Law note · United Arab Emirates

Federal Decree-Law on the Protection of Personal Data, breach notification

cite Federal Decree-Law No. 45 of 2021, Art. 9 stage IN FORCE in force since 2022-01-02 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a breach affecting the personal data of an individual in the onshore UAE must notify the Bureau at the time it becomes aware of the breach; the Decree-Law defers the specific notification window to Executive Regulations whose text could not be confirmed at primary source in this research pass, so an app should not assume a specific hour count without checking current regulator guidance.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 9 requires the Controller to notify the Bureau of a breach that would prejudice the privacy, confidentiality, or security of personal data, at the time it becomes aware of the breach, within a period the Decree-Law itself defers to the Executive Regulations. No fixed number of hours or days is stated in the Decree-Law's own text; the timeline is not established pending the unconfirmed Executive Regulations (see the jurisdiction summary).

Data Subject notification is also required where the breach meets a threshold the Decree-Law's text does not fully set out in the provisions read.

← Back to the example  ·  Lint your app →