Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
Middle EastMEDIUM coverage

UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031: AI Compliance Requirements

The UAE Personal Data Protection Law (PDPL/PDPA) is enforced by the UAE Data Office. It covers processing of personal data of individuals in the UAE regardless of where the organization is located. The UAE AI Strategy 2031 targets becoming a global AI hub and requires compliance with both PDPL and sectoral regulations. Financial services, healthcare, and government AI deployments face additional CBUAE, DoH, and TDRA requirements. Dubai DIFC and Abu Dhabi ADGM have separate data protection frameworks.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 2, 2022

Enforcement Begins

October 2, 2022

Maximum Penalty

AED 5,000,000 (~$1.36M USD) is the administrative-fine ceiling most consistently cited by secondary sources (the specific violation-to-penalty schedule is set by a separate Cabinet Decision under PDPL Article 26, not stated as a fixed figure in the Decree-Law itself — not independently fetched this cycle). Criminal liability (imprisonment plus fine) is also possible for intentional unlawful processing per secondary sources, but no specific criminal-fine ceiling is confirmed this cycle. Some secondary sources instead cite an AED 20,000,000 ceiling for the most serious violation category (e.g. processing without any compliant framework) — see the parallel uae_pdpl entry's maxPenalty for the same unresolved-pinpoint finding.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Establish Lawful Basis for AI Data Processing

Critical

UAE PDPL Article 4 requires a lawful basis for processing personal data: consent, contractual necessity, legal obligation, vital interests, or legitimate interests. AI systems processing UAE residents' data must document the lawful basis for each processing activity, with explicit consent for sensitive data categories.

Deadline: October 2, 2022

PDPL Federal Decree-Law 45/2021 Art. 4

Data Subject Rights Implementation

Critical

UAE PDPL Articles 14-16 grant individuals rights of access, correction, deletion, restriction, and objection. AI systems must have mechanisms to honor these rights within 30 days. Profiling and automated decision-making must be disclosed.

PDPL Federal Decree-Law 45/2021 Arts. 14-16

Cross-Border Data Transfer Controls

High Priority

UAE PDPL Article 22 restricts transfer of UAE personal data outside the UAE to countries with adequate protection. AI cloud services, training data, and API calls that process UAE data internationally require adequacy determination or Standard Contractual Clauses approved by the UAE Data Office.

PDPL Federal Decree-Law 45/2021 Art. 22

UAE AI Strategy 2031 Alignment

Medium Priority

Government and regulated-sector AI deployments must align with the UAE National AI Strategy 2031, which requires responsible AI governance, human oversight for consequential decisions, and bias auditing. CBUAE circular requires financial institutions to have an AI governance framework.

UAE National AI Strategy 2031 (policy framework); CBUAE AI governance circular for financial institutions

Recent Regulatory Guidance

guidance2024-04

UAE Data Office + DIFC Commissioner of Data Protection — AI and Personal Data Guidance (2023-2024)

Coordinated UAE Data Office guidance laid out Federal PDPL application to AI: (1) controllers must publish privacy policies disclosing AI-driven processing and lawful basis; (2) cross-border transfers to non-adequate jurisdictions require Data Office authorization or supplementary measures; (3) AI-driven automated decisions affecting UAE residents trigger transparency and human-review rights under Article 11; (4) sectoral overlays apply (CBUAE for financial services, DoH for healthcare, TDRA for telecoms). DIFC Commissioner of Data Protection's separate AI guidance applies in DIFC. ADGM Data Protection Regulations (DPR 2021) cover ADGM-licensed entities with parallel AI-governance expectations.

Industry Playbooks covering UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031

These industry playbooks include jurisdiction-specific checklist items and guidance for UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031.

Frequently Asked Questions

Does UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031 apply to my business?

The UAE Personal Data Protection Law (PDPL/PDPA) is enforced by the UAE Data Office. It covers processing of personal data of individuals in the UAE regardless of where the organization is located. The UAE AI Strategy 2031 targets becoming a global… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031 is: AED 5,000,000 (~$1.36M USD) is the administrative-fine ceiling most consistently cited by secondary sources (the specific violation-to-penalty schedule is set by a separate Cabinet Decision under PDPL Article 26, not stated as a fixed figure in the Decree-Law itself — not independently fetched this cycle). Criminal liability (imprisonment plus fine) is also possible for intentional unlawful processing per secondary sources, but no specific criminal-fine ceiling is confirmed this cycle. Some secondary sources instead cite an AED 20,000,000 ceiling for the most serious violation category (e.g. processing without any compliant framework) — see the parallel uae_pdpl entry's maxPenalty for the same unresolved-pinpoint finding.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://u.ae/en/information-and-services/justice-safety-and-the-law/handling-cybercrimes-and-other-offences/personal-data-protection

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan