THE UAE PICTURE
Federal, emirate and financial free zone regimes apply at the same time, and they do not align neatly.
The UAE is the market where most groups discover that compliance is not one programme. A single group can sit under federal law, an emirate-level regulation and a free zone regime simultaneously — with three different privacy laws and three different notification clocks.
What is different here
- Three privacy regimes in one country. Federal Decree-Law 45 of 2021 onshore, the ADGM Data Protection Regulations 2021, and DIFC Data Protection Law 5 of 2020. A group with entities in two of them needs one privacy operating model that applies the right rules to the right processing.
- Emirate-level standards sit on top of federal ones. The Dubai Electronic Security Center's ISR for Dubai government and designated entities; ADHICS for Abu Dhabi healthcare. These run alongside the national standard, not instead of it.
- Free zone supervisors have their own technology expectations. FSRA and DFSA set outsourcing, cloud and technology risk requirements distinct from CBUAE's, and a firm in ADGM or DIFC answers to those.
- Sovereign and government-related entities carry an extra layer. Classification, residency and reporting obligations that a private-sector organisation of the same size does not face.
- It is the natural group headquarters. Which means the UAE entity often carries consolidated oversight for subsidiaries in four other markets — a reporting problem before it is a control problem.