Questions
Frequently asked questions
Do the UAE federal law and the DIFC and ADGM laws overlap?
No, they operate in parallel rather than on top of each other. Federal Decree-Law No. 45 of 2021 applies onshore across the UAE. The DIFC applies its own Data Protection Law No. 5 of 2020 and the ADGM its Data Protection Regulations 2021, each with its own independent commissioner, its own registration or notification mechanics and its own transfer rules. A group with entities in more than one of these zones is running multiple regimes at once, and an onshore entity cannot rely on a DIFC assessment to demonstrate federal compliance.
Are the UAE federal executive regulations in force yet?
Not as at September 2026. Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022, but the executive regulations that were expected to set out detail on transfers, registration, breach mechanics and the grace period have still not been issued. The substantive obligations in the Decree-Law itself apply, so the practical approach is to build to the text of the law and to DIFC or GDPR-grade practice, then adjust when the regulations arrive.
Which GCC regulator is most active?
Saudi Arabia’s SDAIA. The PDPL became fully enforceable on 14 September 2024 following its transition period, and SDAIA has issued implementing regulations, a national register of controllers and detailed guidance. It combines a 72-hour breach notification duty, fines up to SAR 5 million that can be doubled for repeat infringement, and criminal exposure including imprisonment for unlawful disclosure of sensitive data, which is unusual by international standards.
Does Kuwait have a data protection law?
Not a comprehensive one. Kuwait relies on the CITRA Data Privacy Protection Regulation of 2021, which binds telecommunications and internet service providers and entities within CITRA’s regulatory perimeter, alongside constitutional privacy protections, e-transactions and cybercrime legislation and sectoral rules from the Central Bank. Organisations operating in Kuwait should not assume a general statutory regime, but should not assume a vacuum either.
What is the general position on cross-border transfers in the Gulf?
Most Gulf regimes follow an adequacy-plus-safeguards model with a consent-based derogation, but the detail and the maturity differ sharply. Saudi Arabia permits transfers subject to SDAIA’s adequacy assessments and the transfer regulations, with a risk assessment required in defined cases. The DIFC and ADGM operate recognised-jurisdiction lists with standard clauses and binding corporate rules. The UAE federal position awaits its executive regulations. Bahrain requires prior authorisation from the authority unless the destination is on the approved list. Assume you need a documented mechanism per destination per jurisdiction rather than one group-wide answer.
Is there a single GCC-wide data protection instrument?
No. There is no GCC equivalent of the GDPR and no supranational regulator. The GCC has pursued cooperation frameworks and common digital policy positions, but data protection law remains national, and in the UAE’s case sub-national as well. Harmonisation is real at the level of concepts, lawful bases, data subject rights, breach reporting and accountability, and thin at the level of procedure.