Langprotect

UAE PDPL & AI Compliance

Understand how the UAE Personal Data Protection Law applies to AI systems processing personal data, and build the security, privacy, and governance controls needed to protect it.

Federal Decree-Law No. 45 of 2021: In ForceScope: Personal Data Processing
UAE PDPL & AI

What Is the UAE PDPL?

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) establishes the UAE's federal framework for protecting personal data and regulating how organizations collect, process, store, use, and transfer it.

The law defines requirements for data controllers and processors, establishes rights for data subjects, and introduces safeguards for higher-risk processing. These requirements become particularly relevant when AI systems process personal, sensitive, or automatically evaluated data.

What Does the UAE PDPL Require?

The UAE PDPL establishes obligations for data controllers and processors and rights for data subjects. For AI systems, these requirements extend to the data entering AI applications, how it is processed, where it is stored, and how organizations respond to individuals' rights.

Articles 4–5

Lawful & Fair Processing

Process personal data lawfully, fairly, transparently, and for specified purposes.

Article 6

Consent & Lawful Bases

Establish consent or another permitted legal basis before processing personal data.

Article 7

Sensitive Personal Data

Apply additional protections when processing sensitive personal data.

Articles 13–18

Data Subject Rights

Support rights including access, correction, erasure, portability, restriction, objection, and certain automated-decision rights.

Articles 4, 10–12

Controller & Processor Obligations

Define responsibilities, processor relationships, records, and governance requirements.

Article 10

Data Protection Officer

Appoint a DPO in specified high-risk processing circumstances.

Article 20

Data Security

Apply appropriate technical and organizational measures to protect personal data.

Article 24

Data Breach Management

Assess and report qualifying personal-data breaches and notify affected individuals where required.

Article 21

Impact Assessments

Conduct assessments for specified high-risk processing, including certain automated and sensitive-data processing.

Articles 22–23

Cross-Border Transfers

Establish safeguards for transferring personal data outside the UAE.

UAE PDPL at a Glance

Get a quick overview of the UAE Personal Data Protection Law, including its scope, core requirements, and how it applies to organizations processing personal data through AI and other digital systems.

REGULATIONUAE Personal Data Protection Law
ISSUEDSeptember 2021
EFFECTIVEJanuary 2022
STATUSIn Force
SCOPEPersonal Data Processing
APPLICABILITYControllers & Processors within the law's scope
CORE REQUIREMENTSPrivacy, security, data subject rights, governance & transfers
REGULATORUAE data protection authorities / competent authorities

Who Should Consider UAE PDPL Compliance?

The UAE PDPL applies to a wide range of organizations, from UAE-based entities to global businesses processing personal data of individuals in the UAE.

UAE-Based Organizations

UAE-Based Organizations

Organizations established in the UAE that collect or process personal data.

Global Organizations

Global Organizations

Organizations outside the UAE that process personal data of individuals in the UAE.

AI Developers & Providers

AI Developers & Providers

Organizations building or providing AI systems that process personal data.

AI-Enabled Enterprises

AI-Enabled Enterprises

Businesses using AI across customer, employee, operational, or business workflows.

Organizations Processing Sensitive Data

Organizations Processing Sensitive Data

Organizations handling health, biometric, genetic, or other sensitive personal data.

Organizations Using Automated Decisions

Organizations Using Automated Decisions

Businesses using AI for profiling, evaluation, or decisions that may significantly affect individuals.

Technology & Cloud Providers

Technology & Cloud Providers

Providers processing personal data on behalf of organizations through AI, cloud, or other technology services.

Organizations With International Data Flows

Organizations With International Data Flows

Organizations whose AI systems, cloud environments, or third-party providers process personal data across borders.

UAE PDPL Readiness Checklist

Identify AI systems that collect or process personal data
Map personal data across prompts, inputs, outputs, logs, and connected systems
Identify sensitive personal data processed by AI
Document the purpose and legal basis for each processing activity
Apply data minimization and purpose limitation
Establish appropriate retention and deletion practices
Identify controllers, processors, and third-party AI providers
Review processor agreements and data-handling responsibilities
Assess whether DPO requirements apply
Identify AI systems involving profiling or automated decisions
Conduct impact assessments for qualifying high-risk processing
Establish human oversight for consequential automated decisions
Apply appropriate technical and organizational security measures
Protect personal data in AI prompts, context, outputs, and logs
Apply access controls and least-privilege permissions
Use encryption, pseudonymization, or masking where appropriate
Monitor AI interactions for unauthorized data exposure
Test security controls across the AI lifecycle
Establish processes for data subject requests
Support access, correction, erasure, portability, and other applicable rights
Maintain an AI-aware breach response process
Identify personal-data exposure across AI systems and providers
Establish escalation and notification procedures
Maintain evidence of security and privacy controls
Identify where AI providers process personal data
Assess cross-border transfers and applicable safeguards
Review third-party AI security and privacy controls
Monitor changes to AI providers and processing locations
Document shared responsibilities across the AI supply chain

UAE PDPL & AI Security

AI introduces new paths through which personal data can be collected, processed, retained, and exposed. The UAE PDPL's privacy and security requirements therefore need to extend beyond traditional applications to the AI interactions, models, tools, and third-party services handling personal data.

Protect Personal Data in AI Inputs

Prompts, uploaded documents, customer records, employee information, and application context can all contain personal data. Organizations should control what information AI systems can receive and where that data can flow.

Secure AI Outputs & Logs

AI responses, conversation histories, traces, and application logs can contain or reproduce personal information. Organizations need visibility and controls across these outputs and supporting data stores.

Control Sensitive Data

AI systems may encounter health, biometric, genetic, or other sensitive personal data. Sensitive information should be identified, minimized, protected, and monitored throughout AI workflows.

Govern Automated Decisions

AI systems used for profiling or consequential automated decisions require additional consideration. Organizations should understand where automated processing affects individuals and establish appropriate safeguards and human oversight.

Secure Third-Party AI

External AI platforms can act as processors or introduce additional data-processing relationships. Organizations should understand what data third-party AI services receive, how it is used, where it is processed, and what controls protect it.

Monitor AI Activity

Security controls should provide visibility into how AI systems access, process, transmit, and expose personal data. Continuous monitoring can help identify unauthorized access, policy violations, and data leakage.

How UAE PDPL Fits Into the AI Compliance Landscape

The UAE PDPL focuses on protecting personal data and regulating how organizations collect, process, store, and transfer it. Other frameworks can complement it by addressing broader AI governance, security, and risk-management concerns.

DIFC Data Protection Law

DIFC Data Protection Law

The DIFC Data Protection Law establishes data protection requirements for organizations operating within the DIFC. Organizations subject to both frameworks may need to assess the applicable requirements across their UAE operations and data-processing activities.

ADGM Data Protection Regulations

ADGM Data Protection Regulations

The ADGM Data Protection Regulations provide a separate data protection framework for organizations operating within the ADGM. They should be considered alongside the federal UAE PDPL where organizations operate across different UAE jurisdictions.

GDPR

GDPR

The GDPR establishes requirements for protecting personal data and may apply to organizations processing personal data of individuals in the EEA. It can complement the UAE PDPL for organizations managing AI systems and data flows across both jurisdictions.

ISO/IEC 42001

ISO/IEC 42001

ISO/IEC 42001 provides requirements for establishing an Artificial Intelligence Management System. It can complement the UAE PDPL by providing a structured approach to AI governance, risk management, policies, and oversight.

NIST AI RMF

NIST AI RMF

NIST AI RMF provides a broader framework for managing AI risks through Govern, Map, Measure, and Manage. It can help organizations structure AI risk management alongside their privacy and data protection programs.

OWASP GenAI / LLM Security Guidance

OWASP GenAI / LLM Security Guidance

OWASP provides security guidance for LLM-powered applications and AI workflows, covering risks such as prompt injection, sensitive information disclosure, excessive agency, and other AI-specific threats. It can complement UAE PDPL requirements by helping organizations secure AI systems that process personal data.

Frequently Asked Questions

Official UAE PDPL Resources

For authoritative guidance on the UAE Personal Data Protection Law, refer to the official UAE resources: