Appearance
Controllers, Processors, and the Data Protection Officer
This page covers the PDPL's accountability core: the controller's general obligations under Article 7, the processor's general obligations under Article 8, protection by design and by default as a per-application duty, and the Data Protection Officer regime in Articles 10–12. In Modulos these map to four organization requirements in OFF-24 (ORF-457, ORF-458, ORF-460, ORF-461) and one application requirement in MFF-24 (MRF-433). Two of the six new UAE-PDPL controls appear here: OCF-365 and OCF-367.
Primary source
Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, in force since 2 January 2022. Quotes on this page follow the official English translation; the Arabic original prevails in case of conflict. This page draws on Article 7 (The Controller's General Obligations), Article 8 (The Processor's General Obligations), and Articles 10–12 (the Data Protection Officer). The regulator the law calls "the Bureau" is the UAE Data Office, established under Federal Decree-Law No. 44 of 2021; the framework models readiness toward it.
The requirements on this page
| Requirement | Name | PDPL basis | New UAE-PDPL control |
|---|---|---|---|
ORF-457 | Controller Accountability and Records of Processing | Article 7(4)–(7) | none |
ORF-458 | Processor Obligations and Processing Agreements | Article 8 | OCF-367 |
ORF-460 | Data Protection Officer Appointment | Article 10 | OCF-365 |
ORF-461 | Data Protection Officer Roles and Enablement | Articles 11–12 | none |
MRF-433 | Data Protection by Design and by Default | Articles 7(1)–(3), 8(2) | none |
How Modulos splits the controller and processor roles
The PDPL binds controllers and processors as distinct roles, and one organization commonly holds both: controller for its own processing, processor where it processes on a client's behalf. OFF-24 models this with two requirements rather than one:
ORF-457is the controller-side view. It carries the controller's own accountability duties, and it is also where the controller's guarantees about processors live: the Article 7(5) selection duty and the processor-management controls (OCF-189,OCF-213,OCF-218) sit here, because vetting, monitoring, and exiting a processor are things the controller does.ORF-458is the processor-side view: the Article 8 obligations the organization owes when it is the one processing under instructions.
There is no scoping questionnaire in this framework. Each requirement opens with its role condition ("Where the organization acts as controller" / "as processor"), and the processing perimeter documented under ORF-456 determines which condition holds. An organization that never acts as processor records that in the owner-attested fulfillment of ORF-458; the requirement text, not a project setting, carries the applicability.
Article 7 — The Controller's General Obligations (ORF-457)
Article 7 lists seven controller obligations. The first three, the design and default duties, are carried per application by MRF-433 (next section). ORF-457 holds the organization-level remainder:
- Records of processing, Article 7(4). The controller maintains a special record of personal data covering the data of both the controller and the Data Protection Officer, a description of the categories of personal data, details of the persons authorized to access it, processing times, limitations and scope, the mechanism for erasing, modifying or processing personal data, the purpose of processing, any data related to cross-border movement and processing, and the technical and organizational measures related to information security and processing. The article closes with a standing submission duty: "The Controller shall submit such record to the Bureau whenever requested to do so." In Modulos the register is
OCF-190(Records of Processing Register). - Processor selection, Article 7(5). The controller appoints only processors with "sufficient guarantees to implement technical and organizational measures" so that processing meets the requirements, rules and controls stipulated in the Decree-Law, its Executive Regulation, and the decisions issued to implement them; the Executive Regulation and implementing decisions are pending as of this framework release (Modulos templates 1.0.23), so the guarantee currently tests against the Decree-Law itself. The guarantee is evidenced across the processor lifecycle:
OCF-189(Processor Management System) for selection and contracting,OCF-213(Processor Continuous Monitoring) for the ongoing check, andOCF-218(Processor Exit & Data Return) for termination. - Providing information to the Bureau, Article 7(6). The controller provides the Bureau, "pursuant to a decision made by the competent judicial authority", with any information it requests in implementation of its powers. Note the trigger: this duty runs through a judicial decision, not a direct supervisory demand.
OCF-12(Cooperation with Competent Authorities) holds the response process.
OCF-187 (Accountability Framework) anchors the requirement as a whole: the documented allocation of the Article 7 duties to owners inside the organization. Article 7(7) reserves any further controller obligations to the Executive Regulation.
Article 8 — The Processor's General Obligations (ORF-458)
Article 8 defines the processor's position: it acts on instructions, within a contract, for a stated purpose and period, and must be able to prove it.
- Instruction-bound processing, Article 8(1). Processing follows the controller's instructions and the contracts and agreements between them, "which specify in particular the scope, subject, purpose, nature and type of Personal Data, and the category of the Data Subject". Those particulars are the minimum content of a PDPL processing agreement.
- Purpose and period, Articles 8(3)–(4). Processing stays within the specified purpose and period; if it would exceed the period, "the Processor shall so notify the Controller to authorize it to extend such period or give appropriate instructions". At the end: "Erase data after the expiry of the processing period or upon handing it over to the Controller."
- Non-disclosure and security, Articles 8(5)–(6). The processor avoids anything that would disclose personal data or processing results except where the law authorizes it, and protects the data, the electronic media, and the devices used in processing.
- Processor records, Article 8(7). The processor keeps its own record of processing carried out on the controller's behalf, with the same field set as the controller's Article 7(4) record plus the processor's own data, and submits it to the Bureau whenever requested. The same register control,
OCF-190, serves both branches. - Proving compliance, Article 8(8). The processor shall "Provide all means to prove its commitment to the implementation of provisions of this Decree by Law when so requested by the Controller or the Bureau."
- Joint and co-processors, Article 8(10). Where more than one processor participates, processing "shall be carried out in accordance with a written contract or agreement in which they clearly define their obligations, responsibilities and roles with regard to processing, otherwise they shall be deemed jointly responsible" for the Decree-Law's obligations. Absent that written allocation, the law deems the processors jointly responsible; it states that default, not that a written agreement by itself extinguishes joint responsibility.
The operative new control here is OCF-367 (Processor Instruction, Duration and Co-processor Governance): the instruction and contract discipline, the period-extension notification mechanism, and the co-processor role allocation, which have no equivalent in the reused estate. OCF-12 covers Bureau requests on the processor side. Article 8(11) reserves the related procedures, controls, conditions and technical standards to the Executive Regulation.
Protection by design and by default (MRF-433)
Articles 7(1)–(3) and 8(2) group four distinct duties: the controller's general protection-and-security duty, measures applied while determining the means of processing and during processing, the automatic-settings default, and the processor's design-stage measures. Modulos carries them per AI application rather than at the organization level, because the measures are proportionate to the nature, scope and purposes of each processing operation and can only be evidenced against a concrete system.
- Article 7(1) requires appropriate technical and organizational measures to protect and secure personal data, taking into account the nature, scope and purposes of processing and the possibility of risks to the data subject.
- Article 7(2) requires the appropriate measures to be applied "whether while determining the means of processing or while processing", expressly including the Pseudonymization Mechanism.
- Article 7(3) is the by-default duty: automatic settings ensure that processing "is limited to the purpose for which it is intended", applying to "the volume and type of Personal Data collected, the type of processing which will be carried out, the period of storage and accessibility of such data".
- Article 8(2) extends the design-stage duty to the processor, "taking into account the cost of implementing such procedures and the nature, scope and purposes of processing".
MRF-433 maps three application controls: MCF-421 (Privacy by Design Architecture) for the design-stage measures, MCF-422 (Privacy by Default Configuration) for the automatic-settings limitation, and MCF-426 (Pseudonymization Implementation) for the mechanism Article 7(2) names. All three are reused from the existing privacy estate; the PDPL-specific wording lives in the requirement text.
Articles 10–12 — the Data Protection Officer
Appointment, Article 10 (ORF-460)
Appointment is not universal. Article 10(1) obliges the controller and processor to appoint a DPO "who has sufficient skills and knowledge of the Personal Data Protection Law" in three cases:
a. If processing would cause a high-level risk to the confidentiality and privacy of the Personal Data of the Data Subject as a result of adopting new technologies or with regard to the volume of data.
b. If processing would involve a systematic and comprehensive assessment of Sensitive Personal Data, including Profiling and Automated Processing.
c. If processing would be carried out on a large volume of Sensitive Personal Data.
Article 10(4) reserves "the types of technologies and criteria for determining the volume of data" to the Executive Regulation, so the triggers currently operate on the law's own wording without numeric thresholds. That is why the requirement centres on a documented determination rather than a threshold check: OCF-365 (DPO Appointment Trigger Assessment), one of the six new UAE-PDPL controls, records whether each Article 10(1) case applies, the reasoning, and the revisit when processing changes.
Two further points from the article:
- Basing. Article 10(2) permits the DPO to act "whether inside or outside the State". The official translation reads that the DPO "may be an employer of the Controller or the Processor or authorized by them"; the Arabic original prevails on the intended engagement forms.
- Notification. Under Article 10(3) the controller or processor specifies the DPO's contact details and notifies the Bureau of them.
Where a DPO is appointed, OCF-191 (DPO Designation and Independence) holds the designation itself.
Roles and enablement, Articles 11–12 (ORF-461)
Article 11 defines what the DPO does: it ascertains the controller's or processor's compliance with the Decree-Law, its Executive Regulations, and Bureau instructions, and in particular verifies the quality and correctness of procedures in place, receives requests and complaints related to personal data, provides technical advice on evaluation procedures and the periodic examination of data protection and intrusion-prevention systems (documenting the results and recommending, including risk assessment procedures), and acts "as a link between the Controller or the Processor, as the case may be, and the Bureau". Article 11(2) binds the DPO to confidentiality over what it receives in the role.
Article 12 defines what the organization owes the DPO. It shall ensure the DPO "is appropriately and timely involved in all matters relating to the protection of Personal Data", is resourced and supported, and "is not charged with duties which contradict its duties under this Law". The protection against retaliation is explicit:
Not to terminate the Data Protection Officer services or impose any disciplinary penalty for a reason related to the performance of its duties in accordance with the provisions of this Decree by Law.
Article 12(2) adds a direct channel: the data subject may communicate directly with the DPO about all matters relating to his or her personal data processing. ORF-461 maps OCF-41 (Data Protection Officer): the operating role with its Article 11 task set and the Article 12 enablement and protection duties, evidenced together.
Executive Regulation
Articles 7(7), 8(11), 10(4), and 11(1)(e) each reserve further detail to the Executive Regulation of the Decree-Law, which has not yet been issued. The affected requirements carry that marker in their text, and this framework will be updated when the Executive Regulation is issued.
Related pages
Scope, enforcement, and the Executive Regulation
The Article 2 perimeter these role conditions depend on — ORF-456
Lawful processing and data subject rights
The consent, processing-controls, and rights obligations the DPO fields requests about
Security, breaches, DPIA, and cross-border transfers
Breach notification names the appointed DPO's details — Article 9
Operationalizing in Modulos
The OFF-24 / MFF-24 rollout sequence, control reuse, and evidence model
Source attribution
The authoritative source is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, published in Official Gazette No. 712 of 26 September 2021, and in force since 2 January 2022. Quotes follow the official English translation published at uaelegislation.gov.ae; the Arabic original prevails in case of conflict. This page draws on Articles 7, 8, and 10–12. Requirement and control codes are Modulos template identifiers, not references used by the law.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The Executive Regulation of the Decree-Law has not yet been issued; verify obligations against the current official texts and consult qualified advisers.