Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Data Subject Rights (Articles 11-16)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.11_12_13_14_15_16: Data subject rights (UAE PDPL Articles 11-16)

Articles 11-16 establish the DATA SUBJECT RIGHTS regime. Each right is exercisable through a request to the controller + the controller must respond within reasonable time (Data Office guidance suggests 30 days). The 6 rights: (Art 11) RIGHT TO INFORMATION + transparency about processing (similar to GDPR Articles 13-14); (Art 12) RIGHT OF ACCESS - obtain confirmation + a copy of personal data being processed; (Art 13) RIGHT TO RECTIFICATION + correction of inaccurate personal data; (Art 14) RIGHT TO ERASURE (right to be forgotten) in specified circumstances - withdrawal of consent + processing unlawful + objection + data no longer necessary; (Art 15) RIGHT TO RESTRICT PROCESSING + RIGHT TO DATA PORTABILITY in machine-readable + interoperable format; (Art 16) RIGHT TO OBJECT TO PROCESSING (including direct marketing + processing based on legitimate interests) + RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING that produces legal effects or similarly significantly affects the data subject. The rights can be restricted only on specified grounds (legal claims + public-interest research + statistical purposes + national security + compliance with another law).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 88 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

  • 3.3 Configure Data Access Control Lists

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.