ORENTARA

Insights / PDPL & Compliance

The UAE PDPL Executive Regulations: what's actually in force in 2026

The PDPL defers much operational detail to Executive Regulations that, as of 2026, are still not issued — and one widely-copied claim about them is wrong.

OOrentaraFounder-led boutique
Published11 Jul 2026Updated12 Jul 2026Read6 min

Key takeaways

  • The PDPL has been in force since 2 January 2022, but its Executive Regulations remain unissued as of 2026.
  • Response deadlines, breach-notification timing, cross-border mechanisms and fine amounts are deferred to those Regulations — so they are not yet fixed in binding detail.
  • The claim that "Cabinet Decision No. 33 of 2024" is the PDPL Executive Regulation is a widely-copied error, not the law.
  • When the Regulations issue, organisations get a six-month window to bring their processing into line (Article 29).

Status at a glance — reviewed July 2026

Last reviewed: July 2026. We keep this page current as the position changes. Here is where the UAE PDPL and its Executive Regulations actually stand today.

  • In force: the UAE PDPL (Federal Decree-Law No. 45 of 2021), since 2 January 2022.
  • Not yet issued: the Executive Regulations — unissued as of July 2026.
  • Deferred until they issue: data-subject response deadlines, breach-notification timing, cross-border mechanisms, DPO thresholds and administrative fine amounts.
  • On issuance: organisations get a six-month window to comply (Article 29).
  • Debunked: "Cabinet Decision No. 33 of 2024" is not the PDPL Executive Regulation.

In force, but not fully operational

The UAE Personal Data Protection Law — Federal Decree-Law No. 45 of 2021 — took effect on 2 January 2022. But the law was written to defer much of its operational detail to Executive Regulations issued separately. As of 2026, and confirmed by the most recent reputable practice guides, those Regulations have not been issued. The principles are binding; several of the specifics are not yet defined.

What is still undefined

The gaps are not academic — they are exactly the numbers people want to quote:

  • Response deadlines for data-subject requests — the primary law says only "without undue delay".
  • Breach-notification timing — the controller must notify the UAE Data Office "immediately upon becoming aware", but the precise period and procedure are deferred.
  • Cross-border transfer mechanisms and any list of "adequate" countries.
  • The exact thresholds for appointing a Data Protection Officer.
  • Administrative penalty amounts.

The "Cabinet Decision 33/2024" myth

A claim circulates widely that the PDPL Executive Regulations were issued as "Cabinet Decision No. 33 of 2024". It is not supported by any tier-one legal source, and it does not appear in the official UAE legislation database alongside the neighbouring 2024 decisions that are listed. It traces to low-quality, AI-generated content copied from page to page. Treat any site that repeats it as unreliable on the rest of its PDPL detail too.

What to do now

Build to the law as it stands — consent-first, purpose-limited, documented and minimised — and design so the deferred parameters can be tightened the day the Regulations publish. When they do, Article 29 gives organisations six months to comply. A website built on documented data decisions absorbs that as a configuration change, not a rebuild. The businesses that will scramble are the ones that guessed at the missing numbers instead of building something adjustable.

Compliance you can adjust beats compliance you have to redo.

Where to go next

For the full set of instruments and article numbers, see our reference to the sources of UAE data-protection law. For the law in plain language, read the UAE PDPL explained, or check where your own site stands with a free PDPL readiness check.

Written by Orentara

Founder-led boutique

Related insights

Want this handled properly for your business?

A direct, honest view of what a compliant web presence would take — no reading required.

Book a consultation