UAE PDPL Compliance for AI Systems: Federal Decree-Law No. 45 of 2021 Explained
The UAE Personal Data Protection Law (PDPL) is the federal data protection framework that applies to companies on UAE mainland — outside DIFC and ADGM free zones. For AI teams, it introduces obligations around automated processing, sensitive data, data transfers, and disclosure. Here is what applies and what you need to do.
UAE PDPL — scope and applicability
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data came fully into effect in January 2022, with its executive regulations (Cabinet Resolution No. 33 of 2022) providing detailed implementation requirements. The law is enforced by the UAE Data Office, an independent authority established under the same decree.
The PDPL applies to any controller or processor that processes personal data in the UAE, or that processes personal data of UAE residents from outside the UAE. This extraterritorial scope is similar to GDPR's Article 3 approach.
Jurisdiction note
The UAE PDPL does not apply to companies registered in DIFC or ADGM — these free zones have their own data protection laws (DIFC DPL 2020 and ADGM DPR 2021). If your company is registered in a UAE free zone, check whether that zone has its own framework.
Six lawful bases under UAE PDPL
Article 5 of the PDPL and Article 4 of the executive regulations set out the grounds for lawful processing. For AI systems, the most practically relevant are:
- Consent: Explicit, informed, and freely given. Must be documented. Data subjects can withdraw consent at any time.
- Contractual necessity: Processing required to perform or prepare a contract with the data subject. Used for financial services AI, insurance AI, HR AI.
- Legitimate interests: Available but requires balancing test — the controller's interests must not override the data subject's rights. Used for fraud detection, analytics, personalization.
- Legal obligation: Where UAE law requires processing (e.g. AML/KYC).
Article 11 — Automated processing restrictions
Article 11 of the UAE PDPL addresses automated processing. It is less comprehensive than GDPR Article 22 or DIFC DPL Article 19, but it creates important obligations:
- Data subjects have the right to object to automated processing that produces legal or similarly significant effects
- Controllers must disclose that automated processing is used in privacy notices
- Data subjects may request human review of automated decisions in certain circumstances
The UAE PDPL's Article 11 is considered less prescriptive than GDPR Article 22. It does not have the same default prohibition on solely automated decisions — instead, it requires transparency and provides a right to object. The practical implication: you must disclose automated processing and have a process for handling objections and review requests.
What "similarly significant effects" means under UAE PDPL
The executive regulations confirm that significant effects include decisions that affect:
- Financial products or services access (credit, insurance)
- Employment or recruitment outcomes
- Access to housing or public services
- Any other decision with material impact on the individual's rights or circumstances
Sensitive personal data — heightened obligations
Article 6 of the UAE PDPL defines sensitive data categories where stronger protections apply:
- Racial or ethnic origin
- Political or religious opinions
- Health and medical data
- Biometric data used for identification
- Criminal convictions and offences
- Financial account details
- Data about children under 18
For AI systems processing these categories, explicit consent is required — not just any lawful basis. Healthcare AI, biometric authentication, and financial fraud detection AI all involve sensitive categories and require careful compliance structuring.
Data localization requirements
The UAE PDPL has specific localization requirements for government data and certain sensitive categories. Article 22 of the PDPL and related regulations require that personal data with strategic or national importance be stored within UAE territory. The Data Office maintains a list of prohibited transfer categories.
For most private sector AI systems, the localization requirements are less strict — cross-border transfers are permitted with appropriate safeguards. However, if your AI system processes government-related data, health data at scale, or financial transaction data for UAE government entities, localization may apply.
Cross-border data transfers
Article 22 of the UAE PDPL permits transfers to countries with "equivalent" data protection standards, or via contractual mechanisms approved by the UAE Data Office. In practice, this means AI systems running on cloud infrastructure outside the UAE should have:
- An adequacy assessment or confirmation that the destination country meets UAE standards
- Standard contractual clauses (SCCs) adapted for UAE PDPL or processor agreements that meet Article 22 requirements
- Documentation of the transfer and the safeguards in place
Privacy notice requirements for AI systems
Article 9 of the UAE PDPL requires controllers to provide a clear privacy notice before or at the time of collecting personal data. For AI systems, the notice must include:
- Identity and contact details of the data controller
- Purposes of processing and the legal basis
- Categories of data collected
- Recipients of data (including AI model providers)
- Retention periods
- Data subject rights (access, correction, deletion, objection)
- Whether automated processing is used and what effects it may have
Data subject rights relevant to AI
| Right | Article | AI System Implication |
|---|---|---|
| Right of access | Art. 15 | Must provide copy of data used in AI training or decisions |
| Right to correction | Art. 16 | Inaccurate data in AI training sets must be correctable |
| Right to deletion | Art. 17 | Deletion requests may require AI model retraining if data is embedded |
| Right to object | Art. 11 | Must have process for handling objections to automated processing |
| Right to data portability | Art. 19 | Data used for AI personalization must be exportable on request |
UAE National AI Strategy — voluntary framework for private sector
Beyond the PDPL, the UAE has published a National Strategy for Artificial Intelligence 2031 and a National AI Governance Framework managed by the UAE Digital Government Authority (TDRA). The governance framework includes:
- AI risk classification: critical, high, medium, and low risk AI use cases
- Requirements for government AI: mandatory risk assessments, transparency, accountability
- Guidance for private sector: recommended governance practices aligned with international standards
Private sector companies are not legally required to follow the TDRA AI Governance Framework, but demonstrating alignment with it can support regulatory relationships and B2B procurement in the UAE government market.
UAE PDPL enforcement — what to expect
The UAE Data Office began enforcement activities in 2023. Penalties under the PDPL include:
- Fines of up to AED 5 million (approximately USD 1.36 million) for violations
- Higher fines for violations involving sensitive personal data or data of children
- Criminal penalties for intentional or reckless violations of certain provisions
- Compliance orders and audit requirements
Enforcement has focused initially on large-scale violations — data breaches not notified, international transfers without adequate safeguards, and absence of privacy notices. As the regulatory framework matures, AI-specific enforcement is expected to increase, particularly for automated decision-making in financial and employment contexts.
Practical compliance roadmap for AI systems under UAE PDPL
- Data mapping: Document all personal data your AI system processes — inputs, training data, outputs, logs
- Lawful basis: For each processing purpose, identify and document the Article 5 basis
- Privacy notice: Update to disclose automated processing, data categories, and data subject rights including objection rights
- Automated processing register: Document which AI decisions are automated and which have human oversight
- Objection handling process: Build a workflow for processing Article 11 objections and human review requests
- Sensitive data controls: Identify any Article 6 sensitive categories in AI inputs; ensure explicit consent where required
- Transfer assessment: For AI running on non-UAE infrastructure, complete a transfer assessment and put SCCs or equivalent in place
- Incident response: Prepare a breach notification procedure with Data Office notification templates
- Retention: Define data retention periods for AI training data, model logs, and decision records
- Register with Data Office: Confirm registration requirements apply to your processing activities
UAE PDPL compliance in Aegis Firma
Aegis Firma includes UAE PDPL as a supported jurisdiction. The platform generates a task list covering all Article 5, 6, 9, 11, 15–19, and 22 obligations relevant to your AI systems. The compliance score tracks your progress, and the evidence store keeps documentation ready for the Data Office.
Start UAE PDPL compliance assessment