UAE PDPL Executive Regulations — Current Status, and How to Prepare
The Executive Regulations to Federal Decree-Law No. 45 of 2021 have not yet been issued. Here's what the law already requires, what is still to come, and what to do in the next 90 days.
The UAE PDPL Executive Regulations have not yet been issued, but the Decree-Law already sets the core rules.
Federal Decree-Law No. 45 of 2021 leaves several details to Executive Regulations, which have not yet been issued: none are listed on the UAE legislation portal (checked 23 September 2026). Once they are, controllers and processors have six months to comply (Article 29). Here's what the Decree-Law already says, who it applies to, and how to prepare.
Not yet issued
No Executive Regulations are listed on the UAE legislation portal (checked 23 September 2026).
UAE, with exclusions
Article 2(2) excludes government data, health and banking data under their own laws, and free zones with their own data law, such as DIFC and ADGM.
6 months after issuance
Article 29: controllers and processors must comply within six months of the Executive Regulations being issued. The Cabinet may extend this period.
UAE Data Office
Established by Federal Decree-Law No. 44 of 2021.
Five areas to prepare, and what the Decree-Law already says
The Decree-Law sets the principles and leaves some details to the Executive Regulations. Until they are issued, this is what the law already requires, and where more detail is still to come:
- Document the lawful basis for each processing activity Under Article 4, processing needs consent or one of the listed exceptions, such as performing a contract, meeting a legal obligation or protecting the data subject's interests. The PDPL does not include a legitimate-interest basis.
- Get data subject request workflows ready Build workflows to handle requests from individuals about their data now, so they can adapt to any timelines the Executive Regulations set.
- Check your cross-border transfers Articles 22 and 23 allow transfers outside the UAE to countries with an adequate level of protection, and in other listed cases such as under a contract or with explicit consent. Detailed controls are left to the Executive Regulations (Article 23(2)).
- Prepare to notify breaches Breaches must be notified to the UAE Data Office, and to affected individuals where the breach would prejudice the privacy, confidentiality or security of their data (Article 9). The deadline will be set by the Executive Regulations, so have an incident response plan ready.
- Check whether you need a DPO Article 10 already requires a Data Protection Officer where processing poses a high risk because of new technology or data volume, involves systematic assessment of sensitive data including profiling, or covers a large volume of sensitive data. The DPO must have sufficient skills and knowledge.
If you process UAE personal data, this applies to you
The PDPL applies to controllers and processors in the UAE, and to those abroad that process personal data of people in the UAE (Article 2(1)). Article 2(2) excludes government data, security and judicial authorities, health data and banking or credit data governed by their own legislation, and free zones with their own data protection law.
Free zones: DIFC firms are covered by the DIFC Data Protection Law 2020 and ADGM firms by the ADGM Data Protection Regulations 2021. If your group has both onshore and free-zone entities, map which law applies to each.
A pragmatic plan for the next quarter
Don't treat this as a one-shot project. Treat it as a programme. Here's the sequence we run with ITSEC clients:
Data discovery & mapping
Inventory every system that touches personal data. Classify by category (basic, sensitive, biometric, financial). Map data flows in and out of the organisation.
Gap assessment against the Decree-Law
Compare current controls against the Decree-Law's requirements, and against the Executive Regulations once issued. Output: a prioritised remediation list with risk scores.
Policy & control implementation
Records of processing register, consent management, data subject request workflows, breach response runbook, cross-border transfer safeguards, DPO appointment if applicable.
Validation, training, audit-readiness
Tabletop exercises on breach response. Staff training. Mock audit. Documented evidence package for any future Data Office inquiry.
What non-compliance can cost
Article 26 leaves violations and administrative penalties to a Cabinet decision. No such decision appears on the UAE legislation portal (checked 23 September 2026), so there are no official fine amounts yet. The consequences fall into three areas:
Administrative penalties, to be set by Cabinet decision under Article 26.
Cost and disruption of changing systems and processes after a breach or complaint.
Loss of customer trust and knock-on impact on partner due-diligence checks.
Get a PDPL gap assessment
ITSEC has supported UAE compliance programmes since 2011 — banks, healthcare, FinTech, telco, SaaS.
PDPL Executive Regulations — Questions, Answered
What UAE businesses ask about the PDPL Executive Regulations: their status, who is affected, timelines and penalties.