The UAE PDPL: Data Protection Explained

The UAE Personal Data Protection Law requires demonstrably effective safeguards for personal data. Here is who it covers, what it demands, and how testing proves compliance.

Social engineering assessment by Rootsec

What is the UAE PDPL?

The Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) is the UAE’s answer to the GDPR: it applies across sectors to organisations processing personal data of people in the UAE. It requires lawful processing, consent management, breach notification — and, critically for us, appropriate technical and organisational measures to protect the data. Official information is published on the UAE government portal.

What “appropriate technical measures” means in practice

The law does not hand you a checklist — it expects measures that are demonstrably effective for your risk. That word demonstrably is where testing comes in: an independent penetration test is the clearest way to show your safeguards actually hold, and a remediated-and-retested report is exactly the artefact you want on file if a breach or complaint triggers scrutiny.

Map your dataWhere personal data lives: systems, vendors, backups. You cannot protect what you have not mapped.
Test the safeguardsPentest the systems processing personal data; fix and retest. Evidence over intentions.
Prepare for breach responsePDPL expects notification without undue delay — have an incident plan before you need one.

PDPL, free zones and sector rules

DIFC and ADGM have their own data protection regimes, and sector regulators (CBUAE, DoH/ADHICS) layer extra requirements on top. Our UAE compliance guide maps how they fit together.

Related guides and services

Frequently asked questions

Quick answers on the UAE data protection law.
What is the UAE PDPL?

The Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the UAE’s federal privacy law covering organisations that process personal data of people in the UAE.

Does the PDPL apply to my company?

If you process personal data of individuals in the UAE — customers, employees, users — it almost certainly does, unless you fall solely under DIFC or ADGM regimes.

Does the PDPL require penetration testing?

It requires appropriate, demonstrably effective technical measures. Independent testing is the accepted way to demonstrate effectiveness.

What happens after a data breach under PDPL?

The law expects notification to the regulator without undue delay and documentation of the incident — an incident response plan is essential.

Next step

Can you prove your data is protected?

Book a free 30-minute strategy call. You get clarity on scope, approach and a fixed price — no obligations.