Appearance
Operationalizing UAE PDPL in Modulos
This is the rollout playbook for the UAE Personal Data Protection Law in Modulos. It assumes you are already oriented on the law: its scope and exclusions, the lawful-processing model, the controller and processor duties, and the security and transfer obligations (see the framework overview).
The PDPL is a federal law, in force since 2 January 2022. In the Modulos catalogue the templates carry the Regulation label. As of this framework release (Modulos templates 1.0.23), its Executive Regulation has not been issued; several obligations therefore state a duty whose operational detail is pending, and the framework marks each of those points explicitly. This framework will be updated when the Executive Regulation is issued.
Recommended project structure
Most rollouts use the following structure:
- One organization project with the
OFF-24framework template attached. This holds the organization-level machinery set once and consumed by every application: the applicability and scope determination, controller accountability and records of processing, processor governance, breach reporting readiness, the Data Protection Officer determination and enablement, cross-border transfer governance, complaint and grievance readiness, and the regulatory watch on the pending Executive Regulation. - One AI-application project per application processing UAE personal data with the
MFF-24framework template attached. Each application project holds that application's execution evidence: lawful basis and consent, processing controls, data protection by design and by default, transparency, data subject rights handling, automated decision-making safeguards, personal data security, the data protection impact assessment, and cross-border transfer records.
OFF-24 carries 9 requirements (ORF-456–ORF-464); MFF-24 carries 9 requirements (MRF-431–MRF-439): 18 in total. There is no scoping questionnaire, no project settings, and no framework tag family: applicability is handled inside the requirement text, and ORF-456 establishes the perimeter for everything downstream.
Primary source
Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, in force since 2 January 2022. Official English translation: uaelegislation.gov.ae. The Arabic original prevails in case of conflict.
The MFF-24 requirements and their controls
Each application requirement maps to the controls listed below. The mapping is realized at the control layer: fulfilling the controls, with evidence, is how the requirement is worked.
| Requirement | Mapped controls |
|---|---|
MRF-431 Lawful Basis and Consent | MCF-439 (Identify and document purpose), MCF-440 (Identify lawful basis), MCF-441 (Determining when and how to obtain consent), MCF-442 (Obtain and record consent), MCF-450 (Providing mechanism to modify or withdraw consent) |
MRF-432 Personal Data Processing Controls | MCF-427 (Access Control System), MCF-439 (Identify and document purpose), MCF-440 (Identify lawful basis), MCF-448 (Determining information for PII principals), MCF-449 (Providing information to PII principals), MCF-457 (Limit collection), MCF-458 (Limit processing), MCF-459 (Accuracy and quality), MCF-460 (PII minimization objectives), MCF-461 (PII de-identification and deletion at the end of processing), MCF-463 (Retention) |
MRF-433 Data Protection by Design and by Default | MCF-421 (Privacy by Design Architecture), MCF-422 (Privacy by Default Configuration), MCF-426 (Pseudonymization Implementation) |
MRF-434 Transparency and Data Subject Communication | MCF-447 (Determining and fulfilling obligations to PII principals), MCF-448 (Determining information for PII principals), MCF-449 (Providing information to PII principals), MCF-455 (Handling requests) |
MRF-435 Data Subject Rights Handling | MCF-413 (Data Subject Access Portal), MCF-414 (Data Rectification Interface), MCF-415 (Data Erasure System), MCF-416 (Processing Restriction Controls), MCF-417 (Data Portability Export), MCF-418 (Objection Processing System), MCF-455 (Handling requests) |
MRF-436 Automated Decision-Making and Human Review | MCF-419 (Automated Decision-Making Safeguards), MCF-420 (Explainability Controls), MCF-437 (Automated Decision Fairness Assessment) |
MRF-437 Personal Data Security | MCF-234 (Information security risk assessment and documentation), MCF-438 (Privacy risk assessment and documentation), MCF-269 (Independent review of information security), MCF-322 (Security testing in development and acceptance), MCF-424 (Encryption at Rest), MCF-425 (Encryption in Transit), MCF-426 (Pseudonymization Implementation), MCF-427 (Access Control System), MCF-429 (Security Monitoring), MCF-430 (Penetration Testing), MCF-432 (Resilience and Availability), MCF-433 (Backup and Recovery) |
MRF-438 Data Protection Impact Assessment | MCF-438 (Privacy risk assessment and documentation), MCF-443 (Privacy impact assessment) |
MRF-439 Cross-Border Transfers of Application Data | MCF-466 (Identify basis for PII transfer between jurisdictions), MCF-467 (Countries and international organizations to which PII can be transferred), MCF-468 (Records of transfer of PII) |
The OFF-24 requirements and their controls
| Requirement | Mapped controls |
|---|---|
ORF-456 Applicability and Scope Determination | OCF-178 (Information Audit Process), OCF-210 (Sector-Specific Compliance), OCF-219 (PII Role Determination), OCF-366 (Privacy-Law Applicability Determination) |
ORF-457 Controller Accountability and Records of Processing | OCF-12 (Cooperation with Competent Authorities), OCF-187 (Accountability Framework), OCF-189 (Processor Management System), OCF-190 (Records of Processing Register), OCF-213 (Processor Continuous Monitoring), OCF-218 (Processor Exit & Data Return) |
ORF-458 Processor Obligations and Processing Agreements | OCF-12 (Cooperation with Competent Authorities), OCF-190 (Records of Processing Register), OCF-367 (Processor Instruction, Duration and Co-processor Governance) |
ORF-459 Personal Data Breach Reporting | OCF-193 (Breach Response Process), OCF-364 (Breach Notification Readiness) |
ORF-460 Data Protection Officer Appointment | OCF-191 (DPO Designation and Independence), OCF-365 (DPO Appointment Trigger Assessment) |
ORF-461 Data Protection Officer Roles and Enablement | OCF-41 (Data Protection Officer) |
ORF-462 Cross-Border Transfer Governance | OCF-199 (Contractual Transfer Safeguards), OCF-201 (Adequacy Monitoring), OCF-202 (Derogation Documentation), OCF-205 (Cross-Border Processing Register) |
ORF-463 Complaints, Grievances, and Enforcement Readiness | OCF-12 (Cooperation with Competent Authorities), OCF-203 (Supervisory Authority Interface), OCF-368 (Regulatory Decision Grievance Management) |
ORF-464 Executive Regulation Readiness and Regulatory Watch | OCF-363 (Regulatory Instrument Watch and Readiness) |
Several controls are deliberately double-homed. OCF-12 serves accountability, processor obligations, and enforcement readiness (ORF-457, ORF-458, ORF-463); OCF-190 records processing in both the controller and processor capacity (ORF-457, ORF-458); on the app side, MCF-426 serves both the design-and-default and security requirements, MCF-427 serves both the processing-controls and security requirements, and MCF-438 feeds both security and the impact assessment. One implemented control satisfies every requirement it maps to.
Where in Modulos (requirements, controls, evidence, comments)
| Surface | Use |
|---|---|
Project dashboard Add Framework | Attach OFF-24 to the organization project; attach MFF-24 to each project for an application processing UAE personal data |
Project → Settings → Frameworks | Manage attached frameworks: list, freeze, and update |
Project → Requirements | Track the OFF-24 / MFF-24 requirements; status Not fulfilled → Fulfilled, with Out of scope for duties the scope determination excludes (for example ORF-458 where the organization never acts as a processor) |
Project → Controls | Document implemented measures against the mapped controls: the applicability determination, records of processing, consent records, rights-handling interfaces, security controls, the impact assessment, transfer instruments; control status changes can be routed through review requests |
Project → Evidence | Store supporting artifacts (the scope determination, the records of processing register, consent logs, DPIA reports, breach-package templates, the DPO determination, transfer registers, the pending-instrument inventory) and link them to the relevant control components |
| Comments and logs on each requirement | Capture the rationale for fulfillment attestation, scoping decisions, and provisional readings taken while the Executive Regulation is pending |
The control library: 59 reused, 6 new
The framework pair was built reuse-first. Across both templates it maps 65 distinct controls: MFF-24 maps 42 application controls, all reused from existing estates with zero new app controls; OFF-24 maps 23 organization controls, 17 reused and 6 new.
The reuse story. The 59 reused controls come mostly from the platform's GDPR and ISO 27701 control sets, plus ISO-estate security controls (MCF-234, MCF-269, MCF-322). 34 of the 59 were generalized for this framework on a widen-with-named-example basis, and the other 25 reused unchanged: where a shared control previously stated a GDPR-specific figure, the control now states the duty generically and keeps the GDPR figure as a branch, so the GDPR and ISO 27701 branches stay fully correct. The PDPL's own numbers are then supplied by the requirement text, or marked as pending the Executive Regulation where the law defers them.
If you already run the platform's GDPR and ISO 27701 templates, the head start is concrete: 39 of the 42 application controls and 15 of the 17 reused organization controls are already in your estate (either framework alone covers fewer). The remaining reused controls come from other parts of the platform library: the ISO-estate security controls MCF-234, MCF-269, and MCF-322, and the legacy controls OCF-12 and OCF-41. Evidence collected once against a shared control serves every framework that maps it; the net-new implementation work for UAE PDPL is the 6 new organization controls plus a review of existing implementations against the PDPL specifics in each requirement.
The 6 new controls. All six are organization-side and carry the PDPL-shaped work no existing control covered:
| Control | Name | Anchored requirement | What it does |
|---|---|---|---|
OCF-363 | Regulatory Instrument Watch and Readiness | ORF-464 | Maintains the inventory of pending implementing instruments, monitors for their issuance with a named owner and cadence, and keeps a plan to close each provisional obligation inside the compliance window the law allows |
OCF-364 | Breach Notification Readiness | ORF-459 | Keeps the Article 9(1)(a)–(f) Bureau notification content package assembled in advance; the notification period, measures, and requirements are marked as pending the Executive Regulation rather than invented |
OCF-365 | DPO Appointment Trigger Assessment | ORF-460 | Documents the determination against each of the three Article 10(1) appointment cases, with reasoning recorded whether or not an officer is required; the technology types and volume criteria await the Executive Regulation |
OCF-366 | Privacy-Law Applicability Determination | ORF-456 | Records the Article 2 scope determination: which processing and entities fall inside the law's reach, which exclusions apply, and on what basis |
OCF-367 | Processor Instruction, Duration and Co-processor Governance | ORF-458 | Governs the organization in its processor capacity under Article 8: instruction discipline, purpose and period control, erasure at expiry, and the mandatory written co-processor agreement under Article 8(10) |
OCF-368 | Regulatory Decision Grievance Management | ORF-463 | Governs the elective Article 25 grievance remedy: the thirty-day filing window, the recorded grounds, and the rule that no challenge may precede a grievance |
OCF-364 and OCF-365 are placeholder-framed by design. Each states the duty the law already imposes, holds a defined slot for the detail the Executive Regulation will supply, and instructs the implementer not to invent that detail in the meantime. When the Regulation is issued, the slot is filled rather than the control redesigned.
The Executive Regulation watch loop
ORF-464 plus OCF-363 are the operational answer to the pending Executive Regulation. The requirement obliges the organization to monitor four instrument families: the Executive Regulation itself, the Article 26 penalties decision of the Council of Ministers, Bureau approvals under Article 22, and Bureau publications such as the Article 21(6) exemption list. For each, the organization keeps an inventory of the obligations whose detail the instrument will supply (the breach notification period, the DPO criteria, and the transfer controls among them) and an owned, regularly reviewed plan to close each item.
The reason the loop matters is Article 29. It sets a regularisation window that starts only when the Executive Regulation is issued:
The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months as of the date on which its Executive Regulations are issued. The Council of Ministers may extend such period for another similar period.
The regularisation period therefore runs from issuance, while the Decree-Law itself is already in force. An organization running the watch loop learns of issuance through named sources rather than by chance, already knows which of its obligations the Regulation completes, and spends the window executing a prepared plan rather than discovering the gap.
The framework models readiness toward the Bureau (the UAE Data Office, established under Federal Decree-Law No. 44 of 2021), not an active supervision workflow.
Rollout sequence (scope first)
- Determine scope (org). Work
ORF-456first: the Article 2 determination of which processing and entities are in scope, which exclusions apply (government data, security and judicial data, personal use, health and banking or credit data under their own legislation, and free-zone companies with their own data protection laws, such as DIFC and ADGM entities), and the recorded basis for each. Do not rely on the Article 3 exemption power; its standards await the Executive Regulation. - Stand up the regulatory watch (org). Work
ORF-464early. It is one control (OCF-363), and every provisional reading taken in later steps should land in its instrument inventory. - Build the org machinery (org). Controller accountability and records of processing (
ORF-457); processor obligations where the organization acts as a processor (ORF-458); breach reporting readiness (ORF-459); the DPO determination and, where appointed, roles and enablement (ORF-460,ORF-461); cross-border transfer governance (ORF-462); complaint, grievance, and enforcement readiness (ORF-463). - Run the per-app work (app). For each application processing UAE personal data, work
MRF-431–MRF-439: lawful basis and consent, processing controls, design and default, transparency, data subject rights, automated decision-making safeguards, security, the impact assessment, and transfer records. App-side transfer records (MRF-439) consume the transfer instruments governed org-side byORF-462.
Each step is fulfilled through controls plus evidence plus a readiness signal plus owner-attested fulfillment.
Evidencing requirements: readiness signal + owner-attested fulfillment
Requirements in Modulos use a two-step pattern, not a review:
- when all linked controls reach a final state, the requirement becomes ready for review, a signal to the requirement owner;
- the requirement owner attests fulfillment by marking the requirement
Fulfilled; the status change is logged automatically, and recording the rationale in the requirement's comments is the recommended practice.
Review requests in Modulos apply to control status changes (and other reviewable objects), not to the requirements themselves. Remediation loops run at the control layer: a rejected review sends the control back to its owner with the reviewer's comments until the implementation passes.
A defensible UAE PDPL evidence package usually includes: the documented applicability and scope determination with the basis for each exclusion; the records of processing register; lawful-basis and consent records with withdrawal mechanisms; the transparency notices and rights-handling records; the DPIA for qualifying processing; the security control evidence; the DPO determination (either way) and, where appointed, the Bureau notification of contact details; transfer instruments and the per-transfer register; the breach content package kept ready; and the pending-instrument inventory with its review log.
Common pitfalls
- Inventing pending-instrument detail. There is no 72-hour breach window in the PDPL; the Article 9 notification period and the DPO volume and technology criteria are deferred to the Executive Regulation, Article 22 operates only through cases approved by the Bureau, and the Article 26 penalty amounts await a Cabinet decision. State the duty, mark the detail as pending, and track it in
ORF-464. - Mis-handling the free-zone exclusion. The exclusion turns on a free zone having its own personal-data-protection legislation; DIFC and ADGM run such regimes, so entities in those zones are outside the PDPL for data those regimes cover. Treating them as merely lighter-touch under the PDPL, rather than governed by the replacement regime, gets the scope determination wrong in both directions.
- Relying on the Article 3 exemption. The Bureau's exemption standards await the Executive Regulation. No descoping may rest on Article 3 without a valid documented decision.
- Duplicating breach machinery.
OCF-193owns detection, containment, investigation, data-subject notification under Article 9(2), and processor escalation under Article 9(3);OCF-364owns keeping the Article 9(1) Bureau content package ready. Splitting the work this way is deliberate; do not restate one control's scope in the other. - Leaving a "no DPO" conclusion undocumented.
OCF-365requires the reasoning either way. An unrecorded "not required" is the failure mode the control exists to catch. - Looking for a scoping questionnaire or tag family. There is none. The perimeter is set by working
ORF-456, and conditional duties are scoped with rationale on the requirement itself. - Using reviews to sign off requirements. Requirements are evidenced by readiness plus owner attestation; reviews are for control status changes.
Related pages
UAE PDPL overview
Framework structure, scope, and the OFF-24 / MFF-24 split
Scope, enforcement, and the Executive Regulation
Article 2 scope, exclusions, penalties, and the pending Regulation
Lawful processing and data subject rights
Consent, processing controls, and the rights of data subjects
Controllers, processors, and the DPO
Controller and processor duties and the Data Protection Officer
Security, breaches, DPIA, and cross-border transfers
Personal data security, breach reporting, impact assessment, and transfers
Governance operating model
How projects, requirements, controls, and evidence fit together
Source attribution
The authoritative source is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, and in force since 2 January 2022. Quotations on this page are from the official English translation published at uaelegislation.gov.ae; the Arabic original prevails in case of conflict. This page describes how Modulos maps the law's obligations to platform surfaces through the OFF-24 and MFF-24 framework templates; the obligations themselves are in the law. Requirement and control codes are Modulos template identifiers, not references used by the law. The UAE PDPL framework pair ships with Modulos platform templates version 1.0.23; this guide tracks that release.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The PDPL's Executive Regulation has not yet been issued, and several obligations will gain operational detail when it is. Organizations remain fully responsible for their own legal and regulatory compliance. Verify against the current official text and consult qualified advisers.