Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

UAE data protectionFederal PDPL, DIFC and ADGM

UAE data protection compliance across mainland, DIFC and ADGM. Fixed fees from AED 6,500.

The UAE has three data protection regimes, and which one applies depends on where you are licensed. The federal PDPL is law and its executive regulations are still awaited; DIFC and ADGM already enforce theirs. We work out what applies to you and build it into your systems before it becomes urgent.

  • Fixed fees in AED
  • Implemented in your systems, not just a policy
  • Engineers, working alongside your lawyers

What is at stake

Enforcement under the UAE Federal PDPL, the DIFC Data Protection Law and the ADGM Data Protection Regulations

Sector rules also apply: healthcare data, telecoms and financial services carry their own localisation and security requirements.

  1. US$28m

    ADGM Data Protection Regulations 2021 maximum fine

  2. Schedule fines

    DIFC Data Protection Law fines per contravention, plus individual claims in DIFC Courts

  3. To be issued

    Federal PDPL administrative penalties, to be set by Cabinet decision

What the law asks, in plain words

Eight things to get right in United Arab Emirates

  • Know your regime

    Mainland companies fall under the federal PDPL; DIFC and ADGM entities follow their own laws. Many groups are subject to more than one.

  • Notice and legal basis

    Tell people what you process and why, and rely on consent or another permitted basis.

  • Breach notification

    ADGM requires notification within 72 hours; DIFC without undue delay; the federal PDPL requires notifying the Data Office and affected people.

  • Data subject rights

    Access, correction, erasure, restriction, objection and portability, depending on the regime.

  • Security by design

    Technical and organisational measures proportionate to the risk, with impact assessments for high-risk processing.

  • Records and DPO

    Records of processing, and a data protection officer where processing is large-scale or sensitive.

  • Cross-border transfers

    Transfers only to jurisdictions with adequate protection or under approved safeguards.

  • Sector rules

    Health data localisation, TDRA and Central Bank requirements can go further than the general laws.

Free self-check

How ready is your organisation?

Ten questions, two minutes. Nothing is sent anywhere unless you ask for help.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Do you know which regime applies to each entity: mainland, DIFC or ADGM?
  2. 2Do you have an inventory of personal data across your systems?
  3. 3Is your privacy notice available in Arabic and English?
  4. 4Could you notify the regulator within 72 hours of a breach?
  5. 5Can you handle access and erasure requests on time?
  6. 6Do you keep records of processing activities?
  7. 7Are high-risk projects covered by an impact assessment?
  8. 8Are transfers outside the UAE covered by safeguards?
  9. 9Have you checked sector rules such as health data localisation?
  10. 10Are vendors bound by data protection contracts?

How we get you compliant

Four steps, done with your team

  1. 1

    Discover

    Find every copy of personal data

    Website, apps, CRM, ERP, spreadsheets, messaging tools and vendors.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap scored against enforcement exposure and effort, so the serious ones get fixed first.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent, request workflows, access controls, retention and vendor terms.

  4. 4

    Hand over

    Train people, rehearse a breach

    A live session for the staff who handle data and a practice run of breach reporting.

Pricing

Fixed fees. No surprises.

For organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know which rules apply and where the gaps are.

AED6,500one-time
+ VAT

Report in 7 working days

Choose Readiness Audit
  • Discovery session with an engineer
  • Regime mapping for mainland, DIFC and ADGM entities
  • Data map across up to 5 systems
  • Gap report ranked by enforcement risk
  • 90-day action plan

Recommended

Compliance Setup

We implement the controls in your systems.

AED19,500one-time
+ VAT

Typically 4 to 6 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • Arabic and English privacy notices
  • Consent and rights request workflows
  • Breach playbook with 72-hour template
  • Records of processing and impact assessment template
  • Transfer safeguards checklist
  • Live staff training session

Data Protection Care

Stay ready as regulations are issued.

AED2,450per month
+ VAT

Cancel any month

Choose Data Protection Care
  • Rights request handling support
  • Quarterly review of systems and vendors
  • Breach support during UAE business hours
  • Updates when executive regulations are published
  • Annual refresher training

Free readiness call

Talk to an engineer, not a salesperson

An engineer replies within one working day with a suggested approach and a fixed quote.

  1. 1
    You send the formTwo minutes. Tell us the problem, not the solution.
  2. 2
    We talk it throughA short call at a time that suits your working hours.
  3. 3
    You get a fixed quoteIn writing, in AED. Nothing is billed until you approve it.

Book your free readiness call

Interested in

See our privacy policy.

Questions

UAE data protection questions we get asked

Also see how Stratgik works with United Arab Emirates businesses.

Is the UAE federal PDPL enforceable yet?

The law has been in force since January 2022, but its executive regulations had not been issued as of 2026, and penalties are to be set by Cabinet decision. Preparing now avoids a rushed programme when the grace period starts.

We are in DIFC or ADGM. Does the federal law apply?

Entities in DIFC and ADGM are governed by their own data protection laws, which are already enforced. Groups with mainland entities usually need to meet both.

What are the fines in ADGM and DIFC?

ADGM can fine up to US$28 million. DIFC sets fines per contravention in a schedule to its law, and since 2025 individuals can bring claims directly in DIFC Courts.

Does UAE law require data to stay in the country?

Not generally, but sector rules do. Health data, for example, is subject to localisation requirements.

Is this legal advice?

No. Stratgik is a technology firm. We implement the controls and records in your systems and work with your legal counsel for legal opinions.

Are prices fixed?

Yes, for organisations with up to five systems holding personal data. Larger scope is quoted in writing first. VAT is added where applicable.

Find the gaps before a regulator does.

A readiness audit takes 7 working days and gives you a ranked, costed plan.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.