Middle East & North Africa3
The UAE's first federal data protection law, making consent the default legal basis for processing. The UAE operates a unique three-regime system where federal law, DIFC, and ADGM each have separate data protection frameworks. Executive Regulations are still pending, creating enforcement uncertainty around detailed implementation requirements.
ADGM's comprehensive data protection regulations closely modeled on GDPR principles, carrying the highest penalty ceiling in the Middle East at USD 28 million. Requires data protection by design and default, record-keeping of processing activities, and written contracts between controllers and processors. Part of the UAE's three-regime system.
DIFC's standalone data protection law applying within the Dubai financial free zone, significantly strengthened by a 2025 amendment introducing a private right of action for data subjects. Explicitly requires minimum necessary cookies and easily accessible cookie controls, making it one of the more cookie-specific frameworks in the Middle East.