Market · Markets

Delivering in the UAE: Three Data Protection Regimes, and Which One You Are Under Depends on Your Trade Licence

The UAE runs three separate, non-overlapping data protection regimes with three different regulators. Which one applies is decided by where you are registered, not where you operate, and it changes the whole compliance position.

United Arab Emirates Updated 2026-08-10 710 words · about 3 min read

BvLogic is headquartered in Dubai. This is the market we know best and the one where we can be most specific, so this page is longer on detail and shorter on caveats than the others.

The thing that catches almost everybody#

The UAE does not have one data protection law. It has three, and they do not overlap:

Where you are registeredWhat governs youWho enforces it
Mainland UAEFederal Decree-Law No. 45 of 2021 (the PDPL)UAE Data Office
DIFCDIFC Data Protection Law No. 5 of 2020DIFC Commissioner of Data Protection
ADGMADGM Data Protection Regulations 2021ADGM Office of Data Protection

These are parallel regimes with separate supervisory authorities. Your trade licence decides which one you are under, not the emirate your users are sitting in and not where your servers are.

Both free zone regimes are modelled closely on GDPR and are broadly equivalent in substance to the federal PDPL. "Broadly equivalent" is doing real work in that sentence: they are similar enough that teams assume one analysis covers all three, and separate enough that the analysis has to be redone when a group has entities in more than one.

The practical failure we see most: a group with a mainland operating company and a DIFC holding company treats its data protection position as a single question. It is at least two, with two regulators, and the answer can differ.

The 2026 change that matters#

The Executive Regulations to the federal PDPL were issued by Cabinet decision in 2026, which activates full enforcement. The grace period that many organisations were quietly relying on is over.

If your last PDPL assessment was done before the Executive Regulations landed, it was an assessment of an incomplete framework, and it is worth redoing rather than dusting off.

Infrastructure#

The UAE is well served. AWS, Microsoft Azure and Oracle all operate UAE regions, so in-country residency is an ordinary architectural choice here rather than a project in itself. That is not true everywhere in the region, and it is the single biggest practical difference between delivering here and delivering in Saudi Arabia today.

What this means in practice: for most workloads, residency is a configuration decision made at design time and costs you very little. Where it gets expensive is retrofitting it onto a system that was built without it, which is a data migration and a set of integration changes rather than a setting.

How buying tends to work#

Government and semi-government buyers dominate a large share of enterprise technology spend, and they buy differently: longer approval chains, an expectation of local presence, and a genuine preference for suppliers who will sit in the room. Commercial and free zone buyers move considerably faster.

For AI work specifically, the UAE's national posture is unusually forward: there is real appetite at board level and real budget, which means the constraint is more often delivery capacity and data readiness than it is permission.

What we would do differently here#

Establish the regime before the architecture. Which of the three applies, for which entity, is a half-day question and it determines the rest. Doing it last is how a design gets rebuilt.

Use the in-country regions from the start. They exist, they are mature, and residency retrofitted later costs many times what it costs at design time.

Assume group complexity. If there is a free zone entity anywhere in the structure, expect more than one regime and price the analysis accordingly.

Where we are honest about our limits#

We are not a law firm and this is not legal advice. On anything that turns on the precise reading of one of the three regimes, we work alongside your counsel rather than in place of them. What we bring is the architecture and the evidence: building systems that can demonstrate compliance, rather than opinions about what compliance requires.

Start here#

AI Readiness Assessment if the question is which use case is viable. Cloud Assessment if the question is placement and residency. Cybersecurity Assessment if you need an evidenced control position before an audit.

Sources#

What else is coming for United Arab Emirates

Market brief Ready

What is genuinely different here.