Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection; (b) APPROPRIATE SAFEGUARDS - binding contractual clauses similar to GDPR SCCs + binding corporate rules (BCRs) + approved certification mechanisms; (c) EXCEPTIONS - explicit consent of the data subject for the transfer + necessity for performance of a contract + necessity for important reasons of public interest + necessity for the establishment / exercise / defence of legal claims + necessity to protect vital interests + necessity for compelling legitimate interests of the controller proportionate to data subject rights. Article 23 (PROHIBITIONS) - certain transfers are PROHIBITED where they would jeopardise the rights + freedoms of data subjects or where the destination country has been designated as inadequate. Article 24 (NOTIFICATIONS) - controllers must notify the UAE Data Office of cross-border transfers + maintain records. UAE-Data-Office-approved transfer mechanisms include: data subject consent + contractual SCCs + BCRs + adequacy decisions. The 2024 UAE Data Office issued initial adequacy decisions for certain jurisdictions including GDPR-aligned countries (subject to ongoing review).
This control maps to 76 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.