Framework overlap

Does ISO/IEC 27003:2017 cover Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)?

You hold ISO/IEC 27003:2017 and have been told to do Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL). Here is how much overlaps, control by control.

83% of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) you already have

ISO/IEC 27003:2017 already covers about 83% of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), leaving 2 of 12 controls as genuinely new work.

Already covered 1 Likely covered 9 New work 2

What is genuinely new work

Nothing in ISO/IEC 27003:2017 reaches these. This is the list to scope.

UAE-PDPL-Art.1_2_3
Scope, definitions and applicability (UAE PDPL Articles 1-3)
UAE-PDPL-Art.9
Data breach notification (UAE PDPL Article 9)
Show the 10 you already have
UAE-PDPL-Art.18_19_20_21
Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
UAE-PDPL-Art.10
Data Protection Officer (DPO) (UAE PDPL Article 10)
UAE-PDPL-Art.11_12_13_14_15_16
Data subject rights (UAE PDPL Articles 11-16)
UAE-PDPL-Art.22_23_24
Cross-border data transfers (UAE PDPL Articles 22-24)
UAE-PDPL-Art.25_26_27_28_29
UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
UAE-PDPL-Art.4_5
Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
UAE-PDPL-Art.6_7
Sensitive personal data and children's data (UAE PDPL Articles 6-7)
UAE-PDPL-Art.8
Records of processing activities (UAE PDPL Article 8)
UAE-PDPL-FreeZones
Coordination with DIFC, ADGM and sectoral data protection regimes
UAE-PDPL-Status
UAE PDPL status, executive regulations, UAE Data Office guidance evolution

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27003:2017 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition