Law / United Arab Emirates

United Arab Emirates

12 of 16 named instruments researched to a stage, across four of the six areas of law we track: 12 in force. As of 16 September 2026.

When they take effect12 of 12 carry a date.
2020: 1 instrument (1 in force) ’20 2021: 2 instruments (2 in force) 2022: 8 instruments (8 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law7 instruments, 7 in force

Research summary (268 words)

The UAE runs three legally distinct data-protection regimes that must not be collapsed into one posture: the federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, PDPL, in force since 2 January 2022, onshore UAE), the DIFC Data Protection Law No. 5 of 2020 (in force since 1 July 2020, Dubai International Financial Centre free zone only, enforced by the DIFC Commissioner of Data Protection), and the ADGM Data Protection Regulations 2021 (Abu Dhabi Global Market free zone only, enforced by its own Commissioner of Data Protection under ADGM's separate court system).

All three were read at primary source. All three fold biometric data into a General Data Protection Regulation (GDPR)-style sensitive or special category with materially identical definitions naming facial images as a worked example, so a voiceprint or faceprint requires an elevated legal basis, ordinarily explicit consent, in each regime.

The federal PDPL's Article 28 requires Cabinet-issued Executive Regulations to complete its operative detail, including the Article 9 breach-notification timeline; that Executive Regulation's existence and text are not confirmed at primary source.

The corpus's own candidate citing "Cabinet Resolution No. 83 of 2022" as the PDPL Executive Regulations is verified wrong: that instrument number is in fact the Technical Regulations for Vehicle Speed Measuring Devices (Radar), an unrelated traffic-enforcement rule, and is not authored here as an instrument.

Secondary compliance trackers point to Cabinet Decision No. 33 of 2024 as the actual Executive Regulation, but its own primary-source page is not located and confirmed, so the federal PDPL's Executive Regulations are recorded here as unconfirmed, and the Decree-Law's own substantive provisions as in force on their own terms.

Breach notification

ADGM Data Protection Regulations, breach notification

ADGM Data Protection Regulations 2021, personal data breach notification provisionsofficial consolidated Regulations text (PDF), ADGM rulebook

In force since 14 February 2021. Binds private bodies.

What this law does

The ADGM Data Protection Regulations set an explicit 72-hour breach-notification rule to the Commissioner of Data Protection, language read verbatim and drawn from the same family as General Data Protection Regulation (GDPR) Art. 33, unless the breach is unlikely to pose a risk to individuals' rights.

This is the only one of the UAE's three regimes where a specific notification window was confirmed; the federal PDPL defers its timeline to unconfirmed Executive Regulations, and the DIFC Law's own breach-notification timeline (Part 7) was not individually pulled.

What it requires

Federal Decree-Law on the Protection of Personal Data, breach notification

Federal Decree-Law No. 45 of 2021, Art. 9official statute text, UAE Legislation portal

In force since 2 January 2022. Binds private bodies.

What this law does

Art. 9 requires the Controller to notify the Bureau of a breach that would prejudice the privacy, confidentiality, or security of personal data, at the time it becomes aware of the breach, within a period the Decree-Law itself defers to the Executive Regulations. No fixed number of hours or days is stated in the Decree-Law's own text; the timeline is not established pending the unconfirmed Executive Regulations (see the jurisdiction summary).

Data Subject notification is also required where the breach meets a threshold the Decree-Law's text does not fully set out in the provisions read.

What it requires

Comprehensive regime

ADGM Data Protection Regulations, comprehensive regime

ADGM Data Protection Regulations 2021 (consolidated February 2024)official consolidated Regulations text (PDF), ADGM rulebook

In force since 14 February 2021. Binds private bodies.

What this law does

The ADGM Data Protection Regulations are the equivalent statute of the Abu Dhabi Global Market free zone (Abu Dhabi's Al Maryah and Al Reem Island financial free zone), enforced by ADGM's own Commissioner of Data Protection under ADGM's separate court system, and apply only within that free-zone footprint, not to a UAE business operating outside it. The text relied on here is the consolidated version as amended through February 2024.

The exact original 2021 commencement date is not confirmed against primary text, so 14 February 2021 rests on the corpus's own record rather than on primary confirmation. Section 1's Biometric Data definition names facial images and dactyloscopic data as worked examples, with the same adequacy-plus-alternative-safeguards cross-border transfer structure as the federal PDPL and DIFC Law. No source-based exclusion for a recording-derived biometric identifier was found.

What it requires

DIFC Data Protection Law, comprehensive regime

DIFC Law No. 5 of 2020official consolidated statute text, published at assets.u.ae

In force since 1 July 2020. Binds private bodies.

What this law does

The DIFC Data Protection Law is a separate statute of the Dubai International Financial Centre free zone, in force since 1 July 2020, enforced by the DIFC Commissioner of Data Protection, not the federal Bureau. It applies only within the DIFC's own geographic free-zone footprint (Dubai's financial district), not to a UAE business operating onshore elsewhere. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles (Sched. 1). Sched.

1's Special Categories of Personal Data includes "genetic data and biometric data where it is used for the purpose of uniquely identifying a natural person," with no source-based exclusion for an identifier derived from a recording, so processing such data ordinarily requires explicit consent or another qualifying condition.

The DIFC framework is close to full GDPR Chapter III parity on data-subject rights (portability at Art. 37, automated decision-making and profiling safeguards at Art. 38, non-discrimination at Art. 39, confirmed by the Law's own index), and Arts. 26-27 set a near-identical adequacy-plus-alternative-safeguards structure to the federal PDPL for cross-border transfer.

The individual operative texts of these articles, and of the Part 7 breach-notification provisions and any private-right-of-action provision, were not each pulled verbatim; the structure recorded here reflects what the index confirms rather than asserting unconfirmed detail.

What it requires

Federal Decree-Law on the Protection of Personal Data, comprehensive regime and lawful basis

Federal Decree-Law No. 45 of 2021, Arts. 1, 4official statute text, UAE Legislation portal

In force since 2 January 2022. Binds private bodies.

What this law does

The federal PDPL is the UAE's onshore comprehensive personal-data statute, applying outside the DIFC and ADGM free zones. Processing requires a lawful basis, most commonly the Data Subject's consent, with Art. 4 listing alternative grounds including a consent exception at Art. 4(2) for data the Data Subject has made public by their own act. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles, with the Controller determining purposes and means and bearing primary compliance duty.

Art. 1's Biometric Data definition names facial images and fingerprints as worked examples and lists Biometric Data as a category of Sensitive Personal Data, so an identity-linked voiceprint or faceprint ordinarily requires the Data Subject's explicit consent as its legal basis; no exclusion for an identifier derived from a photo, video, or audio recording was found.

The Decree-Law's Art. 28 Executive Regulations, which would supply operative detail including the breach-notification timeline, have not been located at primary source; Cabinet Resolution No. 83 of 2022, sometimes cited as that Executive Regulation, is an unrelated vehicle speed-radar regulation.

What it requires

Cross border transfer

Federal Decree-Law on the Protection of Personal Data, cross-border transfer

Federal Decree-Law No. 45 of 2021, Arts. 22-23official statute text, UAE Legislation portal

In force since 2 January 2022. Binds private bodies.

What this law does

Art. 22 permits transfer of personal data outside the UAE to a jurisdiction the Bureau (the UAE Data Office) has approved as having an adequate data-protection law and enforcement authority. Where no such adequacy finding exists, Art. 23 permits transfer under a contract binding the foreign recipient to PDPL-equivalent standards, or with the Data Subject's explicit consent provided the transfer does not contradict UAE public or security interest.

No blanket data-localization requirement was found; transfer is conditioned on one of these bases rather than prohibited outright.

What it requires

Enforcement supervision

Federal Decree-Law on the Protection of Personal Data, enforcement and supervision

Federal Decree-Law No. 45 of 2021, Arts. 25-26official statute text, UAE Legislation portal

In force since 2 January 2022. Binds private bodies.

What this law does

The UAE Data Office ("the Bureau", established by Federal Decree-Law No. 44 of 2021) is the federal supervisory authority. A grievance against a Bureau decision goes to the Bureau itself first under Art. 25. Administrative penalty amounts are not set in the Decree-Law itself: Art. 26 requires a separate Council of Ministers decision, on the General Director's recommendation, to list violations and set administrative penalties.

No provision creating a private right of action for a Data Subject to sue a Controller directly has been located; the point is not established rather than a confirmed absence.

What it requires

Scraping law3 instruments, 3 in force

Research summary (346 words)

The UAE has no scraping-specific statute, so general federal law governs each dimension separately, and the DIFC and ADGM free zones layer their own data-protection regimes on top for controllers established or targeting users there.

The Federal Decree-Law on Combating Rumours and Cybercrime defines hacking as unauthorized access, access in violation of a license, or illegal access to or stay on an information system, and its base offence requires no proof of defeating a technical security measure, so the text does not on its face exclude a public, unauthenticated page the way a security-measure test would; no reported UAE case has tested the point either way.

No UAE court decision was located on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Federal Decree-Law on Copyright and Neighbouring Rights excludes news, news reports and current events that are merely media news from copyright protection outright, and separately lets a newspaper, circular or broadcasting organisation copy excerpts of a lawfully published work, published articles on matters of current public concern, and speeches at public sessions, provided the source and author are credited; it carries no text-and-data-mining exception, and its personal-copy limitation expressly excludes software, software applications and databases from the ordinary single-copy allowance.

The Decree-Law confers copyright on a compilation only where the selection or arrangement is itself an innovation, so it creates no sui generis database right of the kind the EU Database Directive does.

The federal Personal Data Protection Law's consent basis for data the data subject has made public by their own act is an exception to the consent requirement rather than a scope exclusion, so scraped public personal data of an individual in onshore UAE remains subject to the Law's other duties (security, purpose limitation, cross-border transfer, breach reporting); the DIFC and ADGM data-protection laws apply the same posture within their own free-zone footprints.

No UAE statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine distinct from the general civil and commercial codes, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Federal Decree-Law on Combating Rumours and Cybercrime, hacking offences

Federal Decree-Law No. 34 of 2021, Arts. 1-3 (Hacking)official consolidated Decree-Law text, UAE Legislation portal

In force since 2 January 2022. Binds public and private bodies.

What this law does

Article 1 defines Hacking as the unauthorized access, access in violation of the provisions of a license, or illegal access to or stay on an information system, a computer, an operating system, or an information network.

Article 2 punishes hacking a website, electronic information system, information network or piece of information technology equipment with imprisonment and a fine of not less than AED 100,000 or more than AED 300,000; the penalty rises to imprisonment of at least six months and a fine of AED 150,000 to 500,000 where the hacking causes damage, destruction, interruption, or the copying or disclosure of data, and to imprisonment of at least one year and a fine of AED 200,000 to 500,000 where it is committed to acquire data or information for illegal purposes.

The offence's definition turns on access being unauthorized, in violation of a licence, or illegal, and does not on its own terms require defeating a technical security measure. Article 3 imposes materially higher penalties, including temporary imprisonment, where the same conduct targets a government entity's systems.

What it requires

Copyright and text and data mining (TDM)

Federal Decree-Law on Copyright and Neighbouring Rights, protection exclusions and limitations

Federal Decree-Law No. 38 of 2021, Arts. 3, 22, 24official consolidated Decree-Law text, UAE Legislation portal

In force since 2 January 2022. Binds public and private bodies.

What this law does

Article 3 excludes ideas, procedures, mathematical concepts, official documents, news, news reports and current events that are merely media news, and works in the public domain from copyright protection, though a compilation of such material is protected where the selection or arrangement is itself an innovation.

Article 22 lets a person, after a work is published, make a single personal or non-commercial copy of it, quote short paragraphs or excerpts within reasonable limits for criticism, discussion or information with source and author credited, and make a single copy for legal proceedings or non-profit archival and research purposes. That personal-copy allowance expressly carves software, software applications and databases out of its ordinary scope.

No provision in the Decree-Law creates a text-and-data-mining exception or a machine-readable reservation mechanism of any kind.

Article 24 separately lets a newspaper, circular or broadcasting organisation copy excerpts of a work already lawfully made available to the public, published articles on subjects of current public concern (unless the author stated a publication ban), and speeches delivered at public parliamentary, judicial or public sessions when copied in the context of transmitting breaking news, provided the source and the author's name are credited. The Decree-Law creates no sui generis database right distinct from ordinary compilation copyright.

What it requires

Personal data

Federal Decree-Law on the Protection of Personal Data, reach over scraped public personal data

Federal Decree-Law No. 45 of 2021, Art. 4 (reach over scraped public personal data)official statute text, UAE Legislation portal

In force since 2 January 2022. Binds private bodies.

What this law does

Article 4(2) provides a lawful-basis exception for processing personal data that has become available and known to all by an act of the data subject, which the jurisdiction's privacy record confirms is a consent-basis exception rather than a scope exclusion: personal data a scraper collects from a public, unauthenticated page of a UAE resident remains Personal Data for the Law's other duties, including security, purpose limitation, cross-border transfer, and breach reporting, once collected outside the narrow act that made it public.

The Law carries no publicly-available-data carve-out of the kind some jurisdictions apply to a whole category of public records, and Art. 1's Biometric Data definition names facial images and fingerprints as worked examples of Sensitive Personal Data with no exclusion for an identifier derived from a public recording, so a scraper deriving a biometric identifier from publicly posted photographs or audio faces the Law's elevated consent requirement for Sensitive Personal Data.

What it requires

Age gating law1 instrument, 1 in force

Research summary (185 words)

The UAE has no adult-content age-verification statute, no social-media-specific minor-access restriction, and no app-store age-verification requirement, but it has a general-purpose age-appropriate design code in the Federal Decree by Law Regarding Child Digital Safety, which took effect on 1 January 2026.

The Decree by Law binds internet service providers and digital platforms, defined broadly to include websites, search engines, apps, messaging services, forums, gaming, social media, live-streaming, podcast, streaming, and e-commerce platforms, whenever a child (anyone under eighteen) uses the service or is exposed to its content.

It requires risk-based platform classification, age-verification mechanisms, default privacy settings, parental control tools, and content-filtering and reporting duties, and separately prohibits collecting, processing, publishing, or sharing the personal data of a child under thirteen absent parental consent and other conditions. Administrative penalty amounts are deferred to a Cabinet resolution not yet located at primary source.

Federal Law No. 3 of 2016 on Child Rights (Wadeema's Law) and the Federal Decree-Law on Combating Rumours and Cybercrime, which criminalises possession of child pornographic material, address child protection more generally but carry no internet age-verification or age-gating duty of their own.

Age-appropriate design code

Federal Decree by Law Regarding Child Digital Safety, platform duties

Federal Decree by Law No. 26 of 2025, Arts. 6-13official Decree by Law text, UAE Legislation portal

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

The Decree by Law applies to internet service providers and digital platforms operating in the UAE or directed at users in the UAE, whether natural or legal persons and whether public or private sector, whenever children use the platform or are exposed to its content or services; covered platform types are named non-exhaustively and include websites, search engines, apps, messaging services and forums, gaming platforms, social media, live-streaming, podcast platforms, streaming and video-on-demand services, and e-commerce platforms.

Article 6 requires the Cabinet to issue a risk-based classification system for digital platforms setting age-restriction controls, enforcement means, and age-verification mechanisms scaled to each platform's classification.

Article 7 prohibits a digital platform from collecting, processing, publishing, or sharing the personal data of a child under thirteen unless explicit, documented, verifiable parental consent is obtained, a rapid consent-withdrawal mechanism is provided, the data-privacy policy is disclosed, access is restricted to authorised personnel, and the data is not used for commercial purposes, targeted advertising to the child, or tracking beyond the originally authorised purpose.

Article 8 requires platforms to adopt effective and reasonable age-verification mechanisms scaled to their risk classification. Article 9 prohibits platforms from letting a child participate in, hold an account for, or access online commercial gaming, including gambling, and requires platforms and internet service providers to take technical and administrative measures, including age verification and parental controls, to prevent that access.

Article 10 requires platforms to apply default high-privacy settings for children's accounts, age-based use controls, blocking and content-filtering tools, age classification of content, regulation of targeted advertising to children, parental control tools including daily-use time limits, and reporting channels for child pornographic material and harmful content, and to report such material to the concerned authorities.

Article 11 requires the Telecommunications and Digital Government Regulatory Authority to set internet service providers' obligations, including network-level content filtering and requiring a child caregiver's signature on service terms that mandate parental-control-tool integration. Article 13 places duties on the child caregiver, including monitoring, using parental controls, and not creating accounts for a child on a platform unsuited to the child's age group.

Article 16 defers the administrative penalties for a violation to a separate Cabinet regulation, not yet located at primary source. Article 18 gives covered persons one year from the law's entry into force, extendable by Cabinet resolution, to bring themselves into compliance.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (213 words)

The UAE has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Federal Decree-Law on Copyright and Neighbouring Rights is the only instrument reaching an aggregator's reproduction of news content.

Article 3 excludes news, news reports and current events that are merely media news from copyright protection outright, so a bare news item is never a protected work regardless of which outlet reported it first, unless the compilation or arrangement of that material is itself an innovation.

Article 24 separately lets a newspaper, circular or broadcasting organisation copy excerpts of a work already lawfully made available to the public and published articles on subjects of current public concern, provided the source and author are credited; the exception carries no headline-length or short-extract cap and is not confined to a press-review format, and no reported UAE decision applies it to a systematic news aggregator as opposed to a traditional press summary.

No UAE statute or case law was located establishing a hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, or addressing whether a hyperlink is a communication to the public or whether framing or inline display changes the answer. The Decree-Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Federal Decree-Law on Copyright and Neighbouring Rights, news exclusion and press-review exception

Federal Decree-Law No. 38 of 2021, Arts. 3(3), 24official consolidated Decree-Law text, UAE Legislation portal

In force since 2 January 2022. Binds public and private bodies.

What this law does

Article 3(3) of the Federal Decree-Law on Copyright and Neighbouring Rights excludes news, news reports and current events that are merely media news from copyright protection outright; the exclusion lapses only where the compilation or arrangement of that material is itself an innovation.

Article 24(1)(a) separately lets a newspaper, circular or broadcasting organisation, without the author's consent and with the source and author's name credited, copy excerpts of a work already lawfully made available to the public. Article 24(1)(b) lets the same outlets publish articles on subjects of current public concern, unless the author stated a publication ban.

Article 24(1)(c) lets them reproduce speeches delivered at public parliamentary, judicial or public sessions when copied in the context of transmitting breaking news. The exception carries no headline-length or short-extract cap distinct from the requirement that the copying stay within the limits justified by its purpose.

The Decree-Law creates no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and it predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.