{
 "jurisdiction_id": "AE",
 "jurisdiction": "United Arab Emirates",
 "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 47,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A comprehensive federal statute is in force, but implementing/executive regulation detail (fines, breach timelines) remained unconfirmed in available secondary sources, and the regime is fragmented across federal, DIFC and ADGM authorities.",
   "claims": [
    {
     "statement": "The UAE enacted Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data as part of a sweeping package of legal reforms marking the UAE's 50th anniversary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL decrees established the Emirates Data Office to monitor and enforce the UAE Personal Data Protection Law countrywide.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL took effect on January 2, 2022, with enforcement of its provisions beginning in September 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Like the EU GDPR, the PDPL gives considerable control and rights to data subjects over their personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Virtually all organizations across all seven emirates that collect or process personal data, and organizations elsewhere processing personal data belonging to UAE residents, fall within the PDPL's compliance scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DIFC and ADGM financial free zones operate independent data protection regimes (DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021) outside the federal PDPL's civil and commercial jurisdiction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADGM requires registration of data controllers and notification of processing activities with the Commissioner of Data Protection, together with data protection fees and renewal fees, except for establishments with fewer than five employees unless they carry out high-risk processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC entities must notify the Commissioner of processing operations as soon as possible and in any event within 14 days, paying a $1,250 registration fee and $500 annual renewal fee.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/opinion/difc-round-guidance-difcs-data-protection-law-and-0",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Free-zone (DIFC/ADGM) lawful-basis and special-category rules are well-documented and GDPR-aligned; federal PDPL detail on lawful bases beyond consent-plus-exceptions was not confirmed in available sources.",
   "claims": [
    {
     "statement": "Where consent is not an option or not practical, the PDPL permits processing only for protection of the public interest, judicial or security proceedings, protection of public health, or compliance with other laws such as KYC requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADGM Data Protection Regulations provide lawful grounds for processing similar to GDPR — consent, contractual performance, controller obligations and public interest — but do not reference journalistic or artistic purposes as a legal basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADGM Regulations remain consistent with GDPR definitions of special categories of data while explicitly extending the category to include criminal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADGM Regulations do not explicitly define anonymisation, although pseudonymisation is defined consistently with GDPR and referenced as an appropriate security measure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC Law 2020 makes explicit reference to both anonymisation and pseudonymisation but does not define these concepts with GDPR-level specificity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_difc_law.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights exist in principle across federal, DIFC and ADGM instruments, but response-window specificity at federal level is unconfirmed.",
   "claims": [
    {
     "statement": "The PDPL is characterized as giving data subjects considerable control and rights over their personal data, comparable in intent to the EU GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under ADGM Regulations, the right to erasure does not apply to the extent that processing is necessary for archiving or research purposes where erasure would render impossible or seriously impair those objectives, provided appropriate safeguards are taken.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Shortly after PDPL enactment it remained uncertain exactly how breach reporting timelines (and, by extension, other statutory response windows) would be specified pending executive regulations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Free-zone (DIFC/ADGM) controller duties are well documented and GDPR-aligned; federal PDPL implementing detail (fine schedules, precise breach timelines) is not confirmed.",
   "claims": [
    {
     "statement": "DIFC Law 2020 establishes Data Protection Impact Assessment (DPIA) requirements not present under the prior DIFC Law 2007.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_difc_law.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC Law 2020 introduces accountability as a key requirement, stipulating that controllers and processors establish a Privacy Program to demonstrate compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/difc-difc-announces-enactment-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL allows an organization's DPO to be an employee or outsourced to a third party with data-privacy expertise, and not all organizations are required to appoint one.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC Law 2020 requires DPOs to conduct annual assessments, a requirement more nuanced than the GDPR's baseline DPO obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_difc_law.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADGM Regulations require controllers and processors to maintain a Record of Processing Activities, including maintaining separate records in both jurisdictions where both ADGM and another regime apply.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC controllers must notify the Commissioner of a personal data breach compromising confidentiality, security, or privacy 'as soon as practicable in the circumstances', and processors must notify controllers 'without undue delay'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/difc-difc-announces-enactment-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC controllers must communicate a personal data breach to affected data subjects 'as soon as practicable' where high risk exists, and 'promptly' where there is immediate risk of damage.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/difc-difc-announces-enactment-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPL restricts data retention to only as long as needed for the purpose originally captured (data retention principle).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Strong DIFC/ADGM evidence on transfer mechanisms and adequacy granted; federal PDPL transfer detail and adequacy received status are unconfirmed/pending.",
   "claims": [
    {
     "statement": "ADGM Data Protection Regulations provide transfer mechanisms similar to GDPR, including standard contractual clauses, binding corporate rules, derogations, and adequacy assessment criteria, with neither ADGM nor GDPR requiring data localisation or residency.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DIFC explicitly stated that enactment of the Data Protection Law and adoption of its Regulations was intended to support DIFC's pursuit of adequacy recognition from the European Commission and the UK.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/difc-difc-announces-enactment-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2021 the UK's Department for Digital, Culture, Media and Sport announced it would conduct an adequacy assessment of the DIFC; a confirmed final outcome of that assessment was not located in available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/uae-difc-announces-adequacy-assessment-uk-dcms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC has declared adequacy with a number of jurisdictions including EU member states, the UK, Canada, Singapore, and South Korea.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2023/20230809.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On August 9, 2023, the California Privacy Protection Agency and DIFC recognized each other's frameworks, marking the first time DIFC granted this adequacy-type status to a U.S. state.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2023/20230809.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DIFC Commissioner has approved two sets of standard contractual clauses that may be used for transfers outside the DIFC to a non-adequate jurisdiction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DIFC Authority",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_regualtions_final.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Neither the ADGM Regulations nor the GDPR require data localisation or residency for personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecoms and health overlays are documented; financial-sector overlay evidence is limited to one regulation; credit, education and insurance sub-modules have no confirmed evidence.",
   "claims": [
    {
     "statement": "The UAE Stored Value Facilities Regulation was the first UAE law to specifically mandate information/data minimization as a compliance requirement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uae-data-privacy-oversight-rise",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UAE Health Data Law/ICT Health Law applies to all methods and uses of information and communication technology in the UAE healthcare sector, covering both mainland and free-zone entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uae-data-privacy-oversight-rise",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Department of Health Abu Dhabi's Standards on Healthcare Data Privacy 2020 apply specifically to entities within the Emirate of Abu Dhabi and strictly define how health data may be used, stored, shared and protected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uae-data-privacy-oversight-rise",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Dubai Healthcare City is governed by Federal Law No. 2 of 2019 (Healthcare Data Protection Law), which regulates protection of individuals' data within DHCC, including restrictions on data disclosures and transfers, superseding the 2013 DHCC Data Protection Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/united-arab-emirates-dubai-health-care-city",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Law Regulating the Telecommunications Sector gives the Telecommunications Regulatory Authority jurisdiction to implement regulations concerning customer data use (Article 14) and criminalizes disclosure of the content of a call or message sent through the network (Article 72).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/uae-data-privacy-oversight-rise",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No comprehensive adtech-specific regime was confirmed for the UAE in available research; only the general PDPL consent framework applies.",
   "claims": [
    {
     "statement": "The PDPL requires organizations to create consent forms and disclosures for the processing of all personal data, which in practice would extend to processing for direct-marketing purposes absent a specific statutory exception.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/10-practical-steps-to-prepare-for-the-uaes-personal-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI policy infrastructure and one DIFC-specific binding regulation are documented; federal biometric/genetic/surveillance-carveout specifics are unconfirmed.",
   "claims": [
    {
     "statement": "The DIFC's Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems is in force.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://prod.iapp.org/resources/article/global-ai-legislation-tracker/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAE AI governance is conducted primarily through national strategy, ethical guidelines and sector-specific initiatives — including the UAE National Strategy for Artificial Intelligence 2031 — rather than through dedicated cross-sectoral AI legislation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/global-ai-governance-uae",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In October 2024, the UAE Cabinet approved the country's International Stance on Artificial Intelligence Policy, and the UAE has issued non-binding guidance resources including an AI Ethics Principles and Guidelines document and an AI System Ethics Self-Assessment Tool.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://prod.iapp.org/resources/article/global-ai-legislation-tracker/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Coverage of children's/vulnerable-groups' data is thin and inconsistent across the UAE's fragmented regime; no dedicated federal children's-data regime was confirmed.",
   "claims": [
    {
     "statement": "ADGM Data Protection Regulations define a child as a natural person under the age of 18, in contrast to GDPR's default age of consent of 16 (adjustable by Member States to not younger than 13), but do not explicitly outline requirements for consent to process children's data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._adgm.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DIFC Law 2020, consistent with its 2007 predecessor, does not generally refer to children's data or provide specific requirements for collecting personal data from children.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_difc_law.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-arab-emirates/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "DIFC enforcement track record and powers are well documented; federal PDPL-specific enforcement activity, funding, and any collective-redress mechanism remain unconfirmed, and no confirmed developments within the last 180 days were located.",
   "claims": [
    {
     "statement": "The DIFC Commissioner may issue general fines for contraventions of the Data Protection Law by a controller or processor (including sub-processors), in an amount considered appropriate and proportionate to the seriousness of the contravention and risk of harm to data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/difc-difc-announces-enactment-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DIFC Commissioner may conduct investigations and inspections to verify compliance and may apply to the court for an order compelling payment of unpaid administrative fines, including publishing details of the matter.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DIFC Authority",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_regualtions_final.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Violations of UAE constitutional, Penal Code, Cyber Crime Law and sector-specific privacy provisions can carry penalties as high as AED 1 million or potential imprisonment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/amid-evolving-privacy-regulation-in-the-middle-east-stalling-on-compliance-is-no-longer-an-option",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Authorities in the Dubai International Financial Centre had issued 88 fines since the region's new data protection regulations became effective in late 2020, as of publication in August 2021.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/amid-evolving-privacy-regulation-in-the-middle-east-stalling-on-compliance-is-no-longer-an-option",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A person may file a complaint with the DIFC Commissioner, who applies mediation practices and procedures aimed at timely, fair and effective resolution, and may issue a binding direction to a controller under Article 60(4) of the DIFC Law if mediation does not resolve the matter.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DIFC Authority",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_regualtions_final.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}