Back to blog
Saudi & GCC

UAE data protection: the federal law, the free zones, and which one applies to you

The UAE has a federal personal data protection law and separate regimes in the DIFC and ADGM financial free zones. Establishing which applies is the first question, and getting it wrong invalidates the rest of your programme.
GRC Copilot Team
Read in:
UAE data protection: the federal law, the free zones, and which one applies to you

The most consequential question in UAE privacy compliance is not what the rules say — it is which set of rules applies to you. The UAE operates a federal personal data protection law alongside separate, long-established regimes in the financial free zones, and they are genuinely different instruments.

Three regimes, not one

  • The federal law — applies broadly to processing of personal data in the UAE, with extraterritorial reach to organisations outside the UAE processing data of people inside it. Certain sectors and entities are carved out.
  • DIFC — the Dubai International Financial Centre has its own data protection law, closely modelled on GDPR, with its own commissioner and its own enforcement.
  • ADGM — Abu Dhabi Global Market likewise operates its own regime and regulator.
If your entity is established in DIFC or ADGM, the free zone regime governs your processing — not the federal law. Companies with entities inside and outside a free zone can be subject to more than one, which is common and routinely missed at the design stage.

What the obligations look like

All three follow the familiar architecture: a lawful basis for processing, transparency, purpose limitation and minimisation, retention limits, security appropriate to risk, individual rights, controls on international transfers, breach notification, and accountability — being able to demonstrate compliance rather than assert it.

The free zone regimes track GDPR closely enough that a GDPR-aligned programme transfers well. The federal law shares the architecture with its own definitions, exemptions and procedural detail, so mapping is required rather than assuming equivalence.

Run one privacy control set across jurisdictions

GRC Copilot maps processing records, controls and evidence across UAE, Saudi and international privacy requirements in one place.

The practical questions to settle first

  1. Which regime binds each entity? Determine per legal entity, not per office.
  2. Do you need a representative or a registered DPO? Requirements differ between regimes and thresholds.
  3. Where does the data actually sit, including backups and support access from other regions?
  4. What transfer mechanism applies for each outbound flow?
  5. What is your breach notification clock, and to which regulator?

Sector rules sit on top

Financial services, health and telecoms each carry additional sectoral requirements — including, in some cases, data localisation obligations more demanding than the general privacy law. Health data in particular attracts specific handling and residency expectations. Check the sector rules before concluding your obligations from the privacy law alone.

A note on timing

The federal regime has been developing, with implementing detail issued over time. Confirm the current position on executive regulations and enforcement timelines with local counsel before finalising a programme — the architecture is stable but the procedural specifics have moved, and this is not an area to rely on a secondary source for.

Frequently asked questions

Does GDPR compliance cover us in the UAE?

It gives you a strong foundation, particularly for DIFC and ADGM which are closely modelled on it. It does not automatically satisfy the federal law, and it says nothing about sectoral residency rules.

We are in DIFC — does the federal law apply?

Generally the free zone regime governs your processing. Confirm per entity, especially in group structures spanning free zone and mainland.

Is data localisation required?

Not as a blanket rule under the general privacy law, but sectoral requirements — notably health and parts of financial services — can impose it. Verify by sector.

Who enforces?

The federal regulator for the federal law, and the respective commissioners for DIFC and ADGM. Different regulators, different processes.

Key takeaways

  • Determine the applicable regime per legal entity before anything else.
  • DIFC and ADGM are separate GDPR-modelled regimes with their own regulators.
  • Sector rules can impose residency the general law does not.
  • Confirm current procedural detail with local counsel — the architecture is stable, the specifics have moved.
#uae #pdpl #data-protection #privacy #free-zones #difc #adgm