Skip to content
Regulation

The UAE personal data protection law, and the two regimes beside it

Federal Decree-Law No. 45 of 2021 is not the only data protection law that may apply to you. Two financial free zones run their own, and which one governs depends on where you are established.

6 min read

Most questions we get about UAE data protection are really questions about which law applies. There are three regimes, and they do not overlap the way people assume.

Three laws, three perimeters

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the federal regime. Each of the two financial free zones has its own statute — one enacted in 2020, the other as regulations made in 2021 — and each governs the entities established inside it. A company registered in a free zone is not under the federal law by virtue of being in the UAE; it is under the zone's, and it answers to the zone's own data protection commissioner.

The practical consequence is that a group with an onshore entity and a free-zone subsidiary has two compliance perimeters, two sets of notification duties, and two supervisors — and a single group-wide policy written for one of them is incomplete for the other.

What is common to all three

Whichever applies, the same structural obligations appear: a lawful basis for processing, a record of what you hold and why, transparency to the individual, limits on transferring data out, security proportionate to the risk, and a duty to notify when something goes wrong. The thresholds and timings differ. The shape does not.

Where the detail is still moving

The federal law contemplates executive regulations, and the operational detail — the mechanics of cross-border transfer, the precise breach notification timetable — depends on them. Anything you read that states those specifics flatly, including anything written before they issue, should be checked against the current text before you rely on it.

A reasonable first pass

  • Write down, entity by entity, which of the three regimes applies. Do not do this at group level.
  • Build the record of processing activities. It is the artefact every regulator asks for first, and it is the one that takes longest to reconstruct after the fact.
  • Find every place personal data leaves the country, including inside your own tooling.

Read the instruments themselves on the UAE Legislation platform and in each free zone's own legal database. They are public, and they are shorter than the commentary about them.

Tags

  • data-protection
  • free-zones
  • cross-border

Najem AI produces analysis and drafts for internal use. It is not legal, tax, audit or investment advice and does not create a professional relationship.

Related reading

Put the council to work

Create an account and ask your first question in under a minute.

Najem AI produces analysis and drafts for internal use. It is not legal, tax, audit or investment advice and does not create a professional relationship.

Back to top