RISKFORTIS
Enforcement090d 00h 22m

DPDP vs UAE PDPL

Reviewed August 2026 · Federal Decree-Law No. 45 of 2021 · Executive Regulations still pending

The useful question is not how the two texts differ on paper. It is what a group already compliant in the UAE still has to build for India — and what an Indian business expanding to Dubai or Abu Dhabi still has to build there.

Both laws were drafted after GDPR and borrow its vocabulary, so the mapping looks easy. It is not. The two diverge precisely where the work lives: which processing needs consent, when a breach clock starts, and who has to sit inside the country.

The headline differences

Three differences that change behaviour.

There are more than three differences. These are the three that force an operational change — a workflow, a rota, a piece of infrastructure — rather than a documentation change.

01

The breach clock is a clock, not a judgement

PDPL asks you to notify the UAE Data Office immediately once you become aware, and only where the breach would prejudice the data subject's privacy, confidentiality or security — a judgement call, made under no stated deadline. DPDP Rule 7 removes both the judgement and the ambiguity: every breach, to the Board and to every affected principal, with a detailed report inside 72h. CERT-In adds a separate 6h reporting duty on top.

What changes: your incident rota needs a named responder reachable in under an hour, IST.

02

Legitimate interest carries far less in India

PDPL sets out consent plus a broad list of exceptions, including a legitimate-interest ground that absorbs a great deal of ordinary analytics, security and business processing. DPDP replaces that with a closed list of "legitimate uses" — employment, medical emergency, State functions and a few more. Marketing analytics and product telemetry are not on it.

What changes: processing you run without consent in the UAE needs consent capture in India.

03

The officer has to be in the country

A PDPL data protection officer may sit inside or outside the UAE, and many groups run one regionally from Dubai. A DPDP Significant Data Fiduciary must appoint a Data Protection Officer based in India, answerable to the board, as the point of contact for grievance redressal. A regional DPO in Dubai does not satisfy it.

What changes: a hire or a retained Indian appointment, not a reporting-line edit.

The full comparison

Theme by theme, side by side.

Colour appears only where one regime is genuinely stricter on that theme. Red marks the heavier obligation; green marks the lighter one.

ThemeDPDP (India)UAE PDPL
Territorial scopeDigital personal data processed in India, and processing outside India connected to offering goods or services to data principals in India. No sectoral carve-outs from the Act itself.Data subjects resident or with a place of business in the UAE, and controllers or processors abroad handling their data. Health, credit and government data sit under separate laws, and the DIFC and ADGM free zones have their own regimes entirely.
Lawful basesConsent, or one of a closed list of legitimate uses. No balancing test. Stricter — far more processing falls to consent.Consent, plus a wide set of statutory exceptions covering contract, legal obligation, public interest, legal claims, employment and the controller's legitimate interests.
Consent standardFree, specific, informed, unconditional, unambiguous, by clear affirmative action. Withdrawal must be as easy as giving. An optional registered Consent Manager may hold the record.Specific, clear and unambiguous, evidenced by the controller, and withdrawable at any time. No third-party consent intermediary exists.
NoticeStandalone, itemised notice: the data, the purpose, how to exercise rights, how to complain to the Board — available in English or any of the 22 Eighth Schedule languages. Stricter on delivery.A prescribed information set before processing — purposes, recipients, cross-border destinations, retention, rights and complaint route. Longer content, no language mandate.
Breach trigger and windowEvery personal data breach, no materiality gate. Board and every affected principal without delay; detailed report within 72h. CERT-In adds 6h for covered incidents. Stricter — no threshold, two clocks.Notify the UAE Data Office immediately on becoming aware, and the data subject, where the breach would prejudice their privacy, confidentiality or security. No fixed hour count in the Decree-Law.
Individual rightsAccess, correction, completion, updating, erasure, grievance redressal and nomination. No portability, no objection right, no automated-decision provision. Narrower set to service.Access, portability, rectification, erasure, restriction of processing, objection — including to automated processing and profiling — and the right to stop processing for direct marketing.
Cross-border transfersPermitted except to countries the Central Government restricts by notification. Sectoral localisation — RBI payments data, IRDAI, SEBI records — still bites on top.Only to jurisdictions the Data Office treats as adequate, or on contractual clauses, binding corporate rules, express consent or a narrow set of derogations. Stricter — a transfer instrument is required.
Officer requirementSignificant Data Fiduciaries appoint a DPO based in India, reporting to the board. Every other fiduciary publishes a contact point for rights and grievances.A DPO where processing is high risk, involves large-scale sensitive data, or systematically evaluates individuals. May be located inside or outside the UAE, and may be shared across group entities.
RegistrationNo general fiduciary register. Consent Managers must register with the Board, with a net worth threshold of ₹2 Cr; registration opens 13 Nov 2026.No general controller register either, but where a DPO is required their appointment and contact details must be filed with the UAE Data Office.
PenaltiesFixed ceilings per instance: ₹250 Cr for security failures, ₹200 Cr for breach notification failures. Quantified and enforceable now.Administrative fines to be set by Cabinet resolution under the Executive Regulations, which remain unissued. Exposure is real but not yet quantified.
Enforcement bodyA single Data Protection Board of India, adjudicating by inquiry, with appeals to the TDSAT. Powers live from 13 Nov 2026.The UAE Data Office, which supervises, receives complaints and issues guidance — with DIFC and ADGM commissioners regulating separately inside those free zones.

For GCC and multinational groups

If you are compliant with PDPL, what DPDP still requires.

Your records, security controls and processor contracting discipline carry over. These six do not, and each of them is an operational build rather than a policy edit.

  1. 01

    Re-base everything you run on legitimate interests

    Fraud scoring, marketing analytics, product telemetry, enrichment. In India most of it lands on consent, which means capture, storage, a withdrawal path and a record of what was shown at the moment of asking.

  2. 02

    A breach plan with no assessment step

    Your first decision point under PDPL — would this prejudice the data subject — does not exist under Rule 7. Teams trained to assess before notifying will burn the 6h CERT-In window deciding.

  3. 03

    Notice rebuilt as a standalone, translatable artefact

    Not a clause in your global privacy policy. A separate itemised notice, served at the point of consent, available on request in any Eighth Schedule language. That is a content pipeline, not a legal review.

  4. 04

    An India-resident DPO if you are named an SDF

    Plus annual DPIA and audit obligations. A shared regional DPO in Dubai, which PDPL permits, is not a defence to this.

  5. 05

    Children treated as under 18

    Verifiable parental consent up to eighteen, with tracking and targeted advertising to children prohibited outright. Any age gate you set for the Gulf market will need re-cutting.

  6. 06

    The Indian sectoral stack on top of the Act

    RBI, SEBI and IRDAI retention and reporting mandates interact with DPDP erasure and notification duties. Nothing in a PDPL programme reconciles them, and no free-zone equivalent prepares you for it.

For Indian exporters and GCC expansion

If you are compliant with DPDP, what PDPL still requires.

The mirror. Your consent machinery is stronger than the UAE asks for — but four obligations have no Indian analogue, and one of them decides which law applies at all.

01

Decide the free-zone question first

An entity in the DIFC or ADGM is not governed by the federal PDPL at all, but by that zone's own data protection law and commissioner. Where you incorporate changes the whole obligation set. Get this wrong and the rest of the programme is aimed at the wrong regulator.

02

Transfer instruments you never needed

DPDP lets data leave unless a country is restricted. PDPL requires an adequacy finding or a positive instrument — clauses, binding corporate rules or express consent — for every outbound flow, including intra-group traffic back to your Indian data centre.

03

Rights India does not grant

Portability, restriction of processing, objection to profiling and automated decision-making, and a direct-marketing stop. Your DPDP rights desk has no workflow for any of them, and portability in particular is an engineering task.

04

A longer notice, and a sensitive-data category

PDPL prescribes more content than DPDP — recipients, retention, cross-border destinations — and treats health, biometric, genetic, religious and similar data as a distinct sensitive class. DPDP has no special-category tier, so your Indian notice is not a template for the UAE.

One of the two programmes is nearly done. Find out which parts.

Start a gap assessment

Lending, NBFC or fintech across India and the Gulf? See the sector page →

General information, not legal advice.