Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), together with the DIFC Data Protection Law (Law No. 5 of 2020) and the ADGM Data Protection Regulations (Regulation 13 of 2021).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Breach Notification
| Code | Title |
|---|---|
| Art.9 | Authorization Requirement |
Consent
| Code | Title |
|---|---|
| Art.6 | Processing of Sensitive Data |
| PDPL-DirectMarketing | Direct Marketing and Electronic Communications |
Controller/Processor Obligations
| Code | Title |
|---|---|
| Art.12 | Prohibition of Illegal Interception |
| Art.20 | Service Provider Duties |
| Art.21 | Functions of the SIC Specific to Personal Data |
| Art.7 | Children's Data |
| Art.8 | Rights of Data Subjects |
Cross-Border
| Code | Title |
|---|---|
| Art.22 | Cooperation with Authorities |
| Art.23 | Sanctions |
DPO
| Code | Title |
|---|---|
| Art.10 | Cases When Authorization Is Not Required |
| Art.11 | Prohibition of Illegal Access |
Data Subject Rights
| Code | Title |
|---|---|
| Art.13 | Prohibition of Data Interference |
| Art.14 | Prohibition of System Interference |
| Art.15 | Misuse of Devices |
| Art.16 | Computer-Related Forgery and Fraud |
| Art.17 | Content-Related Offences |
| Art.18 | Duties of Data Processors |
| Art.19 | Superintendencia de Industria y Comercio Functions |
Enforcement
| Code | Title |
|---|---|
| Art.24 | Complaints to UAE Data Office |
| Art.25 | Preservation of Stored Data |
| PDPL-Penalties | Administrative Penalties and Enforcement |
Lawful Processing
| Code | Title |
|---|---|
| Art.4 | Principles for Data Processing |
Other
| Code | Title |
|---|---|
| ADGM-DPR2021 | ADGM Data Protection Regulations 2021 |
| Art.1 | Purpose of the Law |
| DIFC-DPL2020 | DIFC Data Protection Law No. 5 of 2020 |
| Executive Regulations | Implementing Regulations and Standards |
| PDPL-Training | Awareness and Training |
Principles
| Code | Title |
|---|---|
| Art.5 | Scope of Application |
Sensitive Data
| Code | Title |
|---|---|
| HealthData-Law2/2019 | Federal Law No. 2 of 2019 on Health Data |
| PDPL-Children | Processing of Children's Personal Data |
| PDPL-Sensitive | Sensitive Personal Data Processing |
Your Compliance Coverage
If you comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), you already cover:
Chile Personal Data Protection Law (Law No. 21.719)
34%
11 controls mapped
Compare →NIST AI Risk Management Framework (AI RMF 1.0)
31%
10 controls mapped
Compare →NIST AI 600-1 Generative AI Profile
31%
10 controls mapped
Compare →+ 631 more: NIS2 Directive (31%), Laos Law on Prevention and Combating Cybercrime (2015) (31%)
See all 634 mapped frameworks ↓Maps to 634 other frameworks
Frequently Asked Questions
What is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)?
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) is a compliance framework from United Arab Emirates with 11 domains and 32 controls. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), together with the DIFC Data Protection Law (Law No. 5 of 2020) and the ADGM Data Protection Regulations (Regulation 13 of 2021). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) have?
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) has 32 controls organised across 11 domains. The largest domains are Data Subject Rights (7 controls), Controller/Processor Obligations (5 controls), Other (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) map to?
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) maps to 634 other compliance frameworks. The top mapping partners are Chile Personal Data Protection Law (Law No. 21.719) (34% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (31% coverage), NIST AI 600-1 Generative AI Profile (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) compliance?
Start your Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required