The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to far more businesses than most people realize — including many small and mid-sized companies in Dubai and across the Emirates. Use this free self-assessment to know exactly where you stand, then follow the plain-language checklist to get compliant.
Answer a few plain questions about how your business handles personal data. We'll tell you whether PDPL likely applies, your obligation level, and a clear next-step list.
Here is an example of the output the guided tool produces. This sample is a typical result for a Dubai SME that handles customer and employee data. Yours will be tailored to your answers.
| PDPL likely applies | ✅ Yes — UAE-based, processes customer & employee data |
| Obligation level | Controller (and may be Processor for some data) |
| Priority actions | Privacy Policy · Consent mechanism · DSAR workflow · Breach response |
| Likely DPO need | Depends on processing volume & scope — assess with consultation |
Download the full Gap-Analysis Checklist →
Important: This checklist summarizes common points. The PDPL and its Executive Regulations are detailed; use this as a starting point and confirm specifics for your own case. This site does not provide legal advice.
Practical documents you can adapt and hand to your team or legal counsel — built on the structure of the UAE PDPL.
A starting document outlining what data you collect, why, and the rights of data subjects.
Download templateA ready data-subject-access-request form and handling checklist.
Download templateA register to document what, where, and how you process personal data.
Download templatePlain answers to the questions people actually search for. This helps you decide quickly whether (and how) PDPL affects you.
The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, regulates how personal data is collected, processed, stored, and transferred in the UAE. It is the UAE's primary national data-protection law, reinforced with Executive Regulations.
Very possibly yes. PDPL obligations attach to data controllers and processors processing personal data of UAE residents, with exemptions for purely personal or household use and some processing under certain government/small-scale conditions. The key is your processing scope, not simply your company size — confirm with a compliance self-assessment and legal counsel.
DPO requirements depend on the volume, sensitivity, and scope of data processing and specific rules under the PDPL and its Executive Regulations. High-scale or high-sensitivity controllers are more likely to need one. Confirm your classification with a consultation.
Data subjects generally have rights including access, correction, deletion, and more — typically enforced through a Data Subject Access Request (DSAR). Your business should have a process to receive and respond to these requests on time.
Have a breach-response plan: contain the breach, assess impact, and handle notification obligations. PDPL includes provisions relating to breach handling and notification. Prepare a plan before an incident happens.
Tick the items you already have. This gives you a simple readiness status and a clear next priority — no account needed.
This website provides general information about the UAE Personal Data Protection Law for educational purposes. It does not constitute legal advice, and does not create an attorney–client relationship. Laws and regulations can change and interpretation varies by situation. For specific matters, consult a qualified UAE legal professional. By using these free tools you agree you will not enter sensitive categories of data (health, religious, biometric, financial-account, or other special-category data) into them.
Share this free PDPL toolbox with a colleague, HR or compliance contact, or your business group.