If your organisation operates across Europe, the Middle East, and India , or moves data between any of those regions , you’re not dealing with one privacy problem. You’re dealing with three, and they don’t always agree with each other.
That’s not a reason to panic. But it is a reason to stop treating data privacy as a checkbox exercise and start treating it as an operational reality.
GDPR has been in force long enough that most enterprises have formed some kind of compliance muscle around it. The UAE’s Personal Data Protection Law brought a federal framework to a region that previously relied on a patchwork of emirate-level and sectoral rules. And India’s Digital Personal Data Protection Act, notified in late 2025, is the newest entrant, one that will define how 1.4 billion people’s data is handled as the country’s digital economy continues to accelerate.
These three laws share common DNA: consent, rights, breach notification, accountability. But the details diverge in ways that matter enormously when you’re designing systems, drafting policies, or managing an incident across multiple jurisdictions at once.
This blog is a practical guide to those differences , and to building a privacy program that respects them without requiring you to maintain three completely separate compliance teams.
At a Glance: How the Three Laws Compare
Before going deeper, here’s the high-level picture:
| Topic | GDPR (EU) | UAE PDPL | DPDPA (India) |
| Territorial reach | Broad extraterritorial , applies anywhere you process EU residents’ data | Inside and outside UAE when targeting UAE residents | In India, plus outside India when offering services to Indian residents |
| Legal basis for processing | Six lawful bases including consent and legitimate interests | Consent-centric; separate consent required per purpose | Consent plus enumerated exceptions for public purposes |
| Children’s data threshold | Under 16 (member states can lower to 13) with verifiable parental consent | Strict minor protections across the board | Under 18 with verifiable parental consent; stricter rules for profiling |
| Cross-border transfers | Adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules | Adequate protection standard or approved safeguards | Permitted with possible government-notified restrictions and no-go countries |
| Breach notification | 72 hours to regulator; individuals notified if high risk | Regulator and individuals when harm is likely; 72 hours in practice | 72 hours to the Data Protection Board; 6 hours to CERT-In for cyber incidents |
| Accountable role | DPO often mandatory | DPO required in high-risk cases | Additional obligations for Significant Data Fiduciaries |
| Maximum penalties | Up to 4% of global annual turnover or €20M, whichever is higher | Up to AED 5M per violation | Up to INR 250 crore |
The table gives you the skeleton. The sections below give you the practical reasoning behind it.
Understanding the Regional Context
These aren’t just legal frameworks. Each one reflects a specific relationship between government, citizens, and the digital economy , and that context shapes how enforcement actually plays out.
GDPR is rooted in fundamental rights. Data protection in the EU is treated as a constitutional matter, not a regulatory formality. That’s why the enforcement machinery is active and public: Data Protection Authorities across member states issue fines, publish decisions, and set precedent. When the Irish DPA fines a US tech company €1.2 billion, that’s not an accident of geography. It’s a deliberate signal about where the EU places data rights in its hierarchy of values.
UAE PDPL exists in a different context. The UAE has a federal privacy law, but it also has emirate-level frameworks in the DIFC and ADGM that operate independently, plus sectoral regulations that add further layers depending on your industry. The framing here is dual: data protection is part of a growth agenda (the Digital UAE strategy) and a sovereignty agenda. Enforcement is becoming more assertive, with high-profile cases used as deterrents, but the culture still leans toward guidance and remediation before penalties. Saudi Arabia’s PDPL sits nearby with arguably the strictest cross-border transfer controls in the region, and if you’re operating in the GCC more broadly, you can’t treat UAE compliance as a proxy for the whole region.
DPDPA is the newest entrant but arrives with significant ambition. India has been one of the most complex privacy environments to navigate, a large digital economy, long-standing sectoral rules (RBI, IRDAI, SEBI), and years of debate about what a comprehensive privacy law should look like. The DPDPA attempts to balance individual rights against the reality of a government that retains significant exemptions and a digital economy that needs room to grow. The rules are still rolling out as of late 2025, but the framework is clear enough that organisations need to be building toward compliance now.
Consent and Lawful Basis: Where the Divergence Starts
This is the first place where a “one size fits all” approach breaks down.
Under GDPR, organisations have six lawful bases for processing personal data. Consent is one of them, but it’s not the only one, and it’s not always the most practical one. Legitimate interests, contractual necessity, legal obligation, vital interests, and public tasks all have their place. This flexibility is a feature. It means you don’t have to ask for consent for every single processing activity, which would be both burdensome for users and legally fragile for organisations.
Under UAE PDPL, the architecture is more consent-centric. Critically, one consent banner or one broad consent moment cannot satisfy multiple purposes. Each purpose requires its own consent. If you’re using someone’s data for analytics, for marketing, and for personalisation, those are three separate conversations. A single “I agree to the terms” tick-box does not cover all three.
DPDPA follows a similar discipline. Consent must be explicit and specific. The exceptions are narrower than under GDPR, mostly limited to enumerated public-purpose scenarios. And for children, the bar is higher still.
The practical implication: design your consent infrastructure around the strictest combination, not the most permissive one. That means granular, per-purpose consent flows with jurisdiction-tagged records of when and how consent was obtained. If your current consent setup is a single banner with a general opt-in, it is almost certainly non-compliant with at least two of these three regimes.
Data Subject Rights: What People Can Ask For
All three laws give individuals rights over their data. The shape of those rights, and how broad they are, varies.
GDPR provides the most comprehensive set: the right to access, to correct, to erase (the “right to be forgotten”), to restrict processing, to portability, to object, and to not be subject to solely automated decision-making with significant effects. The portability right, the ability to receive your data in a machine-readable format and take it elsewhere, is a meaningful lever that gives individuals real mobility.
UAE PDPL covers access, correction, deletion, restriction, and cessation of processing. Data portability and automated decision-making protections exist but are narrower in scope than GDPR. The rights are real and enforceable, but the architecture is less developed on the technical interoperability side.
DPDPA provides access, correction, and grievance mechanisms. Portability and automated decision protections are present but relatively narrow at this stage of the law’s implementation. Expect these to evolve as the rules are notified and the Data Protection Board begins operating in earnest.
For organisations managing Data Subject Access Requests across all three jurisdictions, the practical answer is to set your SLA based on the strictest timeline, which is typically 30 days under GDPR, and build jurisdiction-specific variations for response content and format into the workflow beneath that. One process, three outputs.
Cross-Border Transfers: The Most Operationally Complex Piece
If there’s one area where getting things wrong creates genuine legal exposure, it’s cross-border data transfers. And for organisations moving data between the EU, UAE, KSA, and India, the combinations multiply quickly.
GDPR has a mature framework: adequacy decisions (which confirm that a third country’s protections are equivalent to the EU’s), Standard Contractual Clauses (contractual protections that travel with the data), and Binding Corporate Rules (for intra-group transfers at multinational scale). Post-Schrems II, organisations are also expected to conduct Transfer Impact Assessments to verify that SCCs actually hold up in the destination jurisdiction.
UAE PDPL requires transfers to go to jurisdictions with adequate protection or to be governed by approved safeguards. Emirate-level rules, particularly in DIFC and ADGM, may add conditions beyond the federal framework. If you’re operating in a financial services or technology context, you likely need to map both layers.
KSA PDPL is where the strictest controls live. Cross-border transfers require a combination of consent, adequacy assessment, SCCs or BCRs, and risk assessments. For repeat violations, fines double. Unauthorized transfers of certain categories of data carry the risk of imprisonment. This is not a jurisdiction where you want to rely on assumptions about what’s covered.
DPDPA permits cross-border transfers with the significant caveat that the Indian government can, by notification, restrict transfers to specific countries or categories of countries. Sectoral localisation pressures, particularly in financial services and health, add further complexity. The full picture won’t be clear until the government’s notifications are published, but the direction of travel is toward greater scrutiny rather than liberalisation.
What to build:
Map every data flow that crosses a border – EU to UAE, UAE to India, India to EU, and all the permutations that involve KSA. Maintain a transfer register that documents the mechanism, the legal basis, and the assessment that supports it. Use SCCs as your baseline, with jurisdiction-specific addenda where required. Review that register on a regular schedule, not just at setup. And give serious consideration to regional data residency for GCC data, both to reduce transfer complexity and to address the sovereignty expectations of the local regulators.
Breach Notification: The Clock Starts the Moment You Know
Data breaches are stressful enough without having three different regulatory clocks ticking simultaneously. Here’s how the timelines stack up.
GDPR: 72 hours to notify the relevant supervisory authority from the moment you become aware of a breach. Individuals must be notified without undue delay if the breach is likely to result in high risk to their rights and freedoms. The “when you become aware” standard is interpreted strictly, the clock doesn’t start when you’ve completed your investigation, it starts when you have reasonable grounds to believe a breach has occurred.
UAE PDPL: notify the regulator and affected individuals when harm is likely. The practical timeline is 72 hours, consistent with the GDPR standard, though the precise framing differs.
KSA PDPL: notification to the regulator and individuals, with particularly strict application in critical sectors like health and finance.
DPDPA: 72 hours to the Data Protection Board and to affected individuals. There is an additional and important requirement: a 6-hour notification window to CERT-In for cyber incidents. This is the tightest timeline in the stack, and it means your incident response playbook needs to distinguish between a data breach and a cyber incident, because the latter triggers a separate and faster obligation.
The practical answer is a single incident response playbook with a decision tree built in. Classify the incident. Identify which jurisdictions are affected. Trigger the appropriate notification workflows in parallel, not sequentially. Build template notifications for each regulator and each individual-facing communication, localised for jurisdiction. Test the playbook before you need it.
Penalties and Enforcement Culture
The numbers matter, but so does the context around them.
GDPR carries the largest absolute penalty ceiling: 4% of global annual turnover or €20 million, whichever is higher. For a large multinational, this can translate to billion-euro exposures. European DPAs are active and publish their decisions publicly, which means enforcement creates deterrence beyond the individual case.
UAE PDPL sets maximum penalties at AED 5 million per violation. The culture is currently more oriented toward guidance and remediation than immediate penalties, but high-profile enforcement actions have been used deliberately to signal expectations. Don’t mistake the current tone for a permanent posture.
KSA PDPL sets fines at up to SAR 5 million, doubling for repeat violations. Critically, it includes the possibility of imprisonment for unauthorized cross-border transfers. This is not a jurisdiction where the enforcement culture can be read as permissive.
DPDPA allows penalties of up to INR 250 crore. India’s enforcement posture in the early phase is expected to lean toward compliance assistance rather than punitive action, but the penalty ceiling is substantial and the direction of travel is toward more active enforcement as the Data Protection Board matures.
The takeaway for compliance teams: don’t calibrate your investment based on enforcement history alone. Calibrate based on where enforcement is going, which is in one direction across all four regimes.
Accountability and Governance: The Organisational Infrastructure
Compliance isn’t just about having the right policies on paper. It’s about having the right people, processes, and documentation in place, and being able to demonstrate that when a regulator asks.
GDPR requirements are the most developed: a Record of Processing Activities (ROPA), Data Protection Impact Assessments (DPIAs) for high-risk processing, mandatory DPO appointments in many cases, and privacy-by-design as an architectural principle rather than an afterthought.
UAE PDPL requires DPO appointment in high-risk cases and expects demonstrable governance – documented policies, training records, evidence of due diligence on vendors. The bar is similar in spirit to GDPR, even if the specific requirements differ.
DPDPA introduces the concept of Significant Data Fiduciaries – organisations that meet certain criteria based on volume, sensitivity, or national security implications of the data they process. These entities have additional obligations including record-keeping, risk controls, DPIAs, and requirements around Consent Managers registered with the Data Protection Board.
The organisational implication is a governance structure that spans jurisdictions without fragmenting into three separate silos. A single global privacy program, mapped to all three regimes. A role matrix that is explicit about who covers EU obligations, who covers UAE and KSA, and who owns DPDPA compliance. DPIAs that use the GDPR format as a baseline with jurisdiction-specific addenda for UAE, KSA, and India. And vendor due diligence processes that validate compliance across all applicable regimes, not just the one closest to your headquarters.
Children’s Data: The Area Where You Cannot Average Down
Every major privacy regime treats children as requiring heightened protection. The age thresholds and consent mechanisms differ, and this is one area where taking the most permissive standard available is a serious risk.
GDPR sets the threshold at under 16, with member states permitted to lower this to 13. Verifiable parental consent is required for processing children’s data where the legal basis would otherwise be consent.
UAE PDPL takes a strict approach to minor protections across the board.
DPDPA sets the threshold at under 18, the highest of the three. Verifiable parental consent is required, and processing for the purpose of profiling children is subject to stricter rules still.
If you’re operating consumer-facing products or platforms, you cannot run a single global age gate and call it done. You need jurisdiction-specific age thresholds and consent flows, with the mechanics to actually verify parental consent rather than rely on a date-of-birth field that anyone can edit. The definition of a child varies. The standard of consent verification varies. Build for the strictest, and create jurisdiction-specific overlays where the bar is lower.
Common Pitfalls That Catch Organisations Off Guard
These are the mistakes that appear repeatedly in organisations navigating multi-jurisdictional privacy compliance. Most of them come from applying a single-jurisdiction mindset to a multi-jurisdiction problem.
Using a single global consent banner. A general opt-in does not satisfy the per-purpose consent requirements of UAE PDPL or the explicit consent requirements of DPDPA. Granularity is not optional.
Missing India’s dual breach reporting obligation. The 72-hour window to the Data Protection Board exists alongside a separate 6-hour obligation to CERT-In for cyber incidents. Many organisations build for one and miss the other.
Underestimating KSA’s transfer rules. Organisations that have GCC operations but treat UAE compliance as a proxy for Saudi Arabia will run into serious gaps. KSA’s controls are stricter, the fines double for repeat violations, and the potential for criminal liability around unauthorised transfers is real.
Running a single children’s age policy. With DPDPA setting the threshold at 18 and GDPR as low as 13 (in some member states), a single global policy will either over-restrict in some jurisdictions or under-protect in others.
Ignoring emirate-level rules in the UAE. The federal UAE PDPL is the baseline, but DIFC and ADGM operate their own independent frameworks with specific requirements that apply depending on where your entity is incorporated or where you’re doing business.
Assuming GDPR compliance covers the GCC. It does not. The UAE and KSA have their own frameworks, their own supervisory authorities, and their own expectations. GDPR compliance is a useful starting point, but it is not a substitute.
No documented ROPA, DPIAs, or transfer register. Documentation is accountability. Without it, you cannot demonstrate compliance to a regulator even if you are in fact compliant. These records need to exist, stay current, and be accessible when needed.
No appointed DPO or representative where required. These are not optional roles in the jurisdictions that require them. Check your threshold against each regime and appoint where the requirement applies.
Your Readiness Checklist
Use this as a starting point for assessing your current state across all three regimes:
- Data inventory mapped across EU, UAE, KSA, and India operations
- Lawful basis and consent mapping documented per purpose per jurisdiction
- Cross-border transfer register maintained with SCCs and supporting assessments
- Incident response playbook with 72-hour and 6-hour CERT-In triggers built in separately
- DSAR workflow with SLA set to the strictest timeline and jurisdiction-specific outputs
- DPO appointments confirmed and documented for each applicable jurisdiction
- DPIAs conducted for all high-risk processing activities
- Vendor due diligence and Data Processing Agreements aligned to all three regimes
- Children’s data controls implemented with jurisdiction-specific age thresholds and consent verification
- Staff training completed and logged
- Monitoring process in place for guidance from EU DPAs, UAE Data Office, SDAIA, and India’s Data Protection Board
What’s Coming Next
The direction of travel across all three regimes is consistent: more enforcement, more scrutiny of AI and automated decision-making, stronger cross-border transfer controls, and growing data sovereignty expectations.
Adequacy-like mechanisms between the GCC, EU, and India may emerge over time, which would simplify some of the transfer complexity. But the near-term outlook is more friction, not less. The organisations that will navigate this most effectively are the ones building unified privacy programs now, not scrambling to retrofit compliance when an enforcement action lands on their desk.
GDPR is no longer the only framework that matters. DPDPA and UAE PDPL are real, enforceable, and being taken seriously by regulators who are actively building their capacity to act on them. The question isn’t whether to invest in multi-jurisdictional privacy compliance. It’s how to do it without duplicating effort across every jurisdiction you operate in.
The answer is a single program architecture with jurisdiction-specific overlays , built once, maintained centrally, localised where the rules require it.
Not sure where your gaps are across GDPR, UAE PDPL, and DPDPA? The team at EGUARDIAN works with organisations navigating exactly this, from data mapping and transfer impact assessments to building compliance programs that hold up in multiple jurisdictions simultaneously.
Talk to our experts at EGUARDIAN and let’s figure out where you stand and what needs to happen next. Reach out to us as hello@eguardian.com.