Back to blog
Comparisons

GDPR, UK GDPR, Saudi PDPL and UAE law compared

Four privacy regimes with one shared architecture and genuinely different mechanics. A side-by-side matrix of scope, lawful bases, rights, transfers, breach clocks and enforcement.
GRC Copilot Team
GDPR, UK GDPR, Saudi PDPL and UAE law compared

Modern privacy laws share an architecture, which is why a programme built for one transfers well to the others. What does not transfer is the mechanics: transfer instruments, representative requirements, notification clocks and registration duties. This matrix separates the two.

EU GDPRUK GDPR + DPA 2018Saudi PDPLUAE federal law
ExtraterritorialYes — targeting or monitoring EU individualsYes — targeting or monitoring UK individualsYes — processing data of individuals in KSAYes — processing data of individuals in the UAE
RegulatorMember-state authorities, one-stop-shopICONational data protection authorityFederal authority; DIFC and ADGM have their own
Lawful basesSix, incl. legitimate interestsSix, same setDefined set; consent prominentDefined set; consent prominent
Core rightsAccess, rectify, erase, restrict, port, objectSameAccess, correct, destroy, withdraw consentAccess, correct, erase, restrict, port, object
Breach notice72h to regulator; high risk to individuals72h to ICO; high risk to individualsPrescribed period; notify authority and, where required, individualsPrescribed period to authority and affected individuals
TransfersAdequacy, SCCs, BCRsUK adequacy, IDTA, or EU SCCs + UK AddendumAdequacy-style conditions; safeguards and exceptionsAdequacy-style conditions; contractual safeguards
DPOMandatory in defined casesMandatory in defined casesRequired in defined casesRequired in defined cases
Registration / feeNo general registrationAnnual ICO feeRegistration duties may applyVaries; free zones differ
Read the transfers row twice. It is the row that most often invalidates an otherwise sound programme: unmodified EU standard contractual clauses do not cover a UK export, and the Gulf regimes have their own conditions rather than recognising either.

One control set across every privacy regime

GRC Copilot maps processing records, controls and evidence across privacy frameworks together, so overlapping obligations are satisfied once.

What genuinely transfers

Records of processing, data mapping, retention schedules, security controls, DPIA methodology, breach triage process, vendor due diligence and privacy notices — the substance. Build these to the strictest applicable standard and they serve every regime.

What must be maintained per regime

  • Transfer instruments — a separate mechanism per jurisdiction pair.
  • Representatives where you process for people in a territory without an establishment there.
  • Registration and fees, which are small administrative duties with penalties attached.
  • Notification routes — different regulators, different portals, credentials registered in advance.
  • Local-language documentation, frequently expected in the Gulf for dealings with government entities.

A practical rule

Build to the strictest requirement, document once, and keep a small per-jurisdiction register for the mechanics. Running a separate privacy programme per country produces duplicated effort and inconsistent answers to the same question.

One caveat on currency: the Gulf regimes have been developing their implementing detail, so confirm procedural specifics with local counsel rather than relying on any secondary source, including this one. The architecture is stable; the procedure has moved.

Frequently asked questions

Does GDPR compliance cover the others?

It covers most of the substance and none of the mechanics. Transfers, representatives and registration all need jurisdiction-specific work.

Can we use EU SCCs for a UK transfer?

Only with the UK Addendum attached, or by using the UK's own transfer agreement instead.

Is consent the safest basis everywhere?

No. Consent is withdrawable and often the weakest option. The Gulf regimes lean on it more heavily than GDPR, but where an alternative basis fits, it is usually more robust.

Which is strictest?

The wrong question — they differ by dimension. Build to the strictest requirement per obligation rather than ranking the laws.

Key takeaways

  • The substance transfers; the mechanics do not.
  • Transfer instruments are the row that most often breaks a programme.
  • Representatives and registration duties are small and easily missed.
  • Confirm Gulf procedural detail with local counsel — it has been moving.
#gdpr #uk-gdpr #pdpl #uae #privacy #comparison #matrix