Two Frameworks, Two Sets of Obligations
Saudi Arabia's Personal Data Protection Law and the UAE Federal Data Protection Law both trace their DNA back to Europe's GDPR. Both establish individual rights over personal data, require transparency about how it is used, and impose breach notification obligations with meaningful penalties. At the headline level they look similar enough that it is tempting to treat compliance with one as sufficient cover for the other. It is not.
This matters for any business that operates in both Saudi Arabia and the UAE, serves customers in both countries, processes data belonging to residents of both, or employs people in both jurisdictions.
Which Businesses Each Law Applies To
Saudi PDPL applies to any processing of personal data belonging to individuals located in Saudi Arabia, regardless of where the processing organisation is based. UAE FDPL applies to processing of personal data of individuals residing in the UAE, and to processing activity taking place within the UAE.
The Differences That Actually Matter
How consent is treated. PDPL takes a more consent-centric approach, with consent as the default lawful basis. UAE FDPL offers a broader menu including legitimate interests, giving more flexibility in how processing is justified.
Breach notification timelines. PDPL requires notification within seventy-two hours. UAE FDPL uses "as soon as reasonably possible," interpreted similarly in practice but expressed differently, with different content requirements.
Data localisation and transfers. PDPL restricts transfers outside Saudi Arabia, with certain transfers requiring SDAIA approval. UAE FDPL is considerably more permissive, requiring only that adequate protection exists in the destination country.
The DPO requirement. UAE FDPL explicitly requires certain organisations to appoint a designated Data Protection Officer. PDPL does not contain the same formal appointment requirement, though it creates accountability obligations that make the function essential regardless of title.
Sensitive data categories. Both laws define special categories, but the lists differ: PDPL includes financial data as sensitive, UAE FDPL includes genetic data.
Building a Compliance Programme That Covers Both
Because PDPL and UAE FDPL share a common structural heritage, a well-designed programme can satisfy both without doubling the work. The strategy is to build to the more stringent requirement wherever the two differ, which typically means PDPL's approach becomes the baseline since it is the more demanding on most points.
Make your data mapping jurisdiction-aware from the start. Your records of processing activities need to capture not just what data you hold, but which regulatory regime governs each category, so your consent mechanisms, retention rules, and transfer safeguards can be applied correctly per jurisdiction rather than as a single blended policy.
This is exactly the kind of dual-jurisdiction work our vDPO service is built around for GCC businesses operating across borders.
