Saudi PDPL vs. UAE PDPL

"PDPL" isn't one law. Saudi Arabia and the UAE each use the same acronym for their own, separate Personal Data Protection Law — and confusing the two means confusing very different levels of real-world enforcement. Saudi's PDPL is fully in force with active fines being issued today; the UAE's federal PDPL is legally in force but still missing the implementing regulations and fine schedule that would make it fully operational.

Side by side

 Saudi Arabia PDPLUAE (federal) PDPL
Base lawRoyal Decree M/19 (2021), amended by M/148 (2023)Federal Decree-Law No. 45 of 2021
In force since14 September 2023 (after a grace period to Sept 2024)2 January 2022
Operational maturity (2026)Fully live and actively enforcedLegally in force, but implementing regulations still unpublished
RegulatorSaudi Data & AI Authority (SDAIA)UAE Data Office (not yet fully operational)
Penalties specified in the law?Yes — up to SAR 5M administrative, up to SAR 3M + prison for sensitive-data misuseNo — deferred to a future Cabinet Decision that hasn't been issued
Cross-border transfersAdequacy + contractual safeguards model (relaxed from a stricter approval requirement in 2023)Adequacy-list model, but no adequacy list published yet

Saudi Arabia's PDPL: live and actively enforced

Saudi's PDPL entered into force on 14 September 2023, after a one-year grace period. Its regulator, SDAIA (via its National Data Management Office), has moved from a quiet first year into real enforcement: its violation-review committees issued roughly 48 enforcement decisions in the year to early 2026, covering unlawful collection, weak security controls, and unconsented marketing. Fines run up to SAR 5 million (about $1.33M) for administrative violations, doubling for repeat offenses, with a separate criminal penalty — up to 2 years' imprisonment and/or a SAR 3 million fine — for sensitive-data disclosure done with intent to cause harm or gain benefit. A 2023 amendment also relaxed the original law's strict prior-approval requirement for cross-border transfers in favor of an adequacy-and-contractual-safeguards model closer to GDPR's.

UAE's federal PDPL: in force on paper, not yet operational

The UAE's federal PDPL took effect on 2 January 2022, but as of the most recent available reporting, its Executive Regulations — and the UAE Data Office named to enforce it — still haven't been fully stood up, several years after they were originally due. The TDRA (Telecommunications and Digital Government Regulatory Authority) fills the administrative gap in the meantime. Critically, the law itself defers all penalty amounts to a future Cabinet Decision that hasn't been issued yet — so there is currently no PDPL-specific fine schedule. What can currently bite around data misuse on UAE mainland comes from older, separate statutes: the Penal Code's confidentiality provisions and the UAE Cybercrime Law.

Don't confuse the UAE's federal PDPL with DIFC or ADGM

This is arguably as important a disambiguation as the Saudi/UAE naming collision itself. The DIFC Data Protection Law (Dubai International Financial Centre) and the ADGM Data Protection Regulations (Abu Dhabi Global Market) are separate, older, already GDPR-mature regimes that apply only to companies registered in those specific financial free zones — and they're actively enforcing today (ADGM fined one company $20,000 in 2024 for failing to fulfil a data subject access request). If a business operates inside DIFC or ADGM, its real, binding data protection obligations come from those regimes, not the still-maturing federal PDPL.

The practical takeaway

If you're advising on Saudi Arabia, treat the PDPL as a fully live compliance obligation today — SDAIA is actively adjudicating cases. If you're advising on the UAE mainland, the federal PDPL exists and technically binds companies, but the enforcement environment is still forming; separately check whether the company sits inside DIFC or ADGM, where the real enforcement action already is.

Regulatory status in this region is moving quickly, especially on the UAE side — verify current specifics directly with SDAIA or the UAE Data Office before relying on this for a compliance decision.

Common Questions

Are Saudi PDPL and UAE PDPL the same law?

No — they're two entirely separate national laws that happen to share the same acronym. Saudi Arabia's PDPL (Royal Decree M/19, amended 2023) and the UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) have different regulators, different penalty structures, and are at very different stages of real-world enforcement.

Which PDPL has actual fines being issued right now?

Saudi Arabia's. Its regulator, SDAIA, issued dozens of enforcement decisions in the year to early 2026. The UAE's federal PDPL has not yet had its implementing regulations or fine schedule published, so it isn't enforced the same way yet.

If a company operates in a UAE free zone like DIFC or ADGM, does the federal PDPL apply?

Not primarily. DIFC and ADGM run their own separate, older, and already actively-enforced data protection regimes for companies registered in those specific financial free zones. The federal PDPL applies more broadly across the UAE mainland.

Working across multiple regional frameworks?

Practice mapping controls across standards in the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is GDPR?

The EU's data protection law that both Gulf laws draw structural inspiration from.

What Is NESA?

The UAE's separate information security standard, distinct from its data protection law.