Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

UAE Personal Data Protection Law (PDPL) Compliance

Pandectes GDPR Compliance helps Shopify stores meet UAE PDPL requirements by blocking non-essential cookies until visitors consent, scanning and classifying cookies, and keeping consent records.

Start Free
PDPL UAE

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is PDPL?

The Personal Data Protection Law (PDPL) is the United Arab Emirates’ federal data protection law, issued as Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data. It sets out how personal data may be processed, what rights individuals have over their data, and what obligations apply to the businesses that collect it. It is overseen by the UAE Data Office, which was established by a separate decree-law in the same year.

The PDPL follows many of the same ideas as the EU’s GDPR. Its key rules include:

  • Personal data may not be processed without the consent of the data subject, unless one of the exceptions in the law applies, such as performing a contract or complying with a legal obligation.
  • Consent must be specific, clear, and unambiguous, the business must be able to prove it, and people can withdraw it at any time.
  • Individuals have rights to information about how their data is processed, and to request correction, erasure, restriction of processing, and data portability, as well as to object to certain processing.
  • Businesses must keep personal data secure, report data breaches to the UAE Data Office, and in some cases appoint a data protection officer.
  • Personal data may be transferred abroad only to countries with adequate data protection or under the other conditions in the law.

The PDPL does not apply everywhere in the country. Free zones with their own data protection laws, such as the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM), are excluded, and so are some types of data covered by separate legislation, such as health and banking data.

Who does the PDPL apply to?

The PDPL applies to the processing of personal data of people who live or have a place of business in the UAE. It covers businesses established in the UAE, and also businesses outside the UAE that process the personal data of people in the UAE, so a foreign online store selling to UAE customers can fall within its scope.

What happens if I don’t comply with the PDPL?

Breaching the PDPL can lead to:

  • Complaints and investigations: Individuals can file a complaint with the UAE Data Office if they believe their data has been processed in breach of the law, and the Data Office can investigate.
  • Administrative penalties: The Data Office can impose administrative penalties. The law leaves the violations and the amount of the administrative penalties to be set by a decision of the UAE Cabinet, so the exact fines depend on those implementing rules.

Because the penalty rules come from implementing regulations, check their current status before relying on any figure.

When did the PDPL go into effect?

The PDPL was issued on 20 September 2021 and came into force on 2 January 2022. Businesses have six months from the issue of its executive regulations to bring their processing into line with the law.

Complying with the PDPL

If your online store sells to customers in the UAE, the PDPL can apply to the personal data you collect from them, including data collected through cookies and tracking tools on your storefront.

For cookies and tracking, the main points are:

  • Consent: Consent is the default legal basis under the PDPL. For analytics, advertising, and other non-essential cookies, ask for consent before they are set, make the request clear and easy to understand, and let visitors withdraw consent as easily as they gave it.
  • Notice: Tell visitors what data you collect, why, and who you share it with, including the third-party tools that place cookies on your store.
  • Proof of consent: The law requires you to be able to prove consent, so keep a record of each visitor’s choice.
  • Cross-border transfers: Many analytics and marketing tools process data outside the UAE. Check that each transfer meets the PDPL’s conditions.
  • Data subject requests: Be ready to respond to requests for access, correction, erasure, and portability.

If your business is set up in the DIFC or ADGM, the free zone’s own data protection rules apply instead, and they have their own requirements.

To make this manageable, consider using a Consent Management Platform (CMP) like Pandectes GDPR Compliance. It shows a cookie banner that blocks non-essential cookies until the visitor consents, scans your store to detect and classify cookies automatically, and generates a cookie declaration for your policy page. It keeps consent logs as proof of each visitor’s choice, helps you handle data subject requests, and uses geolocation to show region-specific banner settings to visitors from different countries. Pandectes GDPR Compliance is designed specifically for Shopify stores.

The PDPL’s implementing rules are still developing, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free