Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)
Article 10 establishes the conditions under which a controller / processor must APPOINT A DATA PROTECTION OFFICER (DPO). A DPO is REQUIRED where: (a) processing involves SENSITIVE PERSONAL DATA on a large scale; (b) processing involves SYSTEMATIC EVALUATION + MONITORING of data subjects on a large scale; (c) processing carried out by an authority (other than judicial activities). The DPO must have expert knowledge of data protection law + practice + the technical aspects of data processing; the DPO may be an employee or external consultant; the DPO must be INDEPENDENT + report DIRECTLY TO THE HIGHEST LEVEL of management of the controller; the DPO must NOT be dismissed or penalised for performing their tasks. The DPO's tasks include: (a) MONITORING compliance with the UAE PDPL; (b) ADVISING the controller / processor on data protection matters; (c) Cooperating with the UAE Data Office + b
- DPO designation + contact details
- DPO terms of reference + independence
- Annual DPO report to senior management
- DPO training programme
- DPO appointed without independence guarantees
- DPO dual-hatted as marketing / IT leader (conflict)
- No annual DPO report to senior management
Article 18 (SECURITY MEASURES) - controllers + processors must implement appropriate TECHNICAL + ORGANIZATIONAL MEASURES proportionate to the nature + scope + purposes + risk of processing to ensure confidentiality + integrity + availability of personal data + protection against unauthorised access + disclosure + alteration + accidental loss. Article 19 (PSEUDONYMISATION + ENCRYPTION + PRIVACY BY DESIGN) - controllers must apply pseudonymisation / encryption where appropriate + apply DATA PROTECTION BY DESIGN AND BY DEFAULT principles. Article 20 (CONTROLLER + PROCESSOR RELATIONSHIP) - the controller must engage processors only where they provide sufficient guarantees of GDPR-style technical + organisational measures; the relationship must be governed by a WRITTEN CONTRACT (Data Processing Agreement DPA) specifying processing details + technical + organisational measures + sub-processor
- TOM register
- Privacy-by-design integration into SDLC
- DPA template + controller-processor evidence
- DPIA register + prior consultation evidence
- Security measures absent or proportionate-to-cost rather than risk
- Privacy by design not applied (retrospective bolt-on)
- DPA with processors weak or missing
- DPIA not conducted for high-risk processing
Article 8 imposes the RECORDS-OF-PROCESSING-ACTIVITIES requirement on controllers + processors. The records must include: (a) name + contact details of the controller / processor + the DPO if any + the joint controller + the representative; (b) purposes of processing; (c) description of categories of data subjects + categories of personal data; (d) categories of recipients to whom personal data has been or will be disclosed; (e) cross-border transfers + the legal basis for transfer; (f) envisaged retention periods; (g) general description of technical + organizational security measures. Records must be maintained in writing + electronic form + made available to the UAE Data Office upon request. The records must be UPDATED + reviewed periodically + retained beyond the processing period in line with the audit-trail expectations. Records are the foundational compliance artefact for UAE PDPL
- RoPA template per controller + processor
- Annual RoPA review
- Cross-border transfer log + legal basis
- RoPA missing or incomplete
- Records not aligned with cross-border transfer log
- Records not made available to UAE Data Office on request
Article 9 imposes the DATA-BREACH-NOTIFICATION regime. Controllers must NOTIFY the UAE Data Office of any personal data breach that may pose a risk to the privacy + confidentiality + security of the data subjects WITHOUT UNDUE DELAY (the UAE PDPL does not specify the GDPR 72-hour timeline; the Data Office guidance recommends prompt notification). The notification must include: (a) NATURE of the breach (categories of data + data subjects affected + approximate numbers); (b) NAME + contact details of the DPO or other contact point; (c) LIKELY CONSEQUENCES of the breach; (d) MEASURES taken or proposed to address the breach + mitigate adverse effects. Article 9 also requires controllers to NOTIFY DATA SUBJECTS without undue delay where the breach is likely to result in a HIGH RISK to their rights + freedoms; the notification to data subjects should be in clear + plain language. Records of br
- Breach-incident-response playbook
- UAE Data Office notification capability
- Data-subject notification template
- Breach record
- No documented incident response
- Delayed notification
- No documented mitigation measures + lessons learned
UAE PDPL: Cross-Border Transfers (Articles 22-24)
Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection; (b) APPROPRIATE SAFEGUARDS - binding contractual clauses similar to GDPR SCCs + binding corporate rules (BCRs) + approved certification mechanisms; (c) EXCEPTIONS - explicit consent of the data subject for the transfer + necessity for performance of a contract + necessity for important reasons of public interest + necessity for the establishment / exercise / defence of legal claims + necessity to protect vital interests + necessity for compelling legitimate interests of the controller proportionate to data subject rights. Article 23 (PROHIBITIONS) - certain transfers are PROHIBITED where they would jeopardise the rights + freedoms of data subjects or where the destination country ha
- Cross-border transfer register + legal basis per transfer
- UAE-Data-Office-approved SCC + BCR documentation
- Article 24 notification records
- Adequacy decision tracking
- Cross-border transfers without documented legal basis
- Standard contractual clauses not aligned with UAE-Data-Office-approved templates
- Article 24 notification missing
- Adequacy assumed without UAE Data Office determination
UAE PDPL: Data Subject Rights (Articles 11-16)
Articles 11-16 establish the DATA SUBJECT RIGHTS regime. Each right is exercisable through a request to the controller + the controller must respond within reasonable time (Data Office guidance suggests 30 days). The 6 rights: (Art 11) RIGHT TO INFORMATION + transparency about processing (similar to GDPR Articles 13-14); (Art 12) RIGHT OF ACCESS - obtain confirmation + a copy of personal data being processed; (Art 13) RIGHT TO RECTIFICATION + correction of inaccurate personal data; (Art 14) RIGHT TO ERASURE (right to be forgotten) in specified circumstances - withdrawal of consent + processing unlawful + objection + data no longer necessary; (Art 15) RIGHT TO RESTRICT PROCESSING + RIGHT TO DATA PORTABILITY in machine-readable + interoperable format; (Art 16) RIGHT TO OBJECT TO PROCESSING (including direct marketing + processing based on legitimate interests) + RIGHT NOT TO BE SUBJECT TO
- DSR-request handling procedure
- 30-day response timeline + escalation
- DSR audit trail + completion records
- Restrictions documentation
- DSR-request handling slow + missing 30-day timeline
- No DSR audit trail
- Right-to-be-forgotten requests handled on case-by-case without policy
- No mechanism for automated-decision-making opt-out
UAE PDPL: Lawful Basis, Consent and Principles (Articles 4-6)
Article 4 establishes the PRINCIPLES for processing: (a) processed in a fair + transparent + lawful manner; (b) collected for specified + clear + legitimate purposes (purpose limitation); (c) limited to what is necessary (data minimization); (d) accurate + kept up to date (accuracy); (e) retained only as long as necessary (storage limitation); (f) processed with appropriate security measures (integrity + confidentiality). Article 5 establishes the LAWFUL BASES for processing: (a) data subject CONSENT; (b) performance of a CONTRACT or pre-contractual steps; (c) compliance with a LEGAL OBLIGATION; (d) protection of VITAL INTERESTS; (e) performance of a TASK IN THE PUBLIC INTEREST; (f) LEGITIMATE INTERESTS of the controller / processor or a third party (balanced against data subject rights); (g) processing of personal data necessary for the realisation of historical / statistical / scientif
- Article 4 principles compliance file
- Lawful-basis-of-processing record per processing activity
- Consent capture + management procedure
- Lawful basis not documented per processing activity
- Consent capture without explicit opt-in or without revocation pathway
- Storage limitation not enforced (no retention schedule)
UAE PDPL: Scope, Definitions and Applicability (Articles 1-3)
Article 1 provides definitions of key terms including: PERSONAL DATA = any data related to an identified or identifiable natural person; SENSITIVE PERSONAL DATA = data revealing racial / ethnic origin, political opinions, religious beliefs, biometric / genetic / health data, criminal records; CONTROLLER / PROCESSOR; DATA SUBJECT; CONSENT; CROSS-BORDER TRANSFER; UAE DATA OFFICE. Article 2 scope: the Law applies to (a) any controller / processor in the UAE; (b) any controller / processor outside the UAE that processes personal data of data subjects in the UAE (extraterritorial scope similar to GDPR Article 3). Article 3 exclusions: the Law does NOT apply within the financial free zones (DIFC + ADGM maintain own sectoral DP regimes) + does NOT apply to personal data held by competent UAE security authorities + does NOT apply to certain personal-personal-or-household processing. The Law is a
- Internal scope memo identifying processing in or for UAE data subjects
- DIFC / ADGM / sectoral free-zone coordination analysis
- Definitional walk-through aligned with Article 1
- Extraterritorial processing not assessed
- DIFC / ADGM processing wrongly subject to federal PDPL
- Sensitive personal data not separately classified per Article 1
UAE PDPL: Sensitive Personal Data and Children (Articles 6-7)
Article 6 (SENSITIVE PERSONAL DATA) - processing of sensitive personal data is PROHIBITED unless one of specific conditions applies: (a) EXPLICIT consent (heightened beyond ordinary consent); (b) processing necessary to protect VITAL interests where data subject is physically / legally incapable; (c) processing carried out by a non-profit body + the data relates to its members + is necessary for the body's activities; (d) processing necessary for substantial PUBLIC INTEREST or LEGAL CLAIMS; (e) processing for occupational MEDICINE / public health / clinical research. Sensitive personal data includes racial / ethnic origin + political opinions + religious / philosophical beliefs + trade union membership + genetic / biometric data for unique identification + health data + sex life / sexual orientation. Article 7 (CHILDREN'S DATA) - processing of personal data of children under 16 years old
- Sensitive-data classification + condition documentation
- Children's age-verification process
- Parental consent capture + verification
- Sensitive data processed under ordinary consent
- Children's data without age verification
- No specific assessment for child best-interest
UAE PDPL: UAE Data Office, Penalties, Free Zones (Articles 25-29 and Free Zone Coordination)
Articles 25-29 establish the UAE DATA OFFICE + its powers + administrative enforcement: (Art 25) ESTABLISHMENT - the UAE Data Office is a federal body established within the Cabinet structure + reports to the federal government; (Art 26) FUNCTIONS - issue executive regulations + guidance + handle data subject complaints + investigate breaches + impose administrative penalties + cooperate with international counterparts + promote data protection awareness; (Art 27) DATA SUBJECT COMPLAINTS - data subjects may file complaints with the UAE Data Office regarding controller / processor compliance + the Data Office investigates + issues binding decisions; (Art 28) ADMINISTRATIVE PENALTIES - the Data Office may impose administrative penalties for non-compliance including: written warnings + suspension of processing + administrative fines (currently up to AED 5 million per violation + escalating
- Data Office engagement + cooperation procedure
- Complaint-response procedure
- Penalty exposure in compliance risk register
- Public-guidance tracking
- No documented Data Office engagement procedure
- Penalty exposure not mapped + no internal escalation
- Data Office public guidance not tracked
Article 3 of the UAE Federal Decree-Law No. 45 of 2021 expressly EXCLUDES financial free zones from the federal PDPL scope. The financial free zones have their own sectoral data protection regimes: (a) DUBAI INTERNATIONAL FINANCIAL CENTRE (DIFC) - DIFC Data Protection Law No. 5 of 2020 (replaced DIFC DP Law 1 of 2007) administered by the DIFC Commissioner of Data Protection; (b) ABU DHABI GLOBAL MARKET (ADGM) - ADGM Data Protection Regulations 2021 administered by the ADGM Office of Data Protection. Sectoral laws also exist: FEDERAL LAW NO. 2 OF 2019 on the Use of Information and Communications Technology in Health Fields (Health Data Law) administered by the UAE Ministry of Health and Prevention. Multi-jurisdictional entities operating across mainland UAE + DIFC + ADGM must apply the relevant regime per jurisdiction + ensure cross-jurisdictional consistency. Free-zone-to-federal cross-b
- Jurisdiction map identifying mainland UAE + DIFC + ADGM operations
- Sectoral compliance matrix (federal PDPL + DIFC + ADGM + Health Data Law)
- Cross-jurisdiction data transfer procedure
- Single compliance program treating all UAE operations as federal-PDPL
- DIFC / ADGM operations applying federal PDPL incorrectly
- Health-data processing without Federal Law 2/2019 alignment
The UAE Federal Decree-Law No. 45 of 2021 entered into force on 2 January 2022 (six months after publication on 28 November 2021). EXECUTIVE REGULATIONS + UAE DATA OFFICE GUIDANCE continue to evolve: the Data Office has issued a series of public guidance documents on cross-border transfers + DPIAs + sensitive data + AI / automated decision-making + minors + records + cooperation; the executive regulations operationalise the PDPL provisions including registration requirements + appointment of DPOs + cross-border transfer mechanisms + breach notification timelines. The 2024-2025 enforcement landscape includes: initial Data Office investigations + complaints + administrative penalties (the first penalties typically up to AED 5 million per violation + escalating for repeat); public consultations on AI + Generative AI data protection considerations; alignment with international data protectio
- Tracking of UAE Data Office public guidance + executive regulation updates
- International alignment (GDPR + CBPR) cross-reference matrix
- AI / Generative AI data protection guidance integration
- Compliance program tied to 2021 baseline without tracking 2024-2025 Data Office guidance
- AI / Generative AI data protection not assessed
- International alignment limited to GDPR without CBPR / GCC
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.