EnglishEspañol

UAE PDPL vs. GDPR: Federal Law, DIFC, and ADGM Compared

Independently fact-checkedBy Recording Law Editorial Team19 min read

Independently fact-checked against primary sources (last audited July 23, 2026). · 15 primary sources cited on this page. How we verify our legal content

UAE PDPL vs. GDPR: Federal Law, DIFC, and ADGM Compared

Frequently Asked Questions

Is the UAE's data protection law the same everywhere in the country?

No. The UAE runs three separate data protection regimes. The federal Personal Data Protection Law covers the mainland and free zones without their own law. The Dubai International Financial Centre and Abu Dhabi Global Market each have their own separate law and regulator, and neither is governed by the federal statute.

Is the UAE's federal PDPL actually enforceable right now?

The law itself has been in force since 2 January 2022, but its Executive Regulations, which were meant to set the specific penalty schedule and procedural detail, have never been issued. The regulator, the UAE Data Office (created by the PDPL's companion statute, Federal Decree-Law No. 44 of 2021), never became operational and was folded into a new Artificial Intelligence and Data Authority in June 2026. There is currently no published penalty schedule and no established federal enforcement pathway.

Are DIFC and ADGM's data protection laws actually enforced?

Yes. Both have standing, active regulators. ADGM's Office of Data Protection has issued two published enforcement actions against named companies, a Penalty Notice against Okadoc Technologies in 2024 and a Direction against VentureRock Global in 2023. DIFC's Commissioner is also active, and since July 2025 data subjects can additionally bring a claim directly in the DIFC Courts.

What changed in DIFC's data protection law in 2025?

The DIFC Laws Amendment Law No. 1 of 2025, in force from 15 July 2025, added a private right of action allowing data subjects to sue a controller or processor directly through the DIFC Courts, expanded the law's extraterritorial reach, and tightened the conditions under which data can be disclosed to public authorities.

Can a company transfer data from an ADGM or DIFC entity to its own UAE mainland affiliate without extra safeguards?

This is not a settled 'adequate' transfer under either free zone's rules. Neither DIFC's nor ADGM's published adequacy list includes the UAE mainland or references the federal PDPL, and the federal regime has no adequacy list of its own because the mechanism intended to create one was never operationalized. Treat mainland transfers as an open compliance question rather than a routine intra-group flow.

How does UAE breach notification timing compare to the GDPR's 72-hour rule?

It varies by regime. ADGM sets a comparable standard: without undue delay, and where feasible not later than 72 hours, to its Commissioner. DIFC sets no fixed hour deadline at all for either the regulator or affected individuals, using only an 'as soon as practicable' standard. The federal PDPL sets no deadline at all. Article 9 requires the controller to notify the UAE Data Bureau when it becomes aware of a breach but leaves the actual period to Executive Regulations that have never been issued, so the 72-hour figure sometimes quoted for the UAE federal regime is not in the statute.

Does the UAE federal PDPL have a private right of action like DIFC now does?

No. The federal PDPL does not establish a comparable court-based enforcement mechanism for data subjects, and with the Executive Regulations and operational regulator both still missing, there is no established federal enforcement pathway of any kind at this time.

Will the UAE's new Artificial Intelligence and Data Authority fix the federal PDPL's gaps?

That is not yet confirmed. The June 2026 Cabinet announcement creating the Authority consolidated the UAE Data Office into a new body focused on AI, the digital economy, and digital government, but the announcement itself did not mention the PDPL or commit to finishing its Executive Regulations. Some legal commentators expect the Authority to eventually take up that task, but this is an outside inference, not a stated government commitment.

Updates

Independently fact-checked against the cited primary sources

The UAE's Vice President and Prime Minister, Sheikh Mohammed bin Rashid Al Maktoum, approved the establishment of a new Artificial Intelligence and Data Authority, consolidating the UAE Data Office (the federal PDPL's intended regulator, which never became operational) with two other government digital and AI bodies. The announcement did not address the status of the PDPL's still-unissued Executive Regulations.

DIFC Laws Amendment Law No. 1 of 2025 entered into force, adding a private right of action through the DIFC Courts, expanding the Data Protection Law's extraterritorial reach, and tightening the standard for disclosing data to public authorities.

Sources and References

  1. Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data — official legislation record (issued, gazette, effective dates, active status)(uaelegislation.gov.ae).gov
  2. UAE government page on data protection laws and the Data Office(u.ae).gov
  3. UAE Cabinet announcement: Mohammed bin Rashid approves establishing the Artificial Intelligence and Data Authority (14 June 2026)(uaecabinet.ae).gov
  4. DIFC Data Protection Law No. 5 of 2020 — legal database entry(difc.com).gov
  5. DIFC announces enactment of amendments through DIFC Laws Amendment Law No. 1 of 2025(difc.com).gov
  6. DIFC Commissioner of Data Protection — Data Export and Sharing (cross-border transfer, adequacy list)(difc.com).gov
  7. DIFC Data Protection Law No. 5 of 2020 — consolidated text (Articles 41-42 breach notification, Schedule 2 penalties)(difc.com).gov
  8. ADGM Office of Data Protection — overview(adgm.com).gov
  9. ADGM Office of Data Protection — registration and renewal fees(adgm.com).gov
  10. ADGM Office of Data Protection — adequate jurisdictions for cross-border transfer(adgm.com).gov
  11. ADGM Office of Data Protection — regulatory actions (Okadoc Technologies Penalty Notice; VentureRock Global Direction Notice)(adgm.com).gov
  12. ADGM Data Protection Regulations 2021, consolidated text, official ADGM Rulebook (sections 32-33 breach notification, sections 55 and 59 penalties and compensation). NOTE: also change this citation's domain field from 'adgm.com' to 'en.adgm.thomsonreuters.com' (the URL's actual host), and note the DPR uses 'sections' not 'Articles'.(en.adgm.thomsonreuters.com).gov
  13. Regulation (EU) 2016/679 (General Data Protection Regulation)(eur-lex.europa.eu).gov
  14. DIFC Commissioner of Data Protection, Supervision and Enforcement (published decision notices and administrative fine volumes)(difc.com).gov
  15. Federal Decree-Law No. 44 of 2021 establishing the Emirates Data Office(uaelegislation.gov.ae).gov
Share: