United Arab Emirates
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in the United Arab Emirates — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Your industry decides the answer here. The national privacy law started in January 2022. But the detailed rules that make it work were never written. So almost none of it can be enforced. Four kinds of data must stay inside the country: health records, payment data, insurance data and identity-check reports. Two financial districts run their own separate privacy systems. Those regulators do issue fines.
Data governance in the United Arab Emirates
The eight things that decide how you handle data about people in the United Arab Emirates. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The national privacy law applies even if you have no office in the country. It catches you if you handle personal data about people inside the country. There is no revenue or staff-size cut-off to fall below. But the law leaves out large areas. It does not cover government bodies, government data, health data, or banking and credit data. It also does not cover companies inside the financial free zones that have their own privacy laws.
- What you have to do here:
- Appoint a data protection officer
Federal Decree-Law No. 45 of 2021, Article 2(1), covers you if you sit outside the country and use personal data about people inside it. Article 2(2) then takes several groups back out. Government data and government bodies are out. Security and judicial authority data are out. Health data and banking or credit data that already have their own laws are out. Companies set up in free zones with their own data protection laws are also out. Article 10 says you need a data protection officer in only three cases. Those are high-risk work, regular checking of sensitive data, and handling large amounts of sensitive data. The law does not say that person must live in the country. The law also does not say you need a local representative. That detail was left to the Executive Regulations, which have never been issued.
Sources
- Official sourceUAE Legislation Portal, Ministry of JusticeFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data — Articles 2, 7 and 10
uaelegislation.gov.ae
“Each Controller or Processor residing outside the State and carrying out the activities of processing Personal Data of Data Subjects inside the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 — official record: issued 20 September 2021, effective 2 January 2022, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
Where the data is allowed to live
It depends on your industry. Under the national law you can send data abroad once you have the right paperwork. Nobody is checking. But four industries have real bans. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. Since April 2026 the national identity-check report may not be taken out of the country at all.
The answer depends on your industry. Here is each one. - Health and social care. Closed. Federal Law No. 2 of 2019, Article 13, says health data created by services inside the country may not be stored, used, generated or sent abroad. The only way out is a decision from the relevant health authority, made with the Ministry. - Payments. Closed. The rule is the Central Bank Retail Payment Services and Card Schemes Regulation, Circular 15/2021. Article 14(22) says personal and payment data must be stored and kept inside the country. - Insurance. Closed. The Electronic Insurance Regulations 2020, Article 9(2), say you must protect data by measures that include storing it inside the country and in the cloud. - Banking and identity checks. Closed for one document. Cabinet Resolution No. 55 of 2026, Article 13, says users must not send the Know Your Customer report, or any data in it, outside the country. - Government and public sector. Outside the national law. Article 2(2) of the national law leaves out government data and government bodies. Whether that data must stay in the country is set by internal government policy, which is not published as law. - Financial free zones, meaning the Dubai International Financial Centre and the Abu Dhabi Global Market. Conditional. Each has its own privacy law and its own list of approved countries you may send data to. - Telecoms. We found no published rule requiring data to stay in the country on the regulator's own list of regulations, checked 18 August 2026. Other sources describe an Internet of Things policy that requires storage inside the country. See the unconfirmed list. - Mapping and geospatial data. We found no federal rule requiring data to stay in the country, checked 18 August 2026, medium confidence.
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019 on the Use of Information and Communications Technology in Health Fields — Article 13
uaelegislation.gov.ae
“It is not permissible to store, process, generate or transform the health data and information outside State -which are related to the health services provided inside State- except in the case where a resolution is issued from the Health Authority in coordination with the Ministry.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation (Circular 15/2021), Article 14(22)
rulebook.centralbank.ae
“Personal and Payment Data shall be stored and maintained in the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Executive Regulations of the Know Your Customer Digital Platform law, Article 13
uaelegislation.gov.ae
“Refrain from transferring the 'Know Your Customer' Report or any data contained therein outside the State.”
Link checked 18 August 2026
What to do: Plan for a database inside United Arab Emirates: this data is not allowed to leave.
Sending data out of the country
On paper, you may only send data to countries the regulator has approved. The regulator has never published that list. So everyone uses the backup route instead. That means a contract where the recipient promises the same level of protection. Or the person's explicit consent. Or a narrow necessity exception. You need no government permission and you file nothing. The rules that would have created those steps were never written.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Explicit consent · Needed for a contract
Federal Decree-Law No. 45 of 2021, Article 22, lets you send data to a country that has its own data protection law. That law must cover privacy, confidentiality and people's rights over their data. It must also give courts oversight of the companies using the data. Article 23 covers countries without such a law. You may send data there if the recipient signs binding promises to give the same protection. You may also rely on the person's explicit consent, where there is no security concern. Or you may send data where it is needed for a contract, legal proceedings, court cooperation or the public interest. The list of approved countries is empty. No approval decision has ever been published. So Article 22 does nothing and Article 23 carries all real traffic. There is also no schedule of fines, so today there is nothing to fine you with. Industry rules override all of this. Health, payments, insurance and the identity-check report have no route abroad at all. The one exception is health data, where the health authority can issue a specific decision.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 — Articles 22 and 23 (cross-border transfer)
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceThe United Arab Emirates' Government portalData protection laws — official government portal description of the law and the UAE Data Office (page updated 4 December 2025)
u.ae
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
On paper, the UAE Data Office. It has never enforced anything. It has no public website. It has published no list of approved countries. The government decision that would set the fines has not been made. The regulators that act are elsewhere. The central bank fined a foreign bank branch about 5.4 million US dollars in June 2026. The data protection commissioner in the Abu Dhabi financial district has published penalty notices.
Federal Decree-Law No. 44 of 2021 created the UAE Data Office. The government portal describes it as the federal data regulator, responsible for policies, standards, complaints systems and guidance. We could not find a website of its own. Two addresses, dataoffice.gov.ae and uaedataoffice.gov.ae, do not work, checked 18 August 2026. We found no published register, no guidance and no decisions. Article 26 of the privacy law leaves breaches and fines to a Cabinet decision, and we found none. Without it there is no fine to impose. The industry regulators are different. The Central Bank of the UAE published a financial penalty of 20,000,000 dirhams (about 5.4 million US dollars) on 24 June 2026. It published another of 1,820,000 dirhams (about 495,000 US dollars) on 6 July 2026. Both were against foreign bank branches. The Abu Dhabi Global Market Office of Data Protection published a penalty notice against Okadoc Technologies Limited on 21 May 2024. It also published a direction against VentureRock Global Limited on 23 June 2023. Both were under its own 2021 rules. We rate enforcement overall as waking. The national law is not enforced. The industry and free-zone regulators are active.
Sources
- Official sourceThe United Arab Emirates' Government portalUAE Data Office — role and establishing law (Federal Decree-Law No. 44 of 2021), government portal, updated 4 December 2025
u.ae
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank of the UAE — 2026 news: financial sanction of AED 20,000,000 (24 June 2026) and AED 1,820,000 (6 July 2026) on foreign bank branches
centralbank.ae
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — published regulatory actions (Okadoc Technologies penalty notice, 21 May 2024; VentureRock Global direction, 23 June 2023)
adgm.com
Link checked 18 August 2026
How long you must keep it — and when to delete it
How long you must keep data is set by your industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years, with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deadline to delete data. The detailed rules that would set one were never issued.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
Government sources confirm these minimum keep-times. Health records: 25 years from the last health procedure, under Federal Law No. 2 of 2019, Article 20. Payment service providers: 5 years for personal and payment data, plus a secure backup in a separate place. That is Circular 15/2021, Article 10(10) and Article 14(22). Identity checks: 5 years for the reports, the requests for them and the records of handing them over, under Cabinet Resolution No. 55 of 2026, Articles 10, 12 and 13. There is no maximum keep-time. The privacy law left the detail on keeping data to a minimum, and on deleting it, to Executive Regulations that do not exist. So there is no enforceable national delete-by date today. We hold medium confidence on that. Clashes between the rules are easy to sort out here, and the minimum keep-times win. The privacy law does not apply to health data, or to banking and credit data that have their own laws. So a person's right to erasure under the privacy law cannot override an industry minimum keep-time.
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019, Article 20 — health records kept not less than 25 years from the last health procedure
uaelegislation.gov.ae
“the keeping period shall not be less than (25) twenty-five years from the last date of the health procedure.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation (Circular 15/2021), Article 10(10) — five-year record keeping
rulebook.centralbank.ae
“Payment Service Providers shall keep all necessary records on Personal and Payment Data for a period of (5) years from the date of receipt of such data”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Articles 10, 12 and 13, five-year retention of identity-check reports
uaelegislation.gov.ae
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you find a breach. It leaves the exact timing and the wording of the notice to detailed rules that were never issued. So the deadlines that really run come from your own regulator. That means the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not private companies.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Federal Decree-Law No. 45 of 2021, Article 9, says the company that decides how data is used must tell the Bureau when it finds a breach. This covers breaches that affect the privacy, confidentiality or security of data. The notice must set out the nature and causes of the breach. It must give the rough number of records affected. It must give contact details for the officer you appointed. It must cover the expected impact and the steps you are taking to fix it. The deadline for telling the affected people was left to the Executive Regulations. A company handling data for you must tell you immediately when it finds a breach. The Executive Regulations do not exist, and neither does the penalty decision under Article 26. So there is no national deadline in hours you can be held to. The telecoms and digital government regulator runs a cyber incident reporting service. Its stated audience is the government sector. Its published service description sets a 3 to 90 working day response window. That is a response time, not a duty on private firms to report. Firms in the Dubai International Financial Centre and the Abu Dhabi Global Market follow their own regulators' deadlines.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 9 — breach notification, timing left to Executive Regulations
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceTelecommunications and Digital Government Regulatory AuthorityReport a cyber incident — service description, audience stated as the government sector
tdra.gov.ae
Link checked 18 August 2026
- Official sourceUAE Cyber Security CouncilUAE Cyber Security Council — national incident response framework; no public reporting deadline published
csc.gov.ae
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things catch people out. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones. Most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine goes up to about 190 thousand US dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but you only need a parent's consent for children under 13. Five: two extra legal systems run inside the country, and their regulators do issue penalties.
- What you have to do here:
- Get a parent's consent for children · Register or notify · Keep the data in the country
- What it costs if you get it wrong:
- Fixed maximum fine · Loss of your licence
(1) Federal Decree-Law No. 45 of 2021, Article 2(2), leaves out government data and government bodies. It also leaves out security and judicial data, health data, and banking and credit data that already have their own laws. It leaves out free-zone companies with their own privacy laws too. If you build your compliance work only on the national law, you will miss the rule that actually binds you. (2) Federal Law No. 2 of 2019, Article 24, sets a fine for storing or sending health data abroad. It runs from 500,000 dirhams (about 136,000 US dollars) to 700,000 dirhams (about 191,000 US dollars). Article 25 lets health authorities add penalties of up to 1,000,000 dirhams (about 272,000 US dollars) and cancel your licence. (3) Cabinet Resolution No. 55 of 2026 has applied since 21 April 2026. It stops users of the national Know Your Customer platform from taking the report, or any data in it, out of the country. This export ban is newer than most published guidance. (4) Federal Decree-Law No. 26 of 2025 on Child Digital Safety says a child is anyone under 18. It requires documented, checkable consent from a caregiver for children under 13. Accounts must start on the highest privacy settings, and withdrawing consent must be easy. Its fines were left to a future Cabinet decision. So the duties apply now, but there are no penalties yet. (5) The Dubai International Financial Centre and the Abu Dhabi Global Market are separate legal jurisdictions. Each has its own privacy law, its own registration duties and its own commissioner. The Abu Dhabi commissioner makes every company that uses personal data register with it, and publishes its enforcement notices.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 2(2) — exclusions for government data, health data, banking data and free-zone companies
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 26 of 2025 on Child Digital Safety — Articles 7, 10 and 11
uaelegislation.gov.ae
“Any human being who has not completed the age of eighteen (18) Gregorian years.”
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — registration of data controllers, adequate jurisdictions approach, regulatory actions
adgm.com
Link checked 18 August 2026
What's changing next
The biggest change could land on any day. When the government publishes the detailed rules under the privacy law, every company gets six months to comply. The law then becomes enforceable. Nothing tells us when that will happen. Meanwhile the new child safety law still needs its schedule of fines. And the national identity-check platform is being rolled out across banks.
Powers the government already holds. It can use any of these with no warning and no consultation. 1. The Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021. They were due within six months of September 2021 and are still not published, nearly five years late. Article 29 gives companies no more than six months from the day they are issued to put their position right. So publication starts a six-month countdown for every company in the country. 2. The Cabinet decision under Article 26 setting out breaches and fines. Until it exists there is no fine. The day it exists, the national law becomes enforceable. 3. The list of approved countries under Article 22. It has never been filled in. Filling it in would set out which destinations are lawful, and so would limit the others. 4. The health authority's power under Article 13 of Federal Law No. 2 of 2019 to allow, or refuse, storing health data abroad, decision by decision. 5. The penalties rules under Article 16 of the 2025 Child Digital Safety law. Known work in progress. The national Know Your Customer digital platform. Its Executive Regulations took effect on 21 April 2026. Its rules on administrative breaches are Cabinet Resolution No. 56 of 2026. The securities regulator has been renamed the Capital Market Authority, and now publishes its rulebook at a new address.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Articles 26, 28 and 29 — penalties by Cabinet decision, Executive Regulations, six-month compliance window
uaelegislation.gov.ae
“The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalRelated legislation for Federal Decree-Law No. 45 of 2021 — no Cabinet Resolution issuing Executive Regulations listed as at 18 August 2026
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Capital Market AuthorityCapital Market Authority regulations listing — the securities regulator's site now redirects from sca.gov.ae to uaecma.gov.ae
uaecma.gov.ae
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields · Federal Law No. 2 of 2019, Articles 13, 20, 24 and 25 · Act of parliament
Health data created by health services inside the country may not be stored, used, generated or moved abroad at all. The only exception is a specific decision from the relevant health authority. Records must be kept for at least 25 years after the last treatment. This is the country's strictest data rule. Breaking it costs up to about 191,000 US dollars, and you can lose your licence.
Enforced by Ministry of Health and Prevention
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryYou may not store, use, generate or convert health data abroad. The only exception is a decision from the health authority, made with the Ministry.
- Keep data for a minimum period — 25 yearsAt least 25 years from the date of the last health procedure.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: AED 700,000 — about $191 thousandStoring, processing or transferring health data outside the country (minimum AED 500,000, about $136,000)
- Fixed maximum fine: AED 1,000,000 — about $272 thousandDisciplinary sanctions imposed by health authorities
- Loss of your licenceRepeated or serious breach
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019 — full text, Articles 13, 20, 24, 25
uaelegislation.gov.ae
“It is not permissible to store, process, generate or transform the health data and information outside State -which are related to the health services provided inside State- except in the case where a resolution is issued from the Health Authority in coordination with the Ministry.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 6 February 2019, effective 14 May 2019, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceThe United Arab Emirates' Government portalHealth policies and laws — official index listing Federal Law No. 2 of 2019 on ICT in health fields
u.ae
Link checked 18 August 2026
Payments data must stay in the country
Official name: Retail Payment Services and Card Schemes Regulation · Circular No. C 15/2021 · Directly binding regulation
If you are licensed to provide retail payment services, personal and payment data must stay inside the country. You also need a separate secure backup, and you must keep the data for five years. The regulation gives no route for sending data abroad. It says nothing about whether an extra copy may sit overseas, so firms treat it as a total ban.
Enforced by Central Bank of the United Arab Emirates
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryPersonal and payment data must be stored and kept inside the country, with a secure backup in a separate location.
- Keep data for a minimum period — 5 years
- Get consentYou need explicit consent before you use the personal data of someone using a payment service.
- Secure the data
Sources
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation, Article 14(22) — storage in the State
rulebook.centralbank.ae
“Personal and Payment Data shall be stored and maintained in the State. Payment Service Providers must also establish a safe and secure backup of all Personal and Payment Data in a separate location for the required period of retention of (5) years.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRegulation contents page — Circular C 15/2021, effective 6 June 2021, status In-Force
rulebook.centralbank.ae
Link checked 18 August 2026
Insurance data must stay in the country
Official name: Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations · Board Resolution No. 18 of 2020, Article 9 · Directly binding regulation
If you sell or service insurance policies online, you must protect customer information held electronically. That includes storing the data inside the country. Confidentiality never expires. You may only hand data over under a court or security order. Supervision moved from the Insurance Authority to the central bank when the two merged.
Enforced by Central Bank of the United Arab Emirates
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryYour data protection measures must include storing data inside the country and in the cloud.
- Secure the dataLayered supervision, minimum security measures, disaster plans, backups and a way to restore your website.
- Get consentYou may not send unsolicited marketing messages without consent first.
Sources
- Official sourceCentral Bank of the UAE RulebookElectronic Insurance Regulations, Article 9 — Information Security and Integrity, effective 28 April 2020, status In-Force
rulebook.centralbank.ae
“storing data inside the State and in the cloud”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank legislation index — Federal Decree-Law No. 6 of 2025 on the Central Bank, financial institutions and insurance business
centralbank.ae
Link checked 18 August 2026
Banking data rules
Official name: Cabinet Resolution No. (55) of 2026 Promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 Regarding the "Know Your Customer" Digital Platform · Cabinet Resolution No. 55 of 2026, Articles 10, 12 and 13 · Directly binding regulation
The national customer identity-check platform came fully into effect on 21 April 2026. If you use it, you must not move the identity report, or any data in it, out of the country. You must also keep copies for at least five years. This is the country's newest export ban, and it is newer than most published compliance guidance.
Enforced by Central Bank of the United Arab Emirates
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country — from 21 April 2026You must not send the customer identity report, or any data in it, outside the country.
- Keep data for a minimum period — 5 years, from 21 April 2026
- Keep records of how you use data
Sources
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Executive Regulations of the Know Your Customer Digital Platform law, Article 13
uaelegislation.gov.ae
“Refrain from transferring the 'Know Your Customer' Report or any data contained therein outside the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 20 April 2026, effective 21 April 2026, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank legislation index linking Federal Decree-Law No. 30 of 2024 and Cabinet Resolutions No. 55 and 56 of 2026
centralbank.ae
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Banking rules
Official name: Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data · Federal Decree-Law No. 45 of 2021, Official Gazette No. 712, 26 September 2021 · Act of parliament
The national privacy law. It reaches foreign companies that handle data about people inside the country. You may send data abroad using a contract, consent, or an approved destination. Today it is close to unenforceable. The detailed rules required by Article 28 have never been published. The schedule of fines under Article 26 has never been made. The list of approved destinations is empty. The law also does not apply to government data, health data, banking and credit data, or free-zone companies with their own privacy laws.
Enforced by UAE Data Office — not yet operational
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Legal claims, Important public interest
What you have to do
- Get consent
- Tell people what you do
- Keep records of how you use dataArticle 7(4): you must keep a special record of personal data. It covers the company that decides how data is used, and the data protection officer. It also covers the types of data, who is allowed to see it, how long the data is used, and the security measures.
- Secure the data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulatorArticle 9: tell the regulator when you find the breach. The law sets no number of hours. The timing was left to Executive Regulations that have not been issued.
- Tell affected peopleThe time limit was left to the Executive Regulations.
- Appoint a data protection officer — applies at: High-risk processing, systematic assessment of sensitive data, or large volumes of sensitive data (Article 10).
- Put a transfer safeguard in place
- Written vendor contract
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data — full text
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 20 September 2021, effective 2 January 2022, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World — United Arab Emirates (page last modified 27 January 2025): Executive Regulations still unpublished
dlapiperdataprotection.com
Link checked 18 August 2026
Children's data rules
Official name: Federal Decree-Law No. (26) of 2025 Regarding Child Digital Safety · Federal Decree-Law No. 26 of 2025, Articles 7, 10, 11 and 16 · Act of parliament
A new law in force since 1 January 2026. Online platforms must set children's accounts to the strongest privacy settings by default. They must offer parental controls and reporting tools. For anyone under 13 they need documented, checkable consent from a caregiver. A child is anyone under 18. The fines have not been set yet. They were left to a future government decision. So the duties apply now, but there are no penalties.
Enforced by Telecommunications and Digital Government Regulatory Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get a parent's consent for children — applies at: Under 13 (a child is anyone under 18), from 1 January 2026Consent must be explicit, documented and checkable. Withdrawing it must be easy and always possible.
- Secure the data — from 1 January 2026Privacy settings must start at the highest level of privacy by default.
- Tell people what you do — from 1 January 2026Clear, easy-to-use reporting tools and parental control tools.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 26 of 2025 Regarding Child Digital Safety — full text
uaelegislation.gov.ae
“explicit, documented, and verifiable”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 1 October 2025, effective 1 January 2026, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
Applies only in certain states1 rule
Made by a state or province. It only binds you for the people living there.
Rules for sending data abroad
Official name: ADGM Data Protection Regulations 2021 · Data Protection Regulations 2021, Abu Dhabi Global Market · Directly binding regulation
Two financial districts sit outside the national privacy law and run their own systems. The Abu Dhabi Global Market uses its 2021 regulations. The Dubai International Financial Centre uses its own 2020 law. The Abu Dhabi office keeps a public register. It follows a European-style list of approved destinations. It has published penalty notices and directions. It is one of the few privacy regulators in the country that actually works.
Enforced by Abu Dhabi Global Market Office of Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent
What you have to do
- Register or notifyEvery company that uses personal data must register with the Office of Data Protection and pay a fee.
- Report breaches to the regulator
- Put a transfer safeguard in place
- Let people see their data
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineContravention of the 2021 Regulations — penalty notices issued under section 55(1)
- Order to stopDirections issued under section 54(1)
Sources
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — Data Protection Regulations 2021, controller registration, adequate jurisdictions (page updated 31 July 2024)
adgm.com
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM regulatory actions — penalty notice against Okadoc Technologies Limited (21 May 2024) and direction against VentureRock Global Limited (23 June 2023)
adgm.com
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 2(2) — free-zone companies with their own data protection legislation are excluded from the national law
uaelegislation.gov.ae
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021 have still not been issued as at 18 August 2026
The official legislation portal lists no Cabinet Resolution issuing them. A professional source dated 27 January 2025 says they were still unpublished. We could not fully confirm the position for the period since January 2025. This is the most important claim in this record. Check it first before you rely on it.
That no Cabinet decision setting violations and penalties under Article 26 of the privacy law exists
We found no such decision on the legislation portal, and we could not confirm it against a full government search. Ask the regulator before you rely on there being no fines.
A telecoms or Internet-of-Things rule requiring data to be stored inside the country
The regulator's own regulations page has an Internet of Things section with no documents in it, checked 18 August 2026. Other sources describe an Internet of Things policy that requires storage inside the country. We could not get a government copy, so we do not state it as a rule. If you work in telecoms, check before you rely on this.
The current text, adequacy list and enforcement record of the Dubai International Financial Centre data protection law
We could not open the Centre's own website, so we could not confirm its current law, its approved destinations or its enforcement record. The free-zone rule in this record is based on the Abu Dhabi regulator's own site instead. Treat the Dubai position as medium confidence.
Whether any health authority decision has been issued permitting offshore storage of health data under Article 13 of Federal Law No. 2 of 2019, and how wide it is
The power to grant an exemption is written into the law. We could not find any published decision using it. If you need to store health data abroad, ask the health ministry directly.
The where data has to be stored policy that applies to government bodies and government data
The national privacy law leaves out government data and government bodies, so a separate policy must exist. We could not find a published federal rule setting it out. If this affects you, ask the government body you deal with.
Any mapping or geospatial keeping data in the country rule
We found no such rule, and we could not confirm it against a full government search. Medium confidence. If you handle mapping data, check before you rely on it.
That the 2026 central bank sanctions were for data or privacy breaches
The published notices record financial penalties for breaking the rules. They do not say what the breaches were about. We cite them only to show that the regulator is active and imposes large fines.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.