Cybersecurity
UAE PDPL: What Your Business Must Do Before 1 January 2027
The UAE Personal Data Protection Law is now being enforced on a timetable. Here is what a mid-sized UAE company actually has to do, in the order that reduces risk fastest.
5 September 2026 · PDPL, Compliance, Data Protection, UAE

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, usually shortened to PDPL) has been on the books for years, but 2026 is the year it started to bite. With the executive regulations in force and a compliance deadline of 1 January 2027 being widely reported, the question we get most often from finance directors and IT managers in Dubai is simple: what do we actually have to do?
This is the checklist we use with clients. It is written for a company of 20 to 500 people that processes customer, employee and supplier data and does not have a legal department. Confirm the specifics with your legal counsel; the technical controls are ours.
1. Know what personal data you hold, and where
Everything else depends on this. Build a data map that lists each system holding personal data (Microsoft 365, your ERP, HR platform, CRM, shared drives, WhatsApp groups, that spreadsheet in Finance), what categories of data sit in each, who has access, and where the data physically lives.
Most UAE companies discover two surprises here: far more personal data on unmanaged endpoints and personal cloud accounts than they expected, and at least one SaaS tool storing data outside the country that nobody signed off.
2. Decide the lawful basis for each processing activity
PDPL, like GDPR, requires a lawful basis for every use of personal data. For most business processing this is contract or legitimate interest; for marketing it is usually consent. Write it down per activity. If you cannot articulate a basis, stop the processing or fix the basis.
3. Fix consent and privacy notices
Your website privacy notice, cookie banner and any marketing sign-up flows need to say what you collect, why, for how long and who you share it with, in plain language. Consent must be an active choice. Pre-ticked boxes and "by using this site you agree" wording do not meet the standard.
4. Be able to answer a data subject request
Individuals can ask what data you hold, ask for it to be corrected or deleted, and object to certain processing. Set up a mailbox, a simple procedure and a way to actually find and export a person's data across your systems. Microsoft Purview's content search and eDiscovery cover most of a Microsoft 365 estate; the ERP and HR system will need their own method.
5. Prepare for breach notification
PDPL expects you to detect breaches and notify the UAE Data Office, and in some cases the affected individuals, without undue delay. You cannot notify what you cannot see. At minimum you need:
- Centralised logging for identity, email and endpoints
- Someone watching those logs, whether an internal team or a managed detection and response (MDR) service
- A written incident response plan with named roles and a notification template
6. Decide whether you need a Data Protection Officer
A DPO is mandatory in certain cases, broadly where processing is high-risk, large-scale or involves sensitive data. Many mid-sized firms will not strictly need one, but appointing a named data protection lead is good practice and makes audits far easier.
7. Put the technical controls in place
This is where an IT partner earns its keep. The controls we implement most often for PDPL are:
- Multi-factor authentication on every account, with conditional access for admins
- Data classification and DLP in Microsoft 365 so personal data cannot leave by email or USB unnoticed
- Encryption at rest and in transit, including laptops (BitLocker) and mobile devices (Intune)
- Access reviews so leavers and role changes do not leave stale permissions
- Immutable backups so a ransomware incident does not also become a data loss event
- Retention policies so data is deleted when its purpose ends
8. Document everything
Auditors and regulators want evidence: the data map, the lawful-basis register, DPIAs for high-risk processing, the incident plan, training records and proof that controls exist. A shared folder with dated documents is enough to start.
Where to begin
If you do nothing else this quarter, do steps 1, 5 and 7. They cut the most risk and they are the ones a breach will expose. A PDPL readiness assessment from Binary Minds covers all eight areas in a week and gives you a prioritised plan you can hand to the board.
Penalties under the PDPL framework have been reported at up to AED 5 million. Treat the numbers as a reason to start, not a reason to panic.