Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Lawful Basis, Consent and Principles (Articles 4-6)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.4_5: Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

Article 4 establishes the PRINCIPLES for processing: (a) processed in a fair + transparent + lawful manner; (b) collected for specified + clear + legitimate purposes (purpose limitation); (c) limited to what is necessary (data minimization); (d) accurate + kept up to date (accuracy); (e) retained only as long as necessary (storage limitation); (f) processed with appropriate security measures (integrity + confidentiality). Article 5 establishes the LAWFUL BASES for processing: (a) data subject CONSENT; (b) performance of a CONTRACT or pre-contractual steps; (c) compliance with a LEGAL OBLIGATION; (d) protection of VITAL INTERESTS; (e) performance of a TASK IN THE PUBLIC INTEREST; (f) LEGITIMATE INTERESTS of the controller / processor or a third party (balanced against data subject rights); (g) processing of personal data necessary for the realisation of historical / statistical / scientific RESEARCH purposes. Consent (Article 5(a)) must be freely given + specific + informed + explicit + revocable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 440 controls across 185 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.5 Principles relating to processing of personal data
  • GDPR-Art.6 Lawfulness of processing
  • GDPR-Art.7 Conditions for consent
  • GDPR-Art.9 Processing of special categories of personal data
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 4 controls

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

MARS-E · 4 controls

Malaysia PDPA 2010 · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

Liechtenstein DPA · 3 controls

Mauritius DPA · 3 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7

NIST SP 800-122 · 3 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling

NIST SP 800-53 Rev 5 · 3 controls

  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

POPIA · 3 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

Peru DPL · 3 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements
  • PERU-7 DPO, Records, Retention, Marketing, Training

Qatar DPL · 3 controls

  • QATAR-3 Data Subject Rights
  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training

SASB Standards · 3 controls

SOC 2 · 3 controls

  • SOC2-P3.1 Personal information is collected consistent with privacy commitments
  • SOC2-P4.3 Personal information is securely disposed of
  • SOC2-P6.1 Personal information is disclosed to third parties only as committed

Saudi Arabia PDPL · 3 controls

South Korea ISMS-P · 3 controls

  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)

ISO 13485 · 2 controls

ISO 27799 · 2 controls

ISO/IEC 27014:2020 · 2 controls

India DPDP Act · 2 controls

Indonesia PDP Law · 2 controls

Mexico LFPDPPP · 2 controls

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

PTES · 2 controls

  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication

South Korea PIPA · 2 controls

Taiwan PDPA · 2 controls

Vietnam PDPD · 2 controls

  • ASD37-17 TLS encryption between email servers (Limited)
  • DS-2 Ensure software supply chain security

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data
  • CA-10 Selects and Develops Control Activities

FIDO2 / WebAuthn · 1 control

FISMA · 1 control

GLBA · 1 control

  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

HITECH Act · 1 control

HKMA SPM · 1 control

  • 62351-9 Cyber security key management

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 19011 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security
  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

NIST SP 800-61 · 1 control

  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification

NIST SP 800-88 · 1 control

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RCEPEC-1 Online Personal Information Protection (12.13)

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SAPAIA-4 Information Regulator Cooperation and Appeals
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)
  • SO3.2 Regulatory frameworks for digital health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 440 it maps to, and the evidence behind each claim, over MCP and REST.