Compliance/Global/UAE PDPL
Thirty-one articles: sixteen leave evidence in the file.
The Decree-Law makes the controller and processor responsible for personal data processed in the UAE. Vaultize adds records that stay with the file.
- Federal Decree-Law No. 45 of 2021
- Issued 20 September 2021
- Effective 2 January 2022
- Capability mapping, not legal advice
5(6)Processing rules
Personal Data must be kept securely and protected from any breach, infringement, or illegal or unauthorized Processing by establishing and applying appropriate technical and organizational measures and procedures in accordance with the laws and legislation in force in this regard.
Vaultize Seal · Vaultize Secure
A
Definitions and scope
0 of 3
- 1
- 2
- 3
B
Processing rules
1 of 3
- 4
- 5
- 6
C
Controller and processor duties
3 of 6
- 7
- 8
- 9
- 10
- 11
- 12
D
Rights of the data subject
2 of 7
- 13
- 14
- 15
- 16
- 17
- 18
- 19
E
Security and impact assessment
1 of 2
- 20
- 21
F
Cross-border transfer
1 of 2
- 22
- 23
G
Data Office and penalties
0 of 5
- 24
- 25
- 26
- 27
- 28
H
Final provisions
0 of 3
- 29
- 30
- 31
The answer in 30 seconds
Vaultize adds file-level records to sixteen provisions across eight articles, in five of the groups we have drawn from the Decree-Law: the processing controls, controller and processor obligations, rights of the data subject, personal data security, and cross-border transfer. Scope, the Data Office's complaints and penalties process, and the Decree-Law's final provisions sit outside a governed file, with the organisation and its counsel.
The Decree-Law in one view
Thirty-one articles. No chapters. Where file evidence lands.
The Decree-Law has no chapters. The groups below are ours, drawn from the article titles in article order. Select a group to see which of its articles a governed file can evidence.
A
Definitions and scope
Articles 1 to 3. The definitions the Decree-Law uses, who and what falls within its scope, the personal data and organisations it excludes, and the Office's power to exempt smaller Establishments.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Scope, definitions and exemptions are matters for counsel. A governed file adds no evidence here.
- Evidence to retain
- None from Vaultize.
Article by article
What each provision asks. What the file can answer.
Wording is quoted from an unofficial English translation of Federal Decree-Law No. 45 of 2021, published by Lexis Middle East. The UAE Government's own text of the Decree-Law is Arabic only. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Decree-Law and take advice on applicability, roles and lawful basis.
Using this page
Where these rows fit in a UAE PDPL programme.
The Decree-Law has applied since 2 January 2022. The rows above are evidence for the obligations that touch documents.
- 1
Confirm scope
Articles 2 and 3. Whether the Data Subject, Controller or Processor falls within the Decree-Law, and its exclusions for government data, security and judicial authorities, health and banking data under their own legislation, and free zones with their own Personal Data Protection legislation.
- 2
Apply the processing rules
Articles 4 to 6. The lawful cases for processing without consent, the controls that apply to every processing activity, and the conditions a valid consent must meet.
- 3
Apply the security measures
Article 20. Encryption and pseudonymisation, confidentiality and resilience of processing systems, and timely restoration after a failure. These rows belong here.
Bring the sixteen rows above as evidence of the technical and organisational measures Article 20 requires.
- 4
Report a breach to the Data Office
Article 9. Report the breach and the investigation to the Office within the period the Executive Regulations set, and notify the Data Subject where the breach would prejudice their privacy.
- 5
Assess a cross-border transfer
Articles 22 and 23. Whether the destination has an adequate level of protection recognised by the Office, or one of the safeguards and derogations applies.
Responsibility boundary
Controls support compliance. They are not legal advice.
Vaultize contributes technical measures and evidence for documents that carry personal data. It does not decide whether the Decree-Law applies, appoint or act as the Data Protection Officer, carry out the impact assessment Article 21 requires, or decide whether a cross-border transfer meets Articles 22 and 23 in full. Read the Decree-Law and take qualified advice before relying on this page.
“The Controller and Processor shall establish and take appropriate technical and organizational measures and procedures to ensure achievement of the information security level that is commensurate with the risks associated with Processing, in accordance with the best international standards and practices, which may include the following:”
Article 20(1), Federal Decree-Law No. 45 of 2021 (UAE PDPL)
Official references
Read the source before relying on the mapping.
The first item is the Decree-Law on the UAE legislation portal. Article wording on this page comes from the second, an unofficial English translation, because the UAE Government's own text is published in Arabic only. The third is the UAE Government's page on data protection laws.
- Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal DataThe Decree-Law on the UAE Government's legislation portal. The authoritative text is the Arabic.
- Federal Decree-Law No. 45 of 2021, English translation by Lexis Middle EastUnofficial English translation. Every article quoted on this page is from it.
- u.ae: Data protection lawsThe Official Platform of the UAE Government's data protection laws page. It links the Decree-Law and states that its own PDF is available in Arabic only.
A practical next step
Bring one document that carries personal data.
We will show which articles the governed document can evidence today. We will name the owner responsible for the rest.
