Appearance
Scope, enforcement, and the Executive Regulation
This page establishes the perimeter and enforcement posture of the UAE PDPL framework in Modulos: the Article 1 defined terms the whole framework builds on, the Article 2 scope limbs and exclusions, the Article 3 exemption power, the complaint and grievance path under Articles 24–25, the pending Article 26 penalties decision, and the Article 28–29 Executive Regulation timeline. It covers the org requirements ORF-456 (Applicability and Scope Determination), ORF-463 (Complaints, Grievances, and Enforcement Readiness), and ORF-464 (Executive Regulation Readiness and Regulatory Watch).
The PDPL is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data: issued 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, in force since 2 January 2022. As of this framework release (Modulos templates 1.0.23), its Executive Regulation has not been issued, and that fact shapes everything on this page: the Decree-Law's obligations have been binding since it came into force, while the operational detail it reserves to the Regulation is pending.
Primary source
Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data. This page draws on Article 1 (Definitions), Article 2 (Scope of Application), Article 3 (Bureau's Power of Exemption), Articles 24–26 (Complaints, Grievance, Administrative Penalties), and Articles 27–29 (Authorization, the Executive Regulation, Regularisation). Official English translation: uaelegislation.gov.ae. All quotations on this page are from that translation; in case of conflict, the Arabic original prevails.
This page at a glance
| Requirement | Topic | Source anchor | New UAE-PDPL control |
|---|---|---|---|
ORF-456 | Applicability and Scope Determination | Articles 2–3 | OCF-366 |
ORF-463 | Complaints, Grievances, and Enforcement Readiness | Articles 24–26 | OCF-368 |
ORF-464 | Executive Regulation Readiness and Regulatory Watch | Articles 28–29 and the pending instruments | OCF-363 |
Article 1 — the defined terms
Article 1 fixes the vocabulary. The definitions below are the ones the Modulos requirements lean on most; each is quoted from the official English translation.
- Personal Data — "Any data related to a specific natural person or related to a natural person that can be identified directly or indirectly by linking the data, through the use of identification elements such as his/her name, voice, image, identification number, his/her electronic identifier, his/her geographical location, or by one or more physical, physiological, economic, cultural or social characteristics. It includes Sensitive Personal Data and Biometric Data".
- Sensitive Personal Data — "Any data which directly or indirectly reveals a natural person's family, ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or any data relating to such person's health and physical, psychological, mental, genetic or sexual condition, including information related to the provision of healthcare services to him/her which reveals his/her health status".
- Processing — "Any operation or set of operations performed on Personal Data using any electronic means", including "collecting, storing, recording, organizing, adapting, modifying, circulating, altering, retrieving, exchanging, sharing, using, characterizing, disclosing Personal Data by broadcasting, transmitting, distributing, making available, coordinating, merging, restricting, blocking, erasing or destroying it or creating forms thereof".
- Controller — "An establishment or natural person that has Personal Data, and by virtue of its activity, determines whether individually or jointly with other persons or establishments, the method and criteria for processing such Personal Data and the purpose of processing it".
- Processor — "An establishment or Natural Person that processes Personal Data on behalf of the Controller. It processes it under their supervision and in accordance with their instructions".
- Consent — "The consent whereby the Data Subject authorizes a third party to process his/her Personal Data, provided that this consent indicates, in a specific, clear and unambiguous manner, that he/she accepts the processing of his/her Personal Data through a clear positive statement or action".
- Profiling — "A form of automated processing which involves the use of Personal Data to assess certain personality aspects associated with the Data Subject, including analyzing or predicting aspects related to his/her financial performance or condition, health, personal preferences, interests, behavior, location, movements or reliability".
Two readings matter for AI governance work. Sensitive Personal Data expressly includes biometric data and health-status information, which pulls many model training and inference datasets into the stricter branches of the law. And Profiling turns on what the processing assesses: automated processing falls within it where it uses personal data to assess personality aspects associated with the data subject, such as analyzing or predicting financial performance or condition, health, personal preferences, interests, behavior, location, movements or reliability. Whether a scoring, recommendation, or risk-assessment model meets that definition is a determination to record per model, not an assumption; the data subject rights attached to profiling are covered in Lawful processing and data subject rights.
Article 1 also names the regulator. The PDPL's translation defines the "Office" as "The UAE Data Bureau established under the aforementioned Federal Decree by Law No. (44) of 2021", the instrument that established the UAE Data Office, and the operative articles refer to it throughout as the Bureau. This page uses "the Bureau" to match the law's own usage. As of this framework release, the Data Office's supervisory processes are still being stood up. The law's duties toward the Bureau apply regardless of that operational state; the framework models the interactions described below as cooperation and notification readiness toward the Data Office.
Article 2 — who and what is in scope
Article 2(1) applies the law to "the processing of all or part of the Personal Data by means of electronic systems which operate automatically, or by other means". Automated processing is squarely covered, and so is manual processing. The territorial limbs are:
- (a) Data subjects in the UAE — "Each Data Subject residing in the State or having a place of business in it."
- (b) Controllers and processors in the UAE — each controller or processor residing in the State and carrying out processing of personal data of data subjects inside and outside the State.
- (c) Controllers and processors outside the UAE — each controller or processor residing outside the State and carrying out processing of personal data of data subjects inside the State.
Limb (c) gives the law extraterritorial reach comparable to other principal data protection laws: an organization with no UAE establishment is in scope when it processes the personal data of data subjects inside the UAE.
The Article 2(2) exclusions
Article 2(2) removes seven categories from the law's application:
- government data;
- governmental entities which control or process personal data;
- personal data held by the security and judicial authorities;
- "A Data Subject who processes his/her data for personal purposes.";
- personal health data that has legislation regulating its protection and processing;
- personal banking and credit data and information that have legislation regulating their protection and processing;
- "Companies and establishments located in free zones in the Country and have special legislations regarding Personal Data protection."
The last three exclusions do the most work in practice. The health and banking exclusions are case-specific, not categorical: personal health data is excluded where it "has legislation regulating its protection and processing", and personal banking and credit data where such legislation exists for them. The PDPL's preamble points to the candidates, citing among others Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in the Health Fields, Federal Law No. 6 of 2010 on Credit Information, and Federal Decree-Law No. 14 of 2018 on the Central Bank. An organization determines, for the specific data it processes, whether such legislation regulates its protection and processing, and applies that regime to the data it covers.
The free-zone exclusion is stated in general terms: it covers companies and establishments located in UAE free zones that have special legislation regarding personal data protection, and Article 2(2) names no zone. The two established examples are the Dubai International Financial Center and the Abu Dhabi Global Market, which operate their own data protection laws with their own regulators, so companies and establishments in those zones are outside the PDPL for data covered by those regimes. The Modulos framework models the onshore, federal regime only; a group with both onshore and free-zone entities records which entities fall where as part of scope determination.
Article 3 — the Bureau's exemption power
Article 3 provides that "the Bureau may exempt some establishments that do not process a large volume of Personal Data from part, or all of the requirements of the personal data protection provisions stipulated in this Decree by Law, in accordance with the standards and controls set by the Executive Regulations of this Decree by Law."
The power exists, but it is not operational: the standards and controls that would define "a large volume" and the exemption mechanics are reserved to the Executive Regulation, which has not yet been issued. No scoping decision in the framework may rely on an Article 3 exemption, and ORF-456 states this directly. An organization that expects to qualify once the mechanism exists should track it through the regulatory watch under ORF-464 rather than descope today.
Scope determination in Modulos (ORF-456)
ORF-456 (Applicability and Scope Determination) requires the organization to determine and document whether and where the PDPL applies to its processing: which processing falls under the Article 2(1) limbs, which falls under the Article 2(2) exclusions, and which of its entities are in scope. There is no UAE PDPL scoping questionnaire and no framework-specific tags; the scope perimeter is recorded as documented rationale on the requirement itself, which keeps it reviewable without implying an automated descoping mechanism the law does not support.
ORF-456 maps four controls:
OCF-366Privacy-Law Applicability Determination — the UAE-PDPL control for the scope analysis itself: the Article 2 limb-by-limb determination, the exclusion mapping, and the entity inventory.OCF-219PII Role Determination — whether each in-scope entity acts as controller, processor, or both, per the Article 1 definitions.OCF-178Information Audit Process — the audit of what personal data the organization holds and processes, the factual basis for the scope analysis.OCF-210Sector-Specific Compliance — the handling of the sectoral carve-outs: identifying health, banking, and credit data governed by their own legislation and the regime that applies to it.
OCF-219, OCF-178, and OCF-210 are reused from the platform's existing GDPR and ISO 27701 control estate, so an organization already running those frameworks extends existing scope work rather than repeating it.
Articles 24–25 — complaints and the grievance path
Article 24 gives data subjects "the right to submit complaints to the Bureau" where they believe the PDPL has been violated or that a controller or processor is processing their personal data contrary to the rules and procedures the Bureau sets. The Bureau "shall examine such complaints in coordination with the Controller and the Processor", and imposes the Article 26 administrative penalties where a violation is proven. Article 24 places the examination duty on the Bureau, with examination carried out in coordination with the controller and the processor; it does not itself enumerate duties for the organization. The prudent posture is enforcement readiness: an organization the Bureau coordinates with should be able to respond with its records, assessments, and corrective actions.
Article 25 sets the grievance path against the Bureau's own decisions, and its two time limits are in the law itself, not deferred to the Executive Regulation. Any stakeholder may submit a written grievance to the General Director of the Bureau against any decision, administrative penalty, or other action taken against it, within thirty days of notice; the grievance is to be decided within thirty days of submission. The sequencing rule is explicit:
It is not permissible to challenge any decision issued by the Bureau in implementation of the provisions of this Decree by Law before submitting a grievance against the same.
No Bureau decision may be challenged before a grievance against it has been submitted; the law states that sequencing rule without naming the forum for any later challenge. The procedures for submitting and deciding grievances are reserved to the Executive Regulation; the thirty-day windows and the grievance-first rule apply on the face of the law.
Article 26 — administrative penalties
Article 26 does not itself set penalties. It provides that the Council of Ministers, on the suggestion of the General Director of the Bureau, "shall issue a decision to limit the actions which constitute a violation of this Decree by Law and its Executive Regulations, including administrative penalties to be imposed." As of this framework release, that Council of Ministers decision has not been issued, so the PDPL defines no violation list and no penalty amounts. Any figure quoted for UAE PDPL fines is not from this law.
Enforcement readiness in Modulos (ORF-463)
ORF-463 (Complaints, Grievances, and Enforcement Readiness) is framed as readiness toward the Bureau: the organization must be prepared to engage with the Bureau's complaint examination, meet the Article 25 windows if it ever contests a Bureau decision, and understand that penalty exposure remains undefined until the Article 26 Council of Ministers decision is issued. It maps three controls:
OCF-368Regulatory Decision Grievance Management — the UAE-PDPL control for the Article 25 path: recognizing a Bureau decision, the thirty-day submission window, the grievance-before-challenge rule, and the thirty-day decision window.OCF-12Cooperation with Competent Authorities — the organization's readiness to engage with authorities, applied here to the Bureau's Article 24 complaint examination, which the law says the Bureau carries out in coordination with the controller and the processor.OCF-203Supervisory Authority Interface — the named ownership and channel for regulator contact, reused from the GDPR estate.
Articles 27–29 — authorization, the Executive Regulation, and regularisation
Article 27 — Authorization
Article 27 permits the Council of Ministers, on the General Director's suggestion, to authorize a competent local government authority to exercise some of the Bureau's powers within its local competence. This is internal to the state's administrative structure and creates no duty for controllers or processors; its practical relevance is that a local authority may in future act with the Bureau's powers.
Article 28 — The Executive Regulation
Article 28 provides that the Council of Ministers, on the General Director's suggestion, "shall issue the Executive Regulations of this Decree by Law within six (6) months as of the date on which the Decree by Law is promulgated." The Executive Regulation has not yet been issued. As with many principal data protection laws, the implementing detail follows separately from the law itself.
Article 29 — Regularisation
Article 29 is the reason the pending Executive Regulation is a planning question rather than a waiting question:
The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months as of the date on which its Executive Regulations are issued. The Council of Ministers may extend such period for another similar period.
The Decree-Law itself has been in force since 2 January 2022; what Article 29 adds is a regularisation period, measured from the Regulation's issuance, of at most six months, extendable once. An organization that begins its gap analysis at issuance spends that window discovering obligations instead of closing them.
The Executive Regulation: what is pending
The PDPL reserves implementing detail across its articles to the Executive Regulation, and two further instruments sit alongside it. The items an organization cannot pin down as of this framework release:
- Breach notification periods and modalities — the Article 9 notification to the Bureau and to data subjects applies "within the period and in accordance with the measures and requirements set by the Executive Regulations". No notification deadline exists yet, and no analogy to other laws' deadlines applies.
- DPO appointment criteria — Article 10(4) reserves the types of technologies and the data-volume criteria behind the appointment triggers to the Executive Regulation; the law's own Article 10(1) triggers stand in the meantime.
- Cross-border transfer controls — the controls and stipulations for Article 23 transfers are reserved to the Executive Regulation (Article 23(2)), and Article 22 transfers depend on cases approved by the Bureau. Article 22 creates no country-list mechanism, and no Bureau approvals are published.
- Penalty amounts — the Article 26 Cabinet decision defining violations and administrative penalties has not been issued.
- Grievance procedures — the Article 25 submission and decision procedures are reserved to the Executive Regulation; the thirty-day windows are in the law.
- Exemption standards and exempt lists — the Article 3 exemption standards, the Article 21(6) Bureau list of processing operations not requiring an impact assessment (not published as of this framework release), and further detail under Articles 4(11), 5(8), 7(7), 8(11), and 15(3)(d).
ORF-464 (Executive Regulation Readiness and Regulatory Watch) turns this list into an operational posture. It requires a maintained regulatory watch on the pending instruments: the Executive Regulation itself, the Article 26 penalties decision, Bureau approvals under Article 22, and Bureau publications such as the Article 21(6) list. It also requires an inventory of the obligations whose detail those instruments will supply, and an owned, regularly reviewed plan to close each item within the Article 29 regularisation window. The requirement maps a single control, OCF-363 Regulatory Instrument Watch and Readiness, which carries the watch, the inventory, and the plan as one reviewable unit. When the Executive Regulation is issued, ORF-464 becomes the implementation checkpoint for absorbing it rather than being retired.
The same standardized marker appears throughout the framework's requirement text: "The Executive Regulation will specify [X]; it has not yet been issued." The Modulos UAE PDPL framework will be updated when the Executive Regulation is issued.
Related pages
UAE PDPL overview
Framework structure, the OFF-24 / MFF-24 split, and the 18 requirements
Lawful processing and data subject rights
Consent, the Article 4 exceptions, the Article 5 processing controls, and the rights in Articles 13–18
Controllers, processors, and the DPO
The Article 7–8 obligations, processing records, and the Article 10–12 DPO regime
Security, breaches, DPIA, and cross-border transfers
Articles 9 and 20–23: security measures, breach reporting, impact assessment, and transfers
Operationalizing in Modulos
The OFF-24 / MFF-24 rollout sequence, control reuse, and the evidence model
Source attribution
The authoritative source is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, issued 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, in force since 2 January 2022. Quotations are from the official English translation at uaelegislation.gov.ae; for interpretation and application, reference must be made to the original Arabic text, which prevails in case of conflict. Requirement and control codes are Modulos template identifiers, not references used by the law or the Bureau.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The PDPL's Executive Regulation has not yet been issued, and implementing detail on this page is stated as pending for that reason. Verify against the current legislation and consult qualified advisers.