A UAE company that sells to or monitors people in the European Union (EU) answers to two data protection regimes at once. The EU’s General Data Protection Regulation (GDPR) reaches across borders, and the UAE’s own Personal Data Protection Law (PDPL) layers local rules on top. The verdict up front: yes, GDPR can apply to UAE businesses, and UAE law adds a second set of obligations.
This matters because the fines are steep and EU trade ties run deep. GDPR became applicable on 25 May 2018 across every EU Member State, per the official GDPR text on EUR-Lex. This guide covers GDPR compliance in UAE, the PDPL, the DIFC and ADGM free-zone regimes, cross-border transfers, and a full compliance checklist for UAE businesses.
Does GDPR Apply to UAE Companies?
Yes. GDPR applies to a UAE company with no EU establishment whenever it offers goods or services to individuals in the EU, paid or free, or monitors their behavior. This extraterritorial reach comes from GDPR Article 3(2). The trigger is targeting people in the EU, not having an office there. GDPR has been enforceable since 25 May 2018.
A UAE e-commerce store shipping to Germany is caught. So is a UAE app tracking EU users with analytics cookies. A purely domestic firm with no EU customers is not. The test is factual: who your data subjects are and what you do with their data.
What Counts as Personal Data and Processing Under GDPR?
Personal data is any information relating to an identified or identifiable natural person. Processing is any operation performed on that data. A data subject is the individual the data describes. If you handle information that can single out an EU person, directly or indirectly, GDPR treats it as personal data and governs almost everything you do with it.
Personal data includes names, identification numbers, location data, online identifiers, and IP addresses (GDPR Article 4(1)). Processing covers collection, recording, storage, use, disclosure, and erasure, whether automated or not (GDPR Article 4(2), EUR-Lex).
What Is Special Category Data and How Is It Handled?
Special category data is a sensitive subset that GDPR Article 9 prohibits processing unless a specific condition applies. It covers health, biometric, and genetic data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, and data on sex life or sexual orientation. A lawful basis alone is not enough; you also need an Article 9(2) condition, such as explicit consent.
The PDPL uses a similar “sensitive personal data” concept requiring heightened protection. Exact handling rules await the PDPL’s Executive Regulations, so treat GDPR’s Article 9 bar as the working standard for any dataset touching EU data subjects.
What Is the UAE Federal Data Protection Law (PDPL)?
The UAE’s federal data protection framework is Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law (PDPL). It is sometimes informally called the Federal Data Protection Law. It governs processing of personal data through electronic systems, inside or outside the country, giving it extraterritorial reach that parallels GDPR. The regulator is the UAE Data Office.
The PDPL sets an integrated framework for confidentiality and individual privacy, per the UAE government’s data protection page on u.ae. Its core obligations track well-known regimes, including GDPR.
Are the PDPL Executive Regulations in Force Yet?
No. As of the DLA Piper UAE guide updated January 2025, the PDPL’s Executive Regulations that supply its operational detail remain unissued. This leaves transfer mechanisms, DPO thresholds, breach-notification timelines, and penalty amounts undefined. Organizations get six months to comply once the regulations issue.
In practice, the PDPL’s core duties are on the books: consent, security, and data subject rights all apply now. The enforcement mechanics and fine figures are not yet fixed. Do not rely on specific PDPL penalty amounts, and track the Executive Regulations for updates. This hedge applies wherever PDPL specifics appear below.
GDPR vs UAE Federal Data Protection Law: What Are the Key Differences?
The two laws share DNA: consent, controller and processor obligations, data subject rights, and extraterritorial reach. They differ on legal bases, enforcement maturity, penalties, and transfer rules. GDPR is a mature regime with defined fines. The PDPL’s granular mechanics await Executive Regulations. The table below is the core comparison for UAE businesses weighing dual compliance.
| Dimension | GDPR | UAE PDPL (Federal Decree-Law No. 45 of 2021) | Source |
|---|---|---|---|
| Effective date | Applicable 25 May 2018 | Issued 2021; Executive Regulations pending | EUR-Lex; DLA Piper (Jan 2025) |
| Territorial scope | EU data subjects; extraterritorial via Article 3 | UAE data subjects; applies inside and outside UAE | EUR-Lex Art. 3; u.ae |
| Regulator | National supervisory authorities + EDPB | UAE Data Office | EUR-Lex; u.ae |
| Legal basis model | Six lawful bases (Article 6) | Consent plus statutory exceptions | EUR-Lex Art. 6; u.ae |
| Data subject rights | Eight enumerated rights | Correction, restriction, stop processing (more pending) | EUR-Lex Arts. 12–22; u.ae |
| DPO requirement | Required in defined cases (Article 37) | Required in cases set by regulations | EUR-Lex Art. 37; DLA Piper |
| Breach notification | 72 hours to supervisory authority (Article 33) | Notify UAE Data Office; timeline in regulations | EUR-Lex Art. 33; DLA Piper |
| Transfer mechanisms | Adequacy, SCCs, BCRs (Chapter V) | Adequacy list plus safeguards (regulations pending) | EUR-Lex Ch. V; DLA Piper |
| Max penalty | €20M or 4% of worldwide turnover | To be set by Executive Regulations | EUR-Lex Art. 83; DLA Piper |
What Are the Obligations of Data Controllers and Processors?
A controller determines the purposes and means of processing; a processor acts only on the controller’s instructions. Both carry direct obligations under GDPR and under the PDPL. GDPR Article 4(7) defines the controller and Article 4(8) defines the processor. A UAE business can be both at once, depending on the relationship in each activity.
Controllers must establish a lawful basis, give privacy notices, handle rights requests, and keep records under GDPR Article 30. Processors must sign a data processing agreement under Article 28, secure the data under Article 32, and control sub-processors. When you process data for your own purposes you are a controller; when you process it for a client you are a processor.
What Legal Bases Allow Processing Under GDPR and the PDPL?
GDPR Article 6 provides six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The PDPL uses a consent-plus-exceptions model, prohibiting processing without the data owner’s consent except in specified cases such as public interest and legal procedures and rights, per u.ae. Consent is one option under GDPR, not the only one.
When does consent suffice and when do exceptions apply?
Consent fits some purposes and not others. Marketing emails need consent under both laws. Fulfilling a customer order rests on contract under GDPR, but on consent or the legal-procedures exception under the PDPL. Payroll processing rests on legal obligation under GDPR. Verify each PDPL exception against the decree-law text once the Executive Regulations clarify scope.
How do you map processing activities to a lawful basis?
Work through a simple sequence. Inventory every processing activity in a Record of Processing Activities (RoPA) under GDPR Article 30. Assign one basis per purpose. Document the assessment, adding a Legitimate Interests Assessment where you rely on legitimate interests. Then reflect the chosen basis in your privacy notice so data subjects can see it.
Do DIFC and ADGM Have Their Own Data Protection Laws?
Yes. The DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 are separate, GDPR-modeled regimes with their own regulators, independent of the federal PDPL. Your obligations depend on whether you sit onshore, in the Dubai International Financial Centre (DIFC), or in the Abu Dhabi Global Market (ADGM). Each free zone runs its own enforcement.
Verify current fine caps against the official sources before you rely on them, since schedules change.
| Regime | Law | Regulator | Fine structure | GDPR alignment | Source |
|---|---|---|---|---|---|
| Onshore UAE | Federal Decree-Law No. 45 of 2021 (PDPL) | UAE Data Office | Amounts pending Executive Regulations | Closely aligned | u.ae; DLA Piper |
| DIFC | Data Protection Law No. 5 of 2020 | Commissioner of Data Protection | Schedule fines up to USD 100,000 per contravention, plus Commissioner general fines for serious breaches | Closely aligned | DIFC Commissioner of Data Protection |
| ADGM | Data Protection Regulations 2021 | Office of Data Protection | Administrative fines up to USD 28,000,000 | Closely aligned | ADGM Office of Data Protection |
DIFC enforcement runs through its Commissioner of Data Protection, who can escalate beyond the fine schedule for serious breaches. ADGM enforcement runs through its Office of Data Protection.
What Are Data Subject Rights Under GDPR?
GDPR grants eight rights: to be informed, of access, to rectification, to erasure, to restriction of processing, to data portability, to object, and rights around automated decision-making and profiling. UAE companies serving the EU must build systems to honor each one, generally within one month. Subject access request (SAR) handling is the workflow most firms underbuild.
| Right | What it requires operationally | PDPL equivalent | Source |
|---|---|---|---|
| To be informed | Clear privacy notices at collection | Transparency expected | EUR-Lex Arts. 13–14 |
| Access | Provide a copy of the data on request (SAR) | Access-style right | EUR-Lex Art. 15 |
| Rectification | Correct inaccurate data | Correction confirmed | EUR-Lex Art. 16; u.ae |
| Erasure | Delete data when grounds apply | Pending regulations | EUR-Lex Art. 17 |
| Restriction | Pause processing on request | Restriction confirmed | EUR-Lex Art. 18; u.ae |
| Data portability | Export data in a machine-readable format | Pending regulations | EUR-Lex Art. 20 |
| Object | Stop processing on objection | Stop-processing confirmed | EUR-Lex Art. 21; u.ae |
| Automated decisions | Human review of solely automated decisions | Pending regulations | EUR-Lex Art. 22 |
How Do Cross-Border Data Transfers Work Between the UAE and the EU?
Personal data can leave the EU or European Economic Area (EEA) only through a GDPR Chapter V mechanism. The UAE holds no EU adequacy decision, so UAE companies rely on Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). Direction matters: GDPR restricts data flowing out of the EU into the UAE, while the PDPL restricts flows out of the UAE.
What is an adequacy decision and does the UAE have one?
An adequacy decision is a European Commission finding that a country’s protection is essentially equivalent to the EU’s, allowing free transfers without extra safeguards. The UAE is not on the European Commission’s list of adequacy decisions, which lists jurisdictions such as the UK, Switzerland, and Japan. That absence is why contractual mechanisms are mandatory for EU-to-UAE transfers.
How do Standard Contractual Clauses work for UAE companies?
The EU adopted modular SCCs in June 2021. A UAE importer receiving EU personal data signs the module that fits the relationship: controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller. After the Schrems II ruling, the exporter must also run a transfer impact assessment (TIA) to check whether local laws undermine the clauses and add supplementary measures if needed.
When are Binding Corporate Rules the better option?
BCRs suit multinational groups moving data internally across entities. They are internal rules approved by a lead EU supervisory authority, and the approval process is longer than signing SCCs. For a UAE group with EU subsidiaries and constant intra-group flows, BCRs replace a pile of separate SCC contracts with one approved framework.
| Mechanism | Use case | Approval needed | Source |
|---|---|---|---|
| Adequacy decision | Free transfer to listed countries | None (UAE not listed) | European Commission |
| Standard Contractual Clauses | Ad hoc EU-to-UAE transfers | No prior approval; TIA expected | EUR-Lex Ch. V; European Commission |
| Binding Corporate Rules | Intra-group multinational transfers | Lead supervisory authority approval | EUR-Lex Art. 47 |
The PDPL also restricts outbound transfers from the UAE, with detailed mechanisms pending the Executive Regulations.
Do UAE Companies Need an EU Representative Under Article 27?
Yes, in most cases. A UAE company caught by GDPR Article 3(2) with no EU establishment must appoint a written-mandated representative in an EU Member State where its data subjects are. The exception is narrow: processing that is occasional, low-risk, and free of large-scale special category data. Many UAE firms miss this obligation entirely.
The representative is the local contact point for supervisory authorities and data subjects and holds a copy of the processing record. Appoint one by written mandate and name them in your privacy notice. The EDPB Guidelines 3/2018 on territorial scope set out how Article 27 applies.
When Does a UAE Business Need a Data Protection Officer?
GDPR Article 37 requires a Data Protection Officer (DPO) when core activities involve large-scale regular and systematic monitoring, or large-scale processing of special category data, or when the body is a public authority. The PDPL also requires a DPO in circumstances the Executive Regulations will detail. DIFC and ADGM set their own DPO triggers.
The DPO and the Article 27 EU representative are different roles with different duties. The DPO advises and monitors compliance internally; the representative is a local contact point. One person or entity should not casually hold both, because their functions and independence requirements differ.
When Is a Data Protection Impact Assessment Required?
GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) before processing likely to result in high risk to individuals. Common triggers include large-scale special category processing, systematic monitoring of publicly accessible areas, and automated decisions with legal or similarly significant effects. The DPIA is done before the processing starts, not after.
A DPIA describes the processing, assesses necessity and proportionality, identifies risks, and defines mitigations. If high risk cannot be reduced, you must consult the supervisory authority first under Article 36. The PDPL anticipates an equivalent assessment concept, with detail pending its Executive Regulations.
What Must a Privacy Notice Contain Under GDPR and the PDPL?
GDPR Articles 13 and 14 require a privacy notice covering the controller’s identity and contacts, processing purposes and legal basis, any legitimate interests relied on, recipient categories, third-country transfers and their safeguards, retention periods, data subject rights, the right to complain, and any automated decision-making logic. Missing elements are a common enforcement finding.
Use this as a checklist:
- Controller identity, contact details, and DPO contact where applicable
- Purposes of processing and the lawful basis for each
- Legitimate interests, where that basis is used
- Categories of recipients and any third-country transfers with safeguards
- Retention periods and the eight data subject rights, plus the right to complain
The PDPL and u.ae summary require comparable transparency, with fine detail pending the Executive Regulations.
What Are the Breach Notification Rules Under GDPR and the PDPL?
GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to risk individuals. GDPR Article 34 requires notifying affected data subjects without undue delay when the risk to them is high. Documentation of every breach is mandatory even when you do not notify.
The notification must describe the breach, its likely consequences, and the measures taken. The PDPL requires notifying the UAE Data Office, with exact timelines pending the Executive Regulations, per DLA Piper. Because GDPR’s 72-hour clock is fixed, adopt it as your single internal standard.
What Are the GDPR Penalties for UAE Businesses?
GDPR fines run to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements, under Article 83(5). A lower tier of €10 million or 2% applies to failures like record-keeping, DPO, and breach-notification duties, under Article 83(4). Fines must be effective, proportionate, and dissuasive.
| Tier | Cap | Example infringements | Source |
|---|---|---|---|
| Higher (Art. 83(5)) | €20M or 4% of worldwide annual turnover | Breach of core principles, consent, data subject rights, transfer rules | EUR-Lex Art. 83(5) |
| Lower (Art. 83(4)) | €10M or 2% of worldwide annual turnover | Records (Art. 30), security, DPO, breach notification, DPIA | EUR-Lex Art. 83(4) |
Consequences go beyond fines. Supervisory authorities can order processing bans, and enforcement can bring EU market disruption and reputational damage. The PDPL’s fine amounts remain undefined pending its Executive Regulations, so do not quote specific PDPL figures.
How Do UAE Companies Manage GDPR and PDPL Dual Compliance?
Run one program built to the stricter requirement for each obligation. Where the laws overlap, one control satisfies both. Where GDPR demands more, you meet GDPR’s bar and the PDPL is covered too. The laws do not directly conflict, because each governs its own data subjects; where both apply to one dataset, apply both.
Three worked examples make this concrete. The PDPL needs consent or an exception while GDPR needs a documented Article 6 basis, so document a basis for every activity and both are satisfied. GDPR’s 72-hour breach clock is defined while the PDPL’s is not, so adopt 72 hours as your single standard. GDPR requires an EU representative and the PDPL does not, so that duty is simply additive.
How Do You Run a GDPR Compliance Audit for a UAE Business?
A GDPR audit maps your data flows, checks each processing activity for a lawful basis, tests your rights-request and breach procedures, reviews vendor contracts for Article 28 terms, and validates transfer mechanisms. It is an organization-wide gap assessment against the regulation, unlike a DPIA, which is forward-looking and activity-specific.
Audit at least annually, plus after any trigger event such as a new product, vendor, or market entry. Scope the audit separately across your onshore, DIFC, and ADGM entities, because each answers to a different regime. Commenda’s guide to statutory compliance requirements in the UAE sets the wider context.
GDPR Compliance Checklist for UAE Businesses
The checklist below covers every step for a UAE company processing EU personal data. It maps each action to the obligation it satisfies and the source article, so nothing gets missed across onshore and free-zone entities.
| Step | What it satisfies | Source article |
|---|---|---|
| Data inventory and RoPA | Records of processing | GDPR Art. 30 |
| Assign a lawful basis per purpose | Lawfulness | GDPR Art. 6 |
| Publish complete privacy notices | Transparency | GDPR Arts. 13–14 |
| Build consent capture and withdrawal | Valid consent | GDPR Art. 7 |
| Apply special category safeguards | Sensitive data | GDPR Art. 9 |
| Put SCCs or BCRs in place for transfers | Lawful transfers | GDPR Ch. V |
| Appoint an EU representative | Article 27 duty | GDPR Art. 27 |
| Appoint a DPO where triggered | Governance | GDPR Art. 37 |
| Run DPIAs for high-risk processing | Risk control | GDPR Art. 35 |
| Breach response with 72-hour drill | Notification | GDPR Art. 33 |
| Train staff on data protection | Accountability | GDPR Art. 39 |
| Sign Article 28 processor agreements | Vendor control | GDPR Art. 28 |
| Set an annual audit cadence | Ongoing compliance | GDPR Art. 24 |
How Commenda Helps With GDPR and PDPL Compliance in the UAE
GDPR reaches UAE companies that serve the EU, and the PDPL plus the DIFC and ADGM regimes add local obligations. The answer is one compliance program built to the stricter standard for each duty and run consistently across every entity you operate.
Commenda’s entity management platform gives controllers certainty of process: every subsidiary, onshore or free-zone, follows one standardized compliance workflow, with obligations tracked and filings confirmed. Pair it with our guides to statutory compliance requirements in the UAE and penalties for non-compliance in the UAE to see where data protection fits the wider regulatory picture.
Book a demo to map your GDPR and PDPL obligations across every entity.








