GCC regulation 14 July 2026 12 min read

The UAE PDPL deadline is 1 January 2027 — what it means if you use AI

Federal Decree-Law 45/2021 requires full compliance by 1 January 2027. If your team puts customer data into AI tools, that deadline is about you. Here is what changes, what does not, and what to do in the time left.

If you run a business in the UAE and your people use AI tools on customer information, there is a date you should have in your plan: 1 January 2027. That is when full compliance with the UAE’s Personal Data Protection Law is required.

This piece is written for operators rather than lawyers — what the deadline actually means in practice, what it does not mean, and what is worth doing with the months remaining.

It is informational, not legal advice. We are a technology firm; where a question is legal rather than technical we will say so.

What the law is

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — the PDPL — is the cornerstone of onshore privacy regulation in the UAE. It has been in force since 2021, but the runway for full compliance runs to the start of 2027.

Its reach is broader than most people assume. It applies to any controller or processor established in the UAE processing personal data of subjects inside or outside the country, and to organisations outside the UAE processing the data of people residing in the Emirates.

Two consequences fall out of that immediately:

  • Being a small business does not exempt you.
  • Having your AI vendor abroad does not move the obligation off you.

Why a data-protection law is an AI problem

The PDPL does not mention artificial intelligence much. It does not need to.

The obligations attach to processing personal data. When one of your team pastes a customer list into a chat assistant to draft an email, or uploads a contract to summarise it, or feeds call recordings into a transcription tool — that is processing, carried out by a third party, usually under terms nobody in your business has read.

So the practical question the PDPL asks you is not “do you use AI”. It is:

What personal data has left your control, where did it go, on what legal basis, and can you evidence any of it?

For most UAE businesses we assess, the honest answer today is that nobody knows.

The part that catches people out: you may not be under the PDPL at all

This is the single most common misunderstanding we encounter, and getting it wrong wastes an entire compliance programme.

The UAE does not have one regime. It has several, and which one binds you depends on where you are registered:

If you are registered…Your regime
Onshore (mainland UAE)Federal PDPL
In the DIFCDIFC Data Protection Law, including Regulation 10 on autonomous systems
In ADGMADGM Data Protection Regulations

The free-zone regimes apply instead of the federal PDPL for entities incorporated in those zones — not in addition to it.

If you are a DIFC entity, the 2027 federal date is not your deadline, and you have a more specific problem: DIFC Regulation 10 reached full enforcement in January 2026 and deals directly with autonomous and semi-autonomous systems processing personal data. We have written about that separately.

Work out which regime you are in before you do anything else. It takes an afternoon and it determines everything downstream.

And then there is your sector

On top of whichever base regime applies, sectoral rules stack:

  • NESA information-assurance standards for government and critical infrastructure
  • CBUAE cybersecurity framework for banks and financial institutions
  • DHA data regulations for healthcare in Dubai, HAAD in Abu Dhabi

If you are in one of these sectors you comply with both your base regime and your regulator’s requirements. In healthcare in particular this is the reason we will not deploy a patient-facing agent before the governance work is done — the constraints are real, and they change what can be built.

What to actually do with the time

Ordered by what we find takes longest, not by what sounds most important.

1. Find out what is in use — start now

This is the long pole, and everybody underestimates it.

You cannot write a policy about tools you have not identified, and you cannot answer a regulator or a client about data you cannot trace. In every governance engagement we have run, the number of AI tools actually in use exceeded what the leadership team expected — usually by a wide margin, on personal accounts, paid for on personal cards.

Run it as an amnesty, not an investigation. An accurate picture is worth far more than a tidy one, and you will only get an accurate one if nobody fears the consequence of admitting something.

2. Establish which regime binds you

Onshore, DIFC or ADGM. Then your sector. One afternoon.

3. Fix the tool configuration

Genuinely the highest-value hour available in this whole subject.

Most consumer AI products behave completely differently on their business tier: training on your inputs disabled, retention configurable, admin visibility, actual contractual commitments. Most businesses have never changed the defaults because nobody realised there were defaults to change.

Moving your approved tools onto business terms and turning off training will do more for your position than any document.

4. Write the policy — short

Under ten pages. Approved use, prohibited use, what data may never leave the business, and how somebody requests a new tool. If a rule cannot be explained in one sentence it will not be followed, and an unfollowed policy is worse than none because it evidences that you knew.

5. Decide your cross-border position

Where processing happens matters, and for some workloads it constrains which providers you can use at all. Settle it deliberately at design time. Discovering it during an audit is considerably more expensive.

6. Write down what you did

Compliance is a demonstrable state, not a feeling. Keep the tool inventory, the policy version history, the acknowledgements, the vendor reviews and the review dates.

What this does not require

Some perspective, because the compliance-industrial complex will tell you otherwise:

  • You do not need a certification. ISO 27001 and SOC 2 are useful and entirely separate. Nothing above requires one.
  • You do not need a full-time hire. For a fifty-person firm this is a named owner with a few hours a month.
  • You do not need to ban AI. Bans move usage onto personal devices where you have no visibility at all — you trade a manageable risk for an invisible one. A sanctioned route good enough that nobody needs the unsanctioned one is what works.

How long it really takes

A business with nothing in place today can have a tool inventory, a written policy, approved tools configured correctly, a named owner and a review cycle inside four weeks.

The harder part is what follows: changing the habits of people who have been doing this their own way for two years. That is a quarter’s work, and it is the part that determines whether any of it is real.

Which is why starting in 2026 rather than in the last quarter before the deadline is the whole point.


If you want a blunt read on where you would currently stand, our AI Readiness Scorecard covers most of this in about five minutes, and our governance engagement is built around closing the gaps it finds.

Written by the Altus delivery team. We publish what we learn on real engagements, including the findings that do not flatter us.

Want this applied to your operation?

The readiness call is thirty minutes and free. Bring your numbers and we will work through them with you.