Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.18_19_20_21: Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

Article 18 (SECURITY MEASURES) - controllers + processors must implement appropriate TECHNICAL + ORGANIZATIONAL MEASURES proportionate to the nature + scope + purposes + risk of processing to ensure confidentiality + integrity + availability of personal data + protection against unauthorised access + disclosure + alteration + accidental loss. Article 19 (PSEUDONYMISATION + ENCRYPTION + PRIVACY BY DESIGN) - controllers must apply pseudonymisation / encryption where appropriate + apply DATA PROTECTION BY DESIGN AND BY DEFAULT principles. Article 20 (CONTROLLER + PROCESSOR RELATIONSHIP) - the controller must engage processors only where they provide sufficient guarantees of GDPR-style technical + organisational measures; the relationship must be governed by a WRITTEN CONTRACT (Data Processing Agreement DPA) specifying processing details + technical + organisational measures + sub-processor controls + breach notification + return / destruction at end of contract + audit rights. Article 21 (DATA PROTECTION IMPACT ASSESSMENT / DPIA) - controllers must conduct a DPIA before processing that is LIKELY TO RESULT IN A HIGH RISK to the rights + freedoms of data subjects. The DPIA must include a description of the processing + assessment of necessity + assessment of risks + mitigation measures. The UAE Data Office may issue guidance on which processing requires a DPIA + may consult with the controller (prior consultation).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 851 controls across 245 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 10 controls

Saudi Arabia PDPL · 9 controls

Bahrain PDPL · 8 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

BSI IT-Grundschutz · 6 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing

Mauritius DPA · 6 controls

NIST SP 800-53 Rev 5 · 6 controls

PDPA Singapore · 6 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data
  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight
  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

South Korea ISMS-P · 6 controls

API 1164 · 5 controls

APPI · 5 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

IEC 62443 · 5 controls

ISO 27017 · 5 controls

ISO 27018 · 5 controls

ISO 27019 · 5 controls

ISO/IEC 23894:2023 · 5 controls

ISO/IEC 27400:2022 · 5 controls

MTCS (Singapore) · 5 controls

Malaysia PDPA 2010 · 5 controls

Mexico LFPDPPP · 5 controls

  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 5 controls

NIST SP 800-122 · 5 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling
  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-190 · 5 controls

  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight

PDPA Thailand · 5 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-6 Cross-Border Transfer and Processor Engagement
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 5 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • PERU-5 Security of Personal Data and Processor Agreements
  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 5 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-7 Notifiable Privacy Breach Scheme
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

SOC 2 · 5 controls

  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC7.5 Identifies the root cause of security incidents
  • SOC2-P3.1 Personal information is collected consistent with privacy commitments
  • SOC2-P4.3 Personal information is securely disposed of
  • SOC2-P6.1 Personal information is disclosed to third parties only as committed
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

ISO 13485 · 4 controls

ISO 27799 · 4 controls

Indonesia PDP Law · 4 controls

Liechtenstein DPA · 4 controls

NIST SP 800-144 · 4 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

POPIA · 4 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Qatar DPL · 4 controls

  • QATAR-3 Data Subject Rights
  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • QATAR-8 Breach Notification, Compliance, Enforcement

South Korea PIPA · 4 controls

  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • RMD-2 Master Data Management

FDA 21 CFR Part 11 · 3 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

FISMA · 3 controls

FedRAMP Rev 5 · 3 controls

IEEE 7000 · 3 controls

ISMAP (Japan) · 3 controls

ISO 22320:2018 · 3 controls

ISO 27005 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

India DPDP Act · 3 controls

LGPD · 3 controls

MARS-E · 3 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7

NIST SP 800-145 · 3 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 3 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

SASB Standards · 3 controls

  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR

Taiwan PDPA · 3 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)

Vietnam PDPD · 3 controls

  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-13 Board Accountability for Operational Risk Management

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.7 Emergency and Incident Response
  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures

GLBA · 2 controls

IEEE 1686 · 2 controls

ISO/IEC 27003:2017 · 2 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 29147:2018 · 2 controls

ISO/IEC 30111:2019 · 2 controls

Japan AI Guidelines · 2 controls

MDS2 (Medical Device) · 2 controls

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection

NIST SP 800-66 · 2 controls

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process

PSD2 SCA · 2 controls

  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • PSDTWO-4 Fraud Reporting and Incident Management
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • SCA-S10 Annual Risk Assessment
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEF-2 Openness and Transparency
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Turkey KVKK · 2 controls

  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • SO3.2 Regulatory frameworks for digital health
  • SO3.3 Data governance and protection
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • DS-2 Ensure software supply chain security
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures
  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

HITECH Act · 1 control

HKMA SPM · 1 control

ISO 20000-1 · 1 control

ISO 22000 · 1 control

ISO 26000:2010 · 1 control

ISO 45001 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27031:2011 · 1 control

ITIL 4 · 1 control

  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • DSOMM-1 Culture, Organization, Education, and Governance
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning
  • PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SAPAIA-4 Information Regulator Cooperation and Appeals
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • UKOPRES-3 Self-Assessment and Board Engagement
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)

Query this from an agent

The graph holds this control, the 851 it maps to, and the evidence behind each claim, over MCP and REST.