Appearance
Lawful Processing and Data Subject Rights
This page covers the substantive core of the PDPL for a single AI application: the consent-default rule and its exceptions (Article 4), the processing controls (Article 5), the terms a valid consent has to meet (Article 6), and the data subject rights in Articles 13 to 19. In Modulos these obligations live in five requirements of the application-level template MFF-24: MRF-431 (Lawful Basis and Consent), MRF-432 (Personal Data Processing Controls), MRF-434 (Transparency and Data Subject Communication), MRF-435 (Data Subject Rights Handling), and MRF-436 (Automated Decision-Making and Human Review).
Primary source
Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, in force since 2 January 2022. Quotes on this page are from the official English translation; the Arabic original prevails in case of conflict.
Requirements covered on this page
| Requirement | Name | PDPL articles | Mapped controls |
|---|---|---|---|
MRF-431 | Lawful Basis and Consent | 1, 4, 6 | 5 |
MRF-432 | Personal Data Processing Controls | 1, 5 | 11 |
MRF-434 | Transparency and Data Subject Communication | 13(2), 19 | 4 |
MRF-435 | Data Subject Rights Handling | 13–17 | 7 |
MRF-436 | Automated Decision-Making and Human Review | 1, 18 | 3 |
Every control mapped by these five requirements is reused from the platform's existing estate, mostly the GDPR and ISO/IEC 27701 control sets. MFF-24 adds no new application controls; the binding PDPL language lives in the requirement text, and several reused controls were generalized so that their GDPR and 27701 branches stay fully correct.
Article 4 — Cases of Processing Personal Data without the Consent of its Owner
The PDPL starts from consent as the default rule:
It is prohibited to process Personal Data without the consent of its owner. The following cases shall be excluded from such prohibition:
The excluded cases are processing that is:
- necessary to protect the public interest;
- related to personal data which has become available and known to all by an act of the data subject;
- necessary to initiate any procedures of legal claim or defence of rights, or related to judicial or security procedures;
- necessary for occupational or preventive medicine: assessing employees' ability to work, medical diagnosis, health or social care, treatment or health insurance services, or managing health or social care systems and services, in accordance with UAE legislation;
- necessary to protect public health, including protection from existing diseases and epidemics, or for the safety and quality of healthcare, medicines, drugs and medical devices, in accordance with UAE legislation;
- necessary for archival purposes or for scientific, historical and statistical studies, in accordance with UAE legislation;
- necessary to protect the interests of the data subject;
- necessary for the controller or data subject to carry out their obligations and exercise their legally established rights in the field of employment, social security or social protection laws, to the extent permitted by such laws;
- necessary to perform a contract to which the data subject is a party, or to take measures at the data subject's request with the aim of concluding, amending or terminating a contract;
- necessary to fulfill specific obligations stipulated for the controller in other laws in force in the UAE.
Article 4(11) leaves room for further cases: the Executive Regulation may set out additional consent-free processing cases; as of this framework release (Modulos templates 1.0.23) it has not been issued.
No general legitimate-interests basis
The Article 4 list is closed until the Executive Regulation extends it, and it contains no general legitimate-interests basis comparable to GDPR Article 6(1)(f). A processing purpose that rests on legitimate interests in a GDPR record of processing has to rest on consent or on one of the ten listed cases under the PDPL. When reusing a GDPR-era lawful-basis register for UAE processing, re-derive each entry against the Article 4 list rather than carrying the GDPR basis across.
Article 5 — Personal Data Processing Controls
Article 5 sets the controls every processing operation has to satisfy, in parallel to the lawful basis:
- Fairness, transparency and lawfulness — "Processing shall be carried out in a fair, transparent and lawful manner."
- Purpose limitation — "Personal Data shall be collected for a specific and clear purpose. It shall not be processed at any later time in a manner incompatible with such purpose. However, it may be processed if the purpose is similar or close to the purpose for which this data is collected."
- Minimization — "Personal Data shall be sufficient and limited to what is necessary in accordance with the purpose for which the processing is carried out."
- Accuracy — "Personal Data shall be accurate and correct and shall be updated whenever necessary", with the necessary measures taken so that incorrect personal data is deleted or corrected.
- Security — "Personal Data shall be kept securely, including protecting it from any violation, penetration, or illegal or unauthorized processing through the development and use of appropriate technical and organizational measures and procedures in accordance with the laws and legislation in force in this regard."
- Retention — "Personal Data shall not be kept after the purpose of its processing has been exhausted." It may be kept if the data subject's identity has been concealed using the "Anonymization Mechanism"; the underlying Anonymization term is defined in Article 1.
Article 5(8) reserves further controls for the Executive Regulation. Note the purpose-limitation clause: unlike GDPR's compatibility test, the PDPL permits later processing where the purpose "is similar or close to" the collection purpose, and that is the wording an assessment of secondary use has to apply.
Article 6 — Terms of Consent to Data Processing
Where processing rests on consent, Article 6(1) makes it conditional on three terms:
- the controller is able to prove the data subject's consent;
- the consent is prepared in a clear, simple, unambiguous and easily accessible manner, whether in writing or electronically;
- the consent includes the data subject's right to withdraw it easily.
Article 1 defines consent as an authorization that indicates "in a specific, clear and unambiguous manner" that the data subject accepts the processing "through a clear positive statement or action". On withdrawal, Article 6(2) is explicit:
The Data Subject may, at any time, withdraw their consent to the processing of Personal Data. Such withdrawal of consent shall not affect the legality of the processing based on the given consent before withdrawing it.
Withdrawal therefore operates forward only: it does not affect the legality of the consent-based processing already carried out, and it does not cure processing that was unlawful on other grounds. Continuing to process after withdrawal requires valid consent given anew or one of the Article 4 cases, and withdrawal is an erasure ground under Article 15(2)(b).
How lawful basis and processing map in Modulos
MRF-431 (Lawful Basis and Consent) requires a documented lawful basis for every processing purpose of the application, and consent capture that meets the Article 1 and Article 6 terms. Its mapped controls come from the platform's privacy estate:
MCF-439— Identify and document purposeMCF-440— Identify lawful basisMCF-441— Determining when and how to obtain consentMCF-442— Obtain and record consentMCF-450— Providing mechanism to modify or withdraw consent
MRF-432 (Personal Data Processing Controls) requires each Article 5 control to be demonstrably implemented for the application's data flows. It reuses eleven controls:
- Purpose and basis —
MCF-439(Identify and document purpose),MCF-440(Identify lawful basis) - Collection and processing limits —
MCF-457(Limit collection),MCF-458(Limit processing),MCF-460(PII minimization objectives) - Accuracy —
MCF-459(Accuracy and quality) - Transparency toward data subjects —
MCF-448(Determining information for PII principals),MCF-449(Providing information to PII principals) - Security of access —
MCF-427(Access Control System) - End-of-life handling —
MCF-461(PII de-identification and deletion at the end of processing),MCF-463(Retention)
The deeper Article 20 security obligations are covered separately under Security, breaches, DPIA, and cross-border transfers.
Data subject rights (Articles 13–19)
| Article | Right | Requirement |
|---|---|---|
| 13 | Right to Receive Information | MRF-434 (proactive), MRF-435 (on request) |
| 14 | Right to Request Transfer of Personal Data | MRF-435 |
| 15 | Right to correction or erasure of Personal Data | MRF-435 |
| 16 | Right to Restrict Processing | MRF-435 |
| 17 | Right to Stop Processing | MRF-435 |
| 18 | Right to Processing and Automated Processing | MRF-436 |
| 19 | Contacting the Controller | MRF-434 |
Article 13 — Right to Receive Information
Article 13(1) entitles the data subject, on a request submitted "without any consideration" (free of charge), to information including the types of their personal data being processed, the purposes of processing, decisions made based on automated processing including profiling, the sectors or establishments inside and outside the UAE with which the data will be shared, storage-period controls and standards, the procedures for correction, erasure, restriction and objection, the protection measures for cross-border processing under Articles 22 and 23, the actions to be taken in the event of a breach or misuse, and how to submit complaints to the Bureau (the UAE Data Office, established under Federal Decree-Law No. 44 of 2021).
Part of this is owed before any request is made. Article 13(2):
In all cases, the Controller shall, before starting the processing, provide the Data Subject with the information stipulated in paragraphs (b), (d) and (g) of Paragraph (1) of this Article.
That is the proactive minimum: purposes of processing, the sharing targets inside and outside the UAE, and the cross-border protection measures.
Article 13(3) lets the controller reject a request on four grounds: the request is unrelated to the Article 13(1) information or excessively repetitive; it conflicts with judicial procedures or investigations by competent authorities; it may negatively affect the controller's information-security efforts; or it affects the privacy and confidentiality of third parties' personal data. A refusal should record which ground applies.
Article 14 — Right to Request Transfer of Personal Data
Article 14 carries two separately worded rights. Article 14(1) is the right to receive: the data subject may receive his or her personal data "in an orderly and machine-readable manner" where the data was provided to the controller for processing, the processing rests on consent or is necessary for a contractual obligation, and it is carried out by automated means. Article 14(2) is the right to have personal data transferred to another controller, and its text states a single condition, technical feasibility:
The Data Subject shall have the right to request the transfer of its Personal data to another Controller whenever it is technically feasible.
The paragraph 1 conditions are not restated in paragraph 2, and the framework does not import them there.
Article 15 — Right to correction or erasure of Personal Data
Article 15(1) carries two distinct rights: correction of inaccurate personal data, and completion of the data held by the controller, both "without undue delay". Article 15(2) grants erasure, without prejudice to UAE legislation and public-interest requirements, in four cases: the data is no longer necessary for the purposes it was collected or processed for; the data subject withdraws the consent the processing rests on; the data subject objects to the processing or there are no legitimate reasons for the controller to continue it; or the data is processed in violation of the PDPL and applicable legislation and erasure is necessary for compliance.
Article 15(3) excepts erasure requests relating to public-health data in private facilities, requests affecting the investigation procedures and the claiming and defending of rights, and requests contradicting other legislation binding the controller. The Executive Regulation may determine additional erasure-exception cases; it has not yet been issued.
Article 16 — Right to Restrict Processing
Article 16(1) obliges the controller to restrict and stop processing when the data subject objects to the accuracy of the data (restriction for a specific period while the controller verifies accuracy), objects to processing in violation of the agreed-upon purposes, or where the processing violates the PDPL and applicable legislation. Article 16(2) adds a converse right: the data subject may require the controller to keep their personal data after the processing purposes are complete when it is needed for claiming or defending rights and lawsuits.
Article 16(3) lets the controller proceed despite a restriction in four cases: storage-only processing, processing necessary for claims and judicial proceedings, protection of third-party rights, and protection of the public interest. Article 16(4) requires the controller to notify the data subject when it lifts a restriction.
Article 17 — Right to Stop Processing
The data subject may object to and stop processing on three grounds: processing for direct marketing purposes, including profiling related to direct marketing; processing for statistical surveys, unless the processing is necessary to serve the public interest; and processing carried out in violation of Article 5. The third ground ties this right back to the processing controls above: an Article 5 failure is directly actionable by the data subject.
Article 18 — Right to Processing and Automated Processing
Article 18(1) gives the data subject the right to object to decisions resulting from automated processing, including profiling, "particularly those decisions which have legal impact on or adversely affect the Data Subject". Article 18(2) excludes three cases from the objection right: the automated processing is agreed under a contract between the data subject and the controller; it is required under other UAE legislation; or the data subject gave prior consent to it as set out in Article 6.
The exceptions do not remove the controller's duties. In the excepted cases, Article 18(3) still requires appropriate measures to protect the privacy and confidentiality of the data subject's personal data, without prejudice to their rights. And Article 18(4) applies across the board:
The Controller shall include the human element in reviewing automated processing decisions at the request of the Data Subject.
Note the breadth of the definitions this right runs on: Article 1 defines automated processing to include partial automation "with limited human supervision and intervention", and profiling covers analyzing or predicting financial condition, health, preferences, interests, behavior, location, movements or reliability. For an AI application, Article 18 becomes operative where automated processing results in decisions about data subjects, particularly decisions with legal impact on or adverse effect on them; automated processing that produces no such decision does not trigger it.
Article 19 — Contacting the Controller
The Controller shall provide clear and appropriate ways for the Data Subject to contact the Controller to request any of the rights set forth in this Decree by Law.
A rights process that exists internally but is unreachable by the data subject fails this article on its own.
How the rights map in Modulos
MRF-434 (Transparency and Data Subject Communication) covers the proactive side: the Article 13(2) pre-processing information, the availability of the remaining Article 13(1) information, and the Article 19 contact channels. Its controls:
MCF-447— Determining and fulfilling obligations to PII principalsMCF-448— Determining information for PII principalsMCF-449— Providing information to PII principalsMCF-455— Handling requests
MRF-435 (Data Subject Rights Handling) covers receipt and execution of the Article 13 to 17 requests, with requests, decisions, and response times recorded. Its controls pair one request-intake control with one control per right:
MCF-413— Data Subject Access PortalMCF-414— Data Rectification InterfaceMCF-415— Data Erasure SystemMCF-416— Processing Restriction ControlsMCF-417— Data Portability ExportMCF-418— Objection Processing SystemMCF-455— Handling requests
MRF-436 (Automated Decision-Making and Human Review) covers the Article 18 objection right, the protective measures in the excepted cases, and the Article 18(4) request-triggered human review. Its controls:
MCF-419— Automated Decision-Making SafeguardsMCF-420— Explainability ControlsMCF-437— Automated Decision Fairness Assessment
Generalized deadlines in the reused controls
The rights-handling controls above were built for the GDPR estate and were generalized for reuse rather than duplicated. The main change is deadlines: the PDPL does not fix a response period for rights requests (Article 15(1) requires correction and completion "without undue delay"; no article of the law sets a general response period), so MCF-413 and its siblings now key the response deadline to the period the applicable law prescribes, with the GDPR one-month period kept as a named example rather than a hard-coded default. MCF-416 gained the Article 16(2) continued-keeping and Article 16(4) lift-notification workflow, and MCF-418 and MCF-419 were widened to statutory objection grounds and applicable-law scope. In each case the GDPR wording survives as a named branch, so projects running both frameworks evidence each against its own deadline.
Next steps
Scope, enforcement, and the Executive Regulation
Who the PDPL applies to, the exclusions, and every obligation deferred to the Executive Regulation
Controllers, processors, and the DPO
The Article 7 to 12 duties that sit around the rights on this page, including the processing record
Security, breaches, DPIA, and cross-border transfers
The Article 20 security standard behind the Article 5 security control, plus Articles 9 and 21 to 23
Operationalizing in Modulos
How MFF-24 and OFF-24 run together across application and organization projects
Source attribution
The authoritative source is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, published in Official Gazette No. 712 of 26 September 2021, and in force since 2 January 2022. Quotes are from the official English translation published at uaelegislation.gov.ae; for interpretation and application, the Arabic original prevails. Requirement and control codes are Modulos template identifiers, not references used by the law.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The Executive Regulation of the PDPL has not yet been issued; obligations deferred to it are marked as such above, and organizations remain responsible for their own compliance assessment. Verify against the current published text and consult qualified advisers.