Article 10 establishes the conditions under which a controller / processor must APPOINT A DATA PROTECTION OFFICER (DPO). A DPO is REQUIRED where: (a) processing involves SENSITIVE PERSONAL DATA on a large scale; (b) processing involves SYSTEMATIC EVALUATION + MONITORING of data subjects on a large scale; (c) processing carried out by an authority (other than judicial activities). The DPO must have expert knowledge of data protection law + practice + the technical aspects of data processing; the DPO may be an employee or external consultant; the DPO must be INDEPENDENT + report DIRECTLY TO THE HIGHEST LEVEL of management of the controller; the DPO must NOT be dismissed or penalised for performing their tasks. The DPO's tasks include: (a) MONITORING compliance with the UAE PDPL; (b) ADVISING the controller / processor on data protection matters; (c) Cooperating with the UAE Data Office + being the CONTACT POINT for the Data Office + data subjects; (d) Conducting periodic AUDITS + training programmes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.