Federal Decree-Law No. 44 of 2021 establishes the Emirates Data Office, the federal body that sits behind the Personal Data Protection Law. It was issued on 20 September 2021, the same day as the Personal Data Protection Law, and entered into force the day after publication (Federal Decree-Law No. 44 of 2021, Article 11). The Office is affiliated with the Cabinet and has legal personality with financial and administrative independence (Article 2). Its competences are to propose data-protection policy and legislation, set monitoring standards, build complaints systems, issue guidance, control the application of federal data-protection legislation and investigate compliance, handle complaints, run awareness activities, conduct research, and represent the State internationally (Article 3).
One finding governs how this law should be read, and it cuts against the common summary of it. Federal Decree-Law No. 44 contains no penalty power. Nothing in its eleven articles empowers the Office to impose a fine. The strongest coercive functions the text confers are to control the application of the legislation and conduct investigations, and to receive and verify complaints (Articles 3(5) and 3(6)). The administrative-penalty architecture for data-protection breaches sits in the Personal Data Protection Law, whose Article 26 defers the penalty tariff to a Cabinet decision, as the companion article on the federal law sets out, and not in this constituting statute. A statement that the Data Office Law gives the Office power to fine is therefore an inference the text does not support; the fining power lives in the other instrument of the pair, and that instrument defers it.
The relevance to this series is that the Office is the chokepoint for the federal AI-relevant machinery. The automated-processing and impact-assessment provisions the companion article identified as the federal law’s AI hooks depend on Executive Regulations that are not confirmed issued, and it is this Office that must produce them, publish the impact-assessment list, and handle automated-decision complaints. The institution is established and binds; the machinery it must issue, and its own operational activation, are the open questions. A June 2026 announcement of a successor authority is treated below as an announcement, not analysed as law.
The instrument is institutional, not substantive: it creates a body and equips it, and it imposes no obligations on controllers or processors. The Office is established as a Cabinet-affiliated entity with legal personality and financial and administrative independence, capable of the acts necessary to implement its competences (Federal Decree-Law No. 44 of 2021, Article 2). It has a Director General, appointed and ranked by Federal Decree, whose functions include proposing draft laws, decrees and regulations related to the Office and submitting them to the Cabinet, preparing the budget, supervising the workflow, appointing staff, concluding agreements, representing the Office, and reporting annually to the Cabinet (Article 4). Information submitted to the Office is confidential, including after the purpose for which it was submitted has ended (Article 5). The Office has its own annual budget drawn from State appropriations, its own revenues and approved grants (Article 6), a calendar fiscal year with a defined first year (Article 7), and it applies federal financial and human-resources legislation (Article 8).
The structure of that independence is worth marking against the free-zone regulators this series has examined. The Office is described as financially and administratively independent, yet it is affiliated with the Cabinet, its Director General proposes legislation to the Cabinet and reports to the Cabinet, and its very competences are exercised on Cabinet approval (Articles 2, 3(1) and 4). That is a more executive-embedded design than the DIFC Commissioner or the ADGM Commissioner, the latter of which its regulations require to act with complete independence and to take instructions from nobody. The observation is drawn from comparing the constituting provisions and is stated as a structural comparison, not as a claim about how the Office exercises its role in practice.
One transitional provision has spent its window. For the purpose of operating the Office during its first two years, the Telecommunications and Digital Government Regulatory Authority was to provide administrative and logistical support (Federal Decree-Law No. 44 of 2021, Article 9). With the law in force from September 2021, that two-year period ran to around September 2023 on the face of the text. As at the date of this article the window has closed, so the provision no longer describes a current arrangement; whether the support was extended or transitioned into a permanent structure is not answered by the law itself and is an open item.
Article 3 confers eleven competences, and reading them structurally, as a set with attention to the verbs, is what reveals the limit. The Office may propose and develop policy, strategy and legislation on data protection and supervise implementation on Cabinet approval (Article 3(1)); propose and approve monitoring standards (Article 3(2)); prepare complaints and appeals systems (Article 3(3)); issue guides and instructions for implementation (Article 3(4)); implement control over the application of federal data-protection legislation and conduct investigations to ensure compliance (Article 3(5)); receive and verify complaints and appeals (Article 3(6)); spread awareness (Article 3(7)); conduct studies and research including monitoring regional and international risks (Article 3(8)); propose and represent the State on international instruments (Articles 3(9) and 3(10)); and exercise any other competence the Cabinet authorises (Article 3(11)).
The carve-out that matters is the one that is absent. No provision in Article 3, or anywhere else in the law, confers a power to impose administrative fines, to order the cessation of processing, or to levy any penalty. The coercive edge of the Office under this law reaches control, investigation, and the verification of complaints; it stops short of sanction. This is the operative reading, and it is marked as a reading of the whole text rather than a quotation of a single clause: the enforcement teeth that a data-protection regulator is usually assumed to hold are not granted here. They are granted, if at all, by the Personal Data Protection Law and the Cabinet decision that law defers, which means that the federal enforcement question turns on an instrument outside this one and on machinery not yet issued.
The two laws were issued as a pair on the same day, and the connection between them is structural rather than stated. Federal Decree-Law No. 44 refers throughout to federal legislation regulating data protection in general terms, in its policy, standards and control functions (Articles 3(1), 3(2) and 3(5)), and does not name the Personal Data Protection Law. Reading the contemporaneous pair together, the Emirates Data Office is the supervisory authority for that law, which is the natural construction and the one the market adopts, but it is a construction from the pairing rather than an express cross-reference in either text, and it is marked as such. A terminology note belongs here: the official English of this law calls the body the Emirates Data Office, while the official English of the Personal Data Protection Law renders its regulator variously, so a reader comparing the two translations should treat the Office and the Personal Data Protection Law’s supervisory authority as the same body notwithstanding the difference in rendering.
For the AI thread this series follows, the Office is the single institution on which the federal position turns. The federal law’s AI-relevant provisions, the automated-processing right and the impact-assessment duty, carry operative content that the law defers to Executive Regulations, and the impact-assessment regime requires the supervisory authority to publish a list of the processing operations that trigger an assessment. All of that is work for this Office. Until it issues the Executive Regulations, publishes the required lists, and stands up its complaints machinery, the federal AI-relevant obligations remain, as the companion article found, principles that bind without the mechanics that would give them edges. The institutional question and the deferred-machinery question are therefore one question, and this law is where it sits.
Binding now, on this law’s own text: the Office exists as a Cabinet-affiliated body with legal personality and independence (Article 2), the Director General office and its functions are established (Article 4), the confidentiality duty over submitted information applies (Article 5), and the eleven competences are conferred (Article 3). None of this imposes any obligation on a controller, processor or AI deployer; the law builds the regulator, not the duties.
What is open is the Office’s activation and output. Secondary commentary through 2024 described the Office as not yet fully operational, a characterisation flagged as secondary and not asserted here as the current position; the Executive Regulations it must issue for the Personal Data Protection Law are not confirmed issued on the official sources; and the two-year transitional support arrangement of Article 9 is spent, with no successor arrangement stated in the law. What is moving is the institution itself. A June 2026 approval of a Federal Authority for Artificial Intelligence and Data has been reported, which if enacted would bear directly on the body this law establishes. Consistent with the discipline that governs this whole series, that development is an announcement and not a located instrument, so it is not analysed as law here; it is flagged as the single largest institutional watch item, and references to the Emirates Data Office in this and the companion articles should be re-read against any successor instrument once its text is published on the register.
The refresh triggers follow. The first is the publication of any primary instrument establishing, renaming or absorbing the Office into a successor authority, which would re-anchor this article. The second is the issuance of the Personal Data Protection Law’s Executive Regulations, which is the Office’s most consequential deferred output and the event that converts the federal AI-relevant machinery from principle into operable rule. The third is any Cabinet resolution issued under Article 9 or any of the Cabinet-approval hooks in Article 3. The answer to the question in the title is therefore exact: the federal data regulator is the Emirates Data Office, established and in force since 2021; what it may do under its own constituting law is to make policy, set standards, investigate and handle complaints, but not to fine; and whether it can yet give the federal data and AI rules practical effect depends on Executive Regulations it has still to issue and on its own operational and institutional position, both of which remain open as at the date of this article.
For your facts, in confidence, put the question to the firm.





The bench stands behind it