Article 18 (SECURITY MEASURES) - controllers + processors must implement appropriate TECHNICAL + ORGANIZATIONAL MEASURES proportionate to the nature + scope + purposes + risk of processing to ensure confidentiality + integrity + availability of personal data + protection against unauthorised access + disclosure + alteration + accidental loss. Article 19 (PSEUDONYMISATION + ENCRYPTION + PRIVACY BY DESIGN) - controllers must apply pseudonymisation / encryption where appropriate + apply DATA PROTECTION BY DESIGN AND BY DEFAULT principles. Article 20 (CONTROLLER + PROCESSOR RELATIONSHIP) - the controller must engage processors only where they provide sufficient guarantees of GDPR-style technical + organisational measures; the relationship must be governed by a WRITTEN CONTRACT (Data Processing Agreement DPA) specifying processing details + technical + organisational measures + sub-processor controls + breach notification + return / destruction at end of contract + audit rights. Article 21 (DATA PROTECTION IMPACT ASSESSMENT / DPIA) - controllers must conduct a DPIA before processing that is LIKELY TO RESULT IN A HIGH RISK to the rights + freedoms of data subjects. The DPIA must include a description of the processing + assessment of necessity + assessment of risks + mitigation measures. The UAE Data Office may issue guidance on which processing requires a DPIA + may consult with the controller (prior consultation).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.