Skip to content

Last updated July 16, 2026

GDPR Compliance in UAE

Logan Jackonis
Logan JackonisHead of Services & Operations, Commenda

A UAE company that sells to or monitors people in the European Union (EU) answers to two data protection regimes at once. The EU’s General Data Protection Regulation (GDPR) reaches across borders, and the UAE’s own Personal Data Protection Law (PDPL) layers local rules on top. The verdict up front: yes, GDPR can apply to UAE businesses, and UAE law adds a second set of obligations.

This matters because the fines are steep and EU trade ties run deep. GDPR became applicable on 25 May 2018 across every EU Member State, per the official GDPR text on EUR-Lex. This guide covers GDPR compliance in UAE, the PDPL, the DIFC and ADGM free-zone regimes, cross-border transfers, and a full compliance checklist for UAE businesses.

Does GDPR Apply to UAE Companies?

Yes. GDPR applies to a UAE company with no EU establishment whenever it offers goods or services to individuals in the EU, paid or free, or monitors their behavior. This extraterritorial reach comes from GDPR Article 3(2). The trigger is targeting people in the EU, not having an office there. GDPR has been enforceable since 25 May 2018.

A UAE e-commerce store shipping to Germany is caught. So is a UAE app tracking EU users with analytics cookies. A purely domestic firm with no EU customers is not. The test is factual: who your data subjects are and what you do with their data.

What Counts as Personal Data and Processing Under GDPR?

Personal data is any information relating to an identified or identifiable natural person. Processing is any operation performed on that data. A data subject is the individual the data describes. If you handle information that can single out an EU person, directly or indirectly, GDPR treats it as personal data and governs almost everything you do with it.

Personal data includes names, identification numbers, location data, online identifiers, and IP addresses (GDPR Article 4(1)). Processing covers collection, recording, storage, use, disclosure, and erasure, whether automated or not (GDPR Article 4(2), EUR-Lex).

What Is Special Category Data and How Is It Handled?

Special category data is a sensitive subset that GDPR Article 9 prohibits processing unless a specific condition applies. It covers health, biometric, and genetic data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, and data on sex life or sexual orientation. A lawful basis alone is not enough; you also need an Article 9(2) condition, such as explicit consent.

The PDPL uses a similar “sensitive personal data” concept requiring heightened protection. Exact handling rules await the PDPL’s Executive Regulations, so treat GDPR’s Article 9 bar as the working standard for any dataset touching EU data subjects.

What Is the UAE Federal Data Protection Law (PDPL)?

The UAE’s federal data protection framework is Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law (PDPL). It is sometimes informally called the Federal Data Protection Law. It governs processing of personal data through electronic systems, inside or outside the country, giving it extraterritorial reach that parallels GDPR. The regulator is the UAE Data Office.

The PDPL sets an integrated framework for confidentiality and individual privacy, per the UAE government’s data protection page on u.ae. Its core obligations track well-known regimes, including GDPR.

Are the PDPL Executive Regulations in Force Yet?

No. As of the DLA Piper UAE guide updated January 2025, the PDPL’s Executive Regulations that supply its operational detail remain unissued. This leaves transfer mechanisms, DPO thresholds, breach-notification timelines, and penalty amounts undefined. Organizations get six months to comply once the regulations issue.

In practice, the PDPL’s core duties are on the books: consent, security, and data subject rights all apply now. The enforcement mechanics and fine figures are not yet fixed. Do not rely on specific PDPL penalty amounts, and track the Executive Regulations for updates. This hedge applies wherever PDPL specifics appear below.

GDPR vs UAE Federal Data Protection Law: What Are the Key Differences?

The two laws share DNA: consent, controller and processor obligations, data subject rights, and extraterritorial reach. They differ on legal bases, enforcement maturity, penalties, and transfer rules. GDPR is a mature regime with defined fines. The PDPL’s granular mechanics await Executive Regulations. The table below is the core comparison for UAE businesses weighing dual compliance.

DimensionGDPRUAE PDPL (Federal Decree-Law No. 45 of 2021)Source
Effective dateApplicable 25 May 2018Issued 2021; Executive Regulations pendingEUR-Lex; DLA Piper (Jan 2025)
Territorial scopeEU data subjects; extraterritorial via Article 3UAE data subjects; applies inside and outside UAEEUR-Lex Art. 3; u.ae
RegulatorNational supervisory authorities + EDPBUAE Data OfficeEUR-Lex; u.ae
Legal basis modelSix lawful bases (Article 6)Consent plus statutory exceptionsEUR-Lex Art. 6; u.ae
Data subject rightsEight enumerated rightsCorrection, restriction, stop processing (more pending)EUR-Lex Arts. 12–22; u.ae
DPO requirementRequired in defined cases (Article 37)Required in cases set by regulationsEUR-Lex Art. 37; DLA Piper
Breach notification72 hours to supervisory authority (Article 33)Notify UAE Data Office; timeline in regulationsEUR-Lex Art. 33; DLA Piper
Transfer mechanismsAdequacy, SCCs, BCRs (Chapter V)Adequacy list plus safeguards (regulations pending)EUR-Lex Ch. V; DLA Piper
Max penalty€20M or 4% of worldwide turnoverTo be set by Executive RegulationsEUR-Lex Art. 83; DLA Piper

What Are the Obligations of Data Controllers and Processors?

A controller determines the purposes and means of processing; a processor acts only on the controller’s instructions. Both carry direct obligations under GDPR and under the PDPL. GDPR Article 4(7) defines the controller and Article 4(8) defines the processor. A UAE business can be both at once, depending on the relationship in each activity.

Controllers must establish a lawful basis, give privacy notices, handle rights requests, and keep records under GDPR Article 30. Processors must sign a data processing agreement under Article 28, secure the data under Article 32, and control sub-processors. When you process data for your own purposes you are a controller; when you process it for a client you are a processor.

Do DIFC and ADGM Have Their Own Data Protection Laws?

Yes. The DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 are separate, GDPR-modeled regimes with their own regulators, independent of the federal PDPL. Your obligations depend on whether you sit onshore, in the Dubai International Financial Centre (DIFC), or in the Abu Dhabi Global Market (ADGM). Each free zone runs its own enforcement.

Verify current fine caps against the official sources before you rely on them, since schedules change.

RegimeLawRegulatorFine structureGDPR alignmentSource
Onshore UAEFederal Decree-Law No. 45 of 2021 (PDPL)UAE Data OfficeAmounts pending Executive RegulationsClosely alignedu.ae; DLA Piper
DIFCData Protection Law No. 5 of 2020Commissioner of Data ProtectionSchedule fines up to USD 100,000 per contravention, plus Commissioner general fines for serious breachesClosely alignedDIFC Commissioner of Data Protection
ADGMData Protection Regulations 2021Office of Data ProtectionAdministrative fines up to USD 28,000,000Closely alignedADGM Office of Data Protection

DIFC enforcement runs through its Commissioner of Data Protection, who can escalate beyond the fine schedule for serious breaches. ADGM enforcement runs through its Office of Data Protection.

What Are Data Subject Rights Under GDPR?

GDPR grants eight rights: to be informed, of access, to rectification, to erasure, to restriction of processing, to data portability, to object, and rights around automated decision-making and profiling. UAE companies serving the EU must build systems to honor each one, generally within one month. Subject access request (SAR) handling is the workflow most firms underbuild.

RightWhat it requires operationallyPDPL equivalentSource
To be informedClear privacy notices at collectionTransparency expectedEUR-Lex Arts. 13–14
AccessProvide a copy of the data on request (SAR)Access-style rightEUR-Lex Art. 15
RectificationCorrect inaccurate dataCorrection confirmedEUR-Lex Art. 16; u.ae
ErasureDelete data when grounds applyPending regulationsEUR-Lex Art. 17
RestrictionPause processing on requestRestriction confirmedEUR-Lex Art. 18; u.ae
Data portabilityExport data in a machine-readable formatPending regulationsEUR-Lex Art. 20
ObjectStop processing on objectionStop-processing confirmedEUR-Lex Art. 21; u.ae
Automated decisionsHuman review of solely automated decisionsPending regulationsEUR-Lex Art. 22

How Do Cross-Border Data Transfers Work Between the UAE and the EU?

Personal data can leave the EU or European Economic Area (EEA) only through a GDPR Chapter V mechanism. The UAE holds no EU adequacy decision, so UAE companies rely on Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). Direction matters: GDPR restricts data flowing out of the EU into the UAE, while the PDPL restricts flows out of the UAE.

What is an adequacy decision and does the UAE have one?

An adequacy decision is a European Commission finding that a country’s protection is essentially equivalent to the EU’s, allowing free transfers without extra safeguards. The UAE is not on the European Commission’s list of adequacy decisions, which lists jurisdictions such as the UK, Switzerland, and Japan. That absence is why contractual mechanisms are mandatory for EU-to-UAE transfers.

How do Standard Contractual Clauses work for UAE companies?

The EU adopted modular SCCs in June 2021. A UAE importer receiving EU personal data signs the module that fits the relationship: controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller. After the Schrems II ruling, the exporter must also run a transfer impact assessment (TIA) to check whether local laws undermine the clauses and add supplementary measures if needed.

When are Binding Corporate Rules the better option?

BCRs suit multinational groups moving data internally across entities. They are internal rules approved by a lead EU supervisory authority, and the approval process is longer than signing SCCs. For a UAE group with EU subsidiaries and constant intra-group flows, BCRs replace a pile of separate SCC contracts with one approved framework.

MechanismUse caseApproval neededSource
Adequacy decisionFree transfer to listed countriesNone (UAE not listed)European Commission
Standard Contractual ClausesAd hoc EU-to-UAE transfersNo prior approval; TIA expectedEUR-Lex Ch. V; European Commission
Binding Corporate RulesIntra-group multinational transfersLead supervisory authority approvalEUR-Lex Art. 47

The PDPL also restricts outbound transfers from the UAE, with detailed mechanisms pending the Executive Regulations.

Do UAE Companies Need an EU Representative Under Article 27?

Yes, in most cases. A UAE company caught by GDPR Article 3(2) with no EU establishment must appoint a written-mandated representative in an EU Member State where its data subjects are. The exception is narrow: processing that is occasional, low-risk, and free of large-scale special category data. Many UAE firms miss this obligation entirely.

The representative is the local contact point for supervisory authorities and data subjects and holds a copy of the processing record. Appoint one by written mandate and name them in your privacy notice. The EDPB Guidelines 3/2018 on territorial scope set out how Article 27 applies.

When Does a UAE Business Need a Data Protection Officer?

GDPR Article 37 requires a Data Protection Officer (DPO) when core activities involve large-scale regular and systematic monitoring, or large-scale processing of special category data, or when the body is a public authority. The PDPL also requires a DPO in circumstances the Executive Regulations will detail. DIFC and ADGM set their own DPO triggers.

The DPO and the Article 27 EU representative are different roles with different duties. The DPO advises and monitors compliance internally; the representative is a local contact point. One person or entity should not casually hold both, because their functions and independence requirements differ.

When Is a Data Protection Impact Assessment Required?

GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) before processing likely to result in high risk to individuals. Common triggers include large-scale special category processing, systematic monitoring of publicly accessible areas, and automated decisions with legal or similarly significant effects. The DPIA is done before the processing starts, not after.

A DPIA describes the processing, assesses necessity and proportionality, identifies risks, and defines mitigations. If high risk cannot be reduced, you must consult the supervisory authority first under Article 36. The PDPL anticipates an equivalent assessment concept, with detail pending its Executive Regulations.

What Must a Privacy Notice Contain Under GDPR and the PDPL?

GDPR Articles 13 and 14 require a privacy notice covering the controller’s identity and contacts, processing purposes and legal basis, any legitimate interests relied on, recipient categories, third-country transfers and their safeguards, retention periods, data subject rights, the right to complain, and any automated decision-making logic. Missing elements are a common enforcement finding.

Use this as a checklist:

  • Controller identity, contact details, and DPO contact where applicable
  • Purposes of processing and the lawful basis for each
  • Legitimate interests, where that basis is used
  • Categories of recipients and any third-country transfers with safeguards
  • Retention periods and the eight data subject rights, plus the right to complain

The PDPL and u.ae summary require comparable transparency, with fine detail pending the Executive Regulations.

What Are the Breach Notification Rules Under GDPR and the PDPL?

GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to risk individuals. GDPR Article 34 requires notifying affected data subjects without undue delay when the risk to them is high. Documentation of every breach is mandatory even when you do not notify.

The notification must describe the breach, its likely consequences, and the measures taken. The PDPL requires notifying the UAE Data Office, with exact timelines pending the Executive Regulations, per DLA Piper. Because GDPR’s 72-hour clock is fixed, adopt it as your single internal standard.

What Are the GDPR Penalties for UAE Businesses?

GDPR fines run to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements, under Article 83(5). A lower tier of €10 million or 2% applies to failures like record-keeping, DPO, and breach-notification duties, under Article 83(4). Fines must be effective, proportionate, and dissuasive.

TierCapExample infringementsSource
Higher (Art. 83(5))€20M or 4% of worldwide annual turnoverBreach of core principles, consent, data subject rights, transfer rulesEUR-Lex Art. 83(5)
Lower (Art. 83(4))€10M or 2% of worldwide annual turnoverRecords (Art. 30), security, DPO, breach notification, DPIAEUR-Lex Art. 83(4)

Consequences go beyond fines. Supervisory authorities can order processing bans, and enforcement can bring EU market disruption and reputational damage. The PDPL’s fine amounts remain undefined pending its Executive Regulations, so do not quote specific PDPL figures.

How Do UAE Companies Manage GDPR and PDPL Dual Compliance?

Run one program built to the stricter requirement for each obligation. Where the laws overlap, one control satisfies both. Where GDPR demands more, you meet GDPR’s bar and the PDPL is covered too. The laws do not directly conflict, because each governs its own data subjects; where both apply to one dataset, apply both.

Three worked examples make this concrete. The PDPL needs consent or an exception while GDPR needs a documented Article 6 basis, so document a basis for every activity and both are satisfied. GDPR’s 72-hour breach clock is defined while the PDPL’s is not, so adopt 72 hours as your single standard. GDPR requires an EU representative and the PDPL does not, so that duty is simply additive.

How Do You Run a GDPR Compliance Audit for a UAE Business?

A GDPR audit maps your data flows, checks each processing activity for a lawful basis, tests your rights-request and breach procedures, reviews vendor contracts for Article 28 terms, and validates transfer mechanisms. It is an organization-wide gap assessment against the regulation, unlike a DPIA, which is forward-looking and activity-specific.

Audit at least annually, plus after any trigger event such as a new product, vendor, or market entry. Scope the audit separately across your onshore, DIFC, and ADGM entities, because each answers to a different regime. Commenda’s guide to statutory compliance requirements in the UAE sets the wider context.

GDPR Compliance Checklist for UAE Businesses

The checklist below covers every step for a UAE company processing EU personal data. It maps each action to the obligation it satisfies and the source article, so nothing gets missed across onshore and free-zone entities.

StepWhat it satisfiesSource article
Data inventory and RoPARecords of processingGDPR Art. 30
Assign a lawful basis per purposeLawfulnessGDPR Art. 6
Publish complete privacy noticesTransparencyGDPR Arts. 13–14
Build consent capture and withdrawalValid consentGDPR Art. 7
Apply special category safeguardsSensitive dataGDPR Art. 9
Put SCCs or BCRs in place for transfersLawful transfersGDPR Ch. V
Appoint an EU representativeArticle 27 dutyGDPR Art. 27
Appoint a DPO where triggeredGovernanceGDPR Art. 37
Run DPIAs for high-risk processingRisk controlGDPR Art. 35
Breach response with 72-hour drillNotificationGDPR Art. 33
Train staff on data protectionAccountabilityGDPR Art. 39
Sign Article 28 processor agreementsVendor controlGDPR Art. 28
Set an annual audit cadenceOngoing complianceGDPR Art. 24

How Commenda Helps With GDPR and PDPL Compliance in the UAE

GDPR reaches UAE companies that serve the EU, and the PDPL plus the DIFC and ADGM regimes add local obligations. The answer is one compliance program built to the stricter standard for each duty and run consistently across every entity you operate.

Commenda’s entity management platform gives controllers certainty of process: every subsidiary, onshore or free-zone, follows one standardized compliance workflow, with obligations tracked and filings confirmed. Pair it with our guides to statutory compliance requirements in the UAE and penalties for non-compliance in the UAE to see where data protection fits the wider regulatory picture.

Book a demo to map your GDPR and PDPL obligations across every entity.

About the author

Logan Jackonis

Logan Jackonis

Head of Services & Operations, Commenda

Logan leads Commenda’s Services and Operations team, helping controllers, heads of tax, and finance leaders navigate international expansion. He built a global expert network across 70 countries and previously worked in management consulting across the Middle East and Southeast Asia.

Disclaimer: Commenda and its affiliates do not provide tax, accounting, or legal advice. This material has been prepared for informational purposes only, and is not intended to provide or be relied on for tax, accounting, or legal advice. You should consult your own tax, accounting, and legal advisors before engaging in any related activities or transactions.

Subscribe to our newsletter today

Tax rules change every month. Get the updates that matter for your cross-border business, straight to your inbox.

Frequently asked questions

Real questions from the finance and tax teams we work with.

From the field

Trusted by businesses across the globe

TRX
TRX
The platform works exactly the way I need it to. I have one team member who manages all of our exemption certificates, and that functionality has been particularly efficient for us. It allows him to handle everything seamlessly, making the handoff significantly easier.
Matt Preston, CPA

VP of Finance, TRX

Read the full story

Ready to get started?

Talk to our team about your tax and compliance setup. We reply within one business day.

Tax & Accounting

Bookkeeping, tax filings, and audit support handled by local experts in every market you operate.

Explore the product