Compliance

UAE PDPL website privacy checklist for Dubai businesses

What the UAE's personal data law means for your contact forms, tracking tags, privacy policy, hosting and breach plans, checked against the official text.

Under the UAE’s personal data law, a business website must collect only the personal data it needs, get clear consent that can be proved and withdrawn (unless another legal basis applies), tell visitors why their data is collected and who it is shared with, keep it secure, and be ready to report a breach. Companies in the DIFC and ADGM follow their own free zone data protection rules instead.

In short:

  • Confirm which law applies: the federal PDPL, DIFC, ADGM or a sector law.
  • Trim every form to the fields you actually use.
  • Record consent, with an easy way to withdraw it.
  • Hold analytics and advertising tags until the visitor agrees.
  • Publish a privacy policy that says what, why, who and where.
  • Know where your hosting, CRM and email tools store data.
  • Write down what happens in the first hours of a breach.

This article is general information about UAE data protection rules as they apply to websites. It is not legal advice. Check your own position with a qualified adviser.

What the UAE PDPL is, and when it took effect

The law is Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data, usually called the PDPL. According to the UAE’s official legislation portal, it was issued on 20 September 2021, published in the Official Gazette on 26 September 2021, and came into effect on 2 January 2022. The portal notes that its English version is a translation and the Arabic text prevails in case of conflict.

Several of its definitions matter for websites. Personal data covers anything that identifies a person directly or indirectly, with examples including name, image, identification number, electronic identifier and geographical location. Consent must be specific, clear and unambiguous, given through a clear positive statement or action, which a pre ticked box is not.

Who the PDPL does not apply to

Article 2 sets the scope. It covers data subjects in the UAE, controllers and processors in the UAE processing data of people inside or outside the country, and controllers and processors abroad processing data of people in the UAE. It then excludes, among others:

  • Government data, and government entities that control or process personal data.
  • Personal data held by security and judicial authorities.
  • Individuals processing their own data for personal purposes.
  • Personal health data that has its own legislation regulating its protection and processing.
  • Personal banking and credit data that has its own legislation.
  • Companies in free zones that have their own personal data protection legislation.

DIFC and ADGM

The two best known free zone regimes are in the financial centres. The DIFC Commissioner of Data Protection supervises and enforces the Data Protection Law, DIFC Law No. 5 of 2020, which DIFC says was enacted in May 2020. DIFC entities must submit a data protection notification at incorporation and when there are changes, and DIFC provides a personal data breach reporting form.

In Abu Dhabi, ADGM issued its Data Protection Regulations 2021 on 14 February 2021, replacing the 2015 regulations. Its Office of Data Protection maintains the register of data controllers, enforces their obligations and handles data breach notifications.

Health and other sector laws

The UAE Government’s data protection page also lists Federal Law No. 2 of 2019 on the use of information and communication technology in health fields, among other laws. For a clinic or pharmacy, patient data may fall under health legislation, a question for a lawyer rather than a web agency.

Your businessMain regime to checkOfficial source
Mainland company in Dubai or elsewhere in the UAEFederal Decree by Law No. 45 of 2021 (PDPL)uaelegislation.gov.ae
Company registered in DIFCDIFC Data Protection Law No. 5 of 2020difc.com
Company registered in ADGMADGM Data Protection Regulations 2021adgm.com
Company in another free zoneDepends on whether that zone has its own data protection legislationYour free zone authority
Healthcare providerHealth sector legislation may apply to patient dataYour regulator and adviser

Executive regulations and enforcement: what is clear and what is not

Online guides disagree here, so this is only what the official sources show. Article 28 required the Council of Ministers to issue executive regulations within six months of the decree. Article 29 gives controllers and processors up to six months from the date those regulations are issued to bring themselves into compliance, extendable once. Article 26 says violations and administrative penalties will be set by a Council of Ministers decision.

When we checked on 13 September 2026, the official legislation portal’s related legislation list for the PDPL did not include executive regulations or a penalties decision, and the UAE Government’s data protection page, last updated in December 2025, did not mention them either. Some commercial websites say the regulations have been issued; we could not confirm that officially.

The honest position: the decree is in force, but the detail on timings, exemptions and penalties hangs on regulations we could not find on an official source. Build good practice now rather than waiting for a deadline.

The breach notification period, the exemption criteria and the transfer conditions all depend on those regulations, so check the current status with your adviser before relying on any timeline. The principles in Articles 5, 6 and 20 are already in the decree.

Contact, quote and booking forms are where most small UAE websites collect personal data. Article 4 prohibits processing without consent, with exceptions, one of which is processing necessary to take steps at the data subject’s request with the aim of concluding a contract. Replying to someone who asked you for a quote arguably fits that. Adding them to a marketing list does not, and Article 17 gives people the right to object to processing for direct marketing.

Article 6 sets the conditions for valid consent: the controller must be able to prove it, it must be clear, simple and easily accessible, and it must include the right to withdraw it easily.

  • Separate the enquiry from marketing. Use an unticked, optional checkbox for newsletters and offers, not a condition of sending the form.
  • Place a short notice beside the submit button: what you will use the details for, and a link to the privacy policy.
  • Store proof. Save the timestamp, the page, the wording shown and the checkbox state with the lead in your CRM.
  • Make withdrawal easy: an unsubscribe link in every email and a named contact for requests, which Article 19 requires in the form of clear ways to contact the controller.
  • Check where form submissions go. Email inboxes, spreadsheets, CRMs and WhatsApp integrations each hold a copy.

Data minimisation on quote forms

Article 5 requires personal data to be collected for a specific and clear purpose, and to be sufficient and limited to what is necessary for that purpose. It also says data should not be kept after the purpose has been exhausted, unless anonymised.

One issue we often see is the quote form that grew over years of marketing requests: date of birth, nationality, budget, a file upload, three phone fields. Every field is data you must secure, explain and eventually delete. For most service businesses, a first enquiry needs a name, one contact method and the question. Shorter forms also tend to be easier to complete on a phone, which matters for the landing pages behind paid campaigns.

FieldKeep, drop or make optionalReason
NameKeepNeeded to reply
Phone or emailKeep at least oneNeeded to reply; let the visitor choose
Message or service requiredKeepThe purpose of the enquiry
Date of birth, nationality, Emirates IDDropRarely needed for a first enquiry; identification numbers are named in the definition of personal data
Health details on a clinic formDrop from open formsHealth data is sensitive personal data under the decree; collect it through the clinical system instead
File uploadOnly if essentialUploads often contain far more personal data than intended

Set a retention rule too. Decide how long unconverted leads stay in the CRM and delete or anonymise them after that.

Cookies and tracking tags: GA4 and Meta Pixel

The PDPL does not mention cookies by name. It does, however, include electronic identifiers and location in its definition of personal data, and advertising pixels and analytics cookies work by setting or reading identifiers. The cautious approach for a UAE website is to hold non essential tags until the visitor agrees, and to offer a genuine choice to decline.

Google Analytics 4 and Google Ads

Google’s consent mode lets tags adjust their behaviour to the visitor’s choice, using consent types including ad_storage, analytics_storage, ad_user_data and ad_personalization. In basic consent mode, Google says no data is sent before a user consents. In advanced consent mode, tags load with consent denied by default and send cookieless measurements when consent is denied. Choose deliberately and write the choice into your privacy policy.

Two GA4 settings are worth checking. Google states that IP addresses are not logged or stored in GA4. And standard GA4 properties let you set data retention for user level and event level data to 2 months or 14 months. Pick the shorter period unless you genuinely analyse older data.

Meta Pixel

Meta documents a consent control for the pixel: calling fbq('consent', 'revoke') pauses pixel fires, and fbq('consent', 'grant') resumes them once the visitor agrees. Also check whether advanced matching is on. Meta’s documentation shows it can send details such as email, phone number, name and city with conversion events, and that values passed through the base code are hashed automatically by the pixel using SHA 256. Hashed data is still derived from personal data, so disclose it.

  1. List every tag

    Check the tag manager and page source for analytics, advertising, chat and heatmap scripts, including old ones.

  2. Classify them

    Strictly necessary, analytics or advertising.

  3. Wire in consent

    Hold analytics and advertising tags behind a consent tool, using consent mode for Google and revoke and grant for Meta.

  4. Test it

    Decline in a fresh browser and confirm in the network panel that the tags behave as chosen.

What your privacy policy should cover

Article 13 gives people the right to request information including the types of data processed, the purposes, automated decisions, who data is shared with inside and outside the UAE, retention standards, how to correct or erase data, cross border protections, breach measures and how to complain to the UAE Data Office. It also says that before processing starts, the controller must provide the purposes, the sectors or establishments the data is shared with, and the protections for cross border processing. A website privacy policy is the natural place to do that.

  • Who you are: legal entity name, licence jurisdiction and contact details for privacy requests.
  • What you collect through the site: form fields, cookies and identifiers, chat transcripts.
  • Why: each purpose in plain words, and whether it relies on consent or another basis.
  • Who receives it: hosting, CRM, email, analytics and advertising providers, by category or name.
  • Where it is processed, including any countries outside the UAE.
  • How long you keep each type of data.
  • The rights available: information, correction, erasure, restriction, objection to direct marketing, portability, and how to use them.
  • How to complain, including to the regulator.

Do not copy another business’s policy. One that lists tools you do not use, or omits those you do, is not transparent.

Hosting location and cross border transfers

Many UAE websites are hosted in Europe or the United States, and the CRM, email platform and form tools often sit elsewhere again. The decree defines cross border processing as including storage, transmission and processing of personal data outside the State. Article 22 allows transfers, in cases approved by the UAE Data Office, where the destination has adequate data protection legislation or an agreement with the UAE applies. Article 23 adds other routes, including a contract imposing the decree’s protections, the data subject’s explicit consent, or necessity for a contract with the data subject.

Questions to put to your web team and each provider:

  • In which country are the web server, database and backups located?
  • Where do form submissions, CRM records and email lists physically sit?
  • Does the provider offer a data processing agreement, and what does it commit to on security and deletion?
  • Can you choose a data region, and does it cover backups and logs too?

Online stores add payment and shipping integrations, so map those before an ecommerce website launches.

Breach readiness for a website

Article 9 requires the controller to notify the UAE Data Office of a breach within the period set by the executive regulations, describing the breach, its likely effects and the corrective measures. Affected data subjects must also be told, and processors must tell the controller as soon as they become aware. Article 20 requires appropriate technical and organisational security, including encryption and pseudonymisation, and the ability to restore access to data after a failure.

For a typical company website, readiness looks like this:

  • HTTPS everywhere, including form endpoints and the admin area.
  • Unique admin accounts with strong authentication, and old staff and agency accounts removed.
  • CMS core, theme and plugins kept updated, with unused plugins deleted.
  • Daily off site backups, with a restore that has actually been tested.
  • A one page incident plan: who decides, who contacts the host, who drafts notices, and where the contact details for your adviser and regulator are kept.
  • A written agreement with your web agency and host saying they will tell you promptly about any incident.

If you run a healthcare practice, the stakes are higher because health data is sensitive personal data under the decree. Our notes on clinic website design cover how to keep booking forms light.

The website privacy checklist

  1. Confirm the regime

    Mainland PDPL, DIFC, ADGM, another free zone, or a sector law.

  2. Map the data

    Every form, tag and integration, and where each sends data.

  3. Minimise

    Remove unneeded form fields and set a retention period for leads.

  4. Fix consent

    Unticked marketing consent, stored proof, easy withdrawal, tags held until agreement.

  5. Rewrite the privacy policy

    Accurate to your real tools, recipients and locations, in every site language.

  6. Check hosting and providers

    Locations, processing agreements and the basis for any transfer abroad.

  7. Harden and prepare

    Security basics, tested backups and a one page breach plan.

  8. Review regularly

    After every new plugin or integration, and when the executive regulations appear officially.

Much of this is web work rather than legal work. When Codeeo launches a site, conversion tracking is part of the launch, and we set it up with the consent choices agreed with you. If your current site has years of forms and tags nobody fully understands, a website redesign can be the cleanest point to reset it. To talk through your site, contact our Dubai team for a fixed written quote, scoped to you, and bring your adviser’s view on which law applies.

Straight answers

Frequently asked questions

Does the UAE PDPL apply to a small business website?

The decree applies to controllers and processors in the UAE that process personal data, and a contact form that collects names and phone numbers is processing. Article 3 lets the UAE Data Office exempt some establishments that do not process a large volume of personal data, but only under standards set by the executive regulations. Until you have confirmed an exemption applies to you, plan as if the law does.

My company is licensed in a Dubai free zone. Which law applies?

The PDPL excludes companies in free zones that have their own personal data protection legislation. DIFC has its own Data Protection Law and ADGM has its own Data Protection Regulations. Other free zones need checking individually, because the exclusion depends on whether the zone has its own data protection rules. Ask your free zone authority or legal adviser.

Do I need a cookie banner in the UAE?

The PDPL does not mention cookies by name. It does define personal data to include electronic identifiers and location, and it prohibits processing without consent unless an exception applies. If your tags use identifiers to track or advertise to visitors, asking for consent first is the cautious approach, and it is also what many overseas visitors will expect.

Can I host my website outside the UAE?

Hosting abroad means personal data is processed outside the State, which the decree treats as cross border transfer. Articles 22 and 23 set the conditions, such as the destination having data protection legislation, a contract imposing equivalent protections, or the explicit consent of the data subject. Confirm which basis you rely on before choosing a host.

Do I need a data protection officer?

Article 10 requires one where processing causes a high risk because of new technologies or data volume, involves systematic assessment of sensitive personal data including profiling, or covers a large volume of sensitive personal data. A clinic or a business handling health or biometric data should look at this closely. A typical company brochure site usually will not meet those triggers, but take advice.

What are the penalties under the UAE PDPL?

Article 26 says the Council of Ministers will issue a decision setting out the violations and administrative penalties. We could not find that decision published on the official UAE legislation portal when this article was checked on 13 September 2026, so we do not quote any penalty figures. Check the current position with a legal adviser.

Fixed price, in writing

Send your brief. Get a scope and a price within 45 minutes.

  • One fixed number, agreed in writing before work starts
  • You approve the full design before development begins
  • Your domain, hosting, CMS and code stay in your name
  • English and Arabic, built properly right to left

Get your fixed price quote

Written scope and price within 45 minutes in business hours. No obligation.

By sending this you agree to be contacted about your enquiry. See our privacy policy.

Keep reading

More guides for UAE businesses

Call WhatsApp Get a quote