Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data
Federal Decree-Law No. (45) of 2021
The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.

Overview
What this legislation covers
The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.
Who or what it applies to
- Controllers and processors established in the UAE within the decree-law's scope.
- Certain controllers/processors outside the UAE that process personal data of data subjects inside the UAE, subject to the statutory scope.
- Natural persons whose personal data is processed under the federal regime.
- Does not automatically replace sector-specific or free-zone data-protection regimes where the statute excludes them.
Key points
Important points at a glance
Entered into force on 2 January 2022.
Creates a federal framework for processing personal data within its statutory scope.
Contains exclusions for specified government, health, banking/credit and personal/domestic processing contexts where other legislation applies.
Requires lawful and transparent processing and limits processing to appropriate purposes.
Regulates consent and other permitted bases for processing.
Creates data-subject rights concerning information, access, transfer/portability, correction, deletion and restriction/objection subject to statutory conditions.
Defines controller and processor responsibilities.
Requires security measures appropriate to processing risks.
Contains personal-data-breach notification requirements subject to the statutory/implementing framework.
Provides for Data Protection Officers in specified higher-risk circumstances.
Requires impact assessments for specified high-risk processing.
Regulates automated processing/profiling rights in the circumstances described by the law.
Regulates cross-border transfer and sharing of personal data.
Creates oversight/complaint mechanisms involving the UAE Data Office.
Article 31 provides for commencement on 2 January 2022.
Practical explanation
Understanding the law
Purpose and practical effect
The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.
Who the law applies to
- Controllers and processors established in the UAE within the decree-law's scope.
- Certain controllers/processors outside the UAE that process personal data of data subjects inside the UAE, subject to the statutory scope.
- Natural persons whose personal data is processed under the federal regime.
- Does not automatically replace sector-specific or free-zone data-protection regimes where the statute excludes them.
Key definitions
- Personal Data: data relating to an identified or identifiable natural person within the statutory definition.
- Sensitive Personal Data: specially protected categories defined by the law.
- Controller: the person/entity determining the method, criteria and purpose of processing.
- Processor: the person/entity processing personal data on behalf of a controller.
- Data Subject: the natural person to whom the personal data relates.
Main rights, duties and legal consequences
- Data subjects have statutory transparency and access rights subject to exceptions.
- Data subjects may request transfer, correction, deletion, restriction or objection where the legal conditions are met.
- Controllers must establish a lawful basis, implement security and manage processors appropriately.
- Processors must comply with controller instructions and their own statutory security/confidentiality obligations.
Practical compliance / procedure checklist
- Map data categories, purposes, systems, recipients and retention.
- Identify the statutory legal basis for each processing purpose.
- Implement notices, consent mechanisms where required, and data-subject request procedures.
- Put controller-processor terms and security controls in place.
- Assess whether DPO appointment or a data-protection impact assessment is required.
- Document the permitted basis/safeguards before a cross-border transfer.
- Maintain a breach-response process and use the current official notification rules.
Deadlines and effective dates
- Effective date: 2 January 2022.
- Data-subject response, breach notification and other operational periods must be checked against the current decree-law and implementing decisions.
- Retention must be purpose- and law-based rather than indefinite.
Enforcement, violations and penalties
The decree-law provides for oversight, complaints and administrative enforcement. Sector-specific or other criminal/cybercrime consequences can also apply to misuse or unlawful disclosure of data. Specific sanctions should be verified against current implementing decisions.
Practical scenarios
- An e-commerce business collecting customer identity and delivery data should document lawful purposes, retention and processor access.
- A company transferring customer data to an overseas cloud provider should assess the cross-border transfer provisions before transfer.
- A high-risk biometric system may require a DPO and/or data-protection impact assessment.
- A data breach should trigger documented containment, risk assessment and the notification process required by current rules.
Amendments and implementation
The federal data-protection framework should be read with current UAE Data Office rules and any sector-specific legislation applicable to the processing.
Legal research caution
The principal federal statute, its amendments, Executive Regulations, Cabinet/Ministerial/FTA/MOHRE/TDRA decisions and sector-specific rules can operate together. Commentary in this file explains practical operation but does not create duties beyond enacted law. Always confirm the current version applicable to the date and facts in question.
Research status
Official-source review for this package was updated on 2026-09-07.
Practical notes
- Use the official current Arabic text for interpretation and application; the English package is a structured legal-information rendering.
- Verify the current consolidated version and related regulations immediately before a filing, transaction, enforcement decision or court submission.
- Exact penalties, thresholds, exceptions and procedural deadlines must be checked against the exact current article and implementing instrument.
- The supplied cover artwork is used as an editorial cover only and is not a source of legal authority.
Legislation text
Text and provisions
Official-text notice. This file is a comprehensive structured English legal-information rendering based on the official UAE sources listed in this package. It is not presented as a verbatim legally controlling English reproduction. For interpretation and application, consult the original Arabic text, the Official Gazette and the latest consolidated official legislation. Exact offence elements, penalties, exceptions, thresholds and deadlines must be checked against the current article.
Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data
Verified legislative metadata
| Instrument | Federal Decree-Law No. (45) of 2021 |
|---|---|
| Issued | 2021-09-20 |
| Effective | 2022-01-02 |
| Status | Active / in force |
| Official source | Official UAE source |
Legislative purpose and coverage
The UAE federal personal-data law establishes rules for lawful processing, data-subject rights, controller and processor duties, security, breach handling, data protection officers, impact assessments and cross-border transfers.
Complete statutory structure and principal provisions
Definitions and scope
Defines personal data, sensitive personal data, biometric data, controller, processor, data subject and related concepts; sets territorial and material scope and exclusions.
Processing principles
Requires fair, lawful, transparent and purpose-related processing with accuracy, security and appropriate retention.
Consent and lawful processing
Regulates valid consent and circumstances where processing may occur without consent under the law.
Data-subject information and access rights
Provides rights to know about processing and obtain information/access subject to exceptions.
Portability, correction and erasure
Creates rights to data transfer/portability and to request correction, updating or deletion in the circumstances stated by law.
Restriction, objection and automated decisions
Provides controls over continued processing and rights relating to certain automated processing/profiling decisions.
Controller obligations
Requires governance, processing records/controls, protection measures and cooperation with rights requests.
Processor obligations
Requires processors to act within lawful instructions and satisfy statutory security/cooperation duties.
Security and breach management
Requires technical/organisational safeguards and a breach-response framework.
Data Protection Officer and impact assessment
Requires DPO appointment and data-protection impact assessments in specified high-risk circumstances.
Cross-border transfers
Regulates transfer/sharing of personal data outside the UAE using adequacy or other permitted safeguards/routes.
Data Office, complaints and enforcement
Provides institutional oversight, complaints and implementing/enforcement mechanisms.
Final provisions
Provides implementing powers, repeal of conflicting provisions and commencement on 2 January 2022.
Key statutory points
- Entered into force on 2 January 2022.
- Creates a federal framework for processing personal data within its statutory scope.
- Contains exclusions for specified government, health, banking/credit and personal/domestic processing contexts where other legislation applies.
- Requires lawful and transparent processing and limits processing to appropriate purposes.
- Regulates consent and other permitted bases for processing.
- Creates data-subject rights concerning information, access, transfer/portability, correction, deletion and restriction/objection subject to statutory conditions.
- Defines controller and processor responsibilities.
- Requires security measures appropriate to processing risks.
- Contains personal-data-breach notification requirements subject to the statutory/implementing framework.
- Provides for Data Protection Officers in specified higher-risk circumstances.
- Requires impact assessments for specified high-risk processing.
- Regulates automated processing/profiling rights in the circumstances described by the law.
- Regulates cross-border transfer and sharing of personal data.
- Creates oversight/complaint mechanisms involving the UAE Data Office.
- Article 31 provides for commencement on 2 January 2022.
Amendments, executive regulations and related legislation
The federal data-protection framework should be read with current UAE Data Office rules and any sector-specific legislation applicable to the processing.
Reading rule for case-specific use
This structured rendering is designed to give the website a complete substantive map of the legislation and its operative areas. Where a legal conclusion turns on precise wording, an article number, a penalty, an exception, an implementing decision or a transitional rule, the official Arabic text and current related legislation must be used before reliance.
Verification
Official source & references
Official legislation sourcehttps://uaelegislation.gov.ae/en/legislations/1972Open ↗This page is a research and educational resource. Legislation can be amended, repealed, supplemented by regulations or interpreted by courts and authorities. Obtain advice before relying on it for a live matter.
