Skip to content
Qanat

UAE data protection is engineering work, and almost nobody quotes it

· 6 min read

What does UAE data protection compliance require of our software?

UAE PDPL compliance is engineering work, not a policy document. Federal Decree-Law No. 45 of 2021 gives users eight rights, including erasure, portability and human review of automated decisions, and each one is a feature somebody has to build. It belongs in the original scope, not in a retrofit after launch.

What the law actually is

The UAE Personal Data Protection Law is Federal Decree-Law No. 45 of 2021, published in the Official Gazette on 26 September 2021 and in force since 2 January 2022. Most vendors treat it as a privacy policy to paste into the footer. It is not. It is a list of things your software has to be able to do.

Eight rights, eight features

The law grants eight data subject rights. Read them as a backlog and the cost becomes obvious, because a product that cannot perform these operations is not compliant regardless of what the policy page says.

PDPL data subject rights and the product work each one implies
RightWhat the product must be able to doWhere it usually breaks
To be informedState what is collected, at the point of collectionConsent copy written after launch by someone who did not see the schema
AccessExport everything held on one personThe data is spread across four systems and nobody owns the join
RectificationCorrect a record and have the correction propagateStale copies in the analytics warehouse and the email tool
ErasureDelete a person without breaking referential integrityHard deletes cascade into invoices you are legally required to keep
Restriction of processingSuspend processing while keeping the recordThere is no state between active and deleted
PortabilityEmit the data in a structured, machine-readable formatBuilt as a one-off CSV script that nobody maintains
ObjectionStop a specific processing purpose, not the whole accountPurposes were never modelled separately in the first place
Human review of automated decisionsRoute an algorithmic decision to a person and log the outcomeThe AI feature has no appeal path and no decision log

The last row is the one that has changed recently. Any product that scores, ranks, prices or screens people with a model now needs a human in the loop and an audit trail of what the model decided. That is a queue, an interface and a log, and it is never in the AI quote.

The cross-border question nobody answers cleanly

Personal data can leave the UAE only to a jurisdiction the UAE Data Office has determined offers adequate protection, or under approved Standard Contractual Clauses or Binding Corporate Rules. As of 2026 no adequacy decisions have been published.

So "we host in Frankfurt, it is GDPR-grade" is an assertion, not a compliance answer. It may well be defensible under contractual safeguards, but it has to be a documented decision made when the architecture is chosen. Moving a live system's data residency afterwards is one of the most expensive changes there is.

What it adds to the build

Published market data puts UAE data protection work at roughly AED 7,000 to AED 37,000 on a typical app build, depending on how much personal data the product touches. That range is honest for a product designed with it in mind from the start. It is not the cost of adding it later.

Retrofit is a different number entirely, because compliance rarely lands as a feature. It lands as a change to the data model, and every consumer of that model changes with it.

On penalties, and why they are the wrong planning number

Penalty amounts sit with the Cabinet through executive regulations rather than in the statute itself, so anyone quoting you a precise fine is guessing. Plan against the cost that is certain instead: a customer, a partner or a procurement questionnaire asking what you do about erasure and portability, and the answer being a project.

Questions

Related questions

Does the UAE PDPL apply to a small business or only to enterprises?

It applies by activity, not by company size. If your product collects or processes the personal data of people in the UAE, the obligations attach. A ten-person SaaS with a signup form is in scope in the same way a bank is, though the proportionate effort is much smaller.

Can we store UAE customer data on AWS or Google Cloud outside the UAE?

Potentially, but not by default. Transfers out of the UAE need either an adequacy determination from the UAE Data Office, and none have been published as of 2026, or approved Standard Contractual Clauses or Binding Corporate Rules. Decide it when you choose the architecture, not after go-live.

How much does PDPL compliance add to a software build?

Published UAE market data puts data protection work at roughly AED 7,000 to AED 37,000 on a typical app, when it is designed in from the start. Adding it to a live product costs considerably more, because it changes the data model rather than adding a screen.

Start here

Tell us what it has to do.

A scope call, then a written scope and one fixed price against it. 20% of that price is held back until you accept the finished build, and the scope is yours to take elsewhere either way.

Who reads it
Alexandre Arnaud, Founder & Engineer. Not a coordinator, not an inbox.
What happens
A 20-minute call to pin the outcome, then a written scope and one fixed price against it.
What it costs
Nothing to get scoped and quoted. The quote is free and the scope is yours to take elsewhere.

The quote is free and the scope is yours either way.