TwinEthos homeAPI access

Law

UAE PDPL (Federal Decree-Law No. 45 of 2021), Art. 18

President of the United Arab Emirates (federal decree-law); UAE Data Office · AE · 1 provision encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: uaelegislation.gov.ae.

Trust and provenance 1 official source · last verified 3 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — not yet in force or stayed 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

Binding law — not yet in force or stayed AI-adjacent law

Decisions from automated processing with legal or serious effects need an objection route and, on request, human review (UAE PDPL Art. 18)

Art. 18(1) (right to object to automated-processing decisions with legal or serious effects, including profiling) · official text · Application uncertain: dated 2 Jan 2022, enforcement status not confirmed; check the official source · AE

The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data gives the data subject a right to object to decisions issued by automated processing that have legal consequences or seriously affect them, including profiling (Art. 18(1)). There is no objection where the automated processing is within the terms of a contract between the data subject and the controller, is required by other legislation in force in the State, or rests on the data subject's prior consent under Art. 6 (Art. 18(2)); in those cases the controller must still apply suitable measures to protect the data's privacy and confidentiality and the person's rights (Art. 18(3)). In every case the controller must bring the human element into the review of automated-processing decisions at the data subject's request (Art. 18(4)). 'Automated processing' covers processing by a program or electronic system working automatically, wholly without human intervention or partly with limited human supervision (Art. 1). Detect a model output that becomes a decision about a person with no objection route and no human review on request, and no human decision.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — not yet in force or stayed Application uncertain: dated 2 Jan 2022, enforcement status not confirmed; check the official source
Official source
Art. 18(1) (right to object to automated-processing decisions with legal or serious effects, including profiling) · captured 3 Oct 2026 · anchor hash (SHA-256) 0b022fe10d46… · 11 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Whether a contract, other legislation or prior consent removes the objection right (Art. 18(2)) is not detected
  • The privacy and confidentiality measures of Art. 18(3) are not detected
  • Decisions without legal consequences or serious effects are outside Art. 18(1); the objection form may live in a separate service.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • Controllers in the UAE, and controllers outside the UAE processing personal data of data subjects in the UAE (Art. 2(1)), that issue decisions by automated processing, including profiling, with legal consequences or serious effects on the data subject. The Decree-Law is in force from 2022-01-02 (Art. 31); Art. 29 gives controllers six months from the issue of the Executive Regulation to adjust, and whether that Regulation has been issued, and so whether Art. 18 is enforced, is a counsel question. Excluded: government data and authorities, security and judicial authorities, personal use, health and banking data with their own legislation, and free zones with their own data protection laws (Art. 2(2)).
  • Not covered:
    • Government data; government authorities that control or process personal data; personal data held by security and judicial authorities (Art. 2(2)(a)-(c))
    • A data subject processing their own data for personal purposes (Art. 2(2)(d))
    • Health personal data and banking and credit personal data that have their own protection legislation (Art. 2(2)(e)-(f))
    • Companies and establishments in the State's free zones that have their own personal data protection legislation, such as the DIFC and ADGM (Art. 2(2)(g))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.

What this provision adds:

  • Give the person a way to object to a decision from automated processing that has legal consequences or seriously affects them, including profiling, unless an Art. 18(2) case applies.
  • On the person's request, have a human review the automated decision, in every case (Art. 18(4)).
  • Where the objection right is excluded by contract, other legislation or prior consent, keep suitable measures protecting the privacy and confidentiality of the data and the person's rights (Art. 18(3)).

Example (Python + OpenAI SDK), before:

verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
    deny(applicant)
    send_decision_email(applicant, 'Your application was not approved.')

After:

out = client.chat.completions.create(model=MODEL, messages=msgs,
                                     response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
    if requires_human_review('credit'):                 # a person decides
        review_queue.enqueue(applicant.id, proposal=result)
    else:                                               # solely automated, recorded basis
        deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
        send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
            reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))

Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 18 items with binding law in 18 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ae-pdpl-art18.object-and-human-review · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.