DATA PROTECTION LAW IN THE UAE : SIX THINGS CHANGING IN 2026

Companies setting up in the UAE usually ask one question: what does UAE data protection law require? The question assumes a single answer, but there isn’t one. In the UAE, a federal privacy law operates alongside separate laws in the financial free zones, health legislation cutting across all of them, and regulator standards carrying practical weight. Two companies on opposite sides of the same road in Dubai can owe quite different obligations over the same data.

WHICH LAWS ARE WE ACTUALLY TALKING ABOUT?

Four sets of rules do most of the work.

  • Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL“) is the country-wide privacy law, and the closest thing the UAE has to a general standard. It borrows its architecture from the European GDPR.
  • DIFC Law No. 5 of 2020 governs businesses in the Dubai International Financial Centre, which has its own Commissioner of Data Protection, registration system and fines.
  • The ADGM Data Protection Regulations 2021 do the same for the Abu Dhabi Global Market, enforced by its Office of Data Protection. Both these regimes follow the GDPR more closely than the PDPL and in several respects ask for more.
  • Federal Law No. 2 of 2019 on the use of information technology in healthcare (the “Health Data Law“) sits across the whole system, as do sector rules issued by health, banking, insurance and telecoms regulators. A handful of zones, such as Dubai Healthcare City, have narrower regulations of their own.

SO WHICH LAW APPLIES TO YOUR BUSINESS?

This is what catches people out, because the answer does not follow from the licence.

  • The PDPL steps back where a free zone has its own specialised data protection legislation. Only the DIFC and ADGM currently have one, so all the other free zones continue to be regulated by the PDPL.
  • Where a company is licensed is not where it necessarily processes data. Where information is actually collected, stored and accessed often differs from where the entity is registered, and the analysis tends to follow the processing.
  • Group structures multiply this. A mainland trading company, a DIFC holding entity and an engineering team abroad can pull three regimes onto one customer database.
  • These laws also reach outward. The PDPL can capture the handling of UAE residents’ data from overseas, and the free zone laws can capture businesses selling into the zone from outside.

The words “free zone” on a licence do not automatically indicate which privacy law governs the company holding it. Settling this at the outset, with UAE counsel who work across these regimes regularly, costs far less than discovering it later on.

WHY IS HEALTH DATA TREATED DIFFERENTLY?

  • The Health Data Law applies across the UAE, free zones included, to anyone providing services in the health sector. Unlike the PDPL, it does not stand aside for free zone regimes.
  • Its restriction on sending health data abroad is the sharpest edge. Subject to limited exceptions under Ministerial Decision No. (51) of 2021, health data generated in the UAE is expected to stay there, which routinely collides with cloud architecture designed for a global product.
  • It requires records to be kept for long fixed periods (25 years), cutting against the instinct to delete data once its purpose is spent. Health authorities such as the Ministry of Health and Prevention, as well as those in Dubai (the Dubai Health Authority) and Abu Dhabi (the Department of Health – Abu Dhabi) then add licensing conditions, mandatory connection to their health information exchanges and cybersecurity standards.
  • “Health data” is broader than hospital records. Wellness, fitness, nutrition and mental health apps regularly sit inside a perimeter their founders assumed they were outside.

Whether a digital health or wellness product falls inside that perimeter is a matter of legal analysis with licensing, hosting and personal liability attached, and one worth putting to a UAE-qualified adviser before the technology is built.

WHAT DO THESE LAWS BROADLY REQUIRE?

The detail differs between regimes, but the shape of the obligations is broadly familiar.

  • A lawful reason to process personal data at all, whether consent, a contract, a legal duty or a legitimate business interest, settled before collection.
  • Clear notice to individuals about what is collected and why, and a means of honouring their rights to access, correct, delete or port their data.
  • Security measures proportionate to the risk, and written terms imposing equivalent standards on vendors.
  • Notification of significant breaches to the relevant regulator, and sometimes to affected individuals, within short timeframes.
  • A designated data protection officer where processing is large-scale or sensitive, plus internal records of processing activities.
  • A lawful route for sending personal data abroad, usually an adequate jurisdiction as determined by the relevant regulator, or approved contractual protections.

WHAT HAPPENS WHEN MORE THAN ONE APPLIES?

  • The PDPL expressly excludes health data governed by its own legislation, so health information falls to the Health Data Law. Banking and credit data are carved out on the same basis.
  • The DIFC and ADGM displace the PDPL for entities registered in or processing within those zones. The Health Data Law is not displaced in the same way, and is understood to reach healthcare activity inside them.
  • Precedence is less about ranking than scope. Each law claims a slice defined by territory, sector or activity, and one business can sit in several at once.
  • Enforcement can be uneven in practice. The free zone commissioners are visibly active while federal enforcement has matured more slowly, leading some businesses to underestimate exposure and forget that licensing authorities and sector regulators enforce in their own right.

WHAT SHOULD A BUSINESS DO FIRST?

  • Map the data before the entities. Establish where personal data is collected, stored and accessed, then work out which rulebook follows.
  • Settle the jurisdictional question before drafting policies. A privacy notice written for the wrong jurisdiction and laws can be detrimental, as it may create obligations and make commitments that do not actually apply to the business.
  • Treat the choice of free zone as a data decision as much as a tax or licensing one. It is cheap to revisit before incorporation, expensive afterwards.

CONCLUSION

The UAE has built a credible data protection framework that is recognised internationally. What it has not built is a single one. The federal law, the free zone laws and the sector rules answer to different regulators with different priorities, and the boundaries between them are rarely visible from outside. Businesses treating UAE data protection as one exercise tend to find out otherwise during a transaction, an audit or an incident. Working through the analysis early, with experienced UAE counsel, turns an open-ended risk into a manageable one.

Authors: Shantanu Mukherjee, Varun Alase

Leave Us A Message

Cookie Consent with Real Cookie Banner