Data Protection · Regulatory
UAE Data Protection in 2026: What a Company Holding Customer Data Must Do Under the PDPL
Which UAE data protection regime governs your company (PDPL, DIFC or ADGM), what each requires of a business holding customer data, and what failures cost.

In the DIFC, failing to answer a customer's request to see their data carries a maximum fine of USD 100,000, and failing to report a breach to the Commissioner carries USD 50,000.1 In ADGM the breach clock is fixed at 72 hours from the moment you become aware of it.2 Onshore, the federal law reaches processing carried out inside or outside the country, so an offshore server does not put the data beyond its reach.3
Which of those numbers is yours is decided by one thing: where the entity holding the data is registered. Outside the financial free zones, the governing statute is Federal Decree-Law No. 45 of 2021, the UAE Personal Data Protection Law, in force since 2 January 2022.3 A company incorporated in the DIFC answers to DIFC Law No. 5 of 2020 instead, wherever the processing physically happens.4 ADGM runs a third regime with its own regulator and its own deadlines.2
For a company holding customer data, the practical work is short and specific. Establish which regime governs the entity. Fix the lawful basis for what you already collect. Register and keep records where that is required. Appoint a Data Protection Officer if your processing triggers it. Know your breach clock before you need it. Everything below is that list, with the source for each obligation.
Which data protection law applies to your company in Dubai?
Start here, because every deadline below changes with the answer.
Onshore, the federal PDPL governs. It applies to the processing of personal data, whether in full or in part through electronic systems, inside or outside the country.3 Consent is the default position: the law prohibits processing personal data without the consent of its owner, except in limited cases where processing is necessary to protect a public interest or to carry out legal procedures and rights.3 The federal regulator is the UAE Data Office, established by Federal Decree-Law No. 44 of 2021 alongside the PDPL itself.3
Inside the DIFC, a different statute applies. DIFC Law No. 5 of 2020, in its consolidated March 2022 version as amended by DIFC Law No. 2 of 2022, commenced on 1 July 2020 and replaced the older DIFC data protection law of 2007.4 Its reach follows incorporation, not geography: the law applies to processing by a controller or processor incorporated in the DIFC, regardless of whether the processing takes place in the DIFC or not.4
Dubai also has an emirate-level statute of its own, Law No. 26 of 2015 regulating data dissemination and exchange in Dubai, listed by the UAE Government among the emirate's cyber laws and separate from the federal PDPL.5
Governing statute
What triggers it
Regulator
If your group holds a mainland company and a DIFC entity, you are running both columns at once, and a policy written for one does not transfer to the other. This is the point where a reading of the regimes against your actual corporate structure is worth more than a policy template.
Not certain which rulebook governs the entity that holds your customer data?
A licensed UAE specialist can map your entities against the PDPL, DIFC and ADGM regimes and tell you which deadlines are actually yours, before an incident decides it.
Confirm which regime appliesWhat does the UAE PDPL require from a company holding personal data?
Three things are settled on the public record, and they are enough to start.
One. Scope is broad. The law covers processing carried out through electronic systems inside or outside the country.3 A UAE company that routes customer records to a group data centre abroad, or hands support tickets to an offshore team, is still processing under the statute.
Two. Consent is the default. Processing personal data without the consent of its owner is prohibited, save for cases where processing is necessary to protect a public interest or to carry out legal procedures and rights.3 For a business, that puts the burden on the collection points, the sign-up form, the CRM import, the marketing list inherited from an acquisition, rather than on the privacy policy that describes them.
Three. There is a federal regulator to deal with. The UAE Data Office was established by its own decree-law alongside the PDPL.3
There is also a hard line on minors. It is prohibited to collect or use the personal data of children under the age of 13 unless strict conditions are met, including parental consent, an easy way to withdraw it, clear disclosure of the purpose, and no targeted advertising.6 A consumer app with any under-13 users is dealing with a design requirement, not a disclosure.
Two things this article does not state, because no official source confirmed them for this draft: the PDPL penalty figures, and the exact triggers for appointing a Data Protection Officer under the federal law. Both are worth confirming with the Data Office guidance before anyone quotes a number in a board paper.
What a DIFC company has to file, and who it has to appoint
DIFC obligations are unusually specific, which makes them easy to audit and easy to miss.
- 1
Register with the Commissioner
A controller or processor registers by filing a notification of processing operations, kept up to date through amended notifications.
- 2
Keep a written record
A controller maintains a written record, which may be in electronic form, of the processing activities under its responsibility. A processor keeps a record of the processing it carries out for each controller.
- 3
Appoint a DPO where required
Mandatory for DIFC Bodies and for controllers or processors performing High Risk Processing Activities on a systematic or regular basis. The DPO must reside in the UAE, save for the intra-Group exception.
- 4
Assess before high risk processing
A data protection impact assessment is carried out before High Risk Processing Activities begin, not after the product ships.
The registration duty is the one companies discover late. A controller or processor shall register with the Commissioner by filing a notification of processing operations, and shall keep it up to date through amended notifications.7 There is no certificate to obtain and no certification body to pass. The notification, kept current, is the compliance artefact.
The record-keeping duty sits beside it. A controller maintains a written record of the processing activities under its responsibility.7 Failing to maintain it carries a maximum fine of USD 25,000, which is the cheapest of the DIFC bands and the easiest to avoid.1
The DPO duty is narrower but stricter. A DPO shall be appointed by DIFC Bodies and by a controller or processor performing High Risk Processing Activities on a systematic or regular basis.8 And the appointment has a residence condition: the DPO must reside in the UAE, unless the individual is employed within the organisation's Group and performs a similar function for the Group on an international basis.8 For an international group, that exception is the difference between a local hire and a reporting line into an existing group function.
How fast does a data breach have to be reported?
This is where the two free zone regimes visibly diverge, and where a group operating in both is working to two standards on a single incident.
In the DIFC there is no fixed clock. Where a personal data breach compromises a data subject's confidentiality, security or privacy, the controller notifies the Commissioner as soon as practicable in the circumstances.9 Affected customers are told separately, and on their own trigger: when the breach is likely to result in a high risk to the security or rights of a data subject, the controller communicates it to that data subject as soon as practicable.9 Failing to report to the Commissioner carries a maximum fine of USD 50,000.1
In ADGM the standard is numeric. Data controllers notify the Office of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.2
"As soon as practicable" is not a softer version of 72 hours. It is a standard judged after the fact, on what you actually knew and when, which makes the incident log the document that answers it. Deciding who assesses a breach, and who signs the notification, is work to finish while nothing has happened.
How do you answer a customer who asks for their data?
In the DIFC the deadline is fixed. On request, a data subject has the right to obtain from a controller, without charge and within one month of the request, the information the law specifies.10 Where a request is particularly complex, or requests are numerous, the controller may give notice within that first month and extend the period for compliance by a further two months, citing the reasons for the delay.10
The access route itself is regulated too. A controller makes available a minimum of two methods, which must not be onerous, by which a data subject can contact it to exercise these rights, and where it operates a website, at least one free method has to be available there.10
Failing on these rights sits in the top DIFC fine band: a maximum of USD 100,000.1 For a consumer-facing business, that combination, a fixed month, a mandatory contact route and the highest penalty band, is the strongest argument for having a named owner for these requests rather than a shared inbox.
What does getting it wrong cost?
The DIFC publishes maximum fines per failure. They are per contravention and they map directly onto the duties above.
| Failure | DIFC provision | Maximum fine |
|---|---|---|
| Breaching data subject access, rectification or erasure rights | Article 331 | USD 100,0001 |
| Failing to report a personal data breach to the Commissioner | Article 411 | USD 50,0001 |
| Failing to appoint a DPO where required | Articles 16(2) and 16(3)1 | USD 50,0001 |
| Failing to maintain records of processing operations | Article 151 | USD 25,0001 |
| Failing to carry out an impact assessment before High Risk Processing | Article 201 | USD 20,0001 |
ADGM adds a smaller, entirely mechanical cost. Registration is USD 300 and annual renewal is USD 300.11 Miss the renewal within the one-month grace period following the anniversary of incorporation, under Section 24(2) of the Data Protection Regulations 2021, and a fixed monetary penalty of USD 450 is applied automatically.11 Nobody assesses fault. It is a calendar entry that costs money when it is missed.
What changes if the parent company is in the UK, the EU, the US or India?
Most companies reading this are not deciding in isolation. There is a group somewhere else, and its counsel is asking whether the UAE entity is now a separate compliance problem.
Three points hold on the UAE side, whatever the parent's home law says.
- The PDPL follows the processing, not the office. It applies to processing inside or outside the country, so a European or Indian group function handling UAE customer records is inside the statute's scope.3
- DIFC law follows incorporation. A DIFC-incorporated subsidiary is caught by DIFC Law No. 5 of 2020 regardless of where the processing takes place, including on the parent's infrastructure abroad.4
- The DPO residence rule is a group question. The DIFC DPO must reside in the UAE unless the individual sits within the organisation's Group and performs a similar function for the Group internationally.8 Whether your existing group DPO satisfies that exception is worth confirming before you rely on it.
What this article deliberately does not do is state what the law of the parent's country requires. Whether European or UK data protection law reaches your UAE entity is decided by that law, on the entity's own EU-facing or UK-facing activity, and the same applies to US federal and state obligations and to Indian requirements. Those questions are confirmed with an adviser qualified in that jurisdiction. What is settled is that a favourable answer there removes nothing here: the UAE obligations run in parallel, not in the alternative.
The mistakes that turn a compliance gap into a filing
None of these is exotic. Each is avoidable with a map of your entities and a calendar.
- Assuming one policy covers the group. A mainland company and a DIFC entity sit under different statutes with different regulators, and DIFC law follows the place of incorporation rather than the place of processing.4 One policy applied to both leaves one of them uncovered.
- Treating offshore processing as out of scope. The PDPL covers processing inside or outside the country.3 Moving the workload does not move the obligation.
- Skipping the DIFC notification. Registration with the Commissioner is a filing obligation that has to be kept current through amended notifications.7 It is not triggered by a complaint, and it is not satisfied by a privacy policy.
- Reading the DPO rule as optional. It is mandatory for High Risk Processing Activities carried out on a systematic or regular basis, the residence condition is real, and the maximum fine for getting it wrong is USD 50,000.81
- Discovering the breach process during the breach. DIFC asks for notification as soon as practicable, ADGM within 72 hours, and both are judged on what you did from the moment you knew.92
- Letting an ADGM renewal lapse. The USD 450 penalty is applied automatically after the one-month grace period.11 It is the only item on this list that requires no legal judgment at all, and it is still missed.
Where LawyersDubai fits
The obligations above are public, and they reward the company that maps its entities before an incident forces the exercise. Which regime governs each entity. What each one has to file. Who owns a customer request and who signs a breach notification. Those four answers are the compliance programme in practice.
That is where LawyersDubai fits. It is a law consultancy firm, a single confidential point of contact that coordinates access to licensed UAE professionals across the mainland, the DIFC and ADGM, from a first read of which regime applies to a data mapping exercise, to specialist legal advisory when an incident is live. Where the same customer files also carry anti-money laundering and customer due diligence duties, those obligations are read together rather than in separate projects. It does not provide legal advice, and it is not a law firm. It connects you to the professional who does.
Holding customer data across a mainland company and a DIFC or ADGM entity?
Have your entities, your data flows and your filing obligations reviewed by a licensed UAE professional, coordinated for you, before a deadline or an incident sets the timetable.
Speak with a data protection specialistFrequently Asked Questions
Which data protection law applies to my Dubai company, the UAE PDPL or DIFC law?
It follows the place of incorporation. Outside the financial free zones, the federal PDPL applies, Federal Decree-Law No. 45 of 2021. A company incorporated in the DIFC is caught by DIFC Law No. 5 of 2020 regardless of whether the processing takes place in the DIFC or not, and ADGM runs its own Data Protection Regulations 2021. A group with a mainland company and a DIFC entity is running two rulebooks at once, which is a question to settle before an incident rather than during one.
Does the UAE PDPL still apply if our servers and our technical staff sit outside the country?
The law applies to the processing of personal data, whether in full or in part through electronic systems, inside or outside the country. Moving the infrastructure or the engineering team offshore does not move the processing outside the statute. What changes is the practical difficulty of evidencing what you do, not the obligation itself.
Do we have to register with a data protection regulator in the UAE?
In the DIFC, yes. A controller or processor registers with the Commissioner by filing a notification of processing operations, and keeps it up to date through amended notifications. In ADGM there is a registration fee of USD 300 and an annual renewal of USD 300. There is no general certification scheme in either place, so the notification and the renewal are what a regulator will look for, not a certificate.
Do we need to appoint a Data Protection Officer in the DIFC?
A DPO is mandatory for DIFC Bodies and for any controller or processor performing High Risk Processing Activities on a systematic or regular basis. The appointed DPO must reside in the UAE, unless the individual is employed within the organisation's Group and performs a similar function for the Group internationally. Whether your processing is High Risk is assessed on your actual activities, so it is worth confirming before you assume it is not.
How quickly does a data breach have to be reported in the UAE?
It depends on the regime. In the DIFC there is no fixed clock: a breach that compromises a data subject's confidentiality, security or privacy is notified to the Commissioner as soon as practicable in the circumstances, and affected customers are told where the breach is likely to result in a high risk to their security or rights. In ADGM the clock is fixed at not later than 72 hours after becoming aware of the breach. A group operating in both is working to two different standards on the same incident.
How long do we have to answer a customer who asks for their data?
In the DIFC, one month from the request, and without charge. Where the request is particularly complex, or requests are numerous, the controller can extend by a further two months by giving notice within the first month and citing the reasons for the delay. The controller also has to offer at least two non-onerous contact methods for exercising these rights.
What does getting DIFC data protection wrong actually cost?
The DIFC fine schedule sets maximums per failure: USD 100,000 for failing to comply with data subject rights under Article 33, USD 50,000 for failing to report a personal data breach, USD 50,000 for failing to appoint a DPO where required, USD 25,000 for failing to maintain records of processing, and USD 20,000 for failing to carry out an impact assessment before High Risk Processing Activities. In ADGM, missing the annual renewal fee after the one-month grace period triggers an automatic USD 450 penalty.
Our parent company is in the UK or the EU. Does European data protection law still reach the UAE entity?
That is a separate question from the UAE one and it is decided by European law, not by where the subsidiary is registered. It turns on the entity's EU-facing activity, typically offering goods or services to people there or monitoring their behaviour. The UAE analysis does not answer it, and the European analysis does not remove the PDPL or DIFC duties. Confirm the European position with an adviser qualified in that jurisdiction, and treat the two as parallel obligations rather than alternatives.
Can we collect personal data from users under 13 in the UAE?
Not without meeting strict conditions. It is prohibited to collect or use the personal data of children under the age of 13 unless certain strict conditions are fulfilled, including parental consent, an easy way to withdraw it, clear disclosure of the purpose, and no targeted advertising. A consumer product with any under-13 user base should treat this as a design question, not a policy paragraph.
Sources
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022), Schedule 2 maximum fines (Article 33 rights USD 100,000; Article 41 breach reporting USD 50,000; Articles 16(2) and 16(3) DPO USD 50,000; Article 15 records USD 25,000; Article 20 impact assessment USD 20,000), hosted on the UAE Government portal. https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15
-
ADGM, Office of Data Protection, Data breach notifications (notification without undue delay and, where feasible, not later than 72 hours after becoming aware). https://www.adgm.com/operating-in-adgm/office-of-data-protection/data-breach-notifications (as of August 2026) ↩ ↩2 ↩3 ↩4
-
UAE Government (u.ae), Data protection laws (Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, in force 2 January 2022; application to processing inside or outside the country; consent required save for public-interest and legal-procedure exceptions; UAE Data Office established by Federal Decree-Law No. 44 of 2021). https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws (as of August 2026) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022) as amended by DIFC Law No. 2 of 2022 (Article 4 commencement 1 July 2020; Article 1(2) repeal of Law No. 1 of 2007; Article 6(3)(a) application to controllers and processors incorporated in the DIFC regardless of where processing takes place). https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3 ↩4 ↩5
-
UAE Government (u.ae), Cyber laws (Law No. 26 of 2015 Regulating Data Dissemination and Exchange in Dubai). https://u.ae/en/Resources/Cyber-laws (as of August 2026) ↩
-
UAE Government (u.ae), Children's digital safety (prohibition on collecting or using the personal data of children under the age of 13 unless strict conditions are fulfilled, citing Federal Decree-Law No. 26 of 2025 regarding Child Digital Safety alongside the PDPL). https://u.ae/en/information-and-services/social-affairs/children/Childrens-digital-safety (as of August 2026) ↩
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022), Article 14(7) registration by notification of processing operations and Article 15(1) written record of processing activities. https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022), Article 16(2) mandatory DPO for DIFC Bodies and for High Risk Processing Activities carried out on a systematic or regular basis, and Article 16(7) UAE residence requirement with the intra-Group exception. https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3 ↩4
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022), Article 41(1) notification to the Commissioner as soon as practicable in the circumstances and Article 42(1) communication to affected data subjects on high risk. https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3
-
DIFC, Data Protection Law DIFC Law No. 5 of 2020, Consolidated Version (March 2022), Article 33(1) one-month response without charge, Article 33(7) extension of a further two months on notice, and Article 40 minimum of two non-onerous contact methods. https://assets.u.ae/api/public/content/bb94d503629243a7aa548a8cd387ea86?v=df38af26 (as of August 2026) ↩ ↩2 ↩3
-
ADGM, Office of Data Protection, Fee sections (registration USD 300, annual renewal USD 300, automatic fixed monetary penalty of USD 450 where the statutory renewal fee is not paid within the one-month grace period following the anniversary of incorporation under Section 24(2) of the Data Protection Regulations 2021). https://www.adgm.com/operating-in-adgm/office-of-data-protection/fee-sections (as of August 2026) ↩ ↩2 ↩3
Related
LawyersDubai is a Dubai-based law consultancy firm. We coordinate legal services through licensed professionals across the UAE; we do not practise law or provide legal advice. This article is general information and does not constitute legal advice.


