Article 8 imposes the RECORDS-OF-PROCESSING-ACTIVITIES requirement on controllers + processors. The records must include: (a) name + contact details of the controller / processor + the DPO if any + the joint controller + the representative; (b) purposes of processing; (c) description of categories of data subjects + categories of personal data; (d) categories of recipients to whom personal data has been or will be disclosed; (e) cross-border transfers + the legal basis for transfer; (f) envisaged retention periods; (g) general description of technical + organizational security measures. Records must be maintained in writing + electronic form + made available to the UAE Data Office upon request. The records must be UPDATED + reviewed periodically + retained beyond the processing period in line with the audit-trail expectations. Records are the foundational compliance artefact for UAE PDPL programmes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.