
Hands-on UAE company-formation specialists since 2020 · Reviewed for accuracy · Updated August 2026
Quick AnswerData breach UAE 2026: PDPL notification duties, a 72-hour incident runbook, controller vs processor roles and 7-year record retention explained.
A data breach in the UAE is no longer just an IT problem with a communications tail. Since the Federal Decree-Law on the protection of personal data β universally shortened to the PDPL β came into force, an incident that exposes customer, employee or supplier information triggers a defined set of legal obligations with a clock attached. The clock starts when you become aware, not when you finish investigating, and most UAE businesses discover their runbook has gaps only after the first real incident.
The good news is that the obligations are proportionate and largely procedural. What the law wants is that you can say, credibly and quickly, what happened, whose data was involved, what the likely consequences are, what you did to contain it and what you are doing to prevent recurrence. Companies that have written that down in advance handle an incident in days. Companies that have not spend the first week arguing about who owns the decision. This guide sets out the duties, the runbook, the documentation and the practical traps for a UAE business in 2026.
What must a UAE business do after a data breach in 2026?
Under the PDPL, a controller must notify the regulator without undue delay once a personal data breach is identified, and must notify affected individuals directly where harm is likely. Most organisations work to an internal 72-hour target. Records supporting the incident, and any underlying business data, must be retained for at least 7 years where tax substantiation applies.
The obligation sits with whoever determines the purposes and means of processing β the controller. If you decide why customer data is collected and how it is used, you are the controller, even if a third-party platform holds the actual database. That distinction is the single most misunderstood point in UAE incident response, because founders instinctively assume the cloud provider or the outsourced payroll bureau carries the reporting duty. It does not. It has a contractual duty to tell you, promptly, and then you decide and file.
The second thing to understand is that "breach" is broader than "hack". The PDPL concept covers any incident leading to accidental or unlawful destruction, loss, alteration, disclosure of, or unauthorised access to personal data. That includes a laptop left in a taxi, an email sent to the wrong distribution list, a departing employee taking a customer list, a misconfigured storage bucket, a ransomware event that encrypts your own records, and a supplier who suffers an intrusion affecting the data you gave them.
| Incident element | What is required | Practical timeframe |
|---|---|---|
| Internal detection and escalation | Named owner informed, incident log opened | Immediately on discovery |
| Containment | Access revoked, credentials rotated, systems isolated | Within hours 0β12 |
| Risk assessment | Categories of data, number of records, likelihood of harm | Within hours 12β48 |
| Regulator notification | Filed where personal data is affected | Without undue delay; 72-hour internal target |
| Data subject notification | Direct notice where harm is likely | Promptly after assessment |
| Processor notification to controller | Immediate, per contract | Contractually defined, commonly 24 hours |
| Remediation plan | Root cause fixed, controls strengthened | 2β6 weeks |
| Breach register entry | Retained as accountability evidence | Permanent |
| Underlying tax-relevant records | Retained per Federal Tax Authority rules | Minimum 7 years |
The timeframes in the right-hand column are operational conventions rather than a uniform statutory grid. What the law fixes is the standard β without undue delay β and the burden of showing you met it.
Who the PDPL applies to, and who sits outside it
The federal law applies broadly to the processing of personal data of individuals in the UAE, whether the processing happens inside the country or outside it. A Dubai mainland trading company processing customer records is in scope. So is an overseas e-commerce operator selling into the UAE and holding UAE customers' delivery addresses.
There are carve-outs. Government data, and data already covered by dedicated sectoral legislation, sit under their own regimes. Health data is subject to specific federal health information rules and, in Dubai, the Dubai Health Authority's requirements for patient information β including restrictions on where health records may be stored and transferred. Financial institutions carry additional obligations from their own regulators. Where a sector rule and the PDPL both apply, the sector rule usually sets a higher bar rather than replacing the general one.
The most consequential carve-out for business structuring is the financial free zones. Entities registered in DIFC or ADGM are governed by those jurisdictions' own data protection laws, each with its own commissioner, its own registration or notification requirements and its own breach reporting route. ADGM and DIFC regimes are closer in shape to European practice, and in some respects more prescriptive about registration and records of processing. A group with a mainland operating company and an ADGM holding entity therefore has two data protection regimes running in parallel and should not assume one filing covers both. This is one of several reasons jurisdiction choice deserves proper thought at the point of business setup in Dubai rather than being decided purely on licence cost.
Federal obligations that apply regardless of zone are worth naming, because they are administered separately: corporate tax registration and filing with the Federal Tax Authority, VAT where thresholds are met, and beneficial ownership records with your licensing authority. Data protection sits alongside those, not instead of them.
Controller and processor: getting the roles right before the incident
Almost every dispute in the first 48 hours of a UAE data breach is a role dispute. Clarify roles in writing while nothing is on fire.
A controller determines why and how personal data is processed. A processor processes on the controller's documented instructions and for the controller's purposes. Your payroll bureau, your CRM vendor, your cloud hosting provider, your marketing agency and your outsourced call centre are typically processors. Your company is the controller of its own customer, employee and supplier data.
Two organisations can be joint controllers where they genuinely decide purposes together β a marketing partnership where both parties use the resulting contact list for their own ends, for example. Joint control needs an agreement setting out who does what, including who notifies in an incident.
The processor contract is where breach response is actually determined. At minimum it should specify: the subject matter, duration and purpose of processing; the categories of data and data subjects; a commitment to process only on instruction; confidentiality obligations on staff; appropriate technical and organisational security measures; the terms on which sub-processors may be engaged; a duty to notify the controller of any breach immediately and, in practice, within a stated number of hours; a duty to assist with the controller's own notification and with data subject requests; and deletion or return of data at the end of the relationship, with evidence.
The clause founders most often omit is the one that matters most in an incident: an obligation on the processor to give the controller the information needed to notify, not merely to say that something happened. A vendor email saying "we experienced a security event and are investigating" does not let you assess risk or file anything.
What counts as a personal data breach, and what does not
The assessment turns on whether personal data was affected and whether the incident prejudices confidentiality, integrity or availability.
Three examples that are breaches. A finance clerk emails a payroll spreadsheet with staff salaries and passport numbers to the wrong recipient β a confidentiality breach affecting sensitive personal data. A ransomware attack encrypts your CRM and your backups are three weeks old β an availability breach, and if data was exfiltrated first, a confidentiality breach too. A departing sales manager copies the client database to personal storage β an unlawful disclosure regardless of whether the data is ever used.
Three examples that usually are not. A denial-of-service attack takes your marketing website offline for six hours with no personal data touched. An attacker attempts credential stuffing against your admin portal and every attempt fails. An internal system outage caused by a failed update, restored from backup within an hour, with no unauthorised access. These belong in the internal incident log rather than a regulator filing β but log them, because a pattern of near misses is exactly the evidence a regulator uses to judge whether your controls were adequate when a real breach later occurs.
The grey zone is encrypted data. If lost data was strongly encrypted and the keys were not compromised, the risk of harm to individuals may be low enough that notification to data subjects is unnecessary, though the incident still warrants assessment and internal recording. The judgement must be documented β "we decided not to notify because X" is a defensible position; silence is not.
The 72-hour incident runbook, hour by hour
A worked timeline makes the obligations concrete. Assume a mid-sized Dubai company discovers on a Sunday morning that a cloud storage folder containing customer contracts has been publicly accessible for eleven days.
Hour 0 to 2 β Detection and escalation. Whoever finds it tells the named incident owner. That name must exist before the incident; "escalate to management" is not a plan. The incident log opens with the time of discovery, who found it, and what was observed. Nobody deletes anything yet β preserving evidence matters more than tidying.
Hour 2 to 8 β Containment. Access is closed. Credentials and access keys are rotated. Logs are preserved and copied to a location the attacker could not reach. If a vendor is involved, they are formally notified in writing with a reference to the notification clause in the contract. The technical team documents each action with a timestamp.
Hour 8 to 24 β Scoping. What personal data was in the folder? How many individuals? Which categories β names and emails only, or identification data, financial details, health information? Was the data actually accessed, and can access logs show by whom and how often? Was anything exfiltrated? This is where a current data inventory earns its cost. Companies without one spend three days answering a question that should take three hours.
Hour 24 to 48 β Risk assessment and decision. Assess the likelihood and severity of harm: identity theft, financial loss, reputational damage, discrimination, or exposure of sensitive information. Decide whether the threshold for regulator notification is met, and whether harm to individuals is likely enough to require direct notice. Record the reasoning. Involve legal counsel and, if the exposure is material, the shareholders or board.
Hour 48 to 72 β Notification. File the regulator notification with what is known, flagging that the investigation continues β a partial, prompt notification is preferred to a complete, late one. Prepare and issue the data subject notice: what happened, when, what data, what the likely consequences are, what you have done, what the individual should do, and a contact point for questions. Plain language, in Arabic and English where your customer base warrants it.
Week 2 to 6 β Remediation and closure. Root cause analysis, control changes, retraining, contract renegotiation with the vendor if relevant, and a written closure report entered into the breach register. If the regulator asks follow-up questions months later, this report is your answer.
Records, registers and the documentation that proves compliance
Accountability under the PDPL is demonstrated through documents, and four of them do most of the work.
The record of processing activities lists what personal data you hold, why, on what legal basis, who it is shared with, where it is stored, how long it is kept and what security applies. It is tedious to build the first time and trivial to maintain thereafter. It is also the document that turns a 72-hour scoping exercise into a 3-hour one.
The breach register records every incident, including those you decided not to report, with the assessment reasoning. Regulators read the non-reported entries as carefully as the reported ones.
The processor register lists every vendor touching personal data, the contract reference, the notification timeframe agreed, the sub-processors permitted and the data location. When a vendor is breached, this tells you within minutes whether you are exposed.
The transfer log records cross-border transfers and the safeguard relied on for each. Transfers outside the UAE are permitted where the destination provides adequate protection or an approved mechanism such as contractual clauses or explicit consent applies. Cloud services with servers outside the UAE are transfers, whether or not anyone thinks of them that way.
There is a practical overlap with tax record-keeping that companies often manage badly. Customer contracts, invoices and supporting correspondence are simultaneously personal data and accounting records. Personal data principles push toward deleting what you no longer need; tax law requires retention for at least seven years to substantiate a position, and the Federal Tax Authority's services and guidance sit at tax.gov.ae. The resolution is a retention schedule that distinguishes categories: delete marketing contact data on the retention rule you set, retain transaction records for the statutory period, and document the distinction so that neither obligation is breached in the name of the other. The mechanics of what constitutes an adequate accounting record are covered in our UAE corporate tax guide.
Security measures, the DPO question and staff training
The PDPL requires appropriate technical and organisational measures proportionate to the risk. There is no prescribed checklist, which unsettles founders who would prefer one. In practice, a UAE SME is expected to have: access control on a least-privilege basis with periodic review; multi-factor authentication on email, finance and administrative systems; encryption of data at rest and in transit; tested backups held separately from production; logging sufficient to reconstruct who accessed what; a patching routine; and offboarding that actually removes access on the leaver's last day.
That final item deserves emphasis. In UAE incident reviews, dormant accounts belonging to former staff and former contractors are a recurring root cause. Offboarding is a governance control as much as an HR one, and it should be tied to the same checklist that handles visa cancellation and final settlement under the labour law.
A data protection officer must be appointed where processing is high-risk, involves large-scale processing of sensitive data, or entails systematic evaluation of individuals. Many UAE SMEs fall below these triggers and appoint someone voluntarily anyway β usually a senior operations or finance person with an external adviser behind them. The value is not the title; it is having a named individual whose job includes owning the runbook, maintaining the registers and making the notify-or-not call under time pressure.
Training closes the loop. The overwhelming majority of UAE personal data incidents originate in ordinary human error: phishing, misdirected email, weak password reuse, or data sent to a personal account "to work on at home". Two short sessions a year, with a simulated phishing exercise, reduce incident volume more than most technical spend.
How data protection interacts with your wider UAE compliance stack
Data protection is one strand of a compliance picture that regulators increasingly read together, and the Ministry of Economy's broader corporate transparency agenda is part of the same direction of travel.
Beneficial ownership records are personal data about identified individuals, held because the law requires it. That is a straightforward lawful basis, but it also means UBO files need the same access control, retention discipline and breach handling as customer data. Companies that keep passport scans of shareholders in an unrestricted shared drive have a data protection problem sitting on top of their beneficial ownership compliance obligations.
Economic substance work pulls in employee data, payroll records and evidence of where decisions are taken. Where a company must demonstrate substance, the supporting file typically contains board attendance records, staff details and premises evidence β all personal data, all needing a defined retention period. Our economic substance regulations guide sets out what that file needs to contain.
Employment data carries its own overlay. Records held under the federal labour framework β contracts, leave records, gratuity calculations, wage protection system submissions to MOHRE β are personal data with a clear legal basis and a long retention need. Health records collected for insurance or occupational purposes are sensitive data requiring stricter handling, and where the Dubai Health Authority's rules apply, additional storage and transfer restrictions come with them.
The practical takeaway is to run one inventory, not four. A single data map covering customers, employees, shareholders and vendors serves data protection, tax substantiation, UBO maintenance and substance evidence simultaneously.
Data subject rights and the questions that follow a breach
A breach rarely stays a breach. Once individuals know their data was exposed, they exercise rights, and a company that cannot answer them compounds the original incident with a second failure.
The PDPL gives data subjects a defined set of rights, and each has an operational consequence. The right of access means an individual can ask what personal data you hold about them, why, who it has been shared with and how long it will be kept β which is unanswerable without a record of processing activities. The right to rectification requires you to correct inaccurate data and, where relevant, to tell recipients you shared it with. The right to erasure applies where data is no longer needed for the purpose it was collected for, subject to overriding legal retention duties such as the seven-year tax rule. The right to restrict or object to processing covers direct marketing outright and other processing in defined circumstances. The right to data portability allows an individual to receive their data in a structured, machine-readable format. And the framework limits purely automated decision-making that produces significant effects, with a right to human review.
Operationally, three things matter. First, requests must be recognised as requests β an email to a general inbox saying "send me everything you have on me" starts a clock, and front-line staff should know to escalate it rather than reply informally. Second, you must verify identity before disclosing anything, because an access request is itself a vector for social engineering, and responding to an impostor is a fresh breach. Third, responses must be timely, and the only way to be timely is to know where the data lives before the request arrives.
Post-breach, request volumes spike. A company that notifies ten thousand customers should expect a meaningful number of access and erasure requests within days. Plan the response template, the identity verification method and the person who owns the queue as part of the incident runbook, not afterwards.
Common Mistakes UAE Businesses Make With Data Breach Response
- Assuming the vendor reports it. The controller carries the notification duty. A cloud provider or payroll bureau must tell you promptly, but filing with the regulator and notifying affected individuals remains your obligation, and outsourcing the processing never outsources the accountability.
- Waiting for a complete investigation before notifying. The standard is without undue delay, not once fully understood. A prompt partial notification that flags an ongoing investigation is expected; a complete report filed three weeks later is a compliance failure regardless of its quality.
- Having no named incident owner. When escalation goes to "management", the first day is lost deciding who decides. Name one individual and one deputy, put their mobile numbers in the runbook, and give them authority to isolate systems without further approval.
- No record of processing activities. Without a data inventory, scoping a breach takes days instead of hours, and you cannot answer the regulator's first question β whose data, how many people, what categories. Build the inventory before you need it.
- Deleting evidence while containing. Wiping a compromised machine or purging logs to "clean up" destroys the forensic trail and makes it impossible to show what was accessed. Preserve first, then remediate, and copy logs somewhere the attacker cannot reach.
- Processor contracts with no notification clause. Many UAE vendor agreements say nothing about breach notification timing or the information the vendor must supply. Without a stated hour-count and an obligation to provide assessment detail, you learn about incidents late and incompletely.
- Treating DIFC or ADGM entities as covered by the federal filing. Those free zones have separate laws, separate regulators and separate reporting routes. A group with entities in both places needs two runbooks and two notification paths, mapped in advance.
- Confusing deletion duties with retention duties. Purging records to satisfy data minimisation can destroy documents needed for at least seven years of tax substantiation. Set one retention schedule that distinguishes categories and document the reasoning behind each period.
Building Your Data Protection Foundation with Noble Core
Most UAE data breaches are survivable. What turns a manageable incident into a damaging one is the absence of preparation: no inventory, no named owner, no vendor clause, no register, and a first week spent building the machinery that should already have existed.
Noble Core Ventures builds that machinery into the way a company is structured. When we handle business setup in Dubai, we look at what personal data the chosen activity will actually involve and whether the mainland, standard free zone or DIFC/ADGM route puts you under the regime you want. From there we tie data governance into the obligations that sit next to it β the record-keeping and substantiation standards behind UAE corporate tax, the personal data held in your ultimate beneficial owner file, and the employee and premises evidence gathered for economic substance regulations β so one data map serves all four.
Practically, that means a documented processing record, a written incident runbook with named owners and hour-by-hour actions, processor clauses that oblige your vendors to tell you enough to act, a retention schedule that reconciles deletion duties with the seven-year tax rule, and a breach register you can hand to a regulator without embarrassment. If your business holds customer or employee data and nobody can currently say where all of it lives, that is the place to start. Book a free 20-minute consultation and we will map your exposure and tell you what to fix first.
This guidance is general compliance information for UAE businesses and is not legal advice. Data protection requirements vary by sector, emirate and free zone, and executive regulations evolve. Confirm your position with a qualified adviser before acting.
Talk to Our Experts
Noble Core helps UAE companies build data protection into their structure β mapping what personal data the licence and activity involve, drafting processor clauses, setting up an incident runbook and keeping records that survive scrutiny. Free 20-minute consultation.
Frequently Asked Questions
What law governs data breaches in the UAE?
The Federal Decree-Law on the protection of personal data, commonly called the PDPL, together with its executive regulations. DIFC and ADGM operate their own separate data protection laws for entities registered there.
How quickly must a data breach be reported?
The PDPL requires notification without undue delay once a breach affecting personal data is identified. Many organisations adopt an internal 72-hour target to ensure the assessment and filing are completed promptly.
Does every incident have to be reported?
No. Only breaches of personal data that would prejudice the privacy, confidentiality or security of data subjects require notification. A contained incident with no personal data exposure is logged internally instead.
Must affected individuals be told directly?
Yes, where the breach is likely to cause harm to the data subject. The notice must be in clear language explaining what happened, what data was involved and what protective steps to take.
Who is responsible, the controller or the processor?
The controller carries the notification duty. A processor must notify the controller immediately on becoming aware of a breach, which is why processor contracts should state notification timeframes explicitly.
Do free zone companies follow the federal PDPL?
Most do. DIFC and ADGM entities instead follow their own free zone data protection laws, which have separate regulators, separate notification routes and their own registration requirements.
When must a data protection officer be appointed?
Where processing involves high risk, large-scale sensitive data, or systematic evaluation of individuals. Many UAE businesses appoint one voluntarily to hold accountability for the incident runbook.
How long should breach records be kept?
Maintain a breach register indefinitely as evidence of accountability. Underlying business records that also serve tax purposes must be retained for at least 7 years under Federal Tax Authority rules.
Does a ransomware attack count as a personal data breach?
Usually yes. Encryption of personal data by an attacker is a loss of availability, and exfiltration adds a confidentiality breach. Both are assessed and reported on the same basis.
Can personal data be transferred outside the UAE?
Yes, where the destination offers adequate protection or an approved safeguard is in place, such as contractual clauses or explicit consent. Transfers must be documented in your processing records.



