Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Gulf Cooperation Council · Six jurisdictions

Six states, eight regimes, and no single rulebook.

Five of the six GCC states now have comprehensive data protection laws, and the UAE alone runs three regimes at once. The concepts travel well from the GDPR. The procedure does not: registration, prior authorisation, transfer approvals and criminal exposure differ materially from one Gulf state to the next.

At a glance

The Gulf regimes side by side

Treat each jurisdiction as a separate compliance target. Concepts are broadly GDPR-shaped, but registration duties, transfer approvals and penalties diverge, and the UAE requires you to decide which of three regimes applies to each entity.

Data protection regimes across the GCC
JurisdictionPrincipal instrumentRegulatorStatus and distinguishing feature
UAE (onshore)Federal Decree-Law No. 45 of 2021UAE Data OfficeIn force 2 January 2022. Executive regulations still awaited as at September 2026, leaving transfer and registration detail unsettled.
DIFCData Protection Law No. 5 of 2020DIFC Commissioner of Data ProtectionMature and GDPR-aligned. Annual notification, recognised-jurisdiction transfers, and a distinctive Article 14 regime for certain high-risk processing.
ADGMData Protection Regulations 2021ADGM Office of Data ProtectionRegistration and annual renewal. Closely modelled on the GDPR with its own adequacy list.
Saudi ArabiaPersonal Data Protection Law (Royal Decree M/19), as amendedSDAIAFully enforceable since 14 September 2024. The most actively regulated Gulf regime, with implementing regulations, a national register and criminal exposure for sensitive-data disclosure.
QatarLaw No. 13 of 2016NCSA Data Privacy Protection DepartmentThe first comprehensive GCC law. Notable for direct-marketing consent rules and for approval requirements around processing of special-nature data.
BahrainLaw No. 30 of 2018Personal Data Protection AuthorityDistinctive prior-authorisation model for defined processing and for transfers outside the approved country list, with imprisonment available for certain offences.
OmanRoyal Decree No. 6 of 2022MTCITFull effect from 5 February 2026 following its transition period. Permit requirements apply to defined processing, and penalties include criminal sanctions.
KuwaitCITRA Data Privacy Protection Regulation 2021CITRANo comprehensive statute. Sectoral and telecom-facing rules, constitutional protections and cybercrime legislation fill the gap.

United Arab Emirates

Three regimes, decided entity by entity

Federal Decree-Law No. 45 of 2021

Applies onshore to controllers and processors in the UAE processing personal data of data subjects inside or outside the state, and to those outside the UAE processing the data of data subjects inside it. Provides GDPR-shaped lawful bases, data subject rights, DPO requirements in defined cases, breach notification and records of processing.

The missing regulations

The executive regulations were anticipated to set out cross-border transfer mechanics, registration, breach timelines and the compliance grace period. They remain unissued as at September 2026. Build to the Decree-Law and to DIFC or GDPR-grade controls, and keep a change-watch so you can adjust quickly.

DIFC

Data Protection Law No. 5 of 2020 with its own Commissioner. Requires annual notification of processing activities, applies a recognised-jurisdiction and standard-clause model for transfers, and imposes distinct obligations where processing involves high-risk activities. Fines are issued directly by the Commissioner.

ADGM

Data Protection Regulations 2021 with the Office of Data Protection. Requires registration and annual renewal, maintains its own adequacy list, and follows GDPR structure closely on rights, DPIAs and accountability.

Choosing the right regime

The applicable regime follows where the entity is established and licensed, not where the data sits or where the customer is. A group with onshore, DIFC and ADGM entities needs three sets of notices, records and transfer mechanisms, and intra-group flows between them are cross-border transfers.

Sectoral overlays

Health data localisation under the ICT health law, banking and insurance rules, and Federal Law No. 26 of 2025 on child digital safety add duties on top of the general regime.

Saudi Arabia

The PDPL and SDAIA, the region’s most active enforcement

The Personal Data Protection Law became fully enforceable on 14 September 2024. SDAIA supervises it, supported by implementing regulations, separate transfer regulations and a national register of controllers. It is the Gulf regime most likely to generate enforcement activity against foreign organisations.

Extraterritorial reach

Applies to processing of personal data of individuals residing in Saudi Arabia by any means, including by entities outside the Kingdom. Non-resident controllers must appoint a licensed representative in the Kingdom.

Registration and DPO

Controllers register on the national data controller register. A DPO is required where the entity is a public body, where core activities involve regular and systematic large-scale monitoring, or where core activities involve large-scale sensitive data processing.

Breach notification

Notify SDAIA within 72 hours of becoming aware where the breach may cause harm to the data or the data subject, and notify affected data subjects without undue delay where there is serious harm to their data or to them.

Transfers

Permitted for defined purposes subject to SDAIA adequacy assessment, appropriate safeguards or a narrow exception, with a transfer risk assessment required in defined cases. The transfer regulations set the detail.

Penalties

Administrative fines up to SAR 5 million, which may be doubled for repeat infringement. Disclosure of sensitive personal data with intent to harm or for personal benefit carries imprisonment of up to two years, a fine of up to SAR 3 million, or both.

Guidance load

SDAIA publishes substantial guidance on lawful bases, legitimate interest, DPIAs, minimum personal data rules and sector-specific expectations. It is treated as the operative standard in audits, so track it.

Qatar, Bahrain and Oman

Established, procedural, and newly in force

Qatar: Law No. 13 of 2016

The first comprehensive law in the GCC, supervised by the NCSA. Requires privacy notices, data subject rights handling and security measures, imposes specific consent rules on direct electronic marketing, and requires authority approval for processing personal data of a special nature such as health, ethnicity, religious belief and criminal records.

Bahrain: Law No. 30 of 2018

Supervised by the Personal Data Protection Authority. Its defining feature is prior authorisation: defined categories of processing require the authority’s advance approval, as do transfers to countries not on the approved list. Organisations may appoint a registered data protection guardian. Certain breaches carry imprisonment as well as fines.

Oman: Royal Decree No. 6 of 2022

Took full effect on 5 February 2026 after its transition period, supervised by MTCIT. Requires consent-centred processing with defined exceptions, permits for certain processing including sensitive data, notification of breaches, and appointment of a data protection officer in prescribed cases. Penalties include fines and criminal sanctions.

Kuwait

No comprehensive statute, but not a vacuum

Kuwait is the one GCC state without a general data protection law. The principal instrument is CITRA’s Data Privacy Protection Regulation of 2021, which applies to telecommunications and internet service providers and to entities within CITRA’s regulatory perimeter, requiring privacy policies, consent, security measures and defined retention. Constitutional privacy protections, the electronic transactions law, cybercrime legislation and Central Bank rules for financial institutions supply the remainder. Organisations should apply a GDPR-shaped baseline by contract and policy rather than waiting for a statute, and monitor for legislative developments.

Patterns

What repeats across the region

GDPR-shaped concepts

Controller and processor roles, lawful bases, notice, data subject rights, security, records and accountability recur in every Gulf regime. A GDPR programme transfers well at the conceptual level.

Procedure is the divergence

Registration, notification, prior authorisation, permits and licensed local representatives are where Gulf regimes depart from the EU model, and where organisations most often fail.

Criminal exposure

Unlike the GDPR, several Gulf regimes attach imprisonment to defined offences, particularly unlawful disclosure of sensitive data. This changes the risk conversation with executives and local management.

Localisation by sector

Health, banking, telecom and government data frequently carry residency or approval requirements that sit outside the general data protection law. Check the sector rule before designing the architecture.

Arabic and local language

Notices, consents and regulator filings are commonly expected in Arabic. Budget for legal translation rather than treating the English text as sufficient.

Free zones are separate

In the UAE, and in financial free zones more generally, the zone regime displaces the onshore one. Intra-group transfers across zone boundaries are international transfers and need a mechanism.

Implementation

Where to start

1

Map entities to regimes

List every legal entity, its licensing jurisdiction and free-zone status, and assign the applicable regime. This is the step that determines everything downstream in the UAE.

2

Complete registrations and permits

Saudi national register, ADGM registration, DIFC notification, Bahraini prior authorisations and Omani permits all have their own cycles and renewal dates. Calendar them.

3

Appoint local representatives and DPOs

Non-resident controllers need licensed representatives in Saudi Arabia, and DPO triggers differ across the region. Record the appointment basis for each jurisdiction.

4

Build a per-destination transfer register

One group-wide transfer answer will not survive audit. Record the mechanism per destination per jurisdiction, and note where you are awaiting the UAE executive regulations.

5

Rehearse the 72-hour clock

Multiple Gulf regulators expect notification within 72 hours, and several expect parallel notification to sector regulators. Test the multi-regulator scenario, not just one.

Questions

Frequently asked questions

Do the UAE federal law and the DIFC and ADGM laws overlap?

No, they operate in parallel rather than on top of each other. Federal Decree-Law No. 45 of 2021 applies onshore across the UAE. The DIFC applies its own Data Protection Law No. 5 of 2020 and the ADGM its Data Protection Regulations 2021, each with its own independent commissioner, its own registration or notification mechanics and its own transfer rules. A group with entities in more than one of these zones is running multiple regimes at once, and an onshore entity cannot rely on a DIFC assessment to demonstrate federal compliance.

Are the UAE federal executive regulations in force yet?

Not as at September 2026. Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022, but the executive regulations that were expected to set out detail on transfers, registration, breach mechanics and the grace period have still not been issued. The substantive obligations in the Decree-Law itself apply, so the practical approach is to build to the text of the law and to DIFC or GDPR-grade practice, then adjust when the regulations arrive.

Which GCC regulator is most active?

Saudi Arabia’s SDAIA. The PDPL became fully enforceable on 14 September 2024 following its transition period, and SDAIA has issued implementing regulations, a national register of controllers and detailed guidance. It combines a 72-hour breach notification duty, fines up to SAR 5 million that can be doubled for repeat infringement, and criminal exposure including imprisonment for unlawful disclosure of sensitive data, which is unusual by international standards.

Does Kuwait have a data protection law?

Not a comprehensive one. Kuwait relies on the CITRA Data Privacy Protection Regulation of 2021, which binds telecommunications and internet service providers and entities within CITRA’s regulatory perimeter, alongside constitutional privacy protections, e-transactions and cybercrime legislation and sectoral rules from the Central Bank. Organisations operating in Kuwait should not assume a general statutory regime, but should not assume a vacuum either.

What is the general position on cross-border transfers in the Gulf?

Most Gulf regimes follow an adequacy-plus-safeguards model with a consent-based derogation, but the detail and the maturity differ sharply. Saudi Arabia permits transfers subject to SDAIA’s adequacy assessments and the transfer regulations, with a risk assessment required in defined cases. The DIFC and ADGM operate recognised-jurisdiction lists with standard clauses and binding corporate rules. The UAE federal position awaits its executive regulations. Bahrain requires prior authorisation from the authority unless the destination is on the approved list. Assume you need a documented mechanism per destination per jurisdiction rather than one group-wide answer.

Is there a single GCC-wide data protection instrument?

No. There is no GCC equivalent of the GDPR and no supranational regulator. The GCC has pursued cooperation frameworks and common digital policy positions, but data protection law remains national, and in the UAE’s case sub-national as well. Harmonisation is real at the level of concepts, lawful bases, data subject rights, breach reporting and accountability, and thin at the level of procedure.

Verify

Primary sources

General information, not legal advice. Gulf regimes are moving quickly, the UAE executive regulations remain outstanding, and free-zone rules change independently of federal law. Verify the current instrument and any sectoral overlay before relying on this page. Researched 21 September 2026.

Operating across the Gulf?

We map entities to the right regime, complete registrations and permits, and build transfer and breach evidence that holds up in front of SDAIA, the DIFC Commissioner and the UAE Data Office.

Talk to Vedhacon