Country:阿联酋 · Data Privacy
Medium confidenceUpdated 2026-07-15Handbook

United Arab Emirates · Data Privacy

The UAE federal Personal Data Protection Law (PDPL 45/2021, effective 2023-01-02) establishes a GDPR-like framework — lawful basis, purpose limitation, data-subject rights and cross-border rules — supervised by the new UAE Data Office. The two common-law free zones DIFC (DPL 2020) and ADGM (DPPL 2021) run stricter, GDPR-aligned independent regimes. Processing needs consent or contract as lawful basis; cross-border transfer needs adequacy or standard contractual clauses. This creates dual obligations with China's PIPL.

Key points

Procedure

  1. Data mapping; distinguish federal and free-zone applicable law.
  2. Establish lawful basis; obtain consent or sign DPA.
  3. Assess adequacy or SCC applicability before cross-border transfer.
  4. Build breach response and subject-rights mechanism.
  5. DPIA for high-risk processing.

Hard requirements

Costs

Compliance system build; possible certification.⏱ ⏱ Timeline:Framework build weeks; ongoing compliance.

⚠ Common risks

  • DIFC/ADGM entity misapplies federal law → non-compliance.
  • Cross-border without SCC compounds with PIPL obligation.
  • Unnotified breach enlarges liability.
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese-invested entities in the UAE (federal or DIFC/ADGM free zone) processing personal data, or transferring it back to China (governed by federal PDPL 45/2021 and free-zone DIFC DPL/ADGM DPPL, supervised by the UAE Data Office).

Prerequisites

  • Distinguish federal vs free-zone law (DIFC/ADGM stricter).
  • Clarify lawful basis and Data Processing Agreement (DPA).
  • Reserve compliance-system and assessment budget.
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data mapping and applicable-law split
Map processing activities; determine whether the entity is in the federal zone or DIFC/ADGM and apply the corresponding law.
Legal2 weeksInternalData inventory, applicable-law matrixFree-zone regimes closer to GDPR
Penalty:Fine and suspended processing
2Establish lawful basis and sign DPA
Per PDPL, obtain consent or contract as lawful basis; sign a DPA with processors.
Legal1–2 weeksInternalPrivacy policy, DPAPurpose limitation, minimisation
Penalty:Same as step 1
3Cross-border assessment and SCC
Before transfer, assess receiving-country adequacy; if none, sign SCCs and link PIPL export requirements.
Legal3–6 weeksInternal / lawyerAdequacy assessment, SCC, PIPL export docsChina not on adequacy list
Penalty:No SCC → violation (compounds with PIPL)
4Breach response and subject-rights
Build breach-notification mechanism and access/correction/deletion/portability response flows.
DPO / ITOngoingInternalBreach plan, DSAR flowMust be recorded
Penalty:Unnotified or refused response → penalty
5DPIA for high-risk processing
Conduct DPIA for high-risk or large-scale sensitive processing.
Compliance / IT2–4 weeksInternalDPIA reportPer PDPL
Penalty:No DPIA → penalty
6Free-zone entities need extra compliance
DIFC and ADGM entities must register with the relevant office and pass annual review; cross-border or sensitive processing may need permission.
LegalOngoing (annual review)Registration and feeFree-zone DP registrationMisapplying federal law → non-compliance
Penalty:Free-zone independent penalty
7Ongoing compliance and annual review
Periodically review policies, update and train.
ComplianceAnnualInternalAnnual auditUAE Data Office routine
Penalty:Persistent violation accumulates

✅ Self-check list

⚠ Common pitfalls

DIFC/ADGM entity misapplies federal law影响:Non-compliance penalty.规避:Apply the law by entity location.
Cross-border without SCC影响:Violation (compounds with PIPL).规避:Sign SCCs.
China-bound transfer ignores PIPL export影响:Dual violation.规避:Handle China-side mechanism in parallel.
High-risk processing without DPIA影响:Fined.规避:Conduct DPIA upfront.
Free zone not annually reviewed/registered影响:Independent penalty.规避:Complete registration/review on time.
Unnotified breach影响:Aggravated liability.规避:Set auto-escalation reporting.

📅 Ongoing post-incorporation obligations

  • Free-zone registration and annual maintenance (if applicable).
  • Breach notification and subject-rights response.
  • DPIA updates (high-risk).
  • China-bound PIPL export mechanism kept valid.
  • Annual review and training.

🔗 Official portals

📎 Source:UAE Personal Data Protection Law (PDPL, Federal Decree-Law 45/2021); UAE Data Office; DIFC DPL / ADGM DPPL; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.