Skip to main content
UAE PDPL · Federal Decree-Law 45/2021

Be ready for UAE data protection rules before customers ask for proof.

The UAE federal data protection law is in force, but its executive regulations had not been published in the sources we reviewed. Summit tests the systems holding personal data now, so your board can act on evidence instead of waiting for final detail.

Human-led VAPT · NDA first · report in 48h

2021
year Federal Decree-Law No. 45 was issued
Jan 2022
when the law came into effect
3
separate regimes to check: federal law, DIFC and ADGM
Not yet
executive regulations had not been published in sources we reviewed
Board and leadership view

Why UAE PDPL matters to your board

The work is technical. The consequences of getting UAE PDPL wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Revenue and market access

UAE enterprise, bank and free-zone customers already ask suppliers about personal data safeguards. Evidence keeps deals moving.

Regulatory exposure and liability

The law is in force even though its detail is still developing. A tested, documented baseline is the best protection while rules settle.

Reputation

A breach of customer data is visible fast in a tight-knit market. Finding weaknesses first protects trust.

Deadlines and ownership

Dates may change as regulations arrive. Leadership should own a plan now so that final rules mean small adjustments, not a scramble.

Fit

Who needs to pay attention

Software and cloud companies in the UAE

UAE enterprise customers add data protection questions to security reviews and contracts.

Mainland businesses holding customer data

Retail, real estate, logistics and services firms hold large volumes of personal data.

Firms working with DIFC or ADGM entities

Free-zone counterparties often expect proof of strong safeguards from their suppliers.

International companies serving UAE users

The federal law has reach beyond the borders; confirm your exposure with a legal adviser.

Scope of work

What Summit delivers for UAE PDPL

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

We map your UAE federal, DIFC and ADGM security safeguards against what the law expects and rank the gaps by business impact.

Penetration testing of systems holding personal data

Human-led testing of the applications, APIs, cloud and networks that store or process UAE personal data, with proof of impact.

Control validation

We check that access control, encryption, logging and retention work as your policies say, not just that they exist.

Evidence pack

Test results, screenshots, scope notes and fix records organised so a regulator, auditor or customer can follow them.

Remediation support and retest

Our engineers explain each fix to your developers, then retest and issue updated results showing what closed.

Board-ready report

A short executive summary in plain English with risk ratings, owners and dates, ahead of the technical detail.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A realistic UAE PDPL security roadmap

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Map personal data and regimes

    Weeks 1 to 3

    Identify systems holding personal data and which of federal law, DIFC or ADGM applies to each.

  2. 2

    Gap analysis

    Weeks 3 to 5

    Compare safeguards with the law and with customer expectations, and rank the gaps.

  3. 3

    Test the systems

    Weeks 5 to 9

    Penetration test applications, APIs and cloud environments, with validation of key controls.

  4. 4

    Fix and retest

    Weeks 9 to 14

    Close findings with developer support and retest to confirm.

  5. 5

    Board report and evidence pack

    Week 14 onwards

    Give leadership a plain-English report and keep the evidence ready to update when the rules are finalised.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • One-page executive summary

    Where personal data is most exposed, what it could cost the business and what to fix first.

  • Risk-ranked findings

    Every issue rated by severity and business impact, with a named owner and a target date.

  • Evidence you can show

    A tidy pack of testing evidence for regulators, customers, insurers and your own auditors.

  • Verified fixes

    A retest report confirming which issues are closed, so leadership is not relying on a developer saying so.

  • A clear next 90 days

    A prioritised plan with effort and ownership, ready to take into a board or audit committee meeting.

The detail

What the UAE PDPL actually is

Federal Decree-Law No. 45 of 2021 is the UAE’s first standalone federal data protection law. It took effect in January 2022 and applies across the Emirates, but not to the financial free zones that run their own regimes: DIFC and ADGM each have separate data protection laws that resemble GDPR. It also carves out some categories, including certain government and health data covered by other rules.

The law sets out principles of lawful processing, consent, individual rights, security, breach notification and limits on cross-border transfers. It creates a UAE Data Office as the federal regulator. Honest status check: the executive regulations that fill in the detail had not been published in the sources we reviewed, and the Data Office was not fully operational. We cite no fines or deadlines here because we could not verify them.

That uncertainty is not a reason to wait. Customers, banks and free-zone counterparties already ask for evidence that personal data is protected. Penetration testing and control validation produce that evidence today. This guide is educational and is not legal advice.

Key terms in plain English

Controller
The organisation that decides why and how personal data is processed.
Processor
An organisation that handles personal data on a controller’s instructions, such as a cloud or payroll provider.
Executive regulations
Secondary rules that supply operational detail. Until they are published, some duties lack firm procedures.
Free zone regime
DIFC and ADGM have their own data protection law, regulator and rules, which apply inside the zone.
Requirements

The duties that have a technical side

Because the executive regulations are not in the sources we reviewed, the safest approach is to build on the duties in the law itself and on recognised security practice. Here is where technical evidence matters.

1

Protect personal data with appropriate measures

The law expects controllers and processors to apply technical and organisational measures that protect personal data against loss, alteration and unauthorised access. Testing shows those measures work in practice.

What it looks like in practice

  • Role-based access and regular access reviews
  • Encryption of personal data in transit and at rest
  • Penetration testing of systems holding personal data
  • Logging of access to sensitive records
2

Detect and report breaches

The law requires notice to the regulator and, in some cases, to affected people when a breach threatens their rights. Exact timelines depend on rules still to be confirmed, so detection and a ready response plan are what you can control now.

What it looks like in practice

  • Monitoring that spots unusual data access
  • An incident plan with named owners
  • Rehearsed decisions on when to notify
3

Handle requests to access, correct or delete

People can ask what you hold and ask for correction or erasure in some cases. Your systems must be able to find and change that data reliably.

What it looks like in practice

  • A searchable inventory of where personal data sits
  • A tested process for deletion and export
  • Authentication that stops others abusing request channels
4

Control data leaving the UAE

Transfers abroad depend on adequacy or on safeguards such as contracts and consent. No adequacy list had been published in the sources we reviewed, so teams rely on safeguards and need a clear data-flow map.

What it looks like in practice

  • A map of systems and vendors outside the UAE
  • Contracts that carry security obligations
  • Encryption and access limits on outbound data
5

Know which regime applies where

A group can sit under federal law, DIFC and ADGM at once. Each regime has its own regulator and terms. Align technical controls to the strictest common standard to avoid maintaining several versions.

What it looks like in practice

  • A table of entities, systems and the regime that applies
  • One security baseline across all entities
  • Evidence packs reusable across regimes
Where testing fits

How penetration testing supports UAE PDPL

The federal law does not name penetration testing, and without published executive regulations there is no prescribed test regime. Even so, appropriate security is a stated duty, and a human-led test with a retest is the clearest way to evidence it.

Security duty

Appropriate technical measures

A test shows whether the measures you describe hold up against realistic attacks.

Breach readiness

Detection and response

Testing reveals whether your team would spot an attacker reaching personal data.

Customer assurance

Procurement and due diligence

Banks and enterprise buyers can read a dated report and retest result directly.

Free zones

One baseline across regimes

A single tested baseline reduces rework when DIFC, ADGM and federal expectations overlap.

Avoid these

Common UAE PDPL mistakes, and how to avoid them

!

Waiting for the executive regulations

Customers and counterparties already ask for evidence. A tested baseline now avoids a rush later.

!

Assuming DIFC or ADGM rules cover the whole group

Free-zone laws apply inside the zones. Mainland operations fall under the federal law.

!

Quoting fines without checking

Penalty figures vary by source and regime. Rely on your legal adviser for current numbers.

!

Treating a scan as proof

Automated scans miss access-control and logic flaws, which are the ones that expose personal data.

FAQ

UAE PDPL questions, answered

Is the UAE PDPL in force?

The federal law took effect in January 2022. Its executive regulations had not been published in the sources we reviewed, so some operational detail is still pending. Check the current position before relying on any deadline.

Does it replace DIFC and ADGM law?

No. DIFC and ADGM keep their own data protection regimes inside the free zones. Federal law applies elsewhere in the UAE.

What are the fines?

We have not cited penalty figures because we could not verify them against the current position. Ask your legal adviser for the latest numbers for your sector and regime.

Does the UAE PDPL require penetration testing?

It does not use those words. It does require appropriate security, and testing is a widely used way to evidence that safeguards work.

Should we wait for the executive regulations?

Waiting carries risk because customers and counterparties already ask for evidence. Testing and fixing now means you only adjust paperwork later.

Does a Summit assessment give us legal clearance?

No testing firm can grant legal status. Summit delivers gap analysis, penetration testing, control validation and a board-ready report that show your technical safeguards are tested.

What does a first engagement look like?

A scoped assessment of the systems holding personal data, testing, a fix-and-retest cycle and an executive report, usually over four to six weeks of active work.

Ready to get UAE PDPL sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →