Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Cross-Border Transfers (Articles 22-24)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.22_23_24: Cross-border data transfers (UAE PDPL Articles 22-24)

Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection; (b) APPROPRIATE SAFEGUARDS - binding contractual clauses similar to GDPR SCCs + binding corporate rules (BCRs) + approved certification mechanisms; (c) EXCEPTIONS - explicit consent of the data subject for the transfer + necessity for performance of a contract + necessity for important reasons of public interest + necessity for the establishment / exercise / defence of legal claims + necessity to protect vital interests + necessity for compelling legitimate interests of the controller proportionate to data subject rights. Article 23 (PROHIBITIONS) - certain transfers are PROHIBITED where they would jeopardise the rights + freedoms of data subjects or where the destination country has been designated as inadequate. Article 24 (NOTIFICATIONS) - controllers must notify the UAE Data Office of cross-border transfers + maintain records. UAE-Data-Office-approved transfer mechanisms include: data subject consent + contractual SCCs + BCRs + adequacy decisions. The 2024 UAE Data Office issued initial adequacy decisions for certain jurisdictions including GDPR-aligned countries (subject to ongoing review).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 76 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • CH-FADP-24 Cross-border transfer safeguards
  • FADP-10 Cross-Border Disclosure (Articles 16-18)
  • APP-8 APP 8 - Cross-border disclosure of personal information

Bahrain PDPL · 1 control

  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • ICP-25 Supervisory Cooperation and Coordination

India DPDP Act · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

NIST SP 800-122 · 1 control

  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 1 control

  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 1 control

  • PDPATH-6 Cross-Border Transfer and Processor Engagement

POPIA · 1 control

  • POPIASA-6 Transborder Information Flows, Direct Marketing
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • NORWAY-6 International Transfers and Processor Agreements
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers

Privacy Act 2020 · 1 control

  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)

Qatar DPL · 1 control

  • QATAR-6 Cross-Border Transfer and Processor Management
  • RCEPEC-2 Cross-Border Transfer, Computing Facilities, Localization (12.14-15)
  • RUSPD-4 Special Categories, Biometric Data

Saudi Arabia PDPL · 1 control

South Korea ISMS-P · 1 control

South Korea PIPA · 1 control

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.