Summary
- The UAE lacks a unified data protection law, with Federal Decree-Law No. 45 of 2021 governing onshore processing, while DIFC and ADGM have their own regulations.
- As of September 2026, the federal law is in force but its executive regulations remain unpublished, leaving key operational details incomplete.
- Businesses must navigate parallel compliance requirements based on their location and sector, particularly regarding sensitive personal data and breach notification.
- The absence of adequacy decisions for cross-border data transfers means companies largely rely on contractual safeguards and consent to manage compliance risks.
Join the discussion ā sign up to comment, upvote, and save articles.