Skip to content

Evidence request lists

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)

UAE-PDPL-Art.10
Data Protection Officer (DPO) (UAE PDPL Article 10)

Article 10 establishes the conditions under which a controller / processor must APPOINT A DATA PROTECTION OFFICER (DPO). A DPO is REQUIRED where: (a) processing involves SENSITIVE PERSONAL DATA on a large scale; (b) processing involves SYSTEMATIC EVALUATION + MONITORING of data subjects on a large scale; (c) processing carried out by an authority (other than judicial activities). The DPO must have expert knowledge of data protection law + practice + the technical aspects of data processing; the DPO may be an employee or external consultant; the DPO must be INDEPENDENT + report DIRECTLY TO THE HIGHEST LEVEL of management of the controller; the DPO must NOT be dismissed or penalised for performing their tasks. The DPO's tasks include: (a) MONITORING compliance with the UAE PDPL; (b) ADVISING the controller / processor on data protection matters; (c) Cooperating with the UAE Data Office + b

Artefacts an auditor will ask for
  • DPO designation + contact details
  • DPO terms of reference + independence
  • Annual DPO report to senior management
  • DPO training programme
Where this commonly fails
  • DPO appointed without independence guarantees
  • DPO dual-hatted as marketing / IT leader (conflict)
  • No annual DPO report to senior management
UAE-PDPL-Art.18_19_20_21
Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

Article 18 (SECURITY MEASURES) - controllers + processors must implement appropriate TECHNICAL + ORGANIZATIONAL MEASURES proportionate to the nature + scope + purposes + risk of processing to ensure confidentiality + integrity + availability of personal data + protection against unauthorised access + disclosure + alteration + accidental loss. Article 19 (PSEUDONYMISATION + ENCRYPTION + PRIVACY BY DESIGN) - controllers must apply pseudonymisation / encryption where appropriate + apply DATA PROTECTION BY DESIGN AND BY DEFAULT principles. Article 20 (CONTROLLER + PROCESSOR RELATIONSHIP) - the controller must engage processors only where they provide sufficient guarantees of GDPR-style technical + organisational measures; the relationship must be governed by a WRITTEN CONTRACT (Data Processing Agreement DPA) specifying processing details + technical + organisational measures + sub-processor

Artefacts an auditor will ask for
  • TOM register
  • Privacy-by-design integration into SDLC
  • DPA template + controller-processor evidence
  • DPIA register + prior consultation evidence
Where this commonly fails
  • Security measures absent or proportionate-to-cost rather than risk
  • Privacy by design not applied (retrospective bolt-on)
  • DPA with processors weak or missing
  • DPIA not conducted for high-risk processing
UAE-PDPL-Art.8
Records of processing activities (UAE PDPL Article 8)

Article 8 imposes the RECORDS-OF-PROCESSING-ACTIVITIES requirement on controllers + processors. The records must include: (a) name + contact details of the controller / processor + the DPO if any + the joint controller + the representative; (b) purposes of processing; (c) description of categories of data subjects + categories of personal data; (d) categories of recipients to whom personal data has been or will be disclosed; (e) cross-border transfers + the legal basis for transfer; (f) envisaged retention periods; (g) general description of technical + organizational security measures. Records must be maintained in writing + electronic form + made available to the UAE Data Office upon request. The records must be UPDATED + reviewed periodically + retained beyond the processing period in line with the audit-trail expectations. Records are the foundational compliance artefact for UAE PDPL

Artefacts an auditor will ask for
  • RoPA template per controller + processor
  • Annual RoPA review
  • Cross-border transfer log + legal basis
Where this commonly fails
  • RoPA missing or incomplete
  • Records not aligned with cross-border transfer log
  • Records not made available to UAE Data Office on request
UAE-PDPL-Art.9
Data breach notification (UAE PDPL Article 9)

Article 9 imposes the DATA-BREACH-NOTIFICATION regime. Controllers must NOTIFY the UAE Data Office of any personal data breach that may pose a risk to the privacy + confidentiality + security of the data subjects WITHOUT UNDUE DELAY (the UAE PDPL does not specify the GDPR 72-hour timeline; the Data Office guidance recommends prompt notification). The notification must include: (a) NATURE of the breach (categories of data + data subjects affected + approximate numbers); (b) NAME + contact details of the DPO or other contact point; (c) LIKELY CONSEQUENCES of the breach; (d) MEASURES taken or proposed to address the breach + mitigate adverse effects. Article 9 also requires controllers to NOTIFY DATA SUBJECTS without undue delay where the breach is likely to result in a HIGH RISK to their rights + freedoms; the notification to data subjects should be in clear + plain language. Records of br

Artefacts an auditor will ask for
  • Breach-incident-response playbook
  • UAE Data Office notification capability
  • Data-subject notification template
  • Breach record
Where this commonly fails
  • No documented incident response
  • Delayed notification
  • No documented mitigation measures + lessons learned

UAE PDPL: Cross-Border Transfers (Articles 22-24)

UAE-PDPL-Art.22_23_24
Cross-border data transfers (UAE PDPL Articles 22-24)

Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection; (b) APPROPRIATE SAFEGUARDS - binding contractual clauses similar to GDPR SCCs + binding corporate rules (BCRs) + approved certification mechanisms; (c) EXCEPTIONS - explicit consent of the data subject for the transfer + necessity for performance of a contract + necessity for important reasons of public interest + necessity for the establishment / exercise / defence of legal claims + necessity to protect vital interests + necessity for compelling legitimate interests of the controller proportionate to data subject rights. Article 23 (PROHIBITIONS) - certain transfers are PROHIBITED where they would jeopardise the rights + freedoms of data subjects or where the destination country ha

Artefacts an auditor will ask for
  • Cross-border transfer register + legal basis per transfer
  • UAE-Data-Office-approved SCC + BCR documentation
  • Article 24 notification records
  • Adequacy decision tracking
Where this commonly fails
  • Cross-border transfers without documented legal basis
  • Standard contractual clauses not aligned with UAE-Data-Office-approved templates
  • Article 24 notification missing
  • Adequacy assumed without UAE Data Office determination

UAE PDPL: Data Subject Rights (Articles 11-16)

UAE-PDPL-Art.11_12_13_14_15_16
Data subject rights (UAE PDPL Articles 11-16)

Articles 11-16 establish the DATA SUBJECT RIGHTS regime. Each right is exercisable through a request to the controller + the controller must respond within reasonable time (Data Office guidance suggests 30 days). The 6 rights: (Art 11) RIGHT TO INFORMATION + transparency about processing (similar to GDPR Articles 13-14); (Art 12) RIGHT OF ACCESS - obtain confirmation + a copy of personal data being processed; (Art 13) RIGHT TO RECTIFICATION + correction of inaccurate personal data; (Art 14) RIGHT TO ERASURE (right to be forgotten) in specified circumstances - withdrawal of consent + processing unlawful + objection + data no longer necessary; (Art 15) RIGHT TO RESTRICT PROCESSING + RIGHT TO DATA PORTABILITY in machine-readable + interoperable format; (Art 16) RIGHT TO OBJECT TO PROCESSING (including direct marketing + processing based on legitimate interests) + RIGHT NOT TO BE SUBJECT TO

Artefacts an auditor will ask for
  • DSR-request handling procedure
  • 30-day response timeline + escalation
  • DSR audit trail + completion records
  • Restrictions documentation
Where this commonly fails
  • DSR-request handling slow + missing 30-day timeline
  • No DSR audit trail
  • Right-to-be-forgotten requests handled on case-by-case without policy
  • No mechanism for automated-decision-making opt-out

UAE PDPL: Lawful Basis, Consent and Principles (Articles 4-6)

UAE-PDPL-Art.4_5
Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

Article 4 establishes the PRINCIPLES for processing: (a) processed in a fair + transparent + lawful manner; (b) collected for specified + clear + legitimate purposes (purpose limitation); (c) limited to what is necessary (data minimization); (d) accurate + kept up to date (accuracy); (e) retained only as long as necessary (storage limitation); (f) processed with appropriate security measures (integrity + confidentiality). Article 5 establishes the LAWFUL BASES for processing: (a) data subject CONSENT; (b) performance of a CONTRACT or pre-contractual steps; (c) compliance with a LEGAL OBLIGATION; (d) protection of VITAL INTERESTS; (e) performance of a TASK IN THE PUBLIC INTEREST; (f) LEGITIMATE INTERESTS of the controller / processor or a third party (balanced against data subject rights); (g) processing of personal data necessary for the realisation of historical / statistical / scientif

Artefacts an auditor will ask for
  • Article 4 principles compliance file
  • Lawful-basis-of-processing record per processing activity
  • Consent capture + management procedure
Where this commonly fails
  • Lawful basis not documented per processing activity
  • Consent capture without explicit opt-in or without revocation pathway
  • Storage limitation not enforced (no retention schedule)

UAE PDPL: Scope, Definitions and Applicability (Articles 1-3)

UAE-PDPL-Art.1_2_3
Scope, definitions and applicability (UAE PDPL Articles 1-3)

Article 1 provides definitions of key terms including: PERSONAL DATA = any data related to an identified or identifiable natural person; SENSITIVE PERSONAL DATA = data revealing racial / ethnic origin, political opinions, religious beliefs, biometric / genetic / health data, criminal records; CONTROLLER / PROCESSOR; DATA SUBJECT; CONSENT; CROSS-BORDER TRANSFER; UAE DATA OFFICE. Article 2 scope: the Law applies to (a) any controller / processor in the UAE; (b) any controller / processor outside the UAE that processes personal data of data subjects in the UAE (extraterritorial scope similar to GDPR Article 3). Article 3 exclusions: the Law does NOT apply within the financial free zones (DIFC + ADGM maintain own sectoral DP regimes) + does NOT apply to personal data held by competent UAE security authorities + does NOT apply to certain personal-personal-or-household processing. The Law is a

Artefacts an auditor will ask for
  • Internal scope memo identifying processing in or for UAE data subjects
  • DIFC / ADGM / sectoral free-zone coordination analysis
  • Definitional walk-through aligned with Article 1
Where this commonly fails
  • Extraterritorial processing not assessed
  • DIFC / ADGM processing wrongly subject to federal PDPL
  • Sensitive personal data not separately classified per Article 1

UAE PDPL: Sensitive Personal Data and Children (Articles 6-7)

UAE-PDPL-Art.6_7
Sensitive personal data and children's data (UAE PDPL Articles 6-7)

Article 6 (SENSITIVE PERSONAL DATA) - processing of sensitive personal data is PROHIBITED unless one of specific conditions applies: (a) EXPLICIT consent (heightened beyond ordinary consent); (b) processing necessary to protect VITAL interests where data subject is physically / legally incapable; (c) processing carried out by a non-profit body + the data relates to its members + is necessary for the body's activities; (d) processing necessary for substantial PUBLIC INTEREST or LEGAL CLAIMS; (e) processing for occupational MEDICINE / public health / clinical research. Sensitive personal data includes racial / ethnic origin + political opinions + religious / philosophical beliefs + trade union membership + genetic / biometric data for unique identification + health data + sex life / sexual orientation. Article 7 (CHILDREN'S DATA) - processing of personal data of children under 16 years old

Artefacts an auditor will ask for
  • Sensitive-data classification + condition documentation
  • Children's age-verification process
  • Parental consent capture + verification
Where this commonly fails
  • Sensitive data processed under ordinary consent
  • Children's data without age verification
  • No specific assessment for child best-interest

UAE PDPL: UAE Data Office, Penalties, Free Zones (Articles 25-29 and Free Zone Coordination)

UAE-PDPL-Art.25_26_27_28_29
UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)

Articles 25-29 establish the UAE DATA OFFICE + its powers + administrative enforcement: (Art 25) ESTABLISHMENT - the UAE Data Office is a federal body established within the Cabinet structure + reports to the federal government; (Art 26) FUNCTIONS - issue executive regulations + guidance + handle data subject complaints + investigate breaches + impose administrative penalties + cooperate with international counterparts + promote data protection awareness; (Art 27) DATA SUBJECT COMPLAINTS - data subjects may file complaints with the UAE Data Office regarding controller / processor compliance + the Data Office investigates + issues binding decisions; (Art 28) ADMINISTRATIVE PENALTIES - the Data Office may impose administrative penalties for non-compliance including: written warnings + suspension of processing + administrative fines (currently up to AED 5 million per violation + escalating

Artefacts an auditor will ask for
  • Data Office engagement + cooperation procedure
  • Complaint-response procedure
  • Penalty exposure in compliance risk register
  • Public-guidance tracking
Where this commonly fails
  • No documented Data Office engagement procedure
  • Penalty exposure not mapped + no internal escalation
  • Data Office public guidance not tracked
UAE-PDPL-FreeZones
Coordination with DIFC, ADGM and sectoral data protection regimes

Article 3 of the UAE Federal Decree-Law No. 45 of 2021 expressly EXCLUDES financial free zones from the federal PDPL scope. The financial free zones have their own sectoral data protection regimes: (a) DUBAI INTERNATIONAL FINANCIAL CENTRE (DIFC) - DIFC Data Protection Law No. 5 of 2020 (replaced DIFC DP Law 1 of 2007) administered by the DIFC Commissioner of Data Protection; (b) ABU DHABI GLOBAL MARKET (ADGM) - ADGM Data Protection Regulations 2021 administered by the ADGM Office of Data Protection. Sectoral laws also exist: FEDERAL LAW NO. 2 OF 2019 on the Use of Information and Communications Technology in Health Fields (Health Data Law) administered by the UAE Ministry of Health and Prevention. Multi-jurisdictional entities operating across mainland UAE + DIFC + ADGM must apply the relevant regime per jurisdiction + ensure cross-jurisdictional consistency. Free-zone-to-federal cross-b

Artefacts an auditor will ask for
  • Jurisdiction map identifying mainland UAE + DIFC + ADGM operations
  • Sectoral compliance matrix (federal PDPL + DIFC + ADGM + Health Data Law)
  • Cross-jurisdiction data transfer procedure
Where this commonly fails
  • Single compliance program treating all UAE operations as federal-PDPL
  • DIFC / ADGM operations applying federal PDPL incorrectly
  • Health-data processing without Federal Law 2/2019 alignment
UAE-PDPL-Status
UAE PDPL status, executive regulations, UAE Data Office guidance evolution

The UAE Federal Decree-Law No. 45 of 2021 entered into force on 2 January 2022 (six months after publication on 28 November 2021). EXECUTIVE REGULATIONS + UAE DATA OFFICE GUIDANCE continue to evolve: the Data Office has issued a series of public guidance documents on cross-border transfers + DPIAs + sensitive data + AI / automated decision-making + minors + records + cooperation; the executive regulations operationalise the PDPL provisions including registration requirements + appointment of DPOs + cross-border transfer mechanisms + breach notification timelines. The 2024-2025 enforcement landscape includes: initial Data Office investigations + complaints + administrative penalties (the first penalties typically up to AED 5 million per violation + escalating for repeat); public consultations on AI + Generative AI data protection considerations; alignment with international data protectio

Artefacts an auditor will ask for
  • Tracking of UAE Data Office public guidance + executive regulation updates
  • International alignment (GDPR + CBPR) cross-reference matrix
  • AI / Generative AI data protection guidance integration
Where this commonly fails
  • Compliance program tied to 2021 baseline without tracking 2024-2025 Data Office guidance
  • AI / Generative AI data protection not assessed
  • International alignment limited to GDPR without CBPR / GCC
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.