Article 18 (SECURITY MEASURES) - controllers + processors must implement appropriate TECHNICAL + ORGANIZATIONAL MEASURES proportionate to the nature + scope + purposes + risk of processing to ensure confidentiality + integrity + availability of personal data + protection against unauthorised access + disclosure + alteration + accidental loss. Article 19 (PSEUDONYMISATION + ENCRYPTION + PRIVACY BY DESIGN) - controllers must apply pseudonymisation / encryption where appropriate + apply DATA PROTECTION BY DESIGN AND BY DEFAULT principles. Article 20 (CONTROLLER + PROCESSOR RELATIONSHIP) - the controller must engage processors only where they provide sufficient guarantees of GDPR-style technical + organisational measures; the relationship must be governed by a WRITTEN CONTRACT (Data Processing Agreement DPA) specifying processing details + technical + organisational measures + sub-processor controls + breach notification + return / destruction at end of contract + audit rights. Article 21 (DATA PROTECTION IMPACT ASSESSMENT / DPIA) - controllers must conduct a DPIA before processing that is LIKELY TO RESULT IN A HIGH RISK to the rights + freedoms of data subjects. The DPIA must include a description of the processing + assessment of necessity + assessment of risks + mitigation measures. The UAE Data Office may issue guidance on which processing requires a DPIA + may consult with the controller (prior consultation).
This control maps to 851 controls across 245 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 851 it maps to, and the evidence behind each claim, over MCP and REST.