Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: UAE Data Office, Penalties, Free Zones (Articles 25-29 and Free Zone Coordination)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.25_26_27_28_29: UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)

Articles 25-29 establish the UAE DATA OFFICE + its powers + administrative enforcement: (Art 25) ESTABLISHMENT - the UAE Data Office is a federal body established within the Cabinet structure + reports to the federal government; (Art 26) FUNCTIONS - issue executive regulations + guidance + handle data subject complaints + investigate breaches + impose administrative penalties + cooperate with international counterparts + promote data protection awareness; (Art 27) DATA SUBJECT COMPLAINTS - data subjects may file complaints with the UAE Data Office regarding controller / processor compliance + the Data Office investigates + issues binding decisions; (Art 28) ADMINISTRATIVE PENALTIES - the Data Office may impose administrative penalties for non-compliance including: written warnings + suspension of processing + administrative fines (currently up to AED 5 million per violation + escalating for repeat violations + considering the violation's severity + harm caused + cooperation); (Art 29) PUBLICATION + APPEALS - decisions may be published + are subject to administrative + judicial appeal under UAE administrative law. The 2024 enforcement landscape includes initial UAE Data Office consultations + investigations + several public guidance documents on cross-border transfers + DPIAs + sensitive data + AI / automated decision-making.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 128 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 29134:2023 · 3 controls

  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

API 1164 · 2 controls

  • R.16-VATR.Scope Scope and applicability of Travel Rule to VASPs (R.16 + Interpretive Note to R.15/R.16)
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 29147:2018 · 2 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • PMF-SP.3 Security Testing and Monitoring

APPI · 1 control

  • APPI-A31 Provision of Personally Referable Information
  • 4.3.1 Risk Assessment and Impact Analysis
  • APP-8 APP 8 - Cross-border disclosure of personal information

Bahrain PDPL · 1 control

  • BH-PDPL-18 Regular security testing and assessment

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

GLBA · 1 control

HKMA SPM · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 27400:2022 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance
  • 3.11 Encrypt Sensitive Data at Rest
  • NHPA-6 Reasonable Data Security and Breach Response
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-4 Children's Data, Privacy Impact, Sensitive Categories

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • RUSPD-4 Special Categories, Biometric Data

Saudi Arabia PDPL · 1 control

  • SA-PDPL-18 Regular security testing and assessment

South Korea PIPA · 1 control

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in UAE PDPL: UAE Data Office, Penalties, Free Zones (Articles 25-29 and Free Zone Coordination)

Query this from an agent

The graph holds this control, the 128 it maps to, and the evidence behind each claim, over MCP and REST.