, user privileges, administrative accounts, inactive accounts and third-party access.
Access should reflect genuine business requirements, with additional controls around privileged users and sensitive systems.
The objective is straightforward:
Only the people and systems that genuinely need access to personal data should have it.
Your organization's data-security exposure does not stop at your own infrastructure.
Cloud providers, SaaS platforms, outsourced service providers, contractors and other technology partners may process or have access to personal information.
Businesses should therefore understand which third parties receive personal data, what they can access, why they require access and how that information is protected.
This becomes particularly important when data moves across multiple systems, providers and jurisdictions.
Cybersecurity cannot be based on the assumption that every attack will be prevented.
Organizations also need the ability to detect suspicious activity, investigate incidents, contain compromised systems and determine what information may have been affected.
Businesses should know:
Who takes responsibility when an incident occurs?
How quickly can suspicious access be identified?
Can compromised accounts or systems be isolated?
Can the organization determine what data was accessed?
Has the incident-response process actually been tested?
A response plan that exists only on paper may reveal serious gaps when a real incident occurs.
The UAE PDPL should not be treated exclusively as a legal, compliance or IT matter.
Senior management should have visibility into the organization's actual data-security posture.
Start with five questions:
If these questions are difficult to answer, the organization may have a visibility problem as much as a compliance problem.
And what you cannot see is difficult to protect.
There are now two developments UAE businesses should be monitoring closely.
The UAE PDPL Executive Regulations remain outstanding, meaning important implementation detail is still to come.
At the same time, the UAE's federal data-governance structure has changed substantially, with the functions of the UAE Data Office brought into the new Artificial Intelligence and Data Authority.
Neither development changes a fundamental cybersecurity reality:
Businesses need to understand where their personal data is and whether the systems protecting it are secure.
Organizations can already take practical steps:
Know what personal data you hold. Understand where it is exposed. Control who can access it. Test the systems protecting it. Address vulnerabilities. Monitor for compromise. And maintain evidence that your controls work.
Because protecting personal data requires more than documentation.
The real test is whether your controls can protect that data when someone actively tries to get to it.
Identify vulnerabilities and security gaps across the applications, APIs, networks, cloud environments and infrastructure protecting your sensitive data.
Speak with a Cybersecurity Expert: Contact ITSEC
Verified: 24 September 2026
Primary sources: UAE Legislation — Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data; UAE Government Media Office — Mohammed bin Rashid approves establishing Artificial Intelligence and Data Authority, 14 June 2026.