PDPL
PDPL vs GDPR: 7 differences that break a copied privacy policy
Updated 2026-09-25
The PDPL borrows much of its vocabulary from the EU's GDPR, so reusing a European privacy policy looks like a shortcut. It is a shortcut to a document that misstates your legal position. These are the differences that matter most.
1. There is no 'legitimate interests' ground
Under the GDPR, legitimate interests is the most used legal basis after contract. The PDPL has no equivalent. Processing needs consent or one of the exceptions listed in Article 4, such as performing a contract, meeting a legal obligation, employment obligations, or establishing legal claims. A policy that says 'we process your data based on our legitimate interests' cites a basis that does not exist in UAE law.
2. A different regulator
Complaints go to the UAE Data Office, not to an EU supervisory authority. A copied policy usually names the wrong one, or none.
3. Transfers work differently
Transfers outside the UAE are allowed to countries with adequate protection (Article 22) or, where there is none, in specific cases such as under a contract imposing the PDPL's requirements, or with the individual's explicit consent (Article 23). EU standard contractual clauses and adequacy decisions do not automatically satisfy UAE law.
4. DPO criteria are narrower and different
A Data Protection Officer is required where processing poses a high risk because of new technology or volume, involves systematic assessment of sensitive data including profiling, or involves a large volume of sensitive data (Article 10). The DPO may be an employee or an external provider, and need not be based in the UAE.
5. Breach notification has no fixed clock yet
The GDPR sets 72 hours. The PDPL requires notification to the Data Office on becoming aware of a breach that would prejudice privacy, confidentiality or security (Article 9), and leaves the procedure to the Executive Regulations. Until they appear, the safe reading is: as soon as you have assessed the breach.
6. Sector carve-outs
Health data and banking or credit data governed by their own legislation fall outside the PDPL. A clinic's patient records, for example, are also subject to Federal Law No. 2 of 2019, which restricts storing and processing health data outside the UAE.
7. Free zones may be out of scope entirely
DIFC and ADGM entities are governed by their own data protection laws. A company licensed there should not be using a PDPL policy at all, let alone a GDPR one.
What to do
If you also serve EU residents, you may need to satisfy both regimes, and the easiest route is a notice that addresses each explicitly. If you serve only the UAE, replace the GDPR text with a PDPL notice. Our kit generates one from your answers, with your actual purposes, providers and legal grounds.
Where does your company stand on PDPL?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.