Article 1 provides definitions of key terms including: PERSONAL DATA = any data related to an identified or identifiable natural person; SENSITIVE PERSONAL DATA = data revealing racial / ethnic origin, political opinions, religious beliefs, biometric / genetic / health data, criminal records; CONTROLLER / PROCESSOR; DATA SUBJECT; CONSENT; CROSS-BORDER TRANSFER; UAE DATA OFFICE. Article 2 scope: the Law applies to (a) any controller / processor in the UAE; (b) any controller / processor outside the UAE that processes personal data of data subjects in the UAE (extraterritorial scope similar to GDPR Article 3). Article 3 exclusions: the Law does NOT apply within the financial free zones (DIFC + ADGM maintain own sectoral DP regimes) + does NOT apply to personal data held by competent UAE security authorities + does NOT apply to certain personal-personal-or-household processing. The Law is administered by the UAE DATA OFFICE.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.