Fraud Alert
PDPL Compliance: What UAE Software Teams Must Build

PDPL Compliance: What UAE Software Teams Must Build

Share

The UAE PDPL has been law since 2 January 2022, and its Executive Regulations have never been issued. That single fact governs everything below. The obligations in Federal Decree-Law No. 45 of 2021 are real and binding. The precise numbers everyone quotes for them are not: there is no published fine schedule, no breach-notification deadline in hours, and no response window for a data-subject request. The law states each obligation and then defers the operational detail to regulations that are, as of July 2026, more than four years overdue. Here is what a UAE PDPL compliant system must actually do in the meantime.

Part of Vervali's UAE vendor-selection and compliance series. If you want the testing that evidences it, the security testing service page covers the scope.

What is PDPL compliance, in practice?

The UAE PDPL is the federal data-protection law, established by Federal Decree-Law No. 45 of 2021 and enforced by the UAE Data Office, which was itself created by a companion law, Federal Decree-Law No. 44 of 2021. It came into force on 2 January 2022.

Article 28 of the law required the Cabinet to issue Executive Regulations within six months of promulgation. They have not appeared. As of the most recent dated legal commentary, from June 2026, they remain unissued. Article 29 then says that controllers and processors must regularize their status within six months of those regulations being issued. Read those two together and the position is unusual but clear: the compliance clock has not started, and the obligations are in force anyway.

Be careful here, because this is where most UAE PDPL content on the internet goes wrong. Several sites now state that the Executive Regulations were issued, some citing a decision number that does not appear to exist. It is not supported by any government source or any named law firm. Do not build a compliance programme on it.

So UAE PDPL compliance today means satisfying the obligations the Decree-Law states in its own text, and making a documented, defensible judgment call wherever the law defers a number to regulations that have not been written.

What the UAE PDPL actually requires you to build

Strip the legal framing out of the UAE PDPL and there are six things an engineering team has to be able to do.

Prove a lawful basis for every processing activity. Consent is one basis among several, and where you rely on it, it has to be demonstrable. In practice this means consent is a record, with a timestamp, a version of the notice that was shown, and a mechanism to withdraw that is as easy as the mechanism to grant.

Serve the data-subject rights, on request. Articles 13 to 19 give individuals the right to access their data, to receive it in a portable form, to have it corrected or erased, to restrict its processing, and to object. Two of these have teeth that teams miss. The right to object to direct marketing is unconditional under Article 17. And Article 18 gives a right to object to automated decisions with legal or serious effects, and requires the controller to provide human review of that decision on request. If your product makes automated decisions about people, you owe them a human.

Detect a breach immediately, and be able to prove when you knew. Article 9 requires the controller to report "immediately upon becoming aware" of a breach. It then defers the actual notification period and procedure to the Executive Regulations. There is therefore no numeric deadline in federal UAE law today. What matters, and what an auditor will ask, is the timestamp on your detection: when did you know. Build the logging that answers that question, because the moment the regulations land, that timestamp becomes the thing you are measured against.

Appoint a Data Protection Officer where required, and know that they need not sit in the UAE. Article 10 explicitly permits the DPO to be employed or authorised "whether inside or outside the State." That single clause is worth knowing before anyone sells you a local-entity requirement.

Run a data-protection impact assessment for high-risk processing. Article 21 requires it, and requires the Data Office to publish a list of processing types that are exempt.

Keep records. Not because a regulation says so in a number, but because in the absence of Executive Regulations, your documented reasoning is the only UAE PDPL compliance artefact you have.

Does the UAE PDPL apply to an offshore development team?

Yes. The UAE PDPL reaches offshore teams, and this is the provision to read carefully if your build is in Mumbai, Bengaluru or Kraków.

Article 2(1)(c) extends the law to "any Controller or Processor located outside the State who carries out the activities of Processing Personal Data of Data Subjects inside the State."

That is unambiguous. An offshore engineering team handling the personal data of people in the UAE is inside the scope of the UAE PDPL, regardless of where its servers or its staff are. The practical consequence is that your data-processing agreement, your access controls, your logging and your breach-detection all have to hold up wherever the work is done. Offshore delivery is not a way out of the UAE PDPL. It is a reason to be more deliberate about it.

Can UAE personal data leave the country? The residency myth

This is the most common and most expensive misunderstanding about the UAE PDPL, and it costs teams real money in unnecessary local infrastructure.

The PDPL does not require general commercial personal data to stay in the UAE. Articles 22 and 23 regulate how data crosses the border, not whether it may. Transfer is lawful to a jurisdiction with an adequate level of protection, or, failing that, under contractual guarantees, binding corporate rules or the data subject's explicit consent, among other routes.

Two caveats matter, and they are what people are half-remembering when they insist that the UAE PDPL forces residency.

The first is that health data is genuinely different, and it is governed by a separate law, not the PDPL. Under the UAE's ICT in Health Fields Law, health information may not be stored, processed or transferred outside the UAE except by a decision of the Health Authority. If you are building health software, residency is a real constraint. If you are building a retail app, it is not.

The second is that the mechanisms Articles 22 and 23 rely on are not yet operational. As of February 2026, the UAE Data Office had not published a list of adequate jurisdictions, and no federal standard contractual clauses had been issued. So the UAE PDPL provides the route and the paperwork to walk it does not exist yet. In practice, teams are relying on contractual guarantees drafted from first principles, and documenting why.

What is the fine for the UAE PDPL?

There is no published fine schedule. This is the single most misreported fact about the law.

Article 26 says that the Cabinet "shall issue a decision specifying the acts that constitute a violation of the provisions of this Decree Law and the Executive Regulations thereof and the administrative penalties to be imposed." That decision has not been issued. No amount appears anywhere in the primary text of the UAE PDPL. Any article quoting you a specific dirham figure for a PDPL breach is quoting something that does not exist in the law.

That is not the same as saying the UAE PDPL leaves you no exposure. Three things are real today:

  • The UAE Cyber Crime Law is separate, in force, and has active penalties. Its Article 13 provides fines from AED 50,000 to AED 500,000 for unlawfully collecting or processing personal data. It is a different statute, and it will not wait for the PDPL's regulations.
  • DIFC and ADGM are separate regimes with their own live rules. They are not versions of the PDPL. DIFC penalties run from USD 10,000 to USD 100,000, and ADGM's ceiling is far higher. ADGM also imposes a 72-hour breach-notification deadline, which the federal PDPL does not.
  • Regularization is only six months. Article 29 gives controllers and processors six months from the issuance of the Executive Regulations to comply, extendable once. Whenever those regulations land, six months is not long enough to retrofit consent records, access logs and breach detection into a system that was not designed for them.

What rights do individuals have under the UAE PDPL?

The UAE PDPL grants six, in Articles 13 to 19, and each one is a feature somebody has to build.

Right Article What your system must do
Access 13 Return the data you hold, and what you do with it
Portability 14 Export it in a structured, machine-readable form
Correction and erasure 15 Correct without undue delay; erase on valid request
Restrict processing 16 Suspend processing while a dispute is open, without deleting
Object and stop 17 Unconditional for direct marketing, including profiling for marketing
Object to automated decisions 18 Provide human review of decisions with legal or serious effects

Note what is missing from that table: a deadline. The primary text sets no numeric response window for a rights request. Article 15 says correction should be "without undue delay," and that is the only timing language in the whole set. If you have seen a confident "30 days" in a UAE PDPL summary, it has been borrowed from GDPR by analogy and has no basis in the UAE text.

How is the UAE PDPL different from GDPR?

They rhyme, and the differences are where projects get caught.

The structure of the UAE PDPL is familiar: lawful bases, data-subject rights, controller and processor obligations, breach reporting, a DPO, impact assessments, cross-border rules. If you have built for GDPR, you have built most of the machinery.

What differs is the operational layer. GDPR gives you numbers: 72 hours for a breach, one month for a rights request, four percent of global turnover as a ceiling on fines. The UAE PDPL gives you the obligation and, for now, no number attached to any of them. It is tempting to fill the gaps with the GDPR figures. That is a reasonable engineering default and a poor compliance claim, and the difference matters if anyone ever asks you to justify it. Document the choice as your judgment, not as the law.

The other difference is institutional. Enforcement sits with the UAE Data Office, established under Federal Decree-Law No. 44 of 2021, and its position is in flux: a new Federal Authority for AI and Data was announced in June 2026, and the market expects it to take ownership of this area, though a formal legal transfer of the Data Office's functions has not been confirmed.

What to build now, while the regulations are missing

The instinct is to wait for the regulations before doing UAE PDPL work at all. That is the wrong call, because Article 29 gives you six months from the day they appear, and six months is not enough to retrofit any of this.

Build the four things the law already states plainly and that no regulation will contradict.

Consent as a record, not a checkbox. Timestamp, notice version, and a withdrawal path. Rights as endpoints. Access, export, correct, erase, restrict, object. If these are manual database queries today, they will not survive first contact with a real request. Breach detection with a defensible clock. You will be judged on when you knew. Instrument that. A processing register and a data map. Where personal data enters, where it is stored, who it is shared with, and where it leaves the country. Almost no team has this, and everything else depends on it.

None of that requires the Executive Regulations. All of it will be required by them, and all of it is already implied by the UAE PDPL as written.

A worked example from Vervali's own book, anonymised. A UAE SME finance-management platform handling collections, receivables and financial tracking needed to be trusted with money and with the personal data attached to it. Vervali built it and tested it in the same engagement, and the outcomes included full compliance with UAE rules and regulations, 98% user satisfaction, and a 35% improvement in transaction-processing efficiency. The compliance work was engineering work from the first sprint, not a certificate collected at the end. That is the only approach that survives a regulation you cannot yet read.

Compliance is one of five criteria worth putting to any Dubai firm before you sign. The same framework, applied per build type: ecommerce development companies in Dubai, the best web development companies in Dubai, and the best mobile app development companies in Dubai. For the accessibility mandate that sits alongside the PDPL for UAE government work, see WCAG 2.1 AA compliance for UAE digital services.

Where to go next

Treat the UAE PDPL as a design constraint rather than a document. The obligations are in force, the numbers are not written, and the six-month regularization window will begin without warning.

If you want the testing that evidences it, Vervali's security testing and application testing practices cover compliance readiness, and the case studies are the evidence. Vervali is ISO 27001 certified, with a 300-plus delivery team across Mumbai, Dubai and Auckland, and its own offshore delivery sits squarely inside Article 2(1)(c), which is why this is not an academic question for us either.

Sources

  1. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. In force 2 January 2022. Regulator: the UAE Data Office, established by Federal Decree-Law No. 44 of 2021. The Official Portal of the UAE Government. https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
  2. Article-level provisions quoted above (Articles 2, 9, 10, 13 to 19, 21, 22, 23, 26, 28, 29, 31) are taken from the text of Federal Decree-Law No. 45 of 2021, via a bilingual professional translation published by Amereller Legal Consultants, cross-checked against independent law-firm summaries.
  3. Executive Regulations remain unissued as of 15 June 2026. Morgan Lewis & Bockius LLP.
  4. No adequacy list and no federal standard contractual clauses have been published, as of 3 February 2026. Kayrouz & Associates.
  5. Health-data residency under the ICT in Health Fields Law; DIFC and ADGM as separate regimes with their own penalties and a 72-hour ADGM breach deadline. Chambers and Partners, UAE Data Protection and Privacy guide, updated 10 March 2026.
  6. UAE Cyber Crime Law, Article 13: fines of AED 50,000 to AED 500,000 for unlawfully collecting or processing personal data. DLA Piper Data Protection Laws of the World, UAE.

This article is a practitioner's reading of the law for engineering teams. It is not legal advice. Where the Decree-Law defers an operational detail to Executive Regulations that have not been issued, this article says so rather than supplying a number from another jurisdiction.

FAQ

Frequently Asked Questions

Quick answers to common questions about this article.

There is no published fine schedule. Article 26 of Federal Decree-Law No. 45 of 2021 says the Cabinet shall issue a decision specifying violations and administrative penalties. That decision has not been issued, so no amount appears anywhere in the primary text. Any article quoting a specific dirham figure for a PDPL breach is quoting something that does not exist in the law. Separately, the UAE Cyber Crime Law is in force and its Article 13 provides fines of AED 50,000 to AED 500,000 for unlawfully collecting or processing personal data.

Satisfying the obligations that Federal Decree-Law No. 45 of 2021 states in its own text, and making a documented, defensible judgment call wherever the law defers an operational number to Executive Regulations that have never been issued. In practice: a lawful basis for every processing activity, consent as a timestamped record, the data-subject rights served as real endpoints, breach detection with a defensible clock, a DPO where required, a DPIA for high-risk processing, and a processing register.

Articles 13 to 19 give six: access, portability, correction and erasure, restriction of processing, objection (unconditional for direct marketing), and objection to automated decisions with legal or serious effects, which also requires the controller to provide human review on request. Note that the primary text sets no numeric response deadline. The commonly cited 30 days is borrowed from GDPR and has no basis in the UAE text.

The structure is familiar: lawful bases, data-subject rights, breach reporting, a DPO, impact assessments, cross-border rules. The difference is the operational layer. GDPR gives you numbers: 72 hours for a breach, one month for a rights request, a percentage-of-turnover fine ceiling. The UAE PDPL gives you the obligation and, for now, no number attached to any of them, because the Executive Regulations have not been issued.

Yes. Article 2(1)(c) of Federal Decree-Law No. 45 of 2021 extends the law to "any Controller or Processor located outside the State who carries out the activities of Processing Personal Data of Data Subjects inside the State." An offshore engineering team handling the personal data of people in the UAE is inside the scope of the law, regardless of where its servers or its staff sit. Offshore delivery is not a way out of the PDPL.

Yes. This is the most common misunderstanding about the law. Articles 22 and 23 regulate how personal data crosses the border, not whether it may: transfer is lawful to a jurisdiction with adequate protection, or under contractual guarantees, binding corporate rules or explicit consent. General data residency is not a PDPL requirement. Two caveats: health data is governed by a separate law and genuinely may not leave the UAE without a Health Authority decision, and as of February 2026 the UAE Data Office had published no adequacy list and no standard contractual clauses, so the mechanisms exist in law but the paperwork does not yet exist in practice.

Need Expert QA or
Development Help?

Our Expertise

contact
  • AI & DevOps Solutions
  • Custom Web & Mobile App Development
  • Manual & Automation Testing
  • Performance & Security Testing
contact-leading

Trusted by 150+ Leading Brands

contact-strong

A Strong Team of 275+ QA and Dev Professionals

contact-work

Worked across 450+ Successful Projects

Collaborate with Vervali