UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) compliance software
The UAE's federal data protection law, article by article — 43 obligations on controllers and processors from lawful basis and consent to breach reporting, data subject rights and cross-border transfer, with the points the Executive Regulations will settle flagged as such.
- RegulatorUAE Data Office (Decree-Law 44/2021)
- InstrumentFederal Decree-Law No. 45 of 2021 — in force 2 January 2022; Executive Regulations pending
- Structure8 article groups (Arts 4–23), 43 controls, each citing its article
- Out of scopeDIFC and ADGM (own laws); government data; sector-regulated health and banking data
What UAE PDPL requires
Who it applies to
- Controllers and processors established onshore in the UAE
- Organisations outside the UAE processing the personal data of UAE data subjects
- Organisations required to appoint a Data Protection Officer under Article 10
- Controllers transferring personal data outside the UAE
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the UAE's first comprehensive federal privacy law, in force since 2 January 2022 and administered by the UAE Data Office established under Decree-Law No. 44 of 2021. It applies to controllers and processors established in the UAE or processing the personal data of UAE data subjects — but not inside the DIFC and ADGM, which have their own data protection laws, nor to government data and certain regulated health and banking data governed by their own legislation.
Articles 4 to 23 carry the obligations: a lawful basis and valid consent, processing controls, controller and processor duties, breach reporting to the Data Office and to affected individuals, appointment and independence of a Data Protection Officer, the data subject's rights of access, portability, correction, erasure, restriction and objection, security and impact assessment, and controls on cross-border transfer. Several details — breach reporting periods, the transfer mechanisms — are left to Executive Regulations that had still not been issued when this catalogue was built; each affected control says so in its reference.
GRCLens groups the obligations by article, cites the article on every control, and shares its processing, request and breach registers with the ISO/IEC 27001 and ISO/IEC 42001 assessments in the same tenant.
How GRCLens supports UAE PDPL
UAE PDPL runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Article by article
Lawful basis and consent (4, 6), processing controls (5, 7), processor obligations (8), breach reporting with its six prescribed items (9), the DPO (10–12), the seven data subject rights (13–19), security and impact assessment (20–21), cross-border transfer (22–23).
Honest about the Regulations
Where the Decree-Law defers to Executive Regulations still to be issued — breach reporting periods, transfer mechanisms — the control's reference says so, and the catalogue is revised when they land rather than guessed at now.
Registers shared with the security programme
Processing activities, data subject requests and breach records live in the same registers the ISO/IEC 27001 and ISO/IEC 42001 assessments read.
Arabic and English
The catalogue uses the official Arabic text's terminology, so the privacy officer and the Data Office read the same words.
UAE PDPL frequently asked questions
Does the UAE PDPL apply in the DIFC and ADGM?
No. Both free zones have their own data protection laws — DIFC Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 — administered by their own commissioners. The federal law applies onshore and to foreign processing of UAE data subjects' personal data.
Have the Executive Regulations been issued?
Not at the time this catalogue was built. Controls whose detail depends on them — breach reporting periods, the transfer mechanisms — are marked as pending in their reference, and the catalogue will be updated when the Regulations are published.
How does this relate to the Saudi PDPL?
They are separate laws with separate regulators (the UAE Data Office and SDAIA). GRCLens carries both as separate frameworks on the same control model, so a group operating in both countries assesses shared privacy controls once.
One platform, many obligations

Talk to us about UAE PDPL
Security Solution Consultants provides UAE PDPL and privacy advisory alongside the platform, so you can combine tooling with hands-on expertise.