Law / United Arab Emirates

Federal Decree-Law on the Protection of Personal Data, breach notification

Federal Decree-Law No. 45 of 2021, Art. 9

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 2 January 2022.

A breach notification rule binding private bodies.

As of 29 August 2026.

What it requires

  • An app that suffers a breach affecting the personal data of an individual in the onshore UAE must notify the Bureau at the time it becomes aware of the breach; the Decree-Law defers the specific notification window to Executive Regulations whose text could not be confirmed at primary source, so an app should not assume a specific hour count without checking current regulator guidance.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 9 requires the Controller to notify the Bureau of a breach that would prejudice the privacy, confidentiality, or security of personal data, at the time it becomes aware of the breach, within a period the Decree-Law itself defers to the Executive Regulations. No fixed number of hours or days is stated in the Decree-Law's own text; the timeline is not established pending the unconfirmed Executive Regulations (see the jurisdiction summary).

Data Subject notification is also required where the breach meets a threshold the Decree-Law's text does not fully set out in the provisions read.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official statute text, UAE Legislation portal

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app