Ask a Lawyer
Ask a Lawyer
Free answers to questions about UAE law — browse what others asked, or ask your own
UAE legal professionals answer questions in this forum — no chatbots.
General legal information, not legal advice.
Latest legal questions
21 questions
What are the penalties for breaking the data protection law in the UAE?
Non-compliance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) can expose an organisation to enforcement action, but the specific monetary amounts are not something to assume — they are set out in the framework established under the law and its implementing decisions, and the UAE Data Office oversees enforcement. Rather than quoting a figure that may be inaccurate, it is safer to understand the types of consequence: administrative penalties for breaching obligations, orders to stop or correct unlawful processing, and the reputational and commercial damage that follows a publicised data incident or regulatory finding. Individuals who suffer harm may also pursue remedies. The exposure typically scales with the seriousness of the violation, whether it was repeated, and whether the business cooperated and took remedial steps. The practical takeaway is that the cost of a structured compliance programme — lawful-basis mapping, security measures, breach response, and honouring data-subject rights — is usually far lower than the cost of enforcement. For the current penalty schedule, rely on the UAE Data Office's official guidance, and for a compliance and risk review you can compare verified UAE legal professionals on LEXAI.
What steps should a UAE business take to become PDPL compliant?
Becoming compliant with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) is a structured exercise rather than a single task. Start by mapping your data: what personal data you collect, where it comes from, why you hold it, where it is stored, who has access, and where it is shared or transferred abroad. For each activity, identify and document a lawful basis. Next, update privacy notices so individuals are told clearly how their data is used, and put in place a process to handle data-subject requests (access, correction, erasure, objection) within the timeframes set by the law. Apply appropriate technical and organisational security measures, and assess whether your processing triggers the need for a Data Protection Officer. Put written contracts in place with processors, govern cross-border transfers correctly, and build an incident-response and breach-notification plan. Keep records of your processing and decisions so you can demonstrate accountability. Finally, train staff and review periodically. Because the Executive Regulations carry much of the operational detail, confirm specifics with the UAE Data Office. For a guided implementation, you can browse verified UAE legal professionals on LEXAI.
What rights do I have over my personal data under UAE data protection law?
Under the UAE's Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), individuals — called data subjects — are given a set of rights over their personal data. These generally include the right to be informed about how your data is processed, the right to request access to the data a controller holds about you, the right to have inaccurate data corrected, and the right to request erasure of your data in defined circumstances. The law also recognises rights to restrict or stop certain processing, to object to particular uses, to data portability (receiving your data in a structured, machine-readable form where applicable), and to withhold or withdraw consent. There are conditions and exceptions — for example, where the controller must keep data to comply with another legal obligation. To exercise a right, you normally submit a request directly to the organisation (the controller), which must respond within the period set by the law and its Executive Regulations. If they refuse or ignore you, you can escalate to the UAE Data Office. For complex disputes, you can compare verified UAE legal professionals on LEXAI.
Can I get a copy of all the data a UAE company holds about me?
Yes. The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) gives you a right of access, allowing you to ask a controller whether it processes your personal data and, if so, to obtain information about it. This typically includes the categories of data being processed, the purposes, the parties or categories of recipients it is shared with, the envisaged retention period or the criteria for setting it, and information about the source of the data and your other rights. You can usually also obtain a copy of the data itself. To make the request, contact the organisation's privacy or data protection contact in writing, identify yourself sufficiently so they can verify you, and state what you are seeking. The controller must respond within the period set by the law and its Executive Regulations, and there are limited grounds on which it can decline or restrict the response, for example to protect the rights of others. If the organisation refuses without justification or fails to reply, you can escalate to the UAE Data Office. For a contested access request, you can compare verified UAE legal professionals on LEXAI.
How do I ask a UAE company to delete my personal data under the PDPL?
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), you have a right to request erasure of your personal data held by a controller in defined situations — for example where the data is no longer needed for the purpose it was collected, or where you withdraw the consent the processing relied on and there is no other lawful basis. Start by sending a written request to the organisation, ideally to its data protection contact or privacy team, clearly identifying yourself and the data you want deleted. The controller must consider the request and respond within the timeframe set by the law and its Executive Regulations. Erasure is not absolute: a business may lawfully retain data it needs to meet another legal or regulatory obligation, to establish or defend a legal claim, or for other grounds recognised by the law. If the controller refuses without a valid basis or fails to respond, you can lodge a complaint with the UAE Data Office, the federal supervisory authority. For a contested or high-value matter, you can browse verified UAE legal professionals on LEXAI to get tailored advice.
What must a UAE business do if it suffers a personal data breach?
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), a controller that experiences a personal data breach — a security incident leading to unauthorised access, disclosure, loss or alteration of personal data — has specific obligations. The core duties are to assess the incident, and where it poses a risk to the privacy, confidentiality or security of the affected individuals' data, to notify the UAE Data Office, and in defined circumstances to notify the affected data subjects. A processor that becomes aware of a breach must inform the controller. The notification should describe the nature of the breach, the data and individuals affected, the likely consequences, and the measures taken or proposed to address it and limit harm. The precise notification timing, thresholds and content are set out in the law and its Executive Regulations, so confirm the current requirements with the UAE Data Office rather than relying on assumptions. Businesses should also keep an internal record of breaches. Before an incident occurs, having an incident-response plan and clear contracts with processors is essential. For help building one, you can compare verified UAE legal professionals on LEXAI.
What is the difference between a data controller and a data processor in the UAE?
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), responsibilities depend on whether you are a controller or a processor. A controller is the person or entity that determines the purposes and means of processing personal data — essentially deciding why and how the data is used. A processor is a separate party that processes personal data on the controller's behalf and under its instructions, such as a cloud host, payroll bureau or email-marketing platform. The controller carries primary accountability: establishing a lawful basis, honouring data-subject rights, applying security measures, and ensuring any processor it appoints gives sufficient guarantees. The processor must act only on the controller's documented instructions, keep data secure, support the controller in meeting its obligations, and not engage sub-processors without authorisation. The relationship should be governed by a written contract setting out the subject matter, duration, scope and each party's duties. Many businesses are controllers for their own customer data and processors for clients they serve. Mapping your role for each data flow is the first compliance step. For drafting processing agreements, you can browse verified UAE legal professionals on LEXAI.
Can a UAE company transfer my personal data outside the country legally?
Yes, but cross-border transfers of personal data out of the UAE are regulated under the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). The general principle is that data may be transferred to another country or international organisation where an adequate level of protection exists — for example, where the destination has data protection laws and oversight comparable to the UAE's, or where there is a binding instrument that provides appropriate safeguards. Where adequacy is not established, the law sets out alternative conditions that can permit a transfer, such as the data subject's explicit consent, the necessity of the transfer to perform a contract, to protect vital interests, or other grounds recognised in the law. Controllers remain responsible for ensuring the data stays protected after it leaves the UAE. The detailed mechanisms and any list of approved jurisdictions are governed by the law's Executive Regulations and guidance from the UAE Data Office, so confirm current requirements there. If you believe your data was transferred improperly, you can raise it with the Data Office. For cross-border compliance advice, you can compare verified UAE legal professionals on LEXAI.
Does the UAE PDPL apply to companies in the DIFC or ADGM free zones?
Generally no — the financial free zones run their own data protection regimes. The federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) provides the UAE-wide baseline, but the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) each have their own standalone data protection laws and independent regulators (the DIFC operates under its Data Protection Law, and ADGM under its own data protection regulations). If your entity is established in and processes data within one of these free zones, that zone's law and its commissioner's office usually apply to you rather than the federal PDPL. The free-zone regimes are closely modelled on international standards and share many concepts — lawful basis, data-subject rights, breach notification and cross-border rules — but the precise obligations, timelines and registration requirements differ. The practical step is to confirm which regime governs each data flow, because a group operating across mainland and free zones may be subject to more than one. For a clear assessment of which law applies to your structure, you can compare verified UAE legal professionals on LEXAI who handle privacy and free-zone matters.
What is a lawful basis for processing personal data under the UAE PDPL?
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), an organisation cannot process personal data unless it has a valid lawful basis. Consent — a clear, specific, informed and freely given agreement from the individual — is one basis, but it is not the only one. The law recognises several other grounds where processing is permitted without consent, including where it is necessary to perform a contract to which the data subject is a party, to comply with a legal obligation on the controller, to protect the vital interests of the individual, to carry out functions in the public interest, or to serve legitimate interests of the controller that do not override the individual's rights. The right basis depends on the context: an employer processing payroll, a hospital handling patient records, and a shop running a loyalty programme may each rely on different grounds. Choosing and documenting the correct basis for each processing activity is a core compliance step, and you cannot simply default to consent for everything. Confirm the exact conditions in the law and its Executive Regulations. For help mapping your bases, you can compare verified UAE legal professionals on LEXAI.
Have a legal question?
Post your question and get a free answer about UAE law. For advice on your own situation, speak to a verified lawyer.
Need direct legal help?
Browse Lawyers