The UAE for GDPR-ready companies: what transfers, what changes.
If you already run a GDPR programme, most of the UAE will feel familiar — and familiarity is exactly where teams get caught. A free whitepaper on what carries over, the handful of differences that trip European teams up, and the free-zone islands where your GDPR playbook largely still holds.
Why read it
The UAE is not the GDPR with an Arabic translation. It is its own instrument.
A GDPR-fluent team has a real head start here — the same principles, rights, breach and DPO concepts you already know.
But a few specific differences reliably catch European teams: consent-first with no legitimate-interest basis on the mainland, a differently-worded extraterritorial trigger, and no Article 27 representative.
And the mainland's response deadline and breach clock are not what your GDPR muscle memory expects — the primary law sets neither; both are deferred to regulations that do not yet exist.
A glance
EU GDPR vs UAE federal PDPL — the rows that catch teams out.
A preview of the comparison at the heart of the whitepaper. The full paper adds the citations, the nuance, and the free-zone picture.
| EU GDPR | UAE federal PDPL (mainland) | |
|---|---|---|
| Lawful bases | Six bases, including legitimate interests | Consent-first; no general legitimate-interest basis |
| Rights response deadline | Within one month (extendable +2) | No numeric deadline in the primary law — deferred to the Executive Regulations |
| Breach notification | Within 72 hours of awareness | Upon becoming aware; no fixed 72-hour clock in the primary law |
| Local representative | Required for most extraterritorial controllers (Art. 27) | Not required by the law as enacted |
Not legal advice. A preview of the whitepaper table; the paper cites each row to a primary text or tier-1 source.
What's inside
One spine: what is the same, what is different, what will trip you up.
Written for teams that already know the GDPR, so it spends its time on the deltas rather than re-explaining the basics.
The comparison at a glance
GDPR against the mainland PDPL, dimension by dimension — the anchor of the paper.
What your GDPR work transfers
How much of your existing programme carries over almost intact.
The deltas that catch teams out
Lawful basis, extraterritorial scope, deadlines, and the missing representative mandate.
The free-zone islands
DIFC and ADGM run GDPR-aligned law — where much of your programme still holds.
Free whitepaper
Get the GDPR-to-UAE whitepaper.
Enter your name and email and we send the PDF straight to your inbox. No cost, no obligation — the newsletter opt-in below is entirely optional.
- Direct reply from the founder
- No obligation, no sales sequence
- Your details handled per the PDPL
FAQ
Before you request it
Who is this whitepaper for?
EU-origin and GDPR-fluent teams operating toward or into the UAE — legal, privacy, and operations leads who want to know what their GDPR programme transfers and what it does not.
Is it legal advice?
No. It is factual, regulatory context for decision-makers who already run a GDPR programme. Have a qualified lawyer review anything you intend to rely on for a specific decision.
What does it cost, and what do I need to give?
It is free. We only need your name and a valid email to send the PDF. The optional newsletter opt-in is separate and unbundled — you get the whitepaper either way.
We operate in the DIFC / ADGM — is this still relevant?
Yes — a full section covers the free zones. Both run their own GDPR-aligned law, and knowing whether you sit on the mainland or in a free zone is the first and most consequential decision.
Related
Go deeper, or get it checked.
The companion whitepaper: the UAE landscape and the practical case for getting ready before the Regulations land.
Have us review your live site against the UAE PDPL and send back a written readiness report.
Federal PDPL, DIFC, ADGM and the GDPR, cited by article — the reference behind the whitepaper.