{"id":147056,"date":"2026-08-11T09:53:11","date_gmt":"2026-08-11T09:53:11","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=147056"},"modified":"2026-08-11T09:54:14","modified_gmt":"2026-08-11T09:54:14","slug":"uae-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/uae-tmt\/","title":{"rendered":"United Arab Emirates: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-147056","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-uae"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Gowling WLG<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/Ghazzawi-Gowling-WLG-Positive-RGB-Logo_-PNG8820014.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Gowling WLG<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/Ghazzawi-Gowling-WLG-Positive-RGB-Logo_-PNG8820014.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in United Arab Emirates<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Software \u2013 computer programmes, smart applications, databases and similar works \u2013 is protected as copyright (a literary work) under Federal Decree-Law No 38 of 2021 on Copyright and Neighbouring Rights (in force 2 January 2022, administered by the Ministry of Economy) (&#8216;Copyright Law&#8217;) , covering source code, object code, preparatory materials and documentation. Protection is automatic on creation and registration is optional and evidentiary only. Article 2 extends protection to databases and smart applications.<\/p>\n<p>An author\u2019s economic rights last for life plus 50 years from the following calendar year; for legal persons, and for collective, posthumous, anonymous or pseudonymous works, protection runs 50 years from first publication. Moral rights are perpetual and cannot be assigned.<\/p>\n<p>Trade secrets supplement copyright for undisclosed algorithms and source code. Industrial property rights, patents (Federal Law No 11 of 2021) and trademarks (Federal Decree-Law No 36 of 2021) may also apply; and the UAE is party to the Berne Convention and World Intellectual Property Organisation (&#8216;WIPO&#8217;) treaties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Copyright Law introduces a &#8216;work made for hire&#8217; rule: under Article 28, copyright in works an employee creates within the scope of employment, using employer resources, vests in the employer. Where work falls outside that scope or is created by an independent contractor or consultant, ownership remains with the developer absent an express written assignment. Without one, the customer holds at best an implied licence to use the software for its commissioned purpose, not ownership of the underlying intellectual property (IP) \u2013 limiting its ability to modify, sub-license or commercially exploit the software.\u00a0Moral rights remain perpetual and inalienable, and blanket waivers are untested before UAE courts, so should be drafted narrowly. Development contracts should include clear assignment, moral-rights waiver, originality and non-infringement provisions, and rights to register works in the customer\u2019s name.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no bespoke software-liability statute. Harm caused by software is addressed through general frameworks, principally the Civil Transactions Law (Federal Decree-Law No 25 of 2025, in force 1 June 2026, replacing Federal Law No 5 of 1985) (&#8216;Civil Law&#8217;) alongside the Consumer Protection Law (Federal Law No 15 of 2020) and its Implementing Regulations (Cabinet Decision No. 66 of 2023) , and product-safety rules. As the new Civil Law has been in force only since 1 June 2026, no UAE case law yet interprets its liability provisions, so analysis remains provisional. Courts examine the contractual framework first \u2013 warranties, service levels, limitation clauses \u2013 turning to tortious liability only where contractual allocation is silent, or an independent duty of care exists. Claimants bear the burden of proving fault or breach, causation and quantifiable damage.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Misuse of software and computer systems is criminalised under Federal Decree-Law No 34 of 2021 on Countering Rumours and Cybercrimes (as amended in 2024) , covering unauthorised access to systems and data, data interference and broader system misuse. Unauthorised access carries imprisonment and\/or fines from AED 100,000 (approximately USD 27,226), with higher penalties for personal or sensitive data, and aggravated penalties where critical infrastructure is affected or fraud, identity theft or prohibited content is facilitated. Offences involving government systems or sensitive data can attract up to five years imprisonment and multi-million-dirham fines. The law applies extraterritorially to conduct abroad that targets the UAE and may give rise to concurrent civil claims.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no single technology-specific software statute. Provision of software, cloud and software as a service (SaaS) is shaped by Telecommunications and Digital Government Regulatory Authority (TDRA) policy, the Personal Data Protection Law (&#8216;PDPL&#8217;) (Federal Decree-Law No 45 of 2021), and sector and free-zone rules. TDRA cloud policies address data hosting, security controls and provider obligations. In financial services, the Central Bank of the UAE (CBUAE) regulates cloud outsourcing and technology risk; healthcare regulators, including the Dubai Health Authority (DHA) and the Department of Health \u2013 Abu Dhabi (DoH), govern patient-data hosting; and government entities face classification and security requirements under the UAE Information Assurance Regulations. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) maintain separate frameworks for zone-licensed entities. Data-localisation expectations apply in government, financial services and healthcare, and often require UAE-based infrastructure or local hosting partners, affecting pricing and contractual architecture.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Capping a vendor\u2019s maximum liability is standard, freely negotiated market practice, as there is no statutory cap. A common benchmark is fees paid in the preceding 12 months, though multiples of 2x\u20135x annual fees or aggregate caps apply in larger or higher-risk engagements. The level reflects bargaining power, contract value, data sensitivity, potential consequential loss, and vendor insurance appetite. Caps may be per-claim, aggregate, or both. Vendors with stronger positions resist caps above 1x annual fees; customers in critical deployments (core banking, healthcare platforms) may secure 2x\u20133x or higher. No claim carries a statutory unlimited-liability requirement, though certain heads are conventionally excluded from the cap (see below). That said, Article 340 of the Civil Law provides that courts retain discretion to increase compensation to equal actual loss, which is a relevant nuance the answer appropriately does not contradict.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Certain liability heads are typically carved out from the general cap, either uncapped or subject to an enhanced \u2018super cap\u2019 (i) confidentiality breaches, almost universally excluded, (ii) data protection and security breaches (including data loss), given regulatory and claims exposure, (iii) IP infringement indemnities, typically unlimited or capped at 2x\u20135x; breaches of applicable law with regulatory consequences and (iv) wilful or deliberate breaches. Regulatory fines are more contested, with vendors resisting uncapped exposure and no settled market approach. Super caps commonly sit at 2x\u20133x for data protection and confidentiality, and higher or unlimited for IP rights. Liability for artificial intelligence is an emerging, increasingly negotiated carve-out given output unpredictability and third-party claim risk.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Source-code escrow exists but is not standard practice; where used, international agents (NCC Group, Iron Mountain, Escode) are typically appointed given the absence of a dominant domestic provider. For cloud and SaaS, traditional escrow is less common; parties instead rely on business-continuity, disaster-recovery and data-export commitments, including documented recovery plans, recovery time and point objectives, and periodic testing. Data portability terms increasingly require the right to export data in a machine-readable format during and after migration. Step-in rights, allowing the customer or a nominee to assume operational control on vendor insolvency or material breach, appear in larger engagements, though enforceability depends on subcontractor cooperation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no specific technology laws in the UAE that exclusively govern IT outsourcing transactions; instead, outsourcing is governed by general laws (Civil Law, Commercial Transactions Law , Electronic Transactions Law , PDPL) and sector-specific regulations that apply when the outsourcing party operates in a regulated industry.<\/p>\n<p>The key sector-specific regimes include:<\/p>\n<p>1) the CBUAE&#8217;s Outsourcing Regulation for Banks (Circular 14\/2021) , which imposes minimum risk management standards, board-approved policies, data ownership retention, restrictions on offshore storage of sensitive customer data, and audit rights;<\/p>\n<p>2) the DFSA&#8217;s outsourcing and operational risk frameworks in the DIFC , requiring due diligence, audit rights, business continuity planning, and exit strategies;<\/p>\n<p>3) the FSRA&#8217;s similar risk-based outsourcing requirements for regulated firms in the ADGM ; and<\/p>\n<p>4) VARA&#8217;s Technology and Information Rulebook , which requires virtual asset service providers to assess risk for each outsourcing arrangement, notify VARA of material outsourcing, ensure data confidentiality, manage sub-outsourcing risks, and obtain prior written consent before sharing data with third parties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no automatic transfer of employee equivalent to the UK\u2019s Transfer of Undertakings (Protection of Employment), or TUPE, regime. Employment is governed by the UAE Labour Law (Federal Decree-Law No 33 of 2021) and as amended under Federal Decree-Law No. 20 of 2023 ; staff do not transfer automatically, and the parties manage terminations, entitlements and new hiring. The outgoing employer must settle end-of-service gratuity \u2014 calculated on the employee\u2019s last basic wage, excluding allowances, at 21 days\u2019 pay per year for the first five years and 30 days\u2019 pay per year thereafter, capped at two years\u2019 total wage \u2014 plus unused leave and other entitlements. The incoming provider offers fresh contracts to retained staff, who require new sponsored work permits. Emiratisation quotas apply: mainland companies with 50 or more employees must reach 10% Emiratisation in skilled roles by the end of 2026, arising in annual increments of 2 percentage points, while companies with 20\u201349 employees in specified sectors must recruit and retain at least one Emirati national. Both parties must avoid falling below quota, as non-compliance attracts penalties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law is Federal Law by Decree No 3 of 2003 Regarding the Organisation of the Telecommunications Sector (as amended) (the &#8216;Telecom Law&#8217;), which organises the sector, regulates market entry and competition, manages spectrum and protects consumers. The TDRA is the sector regulator, with powers to license, resolve disputes, allocate spectrum, enforce quality-of-service standards and impose penalties. The market is principally served by e&amp; and du, though the TDRA may license additional entrants. Recent developments include nationwide 5G rollout, the UAE Digital Government Strategy 2025, smart-city programmes, and growing regulatory attention to the internet of things (IoT) and autonomous systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Providing public telecommunications services or networks requires a TDRA licence:<\/p>\n<p>a. Individual licences where scarce resources such as spectrum are used, and<\/p>\n<p>b. Class licences for other regulated activities, each granted for up to ten years.<\/p>\n<p>Applicants must demonstrate technical, financial and operational capability, submit a business plan, and satisfy UAE ownership and governance requirements. Licences typically address quality of service, tariffs, coverage, consumer protection, confidentiality and emergency-service obligations. Equipment also requires TDRA type approval via conformity testing. Ongoing obligations include interconnection on reasonable terms, universal service contributions, and lawful-interception compliance. Breach may result in fines, suspension or revocation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Lawful access to communications data derives principally from the Telecom Law, the Federal Decree-Law No. (34) of 2021 On Countering Rumors and Cybercrimes (&#8216;Cybercrime Law&#8217;) and security agencies\u2019 statutory powers. Licensed providers may be required to assist law enforcement, generally on a confidential basis that is not publicly challengeable. Requested data typically falls into subscriber data, traffic\/metadata (call records, IP addresses, location) and, in serious investigations, content data. Requests are made by authorised government and security bodies; in practice, prior judicial authorisation is not generally required, reflecting the national-security framework, based on practitioner commentary, as the underlying procedural instruments are not fully published. Providers must maintain the technical capability to comply promptly.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity and resilience obligations for telecommunications infrastructure derive from TDRA instruments, the UAE Information Assurance Regulations and computer emergency response team (CERT) requirements, covering risk management, access controls, network segmentation, encryption, vulnerability management and business-continuity planning. Critical-infrastructure operators, including telecoms providers, must report significant incidents to the UAE Computer Emergency Response Team (aeCERT), typically within hours for critical incidents, with detailed follow-up reports, and face heightened controls, auditing and reporting obligations. These duties operate alongside the Cybercrime Law and, where personal data is affected, the PDPL.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The UAE does not have a national SSO specific to mobile communications. At the international level, the principal SSOs relevant to mobile communications include 3GPP, the ITU, IEEE, and ETSI, though the available UAE primary legislation does not expressly name these bodies as adopted or governing standards frameworks.<\/p>\n<p>Domestically, the TDRA is responsible for allocating the necessary frequencies for radio and television broadcasting activities and determining device specifications and uses. The Telecom Law prohibits making, distributing, offering, or providing telecommunications equipment for use in the UAE that is inconsistent with the regulations, directives, instructions, and decisions issued by the Authority.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Interoperability standards support connected-technology development in the UAE by providing a common framework for data exchange and device compatibility. UAE digital health legislation expressly requires compatibility with internationally approved standards, and the executive regulation under that law requires compliance with rules on digital health standards, including approved mechanisms for the exchange of personal health data with relevant authorities and entities.<\/p>\n<p>For connected vehicles, the UAE has adopted at least one mandatory technical standard \u2014 the eCall in Vehicles technical regulation (UAE.S 5019:2024) \u2014 through Cabinet Resolution No. 84 of 2024 . At the IoT level, the National Policy for Internet of Things Security, launched in 2023, outlines directives and responsibilities for the cybersecurity system to strengthen IoT security across the UAE&#8217;s cyberspace.<\/p>\n<p>The TDRA&#8217;s frequency-allocation and device-specification authority, combined with the federal prohibition on non-compliant telecommunications equipment, provides a regulatory mechanism through which equipment standards \u2014 including those supporting interoperability \u2014 are enforced.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal federal law is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), protecting individual privacy and regulating personal data processing. Article 5 of the PDPL sets out the core processing principles, requiring that processing be fair, transparent and lawful; that data be collected for a specific and clear purpose; that data be sufficient and limited to what is necessary; that data be accurate and updated; and that data be kept securely through appropriate technical and organisational measures. Separate provisions of the PDPL establish the lawful bases for processing, which include contractual necessity (where processing is necessary to perform a contract with the data subject, or to take steps at the data subject&#8217;s request before concluding, amending or terminating a contract) and public health necessity, among others. The PDPL also provides for data-subject rights, cross-border transfer requirements including a mechanism permitting transfers to countries without adequate data protection laws where the recipient is bound by contract to adopt PDPL-aligned measures. The Emirates Data Office (referred to in the PDPL as the &#8220;UAE Data Bureau&#8221;), established under Federal Decree-Law No. 44 of 2021, supervises compliance. The federal Executive Regulations had not been published as of mid-2026; pending their issuance, details such as cross-border mechanisms, data protection officer (DPO) thresholds and penalties remain to be confirmed. The DIFC operates its own regime under Data Protection Law No. 5 of 2020, as amended by DIFC Laws Amendment Law No. 1 of 2025, and the ADGM maintains a separate regime under the Data Protection Regulations 2021, enforced by the ADGM Commissioner of Data Protection.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The PDPL provides for administrative penalties under Article 26, to be set by Cabinet decision. The federal Executive Regulations and accompanying penalty schedule had not been published as of mid-2026, so no specific federal penalty figure can yet be stated. Sectoral and free-zone penalties already apply: the DIFC Commissioner of Data Protection may impose fines under DIFC Law No. 5 of 2020, as amended, while the ADGM regime empowers fines under the Data Protection Regulations (Fines) Rules 2021, adopted on 18 July 2021 and enforced by the ADGM Commissioner of Data Protection. Publicly reported federal-level enforcement has to date been limited.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts commonly reference the PDPL, addressing lawful basis, data-subject rights, cross-border transfer and breach notification, with controller\/processor obligations. Federal Decree-Law No. 14 of 2023 on Trading through Modern Technology (&#8216;E-Commerce Law&#8217;) which came into effect in September 2023, further requires that applicable data protection legislation governs consumer information and data, including its description and ownership, and imposes requirements relating to data quality, classification, flow, preservation and restrictions on sharing. As a matter of common contractual practice, typical provisions include (i) data processing addenda defining scope and purpose, (ii) sub-processor consent or approved-list mechanisms, (iii) breach notification obligations, (iv) audit rights and (v) data return\/deletion on termination. International transfers commonly use standard contractual clauses or equivalent safeguards, supported by transfer impact assessments, consistent with the PDPL&#8217;s cross-border transfer framework under Articles 22 and 23. Contracts with an international dimension frequently also reference the GDPR and occasionally the CCPA as a matter of market practice, though there is no statutory requirement to do so.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>National cybersecurity strategy is set by the UAE Cybersecurity Council. Federal cybersecurity is the responsibility of the Signals Intelligence Agency (SIA), supported by the UAE Information Assurance Regulations for government and critical-infrastructure entities. The TDRA operates the aeCERT for incident coordination and threat intelligence, while the Dubai Electronic Security Centre (DESC) operates at emirate level, imposing the Dubai Cyber Security Standard on government and semi-government entities in Dubai. Criminal conduct is addressed under the Cybercrime Law. Organisations may face overlapping requirements from the Cybersecurity Council, SIA, TDRA, DESC and their sector regulator, requiring careful compliance mapping.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions arise principally under the Cybercrime Law and may include imprisonment and significant fines. Specific penalty ranges include: imprisonment and\/or fines of AED 100,000\u2013300,000 (approximately USD 27,226 to 81,678) for basic unauthorised system access (Article 2(1)), increasing to at least six months&#8217; imprisonment and\/or AED 150,000\u2013500,000 (approximately USD 40,839 to 136,130) where damage results (Article 2(2)), and at least one year and\/or AED 200,000\u2013500,000 (approximately USD 54,452 to 136,130) where data is acquired for illegal purposes (Article 2(3)); imprisonment and\/or fines of AED 150,000\u2013500,000 for interception, rising to at least one year and up to AED 1,000,000 (approximately USD 272,260) where intercepted information is disclosed (Article 12); at least one year&#8217;s imprisonment and\/or fines of not less than AED 500,000 (approximately USD 136,130) for causing harm or disruption to information systems, with temporary imprisonment where banking, media or health entities are targeted (Article 4); temporary imprisonment and fines of AED 200,000\u20131,500,000 (approximately USD 54,452 to 408,391) for hacking government systems (Article 3); and temporary imprisonment for at least ten years with fines of AED 500,000\u20135,000,000 (approximately USD 136,130 to 1,361,303) for infringement of government data and information (Article 7). Aggravating factors under Article 60 include commission during or due to performance of one&#8217;s job, use of a minor, and repeat offending.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Registration and compliance obligations apply to critical national infrastructure and certain regulated sectors under the UAE Information Assurance Regulations and related TDRA and SIA frameworks, with the DESC imposing emirate-level requirements. Affected sectors include finance (CBUAE technology risk requirements), energy, healthcare, transport, telecommunications and government services.<\/p>\n<p>Registration typically involves identifying critical systems, completing a self-assessment, submitting it to the relevant authority, and undergoing periodic audits and ongoing monitoring, with an obligation to notify material changes. Non-compliance may result in regulatory action, remediation orders or penalties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Incidents are generally reported to aeCERT and the SIA, with critical-infrastructure and sector entities subject to their own timelines under the UAE Information Assurance Regulations. Critical incidents are typically reported within hours of detection, with detailed follow-up reports covering impact, containment and remediation. Where personal data is involved, the PDPL requires a controller, upon becoming aware of a breach or violation of personal data that would prejudice the privacy, confidentiality, and security of data, to notify the Bureau (the Emirates Data Office). The specific notification period and requirements are to be set by the Executive Regulations of the PDPL, which have not yet been issued. Organisations may need to report simultaneously to aeCERT, sector regulators, the UAE Data Office and, for DIFC or ADGM entities, the relevant free-zone authority, requiring coordinated incident-response planning.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no single AI regulator. The Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications sets government AI policy and coordinates digital-economy initiatives; the Artificial Intelligence and Advanced Technology Council (AIATC) in Abu Dhabi, established under Law No 3 of 2024 , focuses on AI strategy and commercialisation; and the UAE Council for Artificial Intelligence and Blockchain advises at federal level. These bodies set strategy rather than administer licensing, while sector regulators apply existing law \u2013 for example, the CBUAE\u2019s technology risk framework to financial-services AI, and healthcare regulators to AI-enabled medical devices. Organisations deploying AI must identify and comply with each relevant sectoral authority\u2019s requirements. On 14 June 2026, the UAE established the Federal Authority for Artificial Intelligence and Data, a unified national body consolidating the AI Office, the Information and Digital Government Sector within TDRA, and the Emirates Data Office under a single structure reporting directly to the Cabinet and led by the Minister of State for AI. This signals a move toward more centralised AI oversight and may alter the division of responsibilities among the bodies described above as the Authority operationalises its mandate.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no standalone comprehensive AI statute. Governance rests on the UAE National Strategy for Artificial Intelligence 20311 and the non-binding UAE Charter for the Development and Use of Artificial Intelligence (June 2024)2, which sets out ethical principles including safety, fairness, transparency, accountability, privacy and human oversight. Though non-binding, the Charter is expected to inform future sectoral rules. On 14 June 2026, the UAE established the Federal Authority for Artificial Intelligence and Data, as a single federal body reporting directly to the Cabinet, signalling a move toward more centralised AI and data governance. The most significant binding AI-specific regulation is DIFC Regulation 10 (in force from September 2023, full enforcement from January 2026), which regulates the processing of personal data through autonomous and semi-autonomous systems, imposing duties on deployers and operators including transparency, fairness, accountability, human oversight, and mandatory certification for high-risk AI systems. Sector-specific AI applications are emerging in financial services, healthcare and smart cities, each subject to the relevant sectoral authority. Binding obligations on the mainland currently derive from the PDPL and Cybercrime Law as applied to AI use cases.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific binding statute governing LLMs or generative AI, including agentic AI; use is addressed through the PDPL, the Cybercrime Law and IP law, together with the non-binding AI Charter. The PDPL applies where personal data trains, fine-tunes or prompts an LLM, requiring a lawful basis and compliance with data-subject rights, including objection to automated decision-making. IP law raises questions over training-data use and output ownership, and the Cybercrime Law applies to unlawful generated content. Practical measures include data-protection impact assessments, content moderation, human oversight for high-risk deployments, and contractual acceptable-use policies, input restrictions and output-accuracy disclaimers.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no statutorily mandated AI provisions, but contracts increasingly include recommended terms: output-accuracy clauses, transparency, explainability and disclosure obligations, training-data provenance warranties, restrictions on using customer data to train models without consent, human-oversight requirements for high-risk decisions, bias-monitoring obligations, and AI-specific audit rights. These are typically structured as warranties, undertakings, indemnities and service-level obligations. Some organisations adapt frameworks such as the EU AI Act risk taxonomy, the National Institute of Standards and Technology (NIST) AI Risk Management Framework, or OECD AI Principles. Common issues include output reliability, transparency, data use, IP ownership, liability allocation, and compliance with data-protection and confidentiality obligations. Scope and depth are typically negotiated case by case, reflecting the parties&#8217; risk appetite and the criticality of the AI system.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Because no statutory rule allocates ownership of AI-generated outputs, contracts commonly address this expressly. Key issues include authorship (UAE copyright law requires a human author, so purely machine-generated works may not qualify for protection), originality, and infringement risk from outputs reproducing training-data content. Provisions typically specify ownership or licence of inputs, models and outputs, address third-party and open-source materials, and allocate infringement responsibility. Contracts increasingly govern whether a vendor may use customer data to train models, and on what terms, including anonymisation and opt-out rights. Given the ownership uncertainty, parties rely on contractual allocation, indemnities and lawful-training-data representations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no single blockchain statute; digital assets are regulated through securities and financial-services regimes. At federal level, the Capital Market Authority (CMA, which replaced the Securities and Commodities Authority on 1 January 2026 under Federal Decree-Law No. 32 of 2025) regulates virtual assets and has issued an activity-based licensing framework for virtual asset service providers (CMA Decision No. 4\/R.M\/2026) .<\/p>\n<p>The CBUAE separately regulates payment-related activities involving virtual assets, including stablecoins and payment tokens, under the Payment Token Services Regulation and Federal Decree-Law No. 6 of 2025 .<\/p>\n<p>In Dubai, the Virtual Assets Regulatory Authority (VARA) regulates virtual assets under Dubai Law No. 4 of 2022 licensing activities including advisory, broker-dealer, custody, exchange, lending and borrowing, transfer and settlement, and virtual-asset management and investment services.<\/p>\n<p>The ADGM&#8217;s Financial Services Regulatory Authority and the DIFC&#8217;s DFSA operate separate virtual-asset and digital-securities frameworks within their zones, outside VARA&#8217;s mainland Dubai jurisdiction; entities operating across regimes may need multiple licences.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no bespoke law governing search engines; however, online marketplaces and digital commerce are specifically regulated by the E-Commerce Law. The E-Commerce Law applies to any trading conducted via modern technological means inside the UAE and imposes obligations on digital merchants and platform operators, including mandatory disclosure of business identity, product descriptions, all-inclusive pricing, payment and delivery terms, and complaint-handling procedures. Platform operators permitting third-party sellers to trade on their platforms bear responsibility for compliance. The E-Commerce Law operates alongside general frameworks, principally the Consumer Protection Law (Federal Law No. 15 of 2020) and its Implementing Regulations, the PDPL and the Cybercrime Law. Obligations include transparency on seller identity and sale terms, accurate pricing disclosure, clear cancellation and return policies, and prohibitions on misleading practices. Advertising must be clearly identified, with substantiated and non-denigrating comparative claims. Marketplace operators are not generally treated as publishers of third-party content but may face liability where aware of unlawful content and failing to act. Information, advertisements and contracts must be in Arabic or in another language in addition to Arabic.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Social media and online platforms are governed principally by the UAE Media Regulation Law (Federal Decree-Law No 55 of 2023) and licensing by the National Media Authority (established under Federal Decree-Law No 11 of 2025, effective 1 January 2026, assuming the former UAE Media Council\u2019s competences) , together with the Cybercrime Law. The Child Digital Safety Law (Federal Decree-Law No 26 of 2025) took effect 1 January 2026, with extraterritorial reach over platforms and ISPs targeting UAE users; covered entities have up to one year to comply, though the platform classification system and penalty framework await pending Cabinet decisions. Influencers and content creators require a National Media Authority licence before paid promotional activity. Platforms must take reasonable steps against unlawful content (including content that violates public morals, spreads false information, or infringes third-party rights) and cooperate with removal notifications. Non-compliance penalties include fines, suspension and, in serious cases, blocking.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions arise principally under the Cybercrime Law and may include imprisonment and significant fines. Specific penalty ranges include:<\/p>\n<p>a. fines of AED 250,000\u2013500,000 (approximately USD 68,065 to 136,130) and\/or imprisonment for electronic defamation (Article 43);<\/p>\n<p>b. fines of AED 150,000\u2013500,000 with imprisonment of at least six months for privacy invasion, increasing to at least one year where images or recordings are manipulated to defame (Article 44);<\/p>\n<p>c. fines of at least AED 100,000 (approximately USD 27,226) and detention of at least one year for spreading false information harmful to the economy, public health or the public good, increasing to at least AED 200,000 (approximately USD 54,452) and two years where the offence involves a state authority or occurs during a crisis (Article 52);<\/p>\n<p>d. fines of AED 300,000 to AED 1,000,000 (approximately USD 81,678 to 272,260) for publishing false information damaging state interests (Article 53);<\/p>\n<p>e. fines up to AED 1,000,000 (approximately USD 272,260) and temporary imprisonment for content inciting harm to UAE security, public order or national unity (Articles 23\u201324); and, for the most serious offences, temporary imprisonment (up to 15 years under UAE law) with multi-million-dirham fines.<\/p>\n<p>The Media Regulation Law and National Media Authority framework also impose administrative sanctions under Cabinet Resolution No. 42 of 2025, including fines from AED 5,000 to AED 1,000,000 (approximately USD 1,361 to 272,260) (doubled for repeat offences), licence revocation and content-removal orders. The applicable maximum depends on whether the breach is a cybercrime, a media-law breach, or both.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific law governing spatial computing, including augmented, extended and virtual reality and the metaverse. General frameworks apply: intellectual-property law, the PDPL, consumer-protection rules and TDRA telecommunications and standards requirements. The Child Digital Safety Law, also applies broadly to digital platforms and services accessible by children, which would include immersive and metaverse environments. Emerging issues include treatment of biometric and behavioural data (eye-tracking, facial expressions, movement patterns) collected by immersive devices as sensitive personal data under the PDPL, Intellectual property ownership of virtual environments and user-generated content, and consumer protection for virtual goods. The Dubai Metaverse Strategy (2022) encourages development but is not binding law. Targeted regulation may emerge as commercial deployment expands.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific law governing quantum computing or quantum cryptography; the field is addressed through general intellectual property, data-protection and cybersecurity frameworks, with cryptography and export-control considerations potentially relevant. However, in November 2025, the UAE Cybersecurity Council approved a National Encryption Policy and accompanying executive regulation \u2014 one of the first binding national-level PQC migration mandates globally \u2014 requiring government entities to develop formally approved transition plans from traditional encryption to post-quantum cryptography, deploy automated cryptographic inventory tools, and build crypto-agility into new systems by design. A National Post-Quantum Migration Program has been established to identify vulnerable systems and guide the transition.<\/p>\n<p>The UAE has also invested significantly in quantum research, including through the Technology Innovation Institute in Abu Dhabi, which develops quantum-computing hardware and quantum-resistant cryptographic solutions and has contributed to six digital signature schemes in NIST&#8217;s PQC standardization process. As quantum computers threaten to break current encryption, organisations handling sensitive or long-lived data will need to migrate to quantum-resistant algorithms aligned with these emerging national and international standards.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no standalone federal data-centre statute. Data centres are governed by TDRA and cloud-related policies, sector data-localisation rules, free-zone regimes, and general licensing and real-estate requirements. Government data is generally required to be hosted within the UAE; financial-services regulators require certain customer data and critical systems to remain onshore or in approved jurisdictions; and healthcare data is subject to federal localisation requirements under Federal Law No. 2 of 2019 on ICT in Health Fields, with additional emirate-level standards (such as ADHICS in Abu Dhabi and NABIDH in Dubai) layered on top.<\/p>\n<p>Free zones including the DIFC, ADGM and Dubai Silicon Oasis offer streamlined licensing and tax benefits, attracting hyperscale operators including AWS, Microsoft Azure, Google Cloud and Oracle; 100% foreign ownership, historically a free-zone feature, is now also available for most mainland activities. Operators must satisfy sector-specific licensing, security and residency expectations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Over the next three years, we expect three major developments to shape technology law in the UAE.<\/p>\n<p>\u2022 First, the UAE&#8217;s autonomous vehicle regulatory framework is expected to mature rapidly at both the emirate and federal levels, following Dubai&#8217;s adoption of detailed executive regulations under Law No. 9 of 2023 (Administrative Decision No. 939 of 2025) and Ras Al Khaimah&#8217;s issuance of Law No. 1 of 2026 \u2014 the UAE&#8217;s first standalone emirate-level AV statute \u2014 which assigns comprehensive licensing, cybersecurity, data governance, and safety-by-design obligations to RAKTA. With the federal government approving Level-4 AV testing and Dubai targeting 25% autonomous journeys by 2030, we expect federal harmonization legislation and detailed technical standards covering AI liability, real-time data sharing, and cross-emirate interoperability to emerge within the next three years.<\/p>\n<p>\u2022 Second, the UAE is likely to move beyond voluntary charters and ethical guidelines toward binding AI-specific legislation, whether through a standalone federal AI statute or sector-specific regulations in finance, healthcare, and government services, building on the DIFC&#8217;s Regulation 10 model and the institutional consolidation under the new federal AI authority.<\/p>\n<p>\u2022 Third, the overlapping federal and emirate-level virtual asset regulatory frameworks \u2014 spanning the CMA, VARA, CBUAE, ADGM, and DIFC \u2014 will undergo significant consolidation and harmonization, with clearer licensing boundaries, more detailed rules on stablecoins and tokenized real-world assets, and tighter integration with AML\/CFT standards and the PDPL data protection regime.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sustainability and net-zero clauses are emerging but not yet standard in UAE technology contracts. The UAE ratified the Paris Agreement in 2016, announced the Net Zero by 2050 Strategic Initiative in 2021, and hosted COP28 in 2023, reinforcing growing ESG expectations. Also, the UAE has advanced its climate roadmap by enforcing Federal Decree-Law No. 11 of 2024 on the Reduction of Climate Change Effects, requiring all public and private entities to measure and report greenhouse gas emissions. However, no general UAE-wide law mandates the inclusion of sustainability or environmental clauses in technology contracts.<\/p>\n<p>Mandatory sustainability-reporting obligations are currently concentrated in the financial sector through the CBUAE&#8217;s Climate-related Financial Risk Management Regulation and Sustainability-related Disclosure Principles , as well as ADGM&#8217;s mandatory ESG Disclosures Framework for in-scope entities. The 2024 General Framework for Adopting Sustainable Digital Transformation is also relevant \u2014 it establishes sustainability standards for government procurement, including green data centers, sustainable digital procurement, and contracts with digital suppliers, though it applies to federal government entities rather than the private sector broadly. General environmental legislation also imposes EIA and pollution-control obligations that can affect technology infrastructure projects.<\/p>\n<p>Where sustainability provisions are voluntarily included in technology contracts, they typically cover vendor reporting on energy consumption and carbon footprint, renewable-energy commitments, supply-chain ESG requirements, and e-waste obligations. Such clauses reflect market-driven expectations rather than statutory mandates, but are expected to grow as financial-sector disclosure frameworks mature and government sustainable-procurement standards filter into the broader market.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">6531<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/147056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}