Data Protection Atlas

United Arab Emirates

Tier 2 Comprehensive law Middle East

Principal framework: Federal Decree-Law 45/2021 (+ DIFC / ADGM regimes) (2021). Regulator: UAE Data Office. Federal PDPL 45/2021 still awaits its executive regulations, so practical enforcement sits with the GDPR-modelled financial free zones (DIFC DP Law 2020, ADGM DPR 2021).

At a glance

Principal law
Federal Decree-Law 45/2021 (+ DIFC / ADGM regimes)
Regulator
UAE Data Office
Breach notification
Notify the UAE Data Office and affected persons where risk (executive regulations pending)
Maximum penalty
To be set by executive regulations; DIFC and ADGM fine independently
DPO required
DPO required for high-risk processing
Digital consent age
Parental consent for minors
Extraterritorial reach
Yes — processing of persons in the UAE

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
AE

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.