Key takeaways
- Onshore (mainland) UAE businesses fall under the Federal PDPL (Decree-Law No. 45 of 2021), supervised by the UAE Data Office.
- The DIFC and ADGM free zones each have their own data-protection law that displaces the Federal PDPL within the zone.
- DIFC and ADGM are closely modelled on the GDPR (six lawful bases including legitimate interests); the Federal PDPL diverges (consent-first, no legitimate interest).
- The practical differences are real: response deadlines and breach timing vary by regime.
Three regimes, one question
"Which UAE data-protection law applies to me?" has three possible answers, and the deciding factor is where your entity is established — not where your customers are. A mainland company and a DIFC company doing the same thing can face materially different obligations. Get this wrong at the start and you build to the wrong rules.
Federal PDPL — onshore / mainland
The default for businesses established in the UAE outside the financial free zones. Federal Decree-Law No. 45 of 2021, supervised by the UAE Data Office. It is consent-first, has no general legitimate-interest basis, and leaves several operational specifics — deadlines, breach timing, penalties — to Executive Regulations that are still pending.
DIFC — Data Protection Law No. 5 of 2020
The Dubai International Financial Centre free zone has its own law, supervised by the DIFC Commissioner of Data Protection, and it is closely modelled on the GDPR: six lawful bases including legitimate interests, GDPR-style data-subject rights, a one-month response deadline, and breach notification "as soon as practicable". One local wrinkle: a DIFC Data Protection Officer, where required, must reside in the UAE.
ADGM — Data Protection Regulations 2021
The Abu Dhabi Global Market free zone, supervised by its Office of Data Protection, is likewise GDPR-modelled — but with its own numbers: a two-month response deadline rather than one, and a 72-hour breach-notification window. Close to DIFC, not identical.
Why the distinction matters for a website
The regime decides your lawful bases, your response clock, and where a complaint against you would be heard. Assume the Federal PDPL when you are actually a DIFC entity and you may lean on a basis you do not have, or set the wrong deadline. The pragmatic approach is to establish which regime you are in first, then design the site to it — and to build it as something that documents its data decisions, so aligning to whichever regime applies is a known, small job rather than a guess.
In the UAE, "data protection" is three laws wearing a family resemblance. Know which one is yours.
Where to go next
Not sure which is yours? Try the interactive regime picker, see the four instruments by article, or check where your own site stands with a free PDPL readiness check.
Written by Orentara
Founder-led boutique