The UAE PDPL starts with a question most companies cannot answer: what data do you hold?
Before policies and consent banners, the UAE Personal Data Protection Law assumes you know what personal data you process, where it lives and who can see it. Most organisations do not. Here is the practical path.

Discussions of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) usually jump straight to consent, privacy notices and penalties. But every obligation in the law rests on an assumption that goes unexamined: that you know what personal data your organisation processes, where it is stored, why you hold it and who has access. In our assessments, almost no mid-sized organisation can answer those four questions with evidence.
Why "we know roughly" is not enough
Records of processing, responses to data-subject requests, breach notification within the required timelines, retention limits, each of these is impossible to do credibly from memory. If a customer asks what you hold about them, "let us search some mailboxes" is not a defensible answer. And when a regulator or a large client asks for your data map, producing one in a week is not realistic if it does not exist.
The practical path: inventory → classify → govern
1. Inventory
Automated discovery across file shares, mailboxes, databases, SharePoint/OneDrive and SaaS systems, combined with interviews. The output is a register: what data exists, where, owned by whom, and containing which categories of personal data. Expect surprises: HR exports in personal folders, customer lists in old project shares, a decade of CVs nobody remembers.
2. Classify
A scheme of three to four levels (public / internal / confidential / restricted) is enough for most organisations. What matters is that it is applied automatically where possible (sensitivity labels, pattern matching, machine-learning classification for unstructured Arabic and English content) because manual labelling of historical data never finishes.
3. Govern
Classification without consequences is decoration. Each level needs rules that tooling enforces: who can access, whether it can leave the organisation (DLP), how long it is retained, where it may be stored. This is also where residency questions get real answers instead of assumptions.
What this unlocks beyond compliance
The same inventory that satisfies the PDPL is the prerequisite for cloud migration done safely, for AI assistants that respect permissions, and for deleting the redundant data that inflates storage and risk. Compliance pays for the work; the operational clarity is the return.
Where to start
A scoped discovery of your highest-risk repositories (email, file shares, the CRM and HR systems) produces the register, a draft scheme and a prioritised plan; how long it takes depends on how many repositories are in scope and how quickly access is granted. This article is general information, not legal advice; interpretation of the law belongs with your counsel, with whom we work directly.
Do you know your own data?
Tick what you could demonstrate today, not what you intend to do. The unticked lines are where a data request or an incident would find you.
Orientation, not legal advice. The UAE Personal Data Protection Law and any sector rules that apply to you should be read with a qualified adviser.
Start with a conversation
An initial consultation with a consultant rather than a salesperson, about your IT, security or systems question.
