The UAE has a data regulator, at last
The Personal Data Protection Law has bound controllers since January 2022 without a functioning supervisor. That has now changed — and the obligations were never contingent on the Regulations.
On 14 June 2026 the establishment of the Federal Authority for Artificial Intelligence and Data was announced. For the first time since the Personal Data Protection Law came into force, the country has an institution capable of enforcing it.
What was missing
Federal Decree-Law No. 45 of 2021 entered into force on 2 January 2022. What it lacked was machinery. Two pieces were absent.
The first is the Executive Regulations. Article 28 required the Cabinet to issue them within six months of promulgation, placing the deadline in or around March 2022. They have never appeared. The PDPL repeatedly defers operational detail to them: technical and organisational standards, procedures for several of the controller's obligations, conditions for exemptions, and the schedule of administrative penalties. Without them, the law states the duties but withholds much of the apparatus for enforcing them.
The second is the regulator. Federal Decree-Law No. 44 of 2021 created the UAE Data Office as the supervisory authority — the body the PDPL refers to throughout as "the Office", which receives breach reports, handles complaints, proposes the penalty schedule and issues guidance. It was established on paper and never became operational.
The result was a law in force without enforcement. Many businesses concluded the PDPL would not be enforced, and acted accordingly.
What the Authority is
The Authority consolidates three bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications; the Digital Government Sector of the TDRA; and the UAE Data Office. For data protection, the third component is the important one. By absorbing the Data Office, the Authority becomes the "Office" the PDPL has been referring to for four and a half years.
What the law already requires
The substantive obligations bind now and have bound since January 2022. An in-house team waiting for the Regulations before acting has misread what it was waiting for. Already on the face of the law: scope and its carve-outs; lawful basis, with consent the default and the controller bearing the burden of proving it; the processing principles; records of processing; the data protection officer triggers; data subject rights; breach reporting; impact assessments before high-risk processing; and the cross-border transfer regime.
Cross-border transfers deserve particular attention
Transfers are permitted to jurisdictions providing an adequate level of protection. In practice, no adequacy determinations have been published. That leaves the statutory bases — including a contract or undertaking binding the recipient to the PDPL's protections, the data subject's explicit consent, and the necessity grounds. Intra-group flows running on the assumption that the Regulations are not out so nothing applies are running on a misreading. The transfer provisions are in force.
Entities in DIFC and ADGM sit outside the onshore PDPL, under their own regimes and their own commissioners. A group holding both onshore and financial-free-zone entities is managing more than one framework at once, and movements between them are transfers, not internal housekeeping.
What this means for you
Sequence matters, and done in the wrong order the work is wasted. Confirm scope entity by entity and activity by activity. Then map the data and build the record of processing — it is the foundation, not the paperwork. Then fix and document the lawful bases. Then the DPO assessment, rights handling, a breach procedure someone has actually rehearsed, impact assessments where triggered, and transfer mechanisms.
Article 29 allows six months to regularise once the Regulations issue, extendable at the Cabinet's discretion by up to six months more. A team that begins on the day they land is well behind one that has the baseline ready.