Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Sensitive Personal Data and Children (Articles 6-7)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.6_7: Sensitive personal data and children's data (UAE PDPL Articles 6-7)

Article 6 (SENSITIVE PERSONAL DATA) - processing of sensitive personal data is PROHIBITED unless one of specific conditions applies: (a) EXPLICIT consent (heightened beyond ordinary consent); (b) processing necessary to protect VITAL interests where data subject is physically / legally incapable; (c) processing carried out by a non-profit body + the data relates to its members + is necessary for the body's activities; (d) processing necessary for substantial PUBLIC INTEREST or LEGAL CLAIMS; (e) processing for occupational MEDICINE / public health / clinical research. Sensitive personal data includes racial / ethnic origin + political opinions + religious / philosophical beliefs + trade union membership + genetic / biometric data for unique identification + health data + sex life / sexual orientation. Article 7 (CHILDREN'S DATA) - processing of personal data of children under 16 years old requires the consent of the holder of parental responsibility; the controller must make reasonable efforts to verify that consent is given by the parent (or legal guardian); the consent verification mechanism must be proportionate to the available technology + risk; specific protections + special-care for children's data + the requirement that children's data is processed only where there is a clear + legitimate reason in the child's best interest.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 248 controls across 137 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A33 Request for Disclosure of Retained Personal Data

MARS-E · 4 controls

API 1164 · 3 controls

  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 27019 · 3 controls

ISO 27043 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/SAE 21434 · 3 controls

MDS2 (Medical Device) · 3 controls

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

GDPR · 2 controls

  • GDPR-Art.8 Conditions applicable to child's consent
  • GDPR-Art.9 Processing of special categories of personal data

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

MITRE ATT&CK · 2 controls

  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles

OWASP ASVS · 2 controls

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 2 controls

Bahrain PDPL · 1 control

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

HITECH Act · 1 control

  • 62351-8 Role-based access control (RBAC)

IEEE 1686 · 1 control

ISO 20000-1 · 1 control

ITIL 4 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OWASP Top 10:2025 · 1 control

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

SOC 2 · 1 control

  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea PIPA · 1 control

  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 248 it maps to, and the evidence behind each claim, over MCP and REST.