Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) UAE-PDPL-Art.8: Records of processing activities (UAE PDPL Article 8)

Article 8 imposes the RECORDS-OF-PROCESSING-ACTIVITIES requirement on controllers + processors. The records must include: (a) name + contact details of the controller / processor + the DPO if any + the joint controller + the representative; (b) purposes of processing; (c) description of categories of data subjects + categories of personal data; (d) categories of recipients to whom personal data has been or will be disclosed; (e) cross-border transfers + the legal basis for transfer; (f) envisaged retention periods; (g) general description of technical + organizational security measures. Records must be maintained in writing + electronic form + made available to the UAE Data Office upon request. The records must be UPDATED + reviewed periodically + retained beyond the processing period in line with the audit-trail expectations. Records are the foundational compliance artefact for UAE PDPL programmes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 64 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk

GDPR · 2 controls

HITECH Act · 2 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)
  • SO2.3 Open-source health data standards
  • SO3.4 Standards and interoperability governance

APPI · 1 control

  • APPI-A27 Restriction on Provision to Third Parties
  • P3-S3 Cooperative Arrangements/Procedures
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

PDPA Singapore · 1 control

  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights

PDPA Thailand · 1 control

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy

POPIA · 1 control

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • NORWAY-2 Data Subject Rights and Automated Decision-Making

Peru DPL · 1 control

  • PERU-5 Security of Personal Data and Processor Agreements
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy

Qatar DPL · 1 control

  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data

Turkey KVKK · 1 control

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in UAE PDPL: Controller and Processor Obligations (Articles 8-10, 18-21)

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.