REGULATORY UPDATE

UAE PDPL Executive Regulations — Current Status, and How to Prepare

The Executive Regulations to Federal Decree-Law No. 45 of 2021 have not yet been issued. Here's what the law already requires, what is still to come, and what to do in the next 90 days.

Talk to ITSEC
Now
Time to Start Preparing
Since 2011
UAE Compliance Experience
45+
PDPL Audits Completed
6 months
To Comply Once Issued (Art. 29)
Regulatory Update

The UAE PDPL Executive Regulations have not yet been issued, but the Decree-Law already sets the core rules.

Federal Decree-Law No. 45 of 2021 leaves several details to Executive Regulations, which have not yet been issued: none are listed on the UAE legislation portal (checked 23 September 2026). Once they are, controllers and processors have six months to comply (Article 29). Here's what the Decree-Law already says, who it applies to, and how to prepare.

Status

Not yet issued

No Executive Regulations are listed on the UAE legislation portal (checked 23 September 2026).

Applies To

UAE, with exclusions

Article 2(2) excludes government data, health and banking data under their own laws, and free zones with their own data law, such as DIFC and ADGM.

Grace Period

6 months after issuance

Article 29: controllers and processors must comply within six months of the Executive Regulations being issued. The Cabinet may extend this period.

Regulator

UAE Data Office

Established by Federal Decree-Law No. 44 of 2021.

Section 01 · What Applies Now

Five areas to prepare, and what the Decree-Law already says

The Decree-Law sets the principles and leaves some details to the Executive Regulations. Until they are issued, this is what the law already requires, and where more detail is still to come:

  • Document the lawful basis for each processing activity Under Article 4, processing needs consent or one of the listed exceptions, such as performing a contract, meeting a legal obligation or protecting the data subject's interests. The PDPL does not include a legitimate-interest basis.
  • Get data subject request workflows ready Build workflows to handle requests from individuals about their data now, so they can adapt to any timelines the Executive Regulations set.
  • Check your cross-border transfers Articles 22 and 23 allow transfers outside the UAE to countries with an adequate level of protection, and in other listed cases such as under a contract or with explicit consent. Detailed controls are left to the Executive Regulations (Article 23(2)).
  • Prepare to notify breaches Breaches must be notified to the UAE Data Office, and to affected individuals where the breach would prejudice the privacy, confidentiality or security of their data (Article 9). The deadline will be set by the Executive Regulations, so have an incident response plan ready.
  • Check whether you need a DPO Article 10 already requires a Data Protection Officer where processing poses a high risk because of new technology or data volume, involves systematic assessment of sensitive data including profiling, or covers a large volume of sensitive data. The DPO must have sufficient skills and knowledge.
Section 02 · Who Must Comply

If you process UAE personal data, this applies to you

The PDPL applies to controllers and processors in the UAE, and to those abroad that process personal data of people in the UAE (Article 2(1)). Article 2(2) excludes government data, security and judicial authorities, health data and banking or credit data governed by their own legislation, and free zones with their own data protection law.

Free zones: DIFC firms are covered by the DIFC Data Protection Law 2020 and ADGM firms by the ADGM Data Protection Regulations 2021. If your group has both onshore and free-zone entities, map which law applies to each.

Section 03 · A 90-Day Compliance Sprint

A pragmatic plan for the next quarter

Don't treat this as a one-shot project. Treat it as a programme. Here's the sequence we run with ITSEC clients:

Days 1 — 14

Data discovery & mapping

Inventory every system that touches personal data. Classify by category (basic, sensitive, biometric, financial). Map data flows in and out of the organisation.

Days 15 — 30

Gap assessment against the Decree-Law

Compare current controls against the Decree-Law's requirements, and against the Executive Regulations once issued. Output: a prioritised remediation list with risk scores.

Days 31 — 60

Policy & control implementation

Records of processing register, consent management, data subject request workflows, breach response runbook, cross-border transfer safeguards, DPO appointment if applicable.

Days 61 — 90

Validation, training, audit-readiness

Tabletop exercises on breach response. Staff training. Mock audit. Documented evidence package for any future Data Office inquiry.

Section 04 · Penalties & Enforcement

What non-compliance can cost

Article 26 leaves violations and administrative penalties to a Cabinet decision. No such decision appears on the UAE legislation portal (checked 23 September 2026), so there are no official fine amounts yet. The consequences fall into three areas:

Administrative

Administrative penalties, to be set by Cabinet decision under Article 26.

Operational

Cost and disruption of changing systems and processes after a breach or complaint.

Reputational

Loss of customer trust and knock-on impact on partner due-diligence checks.

Free Consultation

Get a PDPL gap assessment

ITSEC has supported UAE compliance programmes since 2011 — banks, healthcare, FinTech, telco, SaaS.

Book Free Assessment →
Frequently Asked

PDPL Executive Regulations — Questions, Answered

What UAE businesses ask about the PDPL Executive Regulations: their status, who is affected, timelines and penalties.

01 What is the status of the UAE PDPL Executive Regulations?
The Executive Regulations to Federal Decree-Law No. 45 of 2021 have not yet been issued: none are listed on the UAE legislation portal (checked 23 September 2026). Under Article 29, controllers and processors will have six months from their issuance to comply, and the Cabinet may extend this. ITSEC recommends building your programme against the Decree-Law's obligations now.
02 Who must comply with the PDPL?
Controllers and processors in the UAE, and those abroad that process personal data of people in the UAE. Article 2(2) excludes government data, security and judicial authorities, health and banking or credit data governed by their own legislation, and free zones with their own data protection law.
03 Do DIFC and ADGM firms need to comply with the PDPL?
DIFC and ADGM firms operate under their own data protection laws: the DIFC Data Protection Law 2020 and the ADGM Data Protection Regulations 2021. The PDPL excludes free zones with their own data protection law. If your group spans onshore and free-zone entities, map which law applies to each.
04 What will the Executive Regulations cover?
The Decree-Law leaves specific points to them, including the breach-notification period (Article 9), controls on transfers outside the UAE (Article 23(2)) and exemption standards (Article 3). Their full content will only be known once they are issued.
05 Is a Data Protection Officer (DPO) mandatory?
Article 10 requires a DPO in three cases: high-risk processing because of new technology or data volume, systematic assessment of sensitive data including profiling, or processing a large volume of sensitive data. The DPO must have sufficient skills and knowledge. More detail may follow in the Executive Regulations. ITSEC offers DPO-as-a-Service.
06 What penalties apply?
Article 26 leaves violations and administrative penalties to a Cabinet decision. No such decision appears on the UAE legislation portal (checked 23 September 2026), so there are no official fine amounts yet. Beyond penalties, a breach carries reputational and commercial costs, including loss of customer trust and tougher partner due-diligence reviews.
07 How long does PDPL compliance typically take to implement?
A pragmatic ITSEC-tested plan runs 90 days: 2 weeks for data discovery and mapping, 2 weeks for gap assessment against the Decree-Law, 4 weeks for policy and control implementation (records of processing register, consent management, breach response runbooks, DPO appointment), and 4 weeks for validation, staff training, and audit readiness. Complex enterprises with legacy systems may need 4-6 months; SMEs with cleaner data architectures can compress to 60 days.