UAE legal support · Confidential consultations

Active / in force2021

Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data

Federal Decree-Law No. (45) of 2021

The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.

Editorial cover for Federal Decree-Law No. (45) of 2021 — Protection of Personal Data
CategoryTelecommunication, Technology & Space
JurisdictionUnited Arab Emirates
Issuing authorityUnited Arab Emirates Federal Government
Issued20 September 2021
Effective2 January 2022
Source checked7 September 2026

Overview

What this legislation covers

The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.

Who or what it applies to

  • Controllers and processors established in the UAE within the decree-law's scope.
  • Certain controllers/processors outside the UAE that process personal data of data subjects inside the UAE, subject to the statutory scope.
  • Natural persons whose personal data is processed under the federal regime.
  • Does not automatically replace sector-specific or free-zone data-protection regimes where the statute excludes them.

Key points

Important points at a glance

01

Entered into force on 2 January 2022.

02

Creates a federal framework for processing personal data within its statutory scope.

03

Contains exclusions for specified government, health, banking/credit and personal/domestic processing contexts where other legislation applies.

04

Requires lawful and transparent processing and limits processing to appropriate purposes.

05

Regulates consent and other permitted bases for processing.

06

Creates data-subject rights concerning information, access, transfer/portability, correction, deletion and restriction/objection subject to statutory conditions.

07

Defines controller and processor responsibilities.

08

Requires security measures appropriate to processing risks.

09

Contains personal-data-breach notification requirements subject to the statutory/implementing framework.

10

Provides for Data Protection Officers in specified higher-risk circumstances.

11

Requires impact assessments for specified high-risk processing.

12

Regulates automated processing/profiling rights in the circumstances described by the law.

13

Regulates cross-border transfer and sharing of personal data.

14

Creates oversight/complaint mechanisms involving the UAE Data Office.

15

Article 31 provides for commencement on 2 January 2022.

Practical explanation

Understanding the law

Purpose and practical effect

The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.

Who the law applies to

  • Controllers and processors established in the UAE within the decree-law's scope.
  • Certain controllers/processors outside the UAE that process personal data of data subjects inside the UAE, subject to the statutory scope.
  • Natural persons whose personal data is processed under the federal regime.
  • Does not automatically replace sector-specific or free-zone data-protection regimes where the statute excludes them.

Key definitions

  • Personal Data: data relating to an identified or identifiable natural person within the statutory definition.
  • Sensitive Personal Data: specially protected categories defined by the law.
  • Controller: the person/entity determining the method, criteria and purpose of processing.
  • Processor: the person/entity processing personal data on behalf of a controller.
  • Data Subject: the natural person to whom the personal data relates.

Main rights, duties and legal consequences

  • Data subjects have statutory transparency and access rights subject to exceptions.
  • Data subjects may request transfer, correction, deletion, restriction or objection where the legal conditions are met.
  • Controllers must establish a lawful basis, implement security and manage processors appropriately.
  • Processors must comply with controller instructions and their own statutory security/confidentiality obligations.

Practical compliance / procedure checklist

  1. Map data categories, purposes, systems, recipients and retention.
  2. Identify the statutory legal basis for each processing purpose.
  3. Implement notices, consent mechanisms where required, and data-subject request procedures.
  4. Put controller-processor terms and security controls in place.
  5. Assess whether DPO appointment or a data-protection impact assessment is required.
  6. Document the permitted basis/safeguards before a cross-border transfer.
  7. Maintain a breach-response process and use the current official notification rules.

Deadlines and effective dates

  • Effective date: 2 January 2022.
  • Data-subject response, breach notification and other operational periods must be checked against the current decree-law and implementing decisions.
  • Retention must be purpose- and law-based rather than indefinite.

Enforcement, violations and penalties

The decree-law provides for oversight, complaints and administrative enforcement. Sector-specific or other criminal/cybercrime consequences can also apply to misuse or unlawful disclosure of data. Specific sanctions should be verified against current implementing decisions.

Practical scenarios

  1. An e-commerce business collecting customer identity and delivery data should document lawful purposes, retention and processor access.
  2. A company transferring customer data to an overseas cloud provider should assess the cross-border transfer provisions before transfer.
  3. A high-risk biometric system may require a DPO and/or data-protection impact assessment.
  4. A data breach should trigger documented containment, risk assessment and the notification process required by current rules.

Amendments and implementation

The federal data-protection framework should be read with current UAE Data Office rules and any sector-specific legislation applicable to the processing.

Legal research caution

The principal federal statute, its amendments, Executive Regulations, Cabinet/Ministerial/FTA/MOHRE/TDRA decisions and sector-specific rules can operate together. Commentary in this file explains practical operation but does not create duties beyond enacted law. Always confirm the current version applicable to the date and facts in question.

Research status

Official-source review for this package was updated on 2026-09-07.

Practical notes

  • Use the official current Arabic text for interpretation and application; the English package is a structured legal-information rendering.
  • Verify the current consolidated version and related regulations immediately before a filing, transaction, enforcement decision or court submission.
  • Exact penalties, thresholds, exceptions and procedural deadlines must be checked against the exact current article and implementing instrument.
  • The supplied cover artwork is used as an editorial cover only and is not a source of legal authority.

Legislation text

Text and provisions

Source control matters.Use the official source link below for the authoritative current text and amendments. This library copy is provided for research and accessibility.
Official-text notice. This file is a comprehensive structured English legal-information rendering based on the official UAE sources listed in this package. It is not presented as a verbatim legally controlling English reproduction. For interpretation and application, consult the original Arabic text, the Official Gazette and the latest consolidated official legislation. Exact offence elements, penalties, exceptions, thresholds and deadlines must be checked against the current article.

Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data

Verified legislative metadata

InstrumentFederal Decree-Law No. (45) of 2021
Issued2021-09-20
Effective2022-01-02
StatusActive / in force
Official sourceOfficial UAE source

Legislative purpose and coverage

The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.

Complete statutory structure and principal provisions

Definitions and scope

Defines personal data, sensitive personal data, biometric data, controller, processor, data subject and related concepts; sets territorial and material scope and exclusions.

Processing principles

Requires fair, lawful, transparent and purpose-related processing with accuracy, security and appropriate retention.

Consent and lawful processing

Regulates valid consent and circumstances where processing may occur without consent under the law.

Data-subject information and access rights

Provides rights to know about processing and obtain information/access subject to exceptions.

Portability, correction and erasure

Creates rights to data transfer/portability and to request correction, updating or deletion in the circumstances stated by law.

Restriction, objection and automated decisions

Provides controls over continued processing and rights relating to certain automated processing/profiling decisions.

Controller obligations

Requires governance, processing records/controls, protection measures and cooperation with rights requests.

Processor obligations

Requires processors to act within lawful instructions and satisfy statutory security/cooperation duties.

Security and breach management

Requires technical/organisational safeguards and a breach-response framework.

Data Protection Officer and impact assessment

Requires DPO appointment and data-protection impact assessments in specified high-risk circumstances.

Cross-border transfers

Regulates transfer/sharing of personal data outside the UAE using adequacy or other permitted safeguards/routes.

Data Office, complaints and enforcement

Provides institutional oversight, complaints and implementing/enforcement mechanisms.

Final provisions

Provides implementing powers, repeal of conflicting provisions and commencement on 2 January 2022.

Key statutory points

  • Entered into force on 2 January 2022.
  • Creates a federal framework for processing personal data within its statutory scope.
  • Contains exclusions for specified government, health, banking/credit and personal/domestic processing contexts where other legislation applies.
  • Requires lawful and transparent processing and limits processing to appropriate purposes.
  • Regulates consent and other permitted bases for processing.
  • Creates data-subject rights concerning information, access, transfer/portability, correction, deletion and restriction/objection subject to statutory conditions.
  • Defines controller and processor responsibilities.
  • Requires security measures appropriate to processing risks.
  • Contains personal-data-breach notification requirements subject to the statutory/implementing framework.
  • Provides for Data Protection Officers in specified higher-risk circumstances.
  • Requires impact assessments for specified high-risk processing.
  • Regulates automated processing/profiling rights in the circumstances described by the law.
  • Regulates cross-border transfer and sharing of personal data.
  • Creates oversight/complaint mechanisms involving the UAE Data Office.
  • Article 31 provides for commencement on 2 January 2022.

Amendments, executive regulations and related legislation

The federal data-protection framework should be read with current UAE Data Office rules and any sector-specific legislation applicable to the processing.

Reading rule for case-specific use

This structured rendering is designed to give the website a complete substantive map of the legislation and its operative areas. Where a legal conclusion turns on precise wording, an article number, a penalty, an exception, an implementing decision or a transitional rule, the official Arabic text and current related legislation must be used before reliance.

Verification

Official source & references

Official legislation sourcehttps://uaelegislation.gov.ae/en/legislations/1972Open ↗