Skip to main content
Insights/UAE Compliance
UAE Compliance

UAE PDPL Breach Notification: What to File and When

Published 8 min read
The short answer

Under Article 9 of the UAE PDPL (Federal Decree-Law No. 45 of 2021), a controller must report a personal data breach to the UAE Data Office immediately on becoming aware of it where the breach would prejudice the privacy, confidentiality or security of the data. The notification must describe the breach, its likely effects, the number of records and subjects affected, and the remedial steps taken. The law says "immediately" — the specific timeframe and forms were left to Executive Regulations, which have not been reliably confirmed as published on official UAE sources. Processors must notify their controller as soon as they become aware.

On this page

Who this applies to: Controllers and processors handling personal data of people in the UAE mainland — excludes DIFC and ADGM free zones, which run separate regimes.

The honest starting point: the UAE PDPL's breach rule is written, in force, and specific about what you file — but deliberately vague about when, because the timing was pushed into Executive Regulations that we cannot confirm as published on any official UAE source. That gap shapes everything below.

Watch out

Multiple compliance sites state a firm "72-hour" PDPL deadline and cite an "Article 11." The primary law text uses the word "immediately" and places the breach duty in Article 9. Do not build your runbook around 72 hours as a settled federal rule. Build it around "immediately," and verify any numeric deadline directly with the UAE Data Office.

What does the PDPL actually require, and where is it written?#

The obligation lives in Article 9 of Federal Decree-Law No. 45 of 2021. The controller shall, immediately upon becoming aware of any infringement or breach of the personal data of the data subject that would prejudice the privacy, confidentiality and security of such data, report the breach and the results of the investigation to the Office within such period and in accordance with such procedures and conditions as set by the Executive Regulations.

Read that carefully. The trigger is a breach that would prejudice the privacy, confidentiality and security of the data — a risk threshold, not every incident. The verb is "immediately." And the precise period, procedures and forms were handed to Executive Regulations.

The processor sits in the chain too. The processor shall, immediately upon becoming aware of any infringement or breach of the personal data of the data subject, notify the controller of such breach in order for the controller, in turn, to report it to the Office. So the processor's duty runs to your controller, not to the regulator directly — which is why your processor contracts need an explicit, fast notification clause.

After you report, the regulator does not just file it. The Office shall verify the causes of the breach to ascertain the integrity of the security measures taken. In other words, your notification opens an assessment of whether your controls were adequate in the first place.

Who does this actually apply to?#

The PDPL reaches broadly by design. It applies to the processing of personal data by any data controller or data processor located in the UAE processing the personal data of data subjects residing or working within or outside the UAE.

Two carve-outs matter for breach planning. First, sectoral data is excluded. The PDPL does not apply to types of data for which other legislation is in place, including government data, personal data held by security and judicial authorities, personal health data, or personal financial data. Financial institutions, for instance, face separate breach duties — Licensed Financial Institutions must notify the CBUAE of significant breaches and must notify consumers without undue delay where a breach may pose a risk to their financial and personal security.

Second, the free zones run their own regimes. If you sit in DIFC or ADGM, the federal PDPL is not your instrument.

UAE PDPL (mainland)

In force

Federal Decree-Law 45/2021, Art. 9

Controller notifies UAE Data Office 'immediately'; timeframe/forms left to Executive Regulations (not confirmed published).

DIFC

In force

DP Law 5/2020 (amended 2025)

Breach reported to the DIFC Commissioner via the DIFC breach reporting form and portal.

ADGM

In force

DP Regulations 2021, Art. 32

Controller informs the Commissioner without undue delay, and where feasible not later than 72 hours.

CBUAE-regulated

Overlay

Consumer Protection Regulation, Art. 6

Licensed Financial Institutions notify CBUAE of significant breaches and affected consumers without undue delay.

View as table
RegimeWho it bindsStatus
UAE PDPL (mainland)Federal Decree-Law 45/2021, Art. 9In force — Controller notifies UAE Data Office 'immediately'; timeframe/forms left to Executive Regulations (not confirmed published).
DIFCDP Law 5/2020 (amended 2025)In force — Breach reported to the DIFC Commissioner via the DIFC breach reporting form and portal.
ADGMDP Regulations 2021, Art. 32In force — Controller informs the Commissioner without undue delay, and where feasible not later than 72 hours.
CBUAE-regulatedConsumer Protection Regulation, Art. 6Overlay — Licensed Financial Institutions notify CBUAE of significant breaches and affected consumers without undue delay.

What exactly do you file?#

The content of the notification is the part the law is clearest about. Pull these together before you sit down to draft, because assembling them is what eats the clock.

Based on the PDPL and the way the Office is expected to assess it, the notification should include:

  • A description of the nature, form and cause of the breach.
  • The approximate number of affected records and data subjects. The breach notification to the UAE Data Office must include a description of the nature of the breach and the categories and approximate number of affected data subjects.
  • The likely consequences, and the measures and remedial action taken. The controller must observe the nature, category, reasons and approximate number of data breach records, a description of the likely consequences, and a description of the measures and remedial action taken.
  • Contact details for your DPO or responsible person.
  • Supporting documentation, and documentation of the data breach and any other requirements requested by the Office.

This maps almost exactly onto the GDPR Article 33 content set and the DIFC form, so if you already run a GDPR-style breach template you are most of the way there. The DIFC list is a useful checklist to borrow: a description of the nature of the breach including the categories and approximate number of data subjects and records concerned; the name and contact details of the DPO or other contact point; a description of the likely consequences; and the measures taken or proposed to address it.

And you do not have to have everything perfect before you file. Where it is not possible to provide all the information at the same time, it may be provided in phases, as it becomes available. An initial notification that flags "scope still under investigation" is better than a late, complete one.

When is the clock — and why is the answer unsatisfying?#

Here is where you need to hold two facts at once.

The primary law says "immediately." The specific number does not exist in the verified text. The Executive Regulations that would set it have been outstanding for years — they were due within six months of the PDPL's issuance, but as of early 2025 had not been published. More recent primary-source checking reached the same conclusion: the Executive Regulations could not be found on the UAE Legislation portal, whose entry for Federal Decree-Law No. 45 of 2021 lists no related legislation, nor on the UAE Government portal's data protection page; several commercial sites cite specific Cabinet decision numbers as the implementing regulations, but those could not be verified against an official source.

So when a compliance vendor tells you "72 hours, Article 11," treat it as a sensible operating assumption imported from neighbouring regimes, not verified UAE federal law. The 72-hour figure is real and verifiable next door: under Article 32(1) of the ADGM Data Protection Regulations 2021, the data controller must inform the Commissioner without undue delay, and where feasible not later than 72 hours after becoming aware.

The practical takeaway is that "immediately" is arguably stricter than 72 hours, not looser. Run to the tighter standard.

Tip

Treat the clock as starting when you have reasonable certainty a breach occurred — not when suspicion first arises, and not when the full forensic picture is complete. Start your internal response on credible suspicion and prepare the regulator notification in parallel, so filing is a decision, not a scramble.

What should Gulf operators do now?#

The uncertainty is not an excuse to wait. The obligation is live, and enforcement posture is tightening.

1

Before any incident

  • Confirm your jurisdiction: PDPL mainland vs DIFC vs ADGM vs CBUAE overlay. One incident can trigger more than one.
  • Build a breach notification template pre-mapped to the Article 9 content set (nature, cause, numbers, consequences, remediation, DPO contact).
  • Add explicit processor-to-controller notification clauses with a hard internal deadline (e.g. 24 hours) in every processing contract.
  • Define your 'awareness' trigger and who owns the go/no-go decision to notify.
2

When a breach is suspected

  • Start the response and the notification draft in parallel from credible suspicion.
  • Run the risk-threshold test: would this prejudice privacy, confidentiality or security? Document the assessment either way.
  • If access cannot be ruled out in time, file on a precautionary basis and mark scope as under investigation.
3

After filing

  • Supplement the notification in phases as facts firm up.
  • Assess whether affected individuals must be told where high risk is present.
  • Keep a written record of the breach, its effects and remedial action — the Office assesses the adequacy of your controls.

Two final points. Employee data counts — the PDPL applies to all personal data of natural persons, including employees, so a breach of names, Emirates IDs, salary or health information triggers the same obligations as a customer-data breach. And the reason to get this right is not hypothetical: the UAE Data Office has escalated enforcement activity from 2025 onward — investigating complaints, issuing fines and publishing enforcement notices — with breach notification and technical security measures among the primary focus areas.

Because the timing rule and penalty schedule still depend on regulations we cannot confirm are published, do not rely on any specific deadline or fine figure from a secondary source. Verify the current position with the UAE Data Office, and treat "immediately" as your working standard until an official timeframe is confirmed.

If you want your breach runbook, processor clauses and jurisdiction mapping reviewed against the PDPL as it actually stands today — not as blog posts describe it — book a consultation with the Solas Security compliance team.

Frequently asked

Is the UAE PDPL breach deadline 72 hours?

The PDPL text itself says "immediately," not 72 hours. Article 9 leaves the precise timeframe to the Executive Regulations. Several commentators cite 72 hours by analogy to GDPR and the ADGM regime, but that figure is not established in the primary law text we could verify. Treat "immediately" as the operative standard and verify any specific deadline with the UAE Data Office.

Who has to notify — the controller or the processor?

The controller notifies the UAE Data Office. Under Article 9, a processor that becomes aware of a breach must notify its controller so the controller can report to the Office. Build this handoff into your processor contracts.

Does the PDPL apply if we are in DIFC or ADGM?

No. The federal PDPL applies to the UAE mainland. DIFC (Data Protection Law No. 5 of 2020, as amended in 2025) and ADGM (Data Protection Regulations 2021) run their own regimes with their own breach-reporting rules and portals. Identify your jurisdiction first.

What must the breach notification contain?

A description of the nature and cause of the breach, the approximate number of affected records and data subjects, the likely consequences, contact details for your DPO or responsible person, and the measures taken to address and mitigate it. Supporting documentation and anything else the Office requests should follow.

What happens if we do not notify?

The Office can verify the breach, assess whether your security measures were adequate, and impose administrative penalties. Penalty detail sits in regulation; commentators reference a cap referenced at AED 5 million, which you should verify with the UAE Data Office before relying on it.

Vishnu Karakkatt

Written by

Vishnu Karakkatt

CEO & Founder

Meet the team
Talk to a practitioner

Get a security consultation

Bring your environment, your regulators, and your hardest question. We answer control-by-control.