Knowledge centre
UAE PDPL basics: what every business needs to know
Federal Decree-Law No. 45 of 2021 introduced the UAE's first comprehensive personal data protection framework. Here is what it requires, who it affects, and how to approach compliance in practical terms.
What is the UAE PDPL?
The UAE Personal Data Protection Law — Federal Decree-Law No. 45 of 2021, supplemented by its Executive Regulation issued in 2023 — is the first national data protection law in the UAE applying across the private sector. It governs how organisations collect, use, store, disclose and transfer the personal data of individuals.
Personal data under the law means any information that identifies, or could identify, a natural person: names, email addresses, phone numbers, Emirates ID numbers, financial records, health information, biometric data, location data and IP addresses all fall within scope. The law distinguishes between ordinary personal data and a narrower "sensitive" category — health data, genetic data, biometric data, financial information, beliefs and criminal records — which attracts stricter handling obligations.
The law applies to any data controller or processor that operates in the UAE, regardless of where the data subject resides or where data is hosted. If your organisation has a presence in the UAE and processes personal data in connection with that presence, you are in scope.
The core obligations on UAE businesses
Understanding the law starts with five practical obligations that affect day-to-day IT and operations:
1. Lawful basis and consent
You must have a valid legal basis for processing personal data. Consent is one basis, but the law also recognises contract performance, legal obligation, vital interests and legitimate interests. Where you rely on consent, it must be informed, specific and freely given — and individuals must be able to withdraw it. Review every place your business collects data and confirm what basis you are relying on.
2. Data subject rights
Individuals have the right to access their data, correct inaccuracies, request deletion in certain circumstances, object to certain types of processing, and receive a copy of their data in a portable format. Honouring these requests requires knowing where personal data lives across your systems — a data inventory is not optional.
3. Breach notification
If a personal data breach is likely to result in serious harm to individuals, you must notify the UAE Data Office and affected data subjects within 72 hours of becoming aware of the breach. Meeting that window is only realistic if you have detection in place — a business that discovers a breach weeks after it happened through a third party will already be non-compliant on timing. This is where managed cybersecurity and threat detection becomes a direct compliance requirement, not just a security preference.
4. Data Protection Officer
Certain organisations are required to appoint a Data Protection Officer — primarily those that process large volumes of sensitive data or whose core activities require systematic monitoring of individuals at scale. Even where not mandatory, having a named individual responsible for data protection governance is a marker of compliance maturity that regulators and enterprise clients increasingly expect.
5. Cross-border transfers
Transferring personal data outside the UAE is restricted to countries that the UAE Data Office has determined offer an adequate level of protection, or where you have contractual safeguards in place. Cloud services, SaaS platforms and offshore IT support arrangements all need to be reviewed against this requirement.
The IT controls that underpin compliance
PDPL is partly a legal exercise and partly a technical one. Policies and privacy notices matter, but the controls that regulators will examine are the ones built into your IT environment:
- Access controls. Only the people who need access to personal data should have it. Role-based access, reviewed regularly and enforced by policy, is foundational. Privileged access — admin rights to systems holding personal data — should be tightly controlled and logged.
- Multi-factor authentication. Credential theft is the most common route into systems holding personal data. MFA enforced across all accounts accessing personal data materially reduces breach risk.
- Encryption. Personal data at rest on servers, laptops and storage devices, and in transit across networks, should be encrypted. An encrypted laptop that is lost or stolen does not trigger a reportable breach the way an unencrypted one does.
- Audit logging. Who accessed what personal data and when? Audit logs are the evidence trail for both breach investigation and regulatory enquiry. They need to be retained and protected from tampering.
- Endpoint security and monitoring. Ransomware and data-exfiltration attacks targeting organisations with customer and employee records are the most common cause of notifiable breaches. Managed endpoint detection reduces dwell time — the gap between breach and discovery — which directly affects your ability to notify within 72 hours.
- Backup and recovery. Tested, isolated backups limit the damage if personal data is destroyed or encrypted in an attack. They also demonstrate to regulators that you had appropriate technical measures in place.
- Document retention controls. PDPL's storage limitation principle requires you not to keep personal data longer than necessary. A structured document management system with retention schedules and automated deletion workflows makes this manageable at scale.
An IT health check is a practical starting point for understanding where your current environment stands against these requirements before you commission a formal compliance programme.
Common mistakes UAE businesses make
The most frequent compliance gap is not knowing what personal data the business holds or where it lives. Spreadsheets on shared drives, old CRM exports in email, customer records in legacy accounting software that nobody has reviewed in years — these are common. A data inventory exercise is usually the first step a compliance-focused managed IT partner will help you run.
The second common mistake is treating consent as the only lawful basis and then over-relying on vague or bundled consent clauses that would not survive scrutiny. Review your privacy notices, data collection forms and third-party agreements. Where consent is relied upon, it needs to meet the standard the law sets.
Third: treating PDPL as a one-time project. Data protection is an ongoing control environment. Staff change, systems change, new data flows emerge. A compliance posture that was accurate last year may not be accurate today.
Where to start
Most UAE businesses should approach PDPL compliance in three stages: understand (map what personal data you hold, where, and what you do with it), fix (put the technical controls and policies in place that close the gaps), and evidence (document your compliance measures so you can demonstrate them to regulators, clients or partners who ask).
The technical controls — access management, encryption, monitoring, backups, audit logging — sit squarely within the scope of a managed IT service. For the governance layer, Missan's PDPL compliance support brings together the IT controls and the documentation framework that organisations need to demonstrate compliance.
Frequently asked questions
Does UAE PDPL apply to my business if we only store customer data in the UAE?
Yes. Federal Decree-Law No. 45 of 2021 applies to any organisation that processes personal data in the UAE, regardless of where the data subject lives or where the data is stored. If you collect names, email addresses, phone numbers, financial records or employee data in the course of your UAE operations, the law applies to you.
What counts as a "personal data breach" under UAE PDPL?
Any incident that results in the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data. This includes ransomware attacks that encrypt customer records, phishing incidents that expose employee credentials, misconfigured cloud storage that makes files publicly accessible, and insider actions that result in data leaving the business without authorisation.
How can an IT provider help with PDPL compliance?
A managed IT partner contributes on the technical side: deploying endpoint and email security to reduce breach risk, enforcing multi-factor authentication, managing access controls so only the right people reach personal data, setting up monitored backup and encryption, and helping maintain audit trails for evidence of compliance. They work alongside your legal and compliance team — they do not replace legal advice, but the technical controls they put in place are a large portion of what regulators will look at.
Need help with PDPL compliance or data security?
Missan Global has worked with UAE organisations since 2004 on the IT controls, documentation and governance that underpin data protection compliance.