UAE - Federal
Summary
Law: Federal Decree-Law No. 45 of 2021 regarding the Protection of Personal Data (the Law)
Regulator: UAE Data Office (not yet operational)
Summary: On November 28, 2021, the UAE Cabinet announced that it had enacted Federal Decree-Law No. 45 of 2021 regarding the Protection of Personal Data (PDPL), as issued on September 20, 2021. At the same time, Federal Decree-Law No. 44 of 2021 (Law No. 44/2021) was enacted to provide for the establishment of the UAE Data Office which will serve as the federal data regulator in the UAE, although it is not yet operational.
The PDPL covers the processing of personal data belonging to data subjects within the UAE, regardless of the location of the data controller or data processor. In addition, the PDPL outlines the conditions for consent, several data subject rights, and comprehensive requirements for controllers and processors, such as mandatory breach notification, the appointment of data protection officers, and the implementation of technical and organizational measures to support data security.
The PDPL entered into effect on January 2, 2022, and the Executive Regulations were expected to be issued within six months of the PDPL's date of issuance (March 20, 2022). However, they are yet to be published. Nonetheless, companies must comply with the PDPL within six months of the publication of the Executive Regulations. Notably, the PDPL does not apply to public entities or free zones in the UAE with their own data protection legislation (such as the DIFC and ADGM), nor does it apply to health or credit data governed by existing sectoral legislation. Furthermore, it repeals all laws which conflict with its provisions.