🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
AE · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United Arab Emirates

AE schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 47 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
47Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive federal statute is in force, but implementing/executive regulation detail (fines, breach timelines) remained unconfirmed in available secondary sources, and the regime is fragmented across federal, DIFC and ADGM authorities.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberA comprehensive federal statute is in force, but implementing/executive regulation detail (fines, breach timelines) remained unconfirmed in available secondary sources, and the regime is fragmented across federal, DIFC and ADGM authorities.

Sub-modules (5)

Regulator And AuthorityAmber

Federal enforcement sits with the Emirates Data Office; DIFC and ADGM each maintain their own Commissioner/Office of Data Protection for their free zones.

Claims: CLM-AE-a1b2c301, CLM-AE-a1b2c306

Act And InstrumentsAmber

Federal Decree-Law No. 45 of 2021 (PDPL) is the primary federal instrument; DIFC Law No. 5 of 2020 and ADGM Data Protection Regulations 2021 are independent free-zone instruments.

Claims: CLM-AE-a1b2c301, CLM-AE-a1b2c302

Material ScopeAmber

The PDPL is described as GDPR-influenced, granting data subjects considerable rights and control over personal data.

Claims: CLM-AE-a1b2c304

Territorial ScopeAmber

The PDPL is reported to apply to virtually all organizations across the seven emirates and to entities elsewhere processing UAE residents' data; DIFC/ADGM regimes apply only within their respective free zones.

Claims: CLM-AE-a1b2c305, CLM-AE-a1b2c306

Regulator Registration And FilingAmber

ADGM requires controller registration and processing notification (fee-bearing, exempt for sub-5-employee entities absent high-risk processing); DIFC requires notification within 14 days via its client portal with initial/renewal fees. No federal PDPL-specific registration mechanism was confirmed in available sources.

Claims: CLM-AE-a1b2c307, CLM-AE-a1b2c308

Category narrative89 words

The UAE federal regime rests on Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), enforced by the newly established Emirates Data Office (UAE Data Office). Layered on top of the federal statute are two independent financial free-zone regimes — the DIFC Data Protection Law No. 5 of 2020 (Commissioner of Data Protection) and the ADGM Data Protection Regulations 2021 (Office of Data Protection) — each with its own registration, fee, and enforcement architecture, plus sector-specific instruments (health, telecoms) that operate alongside the general regime.

Sources and claims (8)
  1. ConfirmedIAPPThe UAE enacted Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data as part of a sweeping package of legal reforms marking the UAE's 50th anniversary.
  2. ConfirmedIAPPThe PDPL decrees established the Emirates Data Office to monitor and enforce the UAE Personal Data Protection Law countrywide.
  3. ConfirmedIAPPThe PDPL took effect on January 2, 2022, with enforcement of its provisions beginning in September 2022.
  4. ProbableIAPPLike the EU GDPR, the PDPL gives considerable control and rights to data subjects over their personal data.
  5. ProbableIAPPVirtually all organizations across all seven emirates that collect or process personal data, and organizations elsewhere processing personal data belonging to UAE residents, fall within the PDPL's compliance scope.
  6. ConfirmedOneTrust DataGuidanceThe DIFC and ADGM financial free zones operate independent data protection regimes (DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021) outside the federal PDPL's civil and commercial jurisdiction.
  7. ConfirmedOneTrust DataGuidanceADGM requires registration of data controllers and notification of processing activities with the Commissioner of Data Protection, together with data protection fees and renewal fees, except for establishments with fewer than five employees unless they carry out high-risk processing.
  8. ConfirmedOneTrust DataGuidanceDIFC entities must notify the Commissioner of processing operations as soon as possible and in any event within 14 days, paying a $1,250 registration fee and $500 annual renewal fee.

#

Free-zone (DIFC/ADGM) lawful-basis and special-category rules are well-documented and GDPR-aligned; federal PDPL detail on lawful bases beyond consent-plus-exceptions was not confirmed in available sources.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 (PDPL); DIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberFree-zone (DIFC/ADGM) lawful-basis and special-category rules are well-documented and GDPR-aligned; federal PDPL detail on lawful bases beyond consent-plus-exceptions was not confirmed in available sources.

Sub-modules (4)

Lawful BasesAmber

PDPL defaults to consent with exceptions for public interest, judicial/security proceedings and public health; ADGM/DIFC mirror GDPR-style bases (consent, contract, legal obligation, public interest), though ADGM omits journalistic/artistic grounds.

Claims: CLM-AE-b2c3d401, CLM-AE-b2c3d402

Special CategoriesGreen

ADGM defines special categories consistently with GDPR while explicitly adding criminal data as a distinct category.

Claims: CLM-AE-b2c3d403

Pseudonymisation And AnonymisationAmber

ADGM references pseudonymisation (GDPR-consistent) as a security measure but does not explicitly define anonymisation; DIFC Law 2020 explicitly references both concepts without GDPR-level definitional specificity.

Claims: CLM-AE-b2c3d404, CLM-AE-b2c3d405

Category narrative43 words

The federal PDPL centers processing lawfulness on consent, with statutory exceptions; the DIFC and ADGM free-zone laws mirror GDPR-style lawful bases and special-category definitions, with ADGM explicitly extending special categories to criminal data and both regimes referencing pseudonymisation without fully GDPR-equivalent anonymisation definitions.

Sources and claims (5)
  1. ConfirmedIAPPWhere consent is not an option or not practical, the PDPL permits processing only for protection of the public interest, judicial or security proceedings, protection of public health, or compliance with other laws such as KYC requirements.
  2. ConfirmedOneTrust DataGuidanceADGM Data Protection Regulations provide lawful grounds for processing similar to GDPR — consent, contractual performance, controller obligations and public interest — but do not reference journalistic or artistic purposes as a legal basis.
  3. ConfirmedOneTrust DataGuidanceADGM Regulations remain consistent with GDPR definitions of special categories of data while explicitly extending the category to include criminal data.
  4. ConfirmedOneTrust DataGuidanceADGM Regulations do not explicitly define anonymisation, although pseudonymisation is defined consistently with GDPR and referenced as an appropriate security measure.
  5. ConfirmedOneTrust DataGuidanceDIFC Law 2020 makes explicit reference to both anonymisation and pseudonymisation but does not define these concepts with GDPR-level specificity.

#

Rights exist in principle across federal, DIFC and ADGM instruments, but response-window specificity at federal level is unconfirmed.

Primary frameworkUAE Federal Decree-Law No. 45 of 2021 (PDPL); ADGM Data Protection Regulations 2021
Supervisory authorityUAE Data Office (Emirates Data Office)
Traffic-light rationale — AmberRights exist in principle across federal, DIFC and ADGM instruments, but response-window specificity at federal level is unconfirmed.

Sub-modules (5)

Access RightRed

General characterization of GDPR-comparable rights exists; specific access-right mechanics for the federal PDPL were not located in available sources.

Absence provenance: not recorded. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Claims: CLM-AE-c3d4e501

Rectification And ErasureAmber

ADGM's right to erasure does not apply where processing is necessary for archiving/research and erasure would seriously impair those objectives.

Claims: CLM-AE-c3d4e502

Restriction And ObjectionRed

No AE-specific restriction/objection mechanics beyond general GDPR-alignment characterization were confirmed.

Absence provenance: not recorded. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Data PortabilityRed

No AE-specific portability provisions were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE Federal Decree Law 45 2021 PDPL fines penalties DPO threshold data subject rights.

Deadlines And Response WindowsRed

Specific statutory response-time deadlines for federal PDPL data-subject requests were not confirmed; secondary commentary noted uncertainty over implementing details shortly after enactment.

Claims: CLM-AE-c3d4e503

Category narrative37 words

The PDPL is characterized as granting GDPR-style data subject rights, though specific statutory response deadlines for federal-law subject-access or erasure requests were not confirmed in available sources; ADGM provides a right to erasure subject to archiving/research exceptions.

Sources and claims (3)
  1. ProbableIAPPThe PDPL is characterized as giving data subjects considerable control and rights over their personal data, comparable in intent to the EU GDPR.
  2. ConfirmedOneTrust DataGuidanceUnder ADGM Regulations, the right to erasure does not apply to the extent that processing is necessary for archiving or research purposes where erasure would render impossible or seriously impair those objectives, provided appropriate safeguards are taken.
  3. UncertainIAPPShortly after PDPL enactment it remained uncertain exactly how breach reporting timelines (and, by extension, other statutory response windows) would be specified pending executive regulations.

#

Free-zone (DIFC/ADGM) controller duties are well documented and GDPR-aligned; federal PDPL implementing detail (fine schedules, precise breach timelines) is not confirmed.

Primary frameworkDIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021; UAE Federal Decree-Law No. 45 of 2021 (PDPL)
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberFree-zone (DIFC/ADGM) controller duties are well documented and GDPR-aligned; federal PDPL implementing detail (fine schedules, precise breach timelines) is not confirmed.

Sub-modules (7)

Accountability And DpiaGreen

DIFC Law 2020 introduced DPIA obligations for high-risk processing (absent from the 2007 predecessor) and requires controllers/processors to maintain a 'Privacy Program' demonstrating accountability.

Claims: CLM-AE-d4e5f601, CLM-AE-d4e5f602

Dpo RequirementsGreen

The PDPL permits but does not universally mandate DPO appointment (employee or outsourced); DIFC requires DPO appointment where necessary, including annual assessments — a requirement more detailed than GDPR's baseline.

Claims: CLM-AE-d4e5f603, CLM-AE-d4e5f604

Ropa RequirementsGreen

ADGM and DIFC both require maintenance of Records of Processing Activities, including separate records where both regimes apply to the same entity.

Claims: CLM-AE-d4e5f605

Joint Controller ArrangementsRed

No AE-specific joint-controller provisions beyond general controller/processor contract requirements were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Security MeasuresAmber

DIFC and ADGM both require technical/organisational security measures, with pseudonymisation referenced as an ADGM security measure.

Claims: CLM-AE-d4e5f602

Breach NotificationAmber

DIFC requires controller notification to the Commissioner 'as soon as practicable' for confidentiality/security/privacy-compromising breaches, processor-to-controller notification 'without undue delay', and data-subject notification 'as soon as practicable' (or 'promptly' for immediate-risk cases); federal PDPL breach-timeline specifics remained unconfirmed shortly after enactment.

Claims: CLM-AE-d4e5f606, CLM-AE-d4e5f607, CLM-AE-c3d4e503

Retention And DisposalAmber

No AE-specific statutory retention period was confirmed; PDPL is described only generally as restricting retention to as long as needed for the original purpose.

Claims: CLM-AE-d4e5f608

Category narrative49 words

DIFC Law 2020 provides the most detailed accountability, DPIA, DPO, ROPA, breach-notification and privacy-program requirements among the UAE's data protection instruments; ADGM imposes parallel ROPA/registration duties; the federal PDPL permits (but does not universally mandate) DPO appointment, with executive-regulation-level detail on breach timelines and fines unconfirmed as of research.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidanceDIFC Law 2020 establishes Data Protection Impact Assessment (DPIA) requirements not present under the prior DIFC Law 2007.
  2. ConfirmedOneTrust DataGuidanceDIFC Law 2020 introduces accountability as a key requirement, stipulating that controllers and processors establish a Privacy Program to demonstrate compliance.
  3. ConfirmedIAPPThe PDPL allows an organization's DPO to be an employee or outsourced to a third party with data-privacy expertise, and not all organizations are required to appoint one.
  4. ConfirmedOneTrust DataGuidanceDIFC Law 2020 requires DPOs to conduct annual assessments, a requirement more nuanced than the GDPR's baseline DPO obligations.
  5. ConfirmedOneTrust DataGuidanceADGM Regulations require controllers and processors to maintain a Record of Processing Activities, including maintaining separate records in both jurisdictions where both ADGM and another regime apply.
  6. ConfirmedOneTrust DataGuidanceDIFC controllers must notify the Commissioner of a personal data breach compromising confidentiality, security, or privacy 'as soon as practicable in the circumstances', and processors must notify controllers 'without undue delay'.
  7. ConfirmedOneTrust DataGuidanceDIFC controllers must communicate a personal data breach to affected data subjects 'as soon as practicable' where high risk exists, and 'promptly' where there is immediate risk of damage.
  8. ProbableIAPPThe PDPL restricts data retention to only as long as needed for the purpose originally captured (data retention principle).

#

Strong DIFC/ADGM evidence on transfer mechanisms and adequacy granted; federal PDPL transfer detail and adequacy received status are unconfirmed/pending.

Primary frameworkDIFC Law No. 5 of 2020; ADGM Data Protection Regulations 2021
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberStrong DIFC/ADGM evidence on transfer mechanisms and adequacy granted; federal PDPL transfer detail and adequacy received status are unconfirmed/pending.

Sub-modules (6)

Transfer MechanismsGreen

ADGM Regulations provide transfer mechanisms mirroring GDPR — SCCs, BCRs, derogations, and adequacy assessment criteria.

Claims: CLM-AE-e5f6g701

Adequacy ReceivedRed

The DIFC's 2020 law was explicitly framed to support DIFC's pursuit of adequacy recognition from the European Commission and the UK; the UK DCMS announced an adequacy assessment of DIFC in 2021, but a confirmed outcome was not located in available sources.

Claims: CLM-AE-e5f6g702, CLM-AE-e5f6g703

Adequacy GrantedGreen

DIFC has declared adequacy toward EU member states, the UK, Canada, Singapore and South Korea, and in August 2023 mutually recognized California, the first US state so recognized.

Claims: CLM-AE-e5f6g704, CLM-AE-e5f6g705

Sccs And BcrsGreen

The DIFC Commissioner has approved two sets of standard contractual clauses for transfers to non-adequate jurisdictions; ADGM also provides for BCRs and SCCs.

Claims: CLM-AE-e5f6g706

Transfer Impact AssessmentRed

No AE-specific formal Transfer Impact Assessment requirement (akin to post-Schrems II EU practice) was confirmed for DIFC, ADGM or the federal PDPL in available sources.

Absence provenance: not recorded. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Data LocalisationAmber

Neither the ADGM Regulations nor the GDPR (as comparator) require data localisation or residency; no general federal PDPL localisation mandate was confirmed, though sector-specific health-data storage standards may impose de facto constraints.

Claims: CLM-AE-e5f6g707

Category narrative70 words

Cross-border transfer detail is best documented at the DIFC and ADGM free-zone level: both provide GDPR-style mechanisms (adequacy, SCCs, BCRs, derogations) with no data-localisation mandate, and the DIFC has declared adequacy toward the EU, UK, Canada, Singapore, South Korea and — since August 2023 — California. Federal PDPL-specific transfer-mechanism detail, and confirmation of any reciprocal adequacy determination received by the UAE from the EU/UK, was not located in available sources.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceADGM Data Protection Regulations provide transfer mechanisms similar to GDPR, including standard contractual clauses, binding corporate rules, derogations, and adequacy assessment criteria, with neither ADGM nor GDPR requiring data localisation or residency.
  2. ConfirmedOneTrust DataGuidanceThe DIFC explicitly stated that enactment of the Data Protection Law and adoption of its Regulations was intended to support DIFC's pursuit of adequacy recognition from the European Commission and the UK.
  3. UncertainOneTrust DataGuidanceIn 2021 the UK's Department for Digital, Culture, Media and Sport announced it would conduct an adequacy assessment of the DIFC; a confirmed final outcome of that assessment was not located in available sources.
  4. ConfirmedCPPADIFC has declared adequacy with a number of jurisdictions including EU member states, the UK, Canada, Singapore, and South Korea.
  5. ConfirmedCPPAOn August 9, 2023, the California Privacy Protection Agency and DIFC recognized each other's frameworks, marking the first time DIFC granted this adequacy-type status to a U.S. state.
  6. ConfirmedDIFC AuthorityThe DIFC Commissioner has approved two sets of standard contractual clauses that may be used for transfers outside the DIFC to a non-adequate jurisdiction.
  7. ConfirmedOneTrust DataGuidanceNeither the ADGM Regulations nor the GDPR require data localisation or residency for personal data.

#

Telecoms and health overlays are documented; financial-sector overlay evidence is limited to one regulation; credit, education and insurance sub-modules have no confirmed evidence.

Supervisory authorityTelecommunications and Digital Government Regulatory Authority (TRA/TDRA)
Traffic-light rationale — AmberTelecoms and health overlays are documented; financial-sector overlay evidence is limited to one regulation; credit, education and insurance sub-modules have no confirmed evidence.

Sub-modules (7)

Financial Sector OverlayAmber

The UAE Stored Value Facilities Regulation was reportedly the first UAE law to mandate data minimization as a compliance requirement.

Claims: CLM-AE-f6g7h801

Health Sector OverlayAmber

The Health Data Law/ICT Health Law governs ICT use in healthcare across mainland and free zones; Abu Dhabi's DOH applies its own 2020 healthcare-data-privacy standards; Dubai Healthcare City is separately governed by Federal Law No. 2 of 2019.

Claims: CLM-AE-f6g7h802, CLM-AE-f6g7h803, CLM-AE-f6g7h804

Telecoms And EprivacyAmber

The Law Regulating the Telecommunications Sector gives the TRA jurisdiction over customer-data-use regulation and criminalizes unauthorized disclosure of call/message content.

Claims: CLM-AE-f6g7h805

Employment DataRed

No AE-specific employment-data overlay was confirmed in available sources beyond the general PDPL framework.

Absence provenance: not recorded. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Credit And ScoringRed

No AE-specific credit-scoring data rules were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

EducationRed

No AE-specific education-sector data rules were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

InsuranceRed

No AE-specific insurance-sector data rules were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Category narrative78 words

Telecommunications and healthcare are the most clearly documented sectoral overlays: the TRA derives customer-data jurisdiction from the Law Regulating the Telecommunications Sector, health data is separately governed by the federal ICT Health Law and (within Dubai Healthcare City) Federal Law No. 2 of 2019, and Abu Dhabi's Department of Health imposes its own healthcare-data-privacy standards. A financial-sector data-minimization requirement appears in the Stored Value Facilities Regulation. Credit-scoring, education, and insurance-sector-specific data rules were not confirmed in available sources.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe UAE Stored Value Facilities Regulation was the first UAE law to specifically mandate information/data minimization as a compliance requirement.
  2. ConfirmedOneTrust DataGuidanceThe UAE Health Data Law/ICT Health Law applies to all methods and uses of information and communication technology in the UAE healthcare sector, covering both mainland and free-zone entities.
  3. ConfirmedOneTrust DataGuidanceThe Department of Health Abu Dhabi's Standards on Healthcare Data Privacy 2020 apply specifically to entities within the Emirate of Abu Dhabi and strictly define how health data may be used, stored, shared and protected.
  4. ConfirmedOneTrust DataGuidanceDubai Healthcare City is governed by Federal Law No. 2 of 2019 (Healthcare Data Protection Law), which regulates protection of individuals' data within DHCC, including restrictions on data disclosures and transfers, superseding the 2013 DHCC Data Protection Regulation.
  5. ConfirmedOneTrust DataGuidanceThe Law Regulating the Telecommunications Sector gives the Telecommunications Regulatory Authority jurisdiction to implement regulations concerning customer data use (Article 14) and criminalizes disclosure of the content of a call or message sent through the network (Article 72).

#

No comprehensive adtech-specific regime was confirmed for the UAE in available research; only the general PDPL consent framework applies.

Traffic-light rationale — RedNo comprehensive adtech-specific regime was confirmed for the UAE in available research; only the general PDPL consent framework applies.

Sub-modules (6)

Cookies And TrackersRed

No AE-specific cookie/tracker law was confirmed.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office, UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Dark PatternsRed

No AE-specific dark-pattern prohibition was confirmed.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Opt Out SignalsRed

No AE-specific recognition of browser-level opt-out signals (e.g., GPC) was confirmed.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Clean Rooms And DcrRed

No AE-specific clean-room/data-collaboration-room rules were confirmed.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Cross Context AdvertisingRed

No AE-specific cross-context-advertising ('sale'/'share') framework analogous to CPRA was confirmed.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Direct MarketingAmber

The PDPL's general consent requirement covers processing for direct-marketing purposes in principle, but no AE-specific suppression-list or marketing-consent statute was confirmed.

Claims: CLM-AE-g7h8i901

Category narrative27 words

No AE-specific cookie/tracker consent regime, dark-pattern prohibition, Global-Privacy-Control-style opt-out recognition, clean-room rule, or direct-marketing-specific consent/suppression regime was located in available sources beyond the PDPL's general consent-for-processing requirement.

Sources and claims (1)
  1. ProbableIAPPThe PDPL requires organizations to create consent forms and disclosures for the processing of all personal data, which in practice would extend to processing for direct-marketing purposes absent a specific statutory exception.

#

AI policy infrastructure and one DIFC-specific binding regulation are documented; federal biometric/genetic/surveillance-carveout specifics are unconfirmed.

Primary frameworkDIFC Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems
Supervisory authorityUAE AI Office / Council for AI and Blockchain
Traffic-light rationale — AmberAI policy infrastructure and one DIFC-specific binding regulation are documented; federal biometric/genetic/surveillance-carveout specifics are unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No AE-specific profiling-restriction statute distinct from general PDPL principles was confirmed.

Absence provenance: not recorded. Searched: UAE artificial intelligence law regulation 2024 2025 AI governance Dubai.

Automated Decision Making TransparencyAmber

DIFC Regulation 10 specifically addresses processing of personal data through autonomous and semi-autonomous systems and is in force.

Claims: CLM-AE-h8i9j001

Ai Risk AssessmentsAmber

UAE AI governance relies on strategy documents, ethics guidelines and self-assessment tools (e.g., AI System Ethics Self-Assessment Tool) rather than a binding AI risk-assessment statute.

Claims: CLM-AE-h8i9j002, CLM-AE-h8i9j003

Biometric RegimeRed

No AE federal-level biometric-data-specific regime was confirmed; ADGM's GDPR-aligned special-category definition (which would typically capture biometric data) is the closest available proxy.

Absence provenance: not recorded. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

Genetic DataRed

No AE-specific genetic-data regime was confirmed in available sources.

Absence provenance: not recorded. Searched: UAE PDPL data subject rights right to access erasure objection cross border transfer adequacy list.

State Surveillance CarveoutsRed

No AE-specific state-surveillance carve-out provisions were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE PDPL executive regulations 2024 issued Cabinet Decision breach notification timeline fine.

Category narrative50 words

UAE AI governance is conducted primarily through national strategy, ethical guidelines and sector initiatives rather than dedicated cross-sectoral AI legislation, though the DIFC has an in-force Regulation 10 specifically governing personal data processing through autonomous/semi-autonomous systems. Federal-level biometric- and genetic-data-specific regimes, and state-surveillance carve-outs, were not confirmed in available sources.

Sources and claims (3)
  1. ConfirmedIAPPThe DIFC's Regulation 10 on Processing Personal Data Through Autonomous and Semi-Autonomous Systems is in force.
  2. ConfirmedIAPPUAE AI governance is conducted primarily through national strategy, ethical guidelines and sector-specific initiatives — including the UAE National Strategy for Artificial Intelligence 2031 — rather than through dedicated cross-sectoral AI legislation.
  3. ConfirmedIAPPIn October 2024, the UAE Cabinet approved the country's International Stance on Artificial Intelligence Policy, and the UAE has issued non-binding guidance resources including an AI Ethics Principles and Guidelines document and an AI System Ethics Self-Assessment Tool.

#

Coverage of children's/vulnerable-groups' data is thin and inconsistent across the UAE's fragmented regime; no dedicated federal children's-data regime was confirmed.

Traffic-light rationale — RedCoverage of children's/vulnerable-groups' data is thin and inconsistent across the UAE's fragmented regime; no dedicated federal children's-data regime was confirmed.

Sub-modules (5)

Age VerificationAmber

ADGM defines a child as a natural person under 18, but no age-verification mechanism was confirmed.

Claims: CLM-AE-i9j0k101

Minor Profiling BansRed

No AE-specific minor-profiling ban was confirmed in available sources.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Education SettingsRed

No AE-specific education-sector children's-data rules were confirmed.

Absence provenance: not recorded. Searched: UAE TDRA telecommunications data protection consumer protection regulation cybercrime law personal data.

Dependent AdultsRed

No AE-specific dependent-adult data protections were confirmed in available sources.

Absence provenance: not recorded. Searched: UAE Federal Data Protection Law 2021 PDPL UAE Data Office.

Category narrative59 words

Free-zone instruments provide limited, inconsistent coverage of children's data: ADGM defines a child as under 18 (versus GDPR's 16, adjustable to 13) but does not set explicit parental-consent mechanics, while DIFC Law 2020, like its 2007 predecessor, does not generally address children's data at all. No federal PDPL-specific children's-data provisions, minor-profiling bans, education-setting rules, or dependent-adult protections were confirmed.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceADGM Data Protection Regulations define a child as a natural person under the age of 18, in contrast to GDPR's default age of consent of 16 (adjustable by Member States to not younger than 13), but do not explicitly outline requirements for consent to process children's data.
  2. ConfirmedOneTrust DataGuidanceDIFC Law 2020, consistent with its 2007 predecessor, does not generally refer to children's data or provide specific requirements for collecting personal data from children.

#

DIFC enforcement track record and powers are well documented; federal PDPL-specific enforcement activity, funding, and any collective-redress mechanism remain unconfirmed, and no confirmed developments within the last 180 days were located.

Primary frameworkDIFC Law No. 5 of 2020
Supervisory authorityDIFC Commissioner of Data Protection
Traffic-light rationale — AmberDIFC enforcement track record and powers are well documented; federal PDPL-specific enforcement activity, funding, and any collective-redress mechanism remain unconfirmed, and no confirmed developments within the last 180 days were located.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The DIFC Commissioner may issue proportionate administrative fines for contraventions and compel payment via court order; broader UAE laws carry penalties up to AED 1 million or imprisonment.

Claims: CLM-AE-j0k1l201, CLM-AE-j0k1l202, CLM-AE-j0k1l203

Enforcement Activity IndexAmber

By August 2021, DIFC authorities had issued 88 fines since the region's late-2020 data protection regulations became effective.

Claims: CLM-AE-j0k1l204

Regulator Funding And CapacityRed

No funding or headcount data for the Emirates Data Office or DIFC Commissioner's office was confirmed in available sources.

Absence provenance: not recorded. Searched: UAE PDPL 2026 update executive regulations status latest.

Collective Redress And Class ActionsRed

No AE-specific collective-redress or class-action mechanism for data protection claims was confirmed; DIFC provides individual complaint/mediation only.

Claims: CLM-AE-j0k1l205

Private Right Of ActionAmber

Data subjects may lodge complaints directly with the DIFC Commissioner, who may mediate and, if unresolved, issue binding directions to controllers.

Claims: CLM-AE-j0k1l205

Recent Developments 180DRed

No confirmed UAE data-protection regulatory developments within the 180 days preceding this run (approx. late January 2026 through July 29, 2026) were located in available sources.

Absence provenance: not recorded. Searched: UAE data protection 2026 enforcement fine Emirates Data Office news, UAE PDPL 2026 update executive regulations status latest.

Category narrative61 words

The DIFC Commissioner has clear, exercised administrative-fine, investigation, and complaint/mediation powers, with 88 fines reported issued since late-2020 regulations took effect. Broader UAE privacy-adjacent statutes (constitution, Penal Code, Cyber Crime Law) carry penalties as high as AED 1 million or imprisonment. Federal PDPL-specific penalty schedules, recent (180-day) enforcement developments, regulator funding/capacity data, and collective-redress/class-action mechanisms were not confirmed in available sources.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe DIFC Commissioner may issue general fines for contraventions of the Data Protection Law by a controller or processor (including sub-processors), in an amount considered appropriate and proportionate to the seriousness of the contravention and risk of harm to data subjects.
  2. ConfirmedDIFC AuthorityThe DIFC Commissioner may conduct investigations and inspections to verify compliance and may apply to the court for an order compelling payment of unpaid administrative fines, including publishing details of the matter.
  3. ConfirmedIAPPViolations of UAE constitutional, Penal Code, Cyber Crime Law and sector-specific privacy provisions can carry penalties as high as AED 1 million or potential imprisonment.
  4. ConfirmedIAPPAuthorities in the Dubai International Financial Centre had issued 88 fines since the region's new data protection regulations became effective in late 2020, as of publication in August 2021.
  5. ConfirmedDIFC AuthorityA person may file a complaint with the DIFC Commissioner, who applies mediation practices and procedures aimed at timely, fair and effective resolution, and may issue a binding direction to a controller under Article 60(4) of the DIFC Law if mediation does not resolve the matter.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United Arab Emirates
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 47 claim(s), 13 source(s) in the cumulative register.