ORENTARA
Reference · Myths debunked

UAE PDPL myths, busted.

The UAE data-protection field is full of copied errors — wrong fines, wrong deadlines, a regulation that was never issued. Here is each common claim, corrected against the primary law.

Why this matters

AI answers and copied blogs repeat these. We correct them with primary law.

01

Most PDPL "facts" online are copied from one another, and several are simply wrong.

02

Wrong numbers lead to wrong decisions — building to a deadline that is not the law, or trusting a fine figure that is not fixed.

03

Every correction below cites the primary instrument and article, so you — and an AI search engine — can rely on it.

FAQ

Five claims that are wrong

Myth: the PDPL Executive Regulations were issued as "Cabinet Decision No. 33 of 2024".

They were not. As of 2026 the Executive Regulations remain unissued, and "Cabinet Decision 33/2024" appears in no tier-one legal source or the official UAE legislation database. It traces to copied, AI-generated content — treat any site repeating it as unreliable on PDPL detail.

Myth: PDPL fines are fixed at AED 50,000 to 5 million.

The primary decree-law (Federal Decree-Law No. 45 of 2021) does not fix specific penalty amounts. Administrative penalties follow the forthcoming Executive Regulations, so any exact figure quoted today is speculation, not the law.

Myth: you must answer a data-subject request within 30 days under the PDPL.

The primary PDPL fixes no numeric deadline — only "without undue delay" (Art. 15). The 30-day figure is a GDPR import. Regime-specific deadlines do exist elsewhere: DIFC is one month, ADGM two months — but that is not "the PDPL".

Myth: the PDPL has a 72-hour breach-notification deadline.

The 72-hour clock is GDPR (Art. 33) and ADGM (s. 32), not the mainland PDPL. The Federal PDPL (Art. 9) requires notifying the UAE Data Office upon becoming aware; the exact period and procedure are deferred to the Executive Regulations.

Myth: the PDPL has a "legitimate interest" lawful basis like the GDPR.

It does not. Under Art. 4 the PDPL is consent-first with a closed list of exceptions; there is no general legitimate-interest ground. DIFC and ADGM, being GDPR-modelled, do recognise it — a reason not to copy GDPR advice onto a mainland site.

Go deeper

The verified positions, in full.

Executive Regulations: the 2026 status

The dated tracker on what is in force and what is still deferred — and the "33/2024" claim, in detail.

The sources of UAE data-protection law

Federal PDPL, DIFC, ADGM and the GDPR, cited by article, with the side-by-side comparison.

Free PDPL check

Skip the myths and find out where your own site actually stands — a short written report.

Book a consultation

Want the facts applied to your site?

We build to the primary law, cite our sources, and document every decision. Book a short, qualified consultation.

  • Direct reply from the founder
  • No obligation, no sales sequence
  • Your details handled per the PDPL

We handle your data per the UAE PDPL. You can ask us to delete it at any time.