UAE PDPL in 2026: The Executive Regulations Still Aren’t Issued. Here’s What Applies Today

The UAE PDPL Executive Regulations remain outstanding, while the UAE’s federal data governance structure changed in 2026. Here’s what businesses need to know and the cybersecurity measures they should be taking now.

The UAE data protection landscape changed in 2026. The PDPL Executive Regulations remain outstanding, while the UAE Data Office has been brought into the new Artificial Intelligence and Data Authority. Here’s what businesses need to know and what they should be doing now.

The UAE data protection law continues to evolve.

Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data — commonly known as the UAE PDPL — established the federal framework for protecting personal data and came into force on 2 January 2022.

But two developments are particularly important for businesses in 2026.

First, the Executive Regulations contemplated by the UAE PDPL remain outstanding. Second, on 14 June 2026, the UAE approved the establishment of the Artificial Intelligence and Data Authority, bringing together functions previously held by the UAE Data Office, the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, and the Digital Government Sector of the TDRA. The new Authority reports directly to the Cabinet.

That raises an important question for organizations:

With the regulatory structure changing but the PDPL Executive Regulations still outstanding, what applies today — and what should businesses be doing now?

What Is the UAE PDPL?

The UAE PDPL is the country's federal framework governing the processing and protection of personal data.

For businesses, personal data can exist across almost every part of the technology environment, including:

  • CRM and customer-management platforms
  • HR and employee systems
  • Websites and customer portals
  • Mobile applications
  • Cloud environments
  • Databases and backups
  • APIs and connected applications
  • Email and collaboration platforms
  • Third-party service providers

This makes data protection more than a legal or policy issue.

Every application, account, database, API or third-party platform processing personal information can also become part of an organization's cybersecurity attack surface.

Have the UAE PDPL Executive Regulations Been Issued?

No. As of 24 September 2026, the Executive Regulations remain outstanding.

Article 28 of Federal Decree-Law No. 45 of 2021 provides for the Council of Ministers to issue the Executive Regulations.

Article 29 is particularly important for businesses because it provides for controllers and processors to regularise their status within six months from the date the Executive Regulations are issued, subject to the possibility of an extension.

The UAE PDPL itself is in force, but the outstanding Executive Regulations are intended to provide important implementation detail.

Businesses should therefore distinguish between the existence of the federal law and the detailed regulatory framework that remains outstanding.

What Changed on 14 June 2026?

The regulatory landscape itself has also changed.

On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum approved the establishment of the Artificial Intelligence and Data Authority.

The official announcement describes it as the single national body responsible for data, artificial intelligence and digital government in the UAE, reporting directly to the Cabinet.

Importantly for the UAE data protection law, the new Authority brings together functions previously held by three bodies:

  • The UAE Data Office
  • The Office of Artificial Intelligence, Digital Economy and Remote Work Applications
  • The Digital Government Sector at the Telecommunications and Digital Government Regulatory Authority

The UAE Data Office is therefore no longer operating in its previous standalone institutional structure; its functions have been brought under the new Authority.

The Authority's announced responsibilities include proposing national policies, legislation and strategies, managing and integrating government data, setting standards and guidelines for data and AI management, supporting cybersecurity efforts and government information-security management, and ensuring compliance across federal entities within its mandate.

For businesses following PDPL UAE developments, this is significant because the institutional framework surrounding federal data governance has changed while the PDPL Executive Regulations remain outstanding.

However, the June announcement does not itself issue the PDPL Executive Regulations or establish a new PDPL compliance deadline. Those are separate issues.

What Does This Mean for Businesses Today?

The current position can be understood through two developments:

1. The UAE PDPL remains the federal personal data protection law.

Federal Decree-Law No. 45 of 2021 remains in force.

2. The Executive Regulations remain outstanding.

The detailed implementation framework contemplated by Articles 28 and 29 has not yet been issued.

3. The federal data-governance structure has changed.

Functions previously held by the UAE Data Office have been consolidated into the new Artificial Intelligence and Data Authority.

For organizations assessing PDPL UAE requirements, this means regulatory developments should be monitored closely.

It does not, however, mean businesses need to wait before assessing whether the personal data they already hold is adequately protected.

Why the UAE Data Protection Law Is Also a Cybersecurity Issue

Personal data rarely exists in isolation.

It sits inside applications, databases, cloud environments, endpoints, APIs and third-party platforms.

A weakness in any of those environments can therefore become a data-protection risk.

Consider an organization with documented privacy policies and data-handling procedures.

Its customer portal contains an exploitable vulnerability.

An API exposes more information than intended.

A cloud environment is misconfigured.

Privileged accounts have excessive permissions.

An employee's credentials are compromised.

Or a third-party provider with access to customer information suffers a breach.

In each scenario, the organization may have policies explaining how personal data should be protected while the underlying technical environment leaves that data exposed.

That is why compliance with the UAE data protection law should not be approached as documentation alone.

Policies establish how data should be handled. Cybersecurity controls help determine whether that data is actually protected.

Five Areas UAE Businesses Should Review Now

1. Know What Personal Data You Hold

You cannot effectively protect data you cannot identify.

Businesses should understand what personal data enters the organization, why it is collected, where it is stored and how it moves between systems.

That includes information held in primary databases as well as backups, cloud storage, SaaS platforms, employee devices and systems operated by third parties.

The objective is to understand the organization's actual data exposure.

2. Test the Systems Protecting Personal Data

Having security controls does not automatically mean those controls are effective.

Applications, APIs, networks, cloud infrastructure and other systems processing personal information should be assessed for vulnerabilities.

Vulnerability Assessment and Penetration Testing (VAPT) can help identify security weaknesses and determine whether they could be exploited in practice.

Testing should also lead to action.

Critical findings should be prioritised, remediated and retested to verify that the exposure has actually been addressed.

3. Control Access to Sensitive Data

One compromised account should not provide unrestricted access to sensitive information.

Organizations should review authentication controls, user privileges, administrative accounts, inactive accounts and third-party access.

Access should reflect genuine business requirements, with additional controls around privileged users and sensitive systems.

The objective is straightforward:

Only the people and systems that genuinely need access to personal data should have it.

4. Understand Third-Party Exposure

Your organization's data-security exposure does not stop at your own infrastructure.

Cloud providers, SaaS platforms, outsourced service providers, contractors and other technology partners may process or have access to personal information.

Businesses should therefore understand which third parties receive personal data, what they can access, why they require access and how that information is protected.

This becomes particularly important when data moves across multiple systems, providers and jurisdictions.

5. Prepare for a Data Breach Before One Happens

Cybersecurity cannot be based on the assumption that every attack will be prevented.

Organizations also need the ability to detect suspicious activity, investigate incidents, contain compromised systems and determine what information may have been affected.

Businesses should know:

Who takes responsibility when an incident occurs?

How quickly can suspicious access be identified?

Can compromised accounts or systems be isolated?

Can the organization determine what data was accessed?

Has the incident-response process actually been tested?

A response plan that exists only on paper may reveal serious gaps when a real incident occurs.

Five Questions Business Leaders Should Be Asking

The UAE PDPL should not be treated exclusively as a legal, compliance or IT matter.

Senior management should have visibility into the organization's actual data-security posture.

Start with five questions:

  1. Do we know what personal data we hold and where it is stored?
  2. When were the systems protecting that data last independently security tested?
  3. Who — internally and externally — can access our most sensitive information?
  4. Would we detect unauthorized access quickly enough to contain it?
  5. Could we demonstrate that our security controls are actually working?

If these questions are difficult to answer, the organization may have a visibility problem as much as a compliance problem.

And what you cannot see is difficult to protect.

Don't Wait for the Executive Regulations to Find Your Security Gaps

There are now two developments UAE businesses should be monitoring closely.

The UAE PDPL Executive Regulations remain outstanding, meaning important implementation detail is still to come.

At the same time, the UAE's federal data-governance structure has changed substantially, with the functions of the UAE Data Office brought into the new Artificial Intelligence and Data Authority.

Neither development changes a fundamental cybersecurity reality:

Businesses need to understand where their personal data is and whether the systems protecting it are secure.

Organizations can already take practical steps:

Know what personal data you hold. Understand where it is exposed. Control who can access it. Test the systems protecting it. Address vulnerabilities. Monitor for compromise. And maintain evidence that your controls work.

Because protecting personal data requires more than documentation.

The real test is whether your controls can protect that data when someone actively tries to get to it.

How Secure Is the Personal Data Your Business Holds?

Identify vulnerabilities and security gaps across the applications, APIs, networks, cloud environments and infrastructure protecting your sensitive data.

Speak with a Cybersecurity Expert: Contact ITSEC

Verified: 24 September 2026

Primary sources: UAE Legislation — Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data; UAE Government Media Office — Mohammed bin Rashid approves establishing Artificial Intelligence and Data Authority, 14 June 2026.

ITSEC UAE cybersecurity coverage map

Ready to Secure Your Digital Assets?

Get a comprehensive security assessment from our expert team. Protecting businesses since 2011.

Consult Cyber Experts
NDA Protected
24hr Response
Global Coverage
×

ITSEC Security Agent

AI-Powered • 24/7 Active

👋 Welcome to ITSEC – UAE's first AI-augmented cybersecurity firm.

I'm your AI Security Agent. How can I assist you with your cybersecurity needs today?
ITSEC AI
Secured by ITSEC AI • ISO 27001 Certified