Skip to content
← All articles
UAE·April 2026·10 min read

UAE PDPL Compliance for AI Systems: Federal Decree-Law No. 45 of 2021 Explained

The UAE Personal Data Protection Law (PDPL) is the federal data protection framework that applies to companies on UAE mainland — outside DIFC and ADGM free zones. For AI teams, it introduces obligations around automated processing, sensitive data, data transfers, and disclosure. Here is what applies and what you need to do.

UAE PDPL — scope and applicability

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data came fully into effect in January 2022, with its executive regulations (Cabinet Resolution No. 33 of 2022) providing detailed implementation requirements. The law is enforced by the UAE Data Office, an independent authority established under the same decree.

The PDPL applies to any controller or processor that processes personal data in the UAE, or that processes personal data of UAE residents from outside the UAE. This extraterritorial scope is similar to GDPR's Article 3 approach.

Jurisdiction note

The UAE PDPL does not apply to companies registered in DIFC or ADGM — these free zones have their own data protection laws (DIFC DPL 2020 and ADGM DPR 2021). If your company is registered in a UAE free zone, check whether that zone has its own framework.

Six lawful bases under UAE PDPL

Article 5 of the PDPL and Article 4 of the executive regulations set out the grounds for lawful processing. For AI systems, the most practically relevant are:

Article 11 — Automated processing restrictions

Article 11 of the UAE PDPL addresses automated processing. It is less comprehensive than GDPR Article 22 or DIFC DPL Article 19, but it creates important obligations:

The UAE PDPL's Article 11 is considered less prescriptive than GDPR Article 22. It does not have the same default prohibition on solely automated decisions — instead, it requires transparency and provides a right to object. The practical implication: you must disclose automated processing and have a process for handling objections and review requests.

What "similarly significant effects" means under UAE PDPL

The executive regulations confirm that significant effects include decisions that affect:

Sensitive personal data — heightened obligations

Article 6 of the UAE PDPL defines sensitive data categories where stronger protections apply:

For AI systems processing these categories, explicit consent is required — not just any lawful basis. Healthcare AI, biometric authentication, and financial fraud detection AI all involve sensitive categories and require careful compliance structuring.

Data localization requirements

The UAE PDPL has specific localization requirements for government data and certain sensitive categories. Article 22 of the PDPL and related regulations require that personal data with strategic or national importance be stored within UAE territory. The Data Office maintains a list of prohibited transfer categories.

For most private sector AI systems, the localization requirements are less strict — cross-border transfers are permitted with appropriate safeguards. However, if your AI system processes government-related data, health data at scale, or financial transaction data for UAE government entities, localization may apply.

Cross-border data transfers

Article 22 of the UAE PDPL permits transfers to countries with "equivalent" data protection standards, or via contractual mechanisms approved by the UAE Data Office. In practice, this means AI systems running on cloud infrastructure outside the UAE should have:

Privacy notice requirements for AI systems

Article 9 of the UAE PDPL requires controllers to provide a clear privacy notice before or at the time of collecting personal data. For AI systems, the notice must include:

Data subject rights relevant to AI

RightArticleAI System Implication
Right of accessArt. 15Must provide copy of data used in AI training or decisions
Right to correctionArt. 16Inaccurate data in AI training sets must be correctable
Right to deletionArt. 17Deletion requests may require AI model retraining if data is embedded
Right to objectArt. 11Must have process for handling objections to automated processing
Right to data portabilityArt. 19Data used for AI personalization must be exportable on request

UAE National AI Strategy — voluntary framework for private sector

Beyond the PDPL, the UAE has published a National Strategy for Artificial Intelligence 2031 and a National AI Governance Framework managed by the UAE Digital Government Authority (TDRA). The governance framework includes:

Private sector companies are not legally required to follow the TDRA AI Governance Framework, but demonstrating alignment with it can support regulatory relationships and B2B procurement in the UAE government market.

UAE PDPL enforcement — what to expect

The UAE Data Office began enforcement activities in 2023. Penalties under the PDPL include:

Enforcement has focused initially on large-scale violations — data breaches not notified, international transfers without adequate safeguards, and absence of privacy notices. As the regulatory framework matures, AI-specific enforcement is expected to increase, particularly for automated decision-making in financial and employment contexts.

Practical compliance roadmap for AI systems under UAE PDPL

  1. Data mapping: Document all personal data your AI system processes — inputs, training data, outputs, logs
  2. Lawful basis: For each processing purpose, identify and document the Article 5 basis
  3. Privacy notice: Update to disclose automated processing, data categories, and data subject rights including objection rights
  4. Automated processing register: Document which AI decisions are automated and which have human oversight
  5. Objection handling process: Build a workflow for processing Article 11 objections and human review requests
  6. Sensitive data controls: Identify any Article 6 sensitive categories in AI inputs; ensure explicit consent where required
  7. Transfer assessment: For AI running on non-UAE infrastructure, complete a transfer assessment and put SCCs or equivalent in place
  8. Incident response: Prepare a breach notification procedure with Data Office notification templates
  9. Retention: Define data retention periods for AI training data, model logs, and decision records
  10. Register with Data Office: Confirm registration requirements apply to your processing activities

UAE PDPL compliance in Aegis Firma

Aegis Firma includes UAE PDPL as a supported jurisdiction. The platform generates a task list covering all Article 5, 6, 9, 11, 15–19, and 22 obligations relevant to your AI systems. The compliance score tracks your progress, and the evidence store keeps documentation ready for the Data Office.

Start UAE PDPL compliance assessment
UAE PDPL Compliance for AI Systems: Federal Decree-Law No. 45 of 2021 Guide 2026 | Aegis Firma