UAE PDPL Compliance for Websites & Apps: A 2026 Checklist for Dubai Businesses
What Federal Decree-Law No. 45 of 2021 means for your Dubai website or app in 2026 — the UAE Data Office, fines up to AED 5,000,000, the 72-hour breach rule, and a practical build-side PDPL compliance checklist.
- PUBLISHED
- 08 SEPT 2026
- READ TIME
- 08 MIN
- AUTHOR
- AQUARIUS · DUBAI
- UNIT
- REV 2026.09
Short answer: If your Dubai website or app collects a name, email, phone number, or location from a person in the UAE, you are a data controller under the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). You need a lawful basis for each purpose, explicit and revocable consent for marketing and cookies, a published privacy policy, a way to honour data-subject requests within 30 days, and a plan to notify the UAE Data Office of a breach — with penalties reaching AED 5,000,000 per violation. This checklist covers what to build.
Why PDPL is now a build requirement, not a legal afterthought (the UAE numbers)
For years, UAE businesses treated data protection as fine print. That window is closed. Three numbers frame the stakes for 2026:
- AED 5,000,000 — the ceiling for administrative fines under the PDPL framework, applied per violation, not per company. A single non-compliant form or cookie banner can be its own finding.
- ~AED 29 million (US$8 million) — the average cost of a data breach in the Middle East in 2026, per IBM's Cost of a Data Breach report — with lost business the single largest component. Compliance is cheaper than the incident it prevents.
- 72 hours — the window in which controllers are expected to notify the UAE Data Office of a personal-data breach that carries risk to individuals. If you cannot detect and report inside three days, you are not ready.
Most Dubai businesses assume PDPL is "an EU/GDPR thing that doesn't apply here." It is UAE federal law, it applies to anyone processing the personal data of people inside the UAE, and the UAE Data Office began escalating enforcement from 2025.
What the law actually says (in plain English)
PDPL — Federal Decree-Law No. 45 of 2021 — took effect in January 2022, and the accompanying Executive Regulation (Cabinet Decision No. 33 of 2024) fills in operational detail on consent, data-subject requests, cross-border transfers, and breach handling. The regulator is the UAE Data Office. Here is what matters when you build:
- Consent must be real. Freely given, specific, informed, and by clear affirmative action — and just as easy to withdraw as to give. Pre-ticked boxes and "by using this site you agree" banners do not qualify.
- Every purpose needs a lawful basis. You cannot collect an email for a booking and then quietly add it to a marketing blast. Each use is its own purpose.
- Data subjects have rights. Access, correction, deletion, restriction of processing, and objection — and you must respond, typically within 30 days.
- Cross-border transfer is restricted. Sending personal data outside the UAE is only allowed to jurisdictions with adequate protection, under approved safeguards (e.g. standard contractual clauses), or with the individual's explicit informed consent. Most Dubai sites do this without realising it — every US-hosted analytics, email, or CRM tool is a transfer.
- You must keep records. Controllers maintain a record of processing activities and produce it for the UAE Data Office on request.
The PDPL build checklist for your website & app
This is the practical part — what a compliant Dubai site or app needs shipped, not just written into a policy. Treat it as a build spec.
1. Consent & cookies
- A real consent banner with granular opt-in (necessary vs analytics vs marketing), no pre-ticked boxes, and an equally easy "reject all". Load non-essential scripts only after consent — not before.
- A consent log: store what each user agreed to and when. If you cannot prove consent, you did not have it.
- A visible way to change or withdraw consent later (a footer link is enough).
2. Transparency
- A plain-language privacy policy naming what you collect, why, the lawful basis, who you share it with, where it is stored, and how long you keep it.
- Just-in-time notices at the point of collection (next to the form), not buried 4,000 words deep.
3. Data-subject requests & security
- A request channel (form or dedicated email) and an internal process to fulfil access/deletion/correction within 30 days.
- Encryption in transit and at rest, role-based access to your admin/CMS, and a breach runbook that lets you notify inside 72 hours.
- A data map: know every third-party tool that touches personal data (analytics, chat, email, CRM, payment) and where each one stores it.
What compliance actually costs to build in Dubai
Retrofitting an existing Dubai site is far cheaper than the AED 5,000,000 exposure — or the ~AED 29M average breach. Typical add-on ranges when we bring a site up to PDPL standard:
| Compliance item | What it involves | Typical cost (AED) |
|---|---|---|
| Consent management (CMP) | Granular cookie banner, script gating, consent logging | 3,000 – 9,000 |
| Privacy policy & notices | Bilingual policy, just-in-time form notices | 2,500 – 7,000 |
| Data-subject request flow | Request form + internal fulfilment process | 3,000 – 8,000 |
| Security & breach runbook | Encryption, access controls, 72-hour notification plan | 5,000 – 15,000+ |
| Full PDPL audit + data map | End-to-end review of every tool touching personal data | 8,000 – 20,000 |
For a new build, PDPL-ready foundations should be baked in from day one at no premium — see our transparent AED pricing. Sectors handling sensitive data (health, finance, kids) sit at the top of every range; if you run a clinic, start with our guide to DHA-ready clinic websites and patient data. Related reading: legally valid e-signatures in the UAE.
How Aquarius builds PDPL-ready by default
We treat consent, transparency, and security as part of the build — not a bolt-on. Every site we ship gets a consent-gated script loader, a bilingual privacy policy, a data-subject request channel, and a documented data map of every third-party tool. The pragmatic stance the market has settled on for 2026 is "reasonable, documented measures": you will not be first-in-line for a AED 5,000,000 fine for a good-faith, well-documented programme — you will be for ignoring the law entirely. The cost of getting it right is a rounding error against a single breach. See how we build, or book a free PDPL review of your current site. Related reading: website and app security basics.
Frequently asked questions
Does PDPL apply to my small Dubai business?
If you process the personal data of people inside the UAE — even just contact-form submissions or newsletter emails — yes. PDPL applies by the data you handle, not your company size. Certain free zones (like DIFC and ADGM) have their own separate data-protection regimes.
What are the penalties for breaking PDPL?
Administrative fines under the framework reach up to AED 5,000,000 per violation, alongside enforcement action from the UAE Data Office. The bigger financial risk is often the breach itself — the Middle East average hit roughly AED 29 million (US$8 million) in 2026.
Do I really need a cookie consent banner in the UAE?
If you use analytics, ad pixels, or any non-essential cookies, yes. Consent must be explicit, granular, and withdrawable, and non-essential scripts should only fire after the user opts in — a "we use cookies, OK?" bar that loads everything upfront does not meet the standard.
Can I use US-based tools like Google Analytics or Mailchimp?
You can, but sending UAE personal data abroad is a cross-border transfer. You need an appropriate safeguard (such as standard contractual clauses) or the individual's explicit informed consent, and your privacy policy must disclose it. This is the single most common gap on Dubai sites.
How fast do I have to report a data breach?
Controllers are expected to notify the UAE Data Office of a risky personal-data breach within 72 hours, and to inform affected individuals where the risk to them is high. If your systems cannot detect and report inside that window, that is the first thing to fix.
