Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection; (b) APPROPRIATE SAFEGUARDS - binding contractual clauses similar to GDPR SCCs + binding corporate rules (BCRs) + approved certification mechanisms; (c) EXCEPTIONS - explicit consent of the data subject for the transfer + necessity for performance of a contract + necessity for important reasons of public interest + necessity for the establishment / exercise / defence of legal claims + necessity to protect vital interests + necessity for compelling legitimate interests of the controller proportionate to data subject rights. Article 23 (PROHIBITIONS) - certain transfers are PROHIBITED where they would jeopardise the rights + freedoms of data subjects or where the destination country has been designated as inadequate. Article 24 (NOTIFICATIONS) - controllers must notify the UAE Data Office of cross-border transfers + maintain records. UAE-Data-Office-approved transfer mechanisms include: data subject consent + contractual SCCs + BCRs + adequacy decisions. The 2024 UAE Data Office issued initial adequacy decisions for certain jurisdictions including GDPR-aligned countries (subject to ongoing review).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.