UAE PDPL vs GDPR: The Differences That Change Your Compliance Programme
The UAE PDPL (Federal Decree-Law No. 45 of 2021) borrows GDPR's structure — controller/processor duties, data subject rights, extraterritorial reach — but diverges on legal bases (no standalone legitimate interest), cross-border transfer routes, DPO triggers and penalty scale. A GDPR programme gives you most controls, but you still need UAE-specific documentation, a transfer review against the Data Office's approach, and a DPO trigger assessment. Executive Regulations remain pending, so several PDPL specifics stay undefined.
On this page
Who this applies to: Controllers and processors handling UAE-resident data, UAE-based fleet operators and IT teams, DPAs and compliance officers running dual GDPR/PDPL programmes.
If your organisation already runs a mature GDPR programme, the honest answer to "how much extra work is UAE PDPL?" is: less than you fear, but more than nothing — and the gaps are specific. This walks through where the two laws align, where they diverge, and what each divergence changes in your controls.
GDPR gives you the machinery. The PDPL asks you to re-point it at UAE data subjects, re-document your legal basis, re-check your transfer routes against the UAE Data Office's approach, and re-run your DPO trigger test. Treat it as a delta project, not a rebuild.
Where do the two laws actually agree?#
Start with the shared DNA, because it's the reason a GDPR programme transfers so well.
Both laws are extraterritorial. The provisions of the UAE law apply to the processing of personal data, whether in full or part through electronic systems, inside or outside the country. In practice that means a controller or processor outside the UAE can still be caught if it processes UAE residents' data — the same logic as GDPR's targeting test.
Both share the controller/processor split, the core data subject rights, an accountability principle, and a breach-notification duty. Under the PDPL, the introduction of data subject rights gives individuals rights over their data such as access, objection, rectification and erasure amongst others (Articles 13–18). The PDPL also imposes accountability obligations on data controllers and processors, requiring them to adopt appropriate technical and organisational measures to ensure and demonstrate compliance. If you already maintain a RoPA, DPIA process, and processor agreements for GDPR, those artefacts largely carry across.
UAE PDPL
Federal Decree-Law No. 45 of 2021
EU GDPR
Regulation (EU) 2016/679
Shared DNA
Controller/processor, DSRs, accountability, extraterritorial reach
What's the single biggest divergence — legal basis?#
Yes. This is the difference most likely to trip a GDPR team.
GDPR gives you six lawful bases in Article 6 — consent, contract, legal obligation, vital interests, public task, and legitimate interests — with no formal hierarchy between them. Legitimate interest, in particular, is the flexible workhorse GDPR programmes lean on for security monitoring, fraud prevention and basic analytics.
The PDPL does not offer that. Unlike the GDPR, the PDPL does not currently include legitimate interest as a standalone basis for personal data processing; consent and specific exceptions play a more central role. The UAE government's own framing is blunt: the law prohibits the processing of personal data without the consent of its owner, except for some cases in which processing is necessary to protect a public interest or to carry out any of the legal procedures and rights.
What this changes: any activity you currently justify under legitimate interest needs a fresh look for the UAE. Either it fits a PDPL exception (contract performance, legal obligation, public interest) or it needs consent. The practical fix is to document a valid basis for every processing activity under both regimes — that way a single mapping satisfies GDPR's Article 6 and the PDPL simultaneously, and you're not exposed if a legitimate-interest justification doesn't hold up in a UAE context.
How different are cross-border transfers?#
Structurally similar, mechanically different — and this is where dual-compliance operators spend real effort.
The PDPL restricts transfers out of the UAE. It permits data transfer outside the UAE only if the destination country provides adequate protection as deemed by the UAE Data Office, or if the transfer is covered by appropriate safeguards such as approved contracts or BCRs, or based on exceptions such as explicit consent. The mechanism lives in the statute: Articles 22 and 23 of the PDPL state when cross-border flows of personal data outside the UAE are permitted based on whether there is an adequate level of protection in each destination country. For a country not yet on the list, Article 22 clarifies that where the state has personal data protection legislation in place and appropriate legal recourse for the individual, a cross-border transfer can take place.
The catch for the export side: the UAE is not a shortcut in the other direction. The UAE is not on the European Commission's list of countries with adequate data protection. So a transfer from the EU into the UAE still needs a GDPR mechanism — typically SCCs. Meanwhile the destination adequacy list the PDPL relies on is tied to the pending Executive Regulations, so the UAE-side "adequate country" route is not yet fully operational — verify the current status with the UAE Data Office.
What this changes: map every overseas data flow in both directions. For EU-to-UAE flows, keep your SCCs. For UAE-outbound flows, document which PDPL route each transfer relies on (adequacy, contractual safeguard, or an exception such as explicit consent) rather than assuming your GDPR paperwork covers it.
| Transfer question | GDPR | UAE PDPL |
|---|---|---|
| Adequacy route | Commission adequacy decisions | Adequacy assessed by the UAE Data Office (list tied to pending Executive Regulations) |
| Contractual route | Standard Contractual Clauses, BCRs | Approved contracts / BCRs; specifics in Executive Regulations |
| Consent route | Explicit consent (as a derogation) | Explicit consent as an exception (Articles 22–23) |
| Is the counterpart "adequate"? | UAE not on EU adequacy list | Destination list not yet published |
Do the DPO and breach rules differ enough to matter?#
The triggers differ, so re-run the test rather than copying your GDPR conclusion.
Under the PDPL, a DPO is conditional. By virtue of Article 10, the controller and processor must designate a DPO if their data processing presents significant risks to personal data privacy as a consequence of adopting new or size-based technologies, involves large-scale sensitive data, or includes systematic profiling or automated processing. Below that threshold it is not mandatory: controllers below the mandatory threshold — including most SMEs processing only ordinary employee and customer data at modest scale — are not legally required to appoint a DPO, though a voluntary appointment demonstrates accountability and can reduce investigative risk. Usefully, the DPO can be based inside or outside the UAE, and their contact details must be shared with the Data Office.
On breaches, the PDPL sets the duty in statute but leaves the clock to the regulations. Article 9 mandates breach notification to the UAE Data Office and, where the breach is likely to result in risk to data-subject rights, to affected individuals; specific timeframes and notification format are expected to be clarified by the Executive Regulations. GDPR, by contrast, fixes the well-known 72-hour reporting window. Don't hard-code a PDPL deadline from a secondary source — verify the notification timeline with the UAE Data Office.
DPIAs align closely: Article 21 requires a Data Protection Impact Assessment before commencing processing that poses high risk to data subject privacy, with triggers including modern technologies, large-scale sensitive-data processing, and automated profiling.
DPO trigger
ConditionalPDPL Art. 10
High-risk, large-scale sensitive data, or systematic profiling. Not mandatory below threshold.
Breach notice
PendingPDPL Art. 9
Duty is in force; exact timeframe awaits Executive Regulations. Verify with the Data Office.
DPIA
In forcePDPL Art. 21
Required before high-risk processing. Closely mirrors GDPR.
View as table
| Regime | Who it binds | Status |
|---|---|---|
| DPO trigger | PDPL Art. 10 | Conditional — High-risk, large-scale sensitive data, or systematic profiling. Not mandatory below threshold. |
| Breach notice | PDPL Art. 9 | Pending — Duty is in force; exact timeframe awaits Executive Regulations. Verify with the Data Office. |
| DPIA | PDPL Art. 21 | In force — Required before high-risk processing. Closely mirrors GDPR. |
What about penalties?#
Different scale, and the PDPL's figures are not yet settled.
GDPR's ceiling is the headline number: under Article 83, infringements of the basic principles for processing including conditions for consent, data subjects' rights, and cross-border transfers are subject to administrative fines up to EUR 20 million, or in the case of an undertaking up to 4% of total worldwide annual turnover, whichever is higher.
The PDPL's enforcement is younger and less defined. The GDPR has mature enforcement structures and well-established fines, while the PDPL's enforcement mechanisms, including how fines will be quantified, are evolving with the anticipated Executive Regulations — but the PDPL imposes strict obligations and carries meaningful penalties. The Data Office is the enforcing body: it possesses investigation and enforcement powers, including audits, corrective orders, and administrative sanctions. Trade press has floated specific AED figures, but with the Executive Regulations still pending, treat exact PDPL penalty amounts as unverified and confirm with the UAE Data Office before citing any number to your board.
What should change in your programme this quarter?#
If you run GDPR today, this is the delta.
Re-scope
- Confirm which of your processing activities touch UAE-resident data
- Re-run the Article 10 DPO trigger test for UAE processing
Re-document
- Replace any legitimate-interest basis with consent or a PDPL exception for UAE activities
- Document a valid legal basis for every activity so GDPR and PDPL are both satisfied
- Update privacy notices to state PDPL compliance and the transfer routes used
Re-check transfers
- Map all UAE-outbound flows to a PDPL route (adequacy, safeguard, or consent)
- Keep SCCs for EU-to-UAE flows — UAE is not EU-adequate
Re-verify dates
- Confirm breach-notification timeframe with the UAE Data Office
- Track the Executive Regulations for penalty and transfer specifics
A closing caution on the moving parts. As of early 2025 the Executive Regulations had not yet been published; once issued, organisations get a further six months from that date to adjust operations to compliance. That means several PDPL specifics — transfer list, exact fine schedule, breach clock — remain "developing". Build the controls you can build now, and leave verifiable placeholders where the regulations haven't landed. For flag-state or free-zone questions (DIFC and ADGM run their own regimes), consult your counsel.
If you'd like a structured gap assessment mapping your current GDPR controls against the PDPL delta, book a consultation and we'll scope the specific remediation steps for your organisation.
Frequently asked
Does GDPR compliance make me PDPL compliant?
No. GDPR gives you most of the controls — consent, security, data subject rights — but the PDPL needs UAE-specific documentation, a transfer review against the Data Office's adequacy approach, and its own DPO trigger assessment. Do not assume automatic overlap.
Can I rely on legitimate interest under the PDPL like I do under GDPR?
Not as a standalone basis. Unlike GDPR Article 6, the PDPL centres on consent plus specific exceptions and does not currently include legitimate interest as a named lawful basis. Document a valid basis for every activity so both regimes are satisfied.
Is the UAE on the EU adequacy list?
No. The UAE is not on the European Commission's list of adequate countries, so exporting personal data from the EU to the UAE still needs a GDPR transfer mechanism such as Standard Contractual Clauses.
Do I need a Data Protection Officer under the PDPL?
Only where processing triggers it — high-risk activities, large-scale sensitive data, or systematic profiling under Article 10. Below that threshold a DPO is not legally required, though a voluntary appointment supports accountability.
What are the PDPL penalties compared with GDPR?
GDPR fines run up to EUR 20 million or 4% of global turnover under Article 83. PDPL penalty amounts and the enforcement mechanics are still being defined in the pending Executive Regulations — verify current figures with the UAE Data Office before relying on any number.

Bring the control-by-control questions
Your environment, your regulators, and your hardest question. We answer control by control, and we publish where the overlay stops before you ask.
