← All frameworks
GCC GCC · 8 Policy & Process · UAE

PDPL – Federal Decree-Law 45/2021

PDPL – Federal Decree-Law 45/2021 (UAE)

29 controls · 8 domains
Mandatory for: Data-protection law
Start assessment in platform →

About this framework

The UAE's Personal Data Protection Law (Federal Decree-Law 45/2021) is the federal framework for handling personal data. It sets rules for consent, security, and cross-border transfers, and gives individuals rights over their data.

Who needs this

For organisations handling the personal data of people in the UAE.

Cross-framework coverage

Controls in PDPL – Federal Decree-Law 45/2021 also cover:

ADHICS 12 shared
GDPR (EU) 12 shared
PDPL 12 shared
PDPL 12 shared

See how PDPL – Federal Decree-Law 45/2021 connects to the rest → the Security Universe

Control domains

DP1 · Governance & Accountability 5
DP1.1
Accountability & compliance ownership
Assign clear ownership and demonstrate compliance with the data-protection law through documented policies, decisions, and evidence of personal-data processing being managed lawfully.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
DP1.2
Data protection officer / responsible person
Designate a data protection officer or equivalent responsible person where required, with defined responsibilities for advising on and monitoring data-protection compliance.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
DP1.3
Records of processing activities
Maintain records of personal-data processing activities, including purposes, categories of data and data subjects, recipients, and retention periods.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP1.4
Data protection by design and by default
Embed data-protection requirements into the design of systems and processes, defaulting to the minimum personal data necessary for each purpose.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP1.5
Data protection impact assessment
Assess and document the privacy risks of high-risk processing before it begins, and apply measures to mitigate identified risks to data subjects.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP2 · Lawful Basis & Consent 3
DP2.1
Lawful basis for processing
Establish and record a valid lawful basis for each processing activity (e.g. consent, contract, legal obligation, or legitimate interest as recognised by the applicable law).
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP2.2
Consent management
Where processing relies on consent, obtain it freely, specifically, and unambiguously, keep records of consent, and provide an accessible means to withdraw it.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP2.3
Processing of sensitive personal data
Apply the additional conditions and safeguards required for sensitive / special categories of personal data before processing them.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP3 · Data Subject Rights 4
DP3.1
Right of access
Provide data subjects with a means to obtain confirmation of, and access to, the personal data held about them within the statutory timeframe.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP3.2
Rights to rectification and erasure
Enable data subjects to have inaccurate personal data corrected and, where applicable, to have their personal data erased.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP3.3
Rights to object, restrict and port
Support data subjects' rights to object to or restrict processing and, where provided by the law, to receive or transfer their data in a portable format.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP3.4
Safeguards for automated decision-making
Provide safeguards, including human review where required, for decisions based solely on automated processing or profiling that significantly affect data subjects.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP4 · Transparency & Data Minimisation 2
DP4.1
Privacy notice and transparency
Inform data subjects clearly about who processes their data, for what purposes, on what basis, and how to exercise their rights, at or before the point of collection.
UK GDPRADHICSGDPR (EU)PDPLData-protection rulesPDPPL
DP4.2
Purpose limitation and data minimisation
Collect personal data only for specified, legitimate purposes and limit it to what is adequate, relevant, and necessary for those purposes.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP5 · Data Security Measures 6
DP5.1
Technical and organisational security measures
Implement appropriate technical and organisational measures to protect personal data, proportionate to the risk to data subjects.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPRNCA CCC
DP5.2
Access control to personal data
Restrict access to personal data to authorised personnel on a least-privilege, need-to-know basis, with access reviewed periodically.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP5.3
Encryption and pseudonymisation
Apply encryption and/or pseudonymisation to personal data in transit and at rest, proportionate to its sensitivity and the risk to data subjects.
UAE IACJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUK GDPR
DP5.4
Data classification and handling
Classify personal data by sensitivity and apply handling, retention, and disposal rules consistent with its classification.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP5.5
Logging and monitoring of processing
Log and monitor access to and processing of personal data to detect and investigate unauthorised or unlawful activity.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP5.6
Confidentiality, integrity, availability and resilience
Maintain the confidentiality, integrity, availability, and resilience of processing systems and restore access to personal data after an incident.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPR
DP6 · Personal Data Breach Management 3
DP6.1
Breach detection and response
Establish processes to detect, assess, contain, and respond to personal data breaches.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP6.2
Breach notification to the regulator
Notify the competent regulator of qualifying personal data breaches within the timeframe and in the manner required by the applicable law.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP6.3
Breach communication to data subjects
Communicate high-risk personal data breaches to affected data subjects where required, with clear information and recommended actions.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP7 · Cross-Border Transfer 3
DP7.1
Conditions for cross-border transfer
Transfer personal data outside the jurisdiction only where the conditions set by the applicable law are met.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP7.2
Transfer safeguards and adequacy
Apply appropriate safeguards (e.g. adequacy findings, contractual clauses, or approved mechanisms) to international transfers of personal data.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP7.3
Data localisation requirements
Identify and meet any data-localisation or in-country storage requirements applicable to specific categories of personal data.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAUAE IAUK GDPRNCA CCC
DP8 · Processor & Third-Party Management 3
DP8.1
Processor obligations and contracts
Engage processors only under binding agreements that set out the subject matter, scope, and data-protection obligations of the processing.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP8.2
Sub-processor management
Authorise and control the use of sub-processors, ensuring equivalent data-protection obligations flow down the supply chain.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR
DP8.3
Due diligence and oversight of processors
Conduct due diligence on processors before engagement and monitor their compliance with data-protection obligations throughout the relationship.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIASAMA CSFUAE IAUK GDPR

Ready to assess against PDPL – Federal Decree-Law 45/2021?

Start free trial →

Where to go next

See it priced

Map PDPL – Federal Decree-Law 45/2021 on any plan — active frameworks scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →