Country:阿联酋 · Data Privacy
United Arab Emirates · Data Privacy
The UAE federal Personal Data Protection Law (PDPL 45/2021, effective 2023-01-02) establishes a GDPR-like framework — lawful basis, purpose limitation, data-subject rights and cross-border rules — supervised by the new UAE Data Office. The two common-law free zones DIFC (DPL 2020) and ADGM (DPPL 2021) run stricter, GDPR-aligned independent regimes. Processing needs consent or contract as lawful basis; cross-border transfer needs adequacy or standard contractual clauses. This creates dual obligations with China's PIPL.
Key points
- Federal PDPL 45/2021 (effective 2023-01): consent, purpose limitation, minimisation, subject rights.
- Supervision: UAE Data Office (federal); DIFC DPL, ADGM DPPL (free-zone, stricter).
- Cross-border: receiving country must have adequate protection or sign SCCs.
- Duties: lawful basis, Data Processing Agreement (DPA), breach notification, DPIA for high-risk.
- Penalty: fines and suspended processing; serious cases liable.
- China data-export duty (pkulaw-verified 2026-07): transferring data back to China requires one of security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, 2025-10-14); 2024–2025 relaxation: the 'Provisions on Promoting and Regulating Cross-Border Data Flows' (Order 16) and 'Network Data Security Management Regulation' (State Council Order 790) exempt some scenarios.
Procedure
- Data mapping; distinguish federal and free-zone applicable law.
- Establish lawful basis; obtain consent or sign DPA.
- Assess adequacy or SCC applicability before cross-border transfer.
- Build breach response and subject-rights mechanism.
- DPIA for high-risk processing.
Hard requirements
- Lawful basis; DPA; cross-border compliance; breach notification.
Costs
Compliance system build; possible certification.⏱ ⏱ Timeline:Framework build weeks; ongoing compliance.⚠ Common risks
- DIFC/ADGM entity misapplies federal law → non-compliance.
- Cross-border without SCC compounds with PIPL obligation.
- Unnotified breach enlarges liability.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese-invested entities in the UAE (federal or DIFC/ADGM free zone) processing personal data, or transferring it back to China (governed by federal PDPL 45/2021 and free-zone DIFC DPL/ADGM DPPL, supervised by the UAE Data Office).
Prerequisites
- Distinguish federal vs free-zone law (DIFC/ADGM stricter).
- Clarify lawful basis and Data Processing Agreement (DPA).
- Reserve compliance-system and assessment budget.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data mapping and applicable-law split Map processing activities; determine whether the entity is in the federal zone or DIFC/ADGM and apply the corresponding law. | Legal | 2 weeks | Internal | Data inventory, applicable-law matrix | Free-zone regimes closer to GDPR Penalty:Fine and suspended processing |
| 2 | Establish lawful basis and sign DPA Per PDPL, obtain consent or contract as lawful basis; sign a DPA with processors. | Legal | 1–2 weeks | Internal | Privacy policy, DPA | Purpose limitation, minimisation Penalty:Same as step 1 |
| 3 | Cross-border assessment and SCC Before transfer, assess receiving-country adequacy; if none, sign SCCs and link PIPL export requirements. | Legal | 3–6 weeks | Internal / lawyer | Adequacy assessment, SCC, PIPL export docs | China not on adequacy list Penalty:No SCC → violation (compounds with PIPL) |
| 4 | Breach response and subject-rights Build breach-notification mechanism and access/correction/deletion/portability response flows. | DPO / IT | Ongoing | Internal | Breach plan, DSAR flow | Must be recorded Penalty:Unnotified or refused response → penalty |
| 5 | DPIA for high-risk processing Conduct DPIA for high-risk or large-scale sensitive processing. | Compliance / IT | 2–4 weeks | Internal | DPIA report | Per PDPL Penalty:No DPIA → penalty |
| 6 | Free-zone entities need extra compliance DIFC and ADGM entities must register with the relevant office and pass annual review; cross-border or sensitive processing may need permission. | Legal | Ongoing (annual review) | Registration and fee | Free-zone DP registration | Misapplying federal law → non-compliance Penalty:Free-zone independent penalty |
| 7 | Ongoing compliance and annual review Periodically review policies, update and train. | Compliance | Annual | Internal | Annual audit | UAE Data Office routine Penalty:Persistent violation accumulates |
✅ Self-check list
⚠ Common pitfalls
DIFC/ADGM entity misapplies federal law影响:Non-compliance penalty.规避:Apply the law by entity location.
Cross-border without SCC影响:Violation (compounds with PIPL).规避:Sign SCCs.
China-bound transfer ignores PIPL export影响:Dual violation.规避:Handle China-side mechanism in parallel.
High-risk processing without DPIA影响:Fined.规避:Conduct DPIA upfront.
Free zone not annually reviewed/registered影响:Independent penalty.规避:Complete registration/review on time.
Unnotified breach影响:Aggravated liability.规避:Set auto-escalation reporting.
📅 Ongoing post-incorporation obligations
- Free-zone registration and annual maintenance (if applicable).
- Breach notification and subject-rights response.
- DPIA updates (high-risk).
- China-bound PIPL export mechanism kept valid.
- Annual review and training.
🔗 Official portals
📎 Source:UAE Personal Data Protection Law (PDPL, Federal Decree-Law 45/2021); UAE Data Office; DIFC DPL / ADGM DPPL; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.