"PDPL" isn't one law. Saudi Arabia and the UAE each use the same acronym for their own, separate Personal Data Protection Law — and confusing the two means confusing very different levels of real-world enforcement. Saudi's PDPL is fully in force with active fines being issued today; the UAE's federal PDPL is legally in force but still missing the implementing regulations and fine schedule that would make it fully operational.
Side by side
| Saudi Arabia PDPL | UAE (federal) PDPL | |
|---|---|---|
| Base law | Royal Decree M/19 (2021), amended by M/148 (2023) | Federal Decree-Law No. 45 of 2021 |
| In force since | 14 September 2023 (after a grace period to Sept 2024) | 2 January 2022 |
| Operational maturity (2026) | Fully live and actively enforced | Legally in force, but implementing regulations still unpublished |
| Regulator | Saudi Data & AI Authority (SDAIA) | UAE Data Office (not yet fully operational) |
| Penalties specified in the law? | Yes — up to SAR 5M administrative, up to SAR 3M + prison for sensitive-data misuse | No — deferred to a future Cabinet Decision that hasn't been issued |
| Cross-border transfers | Adequacy + contractual safeguards model (relaxed from a stricter approval requirement in 2023) | Adequacy-list model, but no adequacy list published yet |
Saudi Arabia's PDPL: live and actively enforced
Saudi's PDPL entered into force on 14 September 2023, after a one-year grace period. Its regulator, SDAIA (via its National Data Management Office), has moved from a quiet first year into real enforcement: its violation-review committees issued roughly 48 enforcement decisions in the year to early 2026, covering unlawful collection, weak security controls, and unconsented marketing. Fines run up to SAR 5 million (about $1.33M) for administrative violations, doubling for repeat offenses, with a separate criminal penalty — up to 2 years' imprisonment and/or a SAR 3 million fine — for sensitive-data disclosure done with intent to cause harm or gain benefit. A 2023 amendment also relaxed the original law's strict prior-approval requirement for cross-border transfers in favor of an adequacy-and-contractual-safeguards model closer to GDPR's.
UAE's federal PDPL: in force on paper, not yet operational
The UAE's federal PDPL took effect on 2 January 2022, but as of the most recent available reporting, its Executive Regulations — and the UAE Data Office named to enforce it — still haven't been fully stood up, several years after they were originally due. The TDRA (Telecommunications and Digital Government Regulatory Authority) fills the administrative gap in the meantime. Critically, the law itself defers all penalty amounts to a future Cabinet Decision that hasn't been issued yet — so there is currently no PDPL-specific fine schedule. What can currently bite around data misuse on UAE mainland comes from older, separate statutes: the Penal Code's confidentiality provisions and the UAE Cybercrime Law.
Don't confuse the UAE's federal PDPL with DIFC or ADGM
This is arguably as important a disambiguation as the Saudi/UAE naming collision itself. The DIFC Data Protection Law (Dubai International Financial Centre) and the ADGM Data Protection Regulations (Abu Dhabi Global Market) are separate, older, already GDPR-mature regimes that apply only to companies registered in those specific financial free zones — and they're actively enforcing today (ADGM fined one company $20,000 in 2024 for failing to fulfil a data subject access request). If a business operates inside DIFC or ADGM, its real, binding data protection obligations come from those regimes, not the still-maturing federal PDPL.
The practical takeaway
If you're advising on Saudi Arabia, treat the PDPL as a fully live compliance obligation today — SDAIA is actively adjudicating cases. If you're advising on the UAE mainland, the federal PDPL exists and technically binds companies, but the enforcement environment is still forming; separately check whether the company sits inside DIFC or ADGM, where the real enforcement action already is.