Article 9 imposes the DATA-BREACH-NOTIFICATION regime. Controllers must NOTIFY the UAE Data Office of any personal data breach that may pose a risk to the privacy + confidentiality + security of the data subjects WITHOUT UNDUE DELAY (the UAE PDPL does not specify the GDPR 72-hour timeline; the Data Office guidance recommends prompt notification). The notification must include: (a) NATURE of the breach (categories of data + data subjects affected + approximate numbers); (b) NAME + contact details of the DPO or other contact point; (c) LIKELY CONSEQUENCES of the breach; (d) MEASURES taken or proposed to address the breach + mitigate adverse effects. Article 9 also requires controllers to NOTIFY DATA SUBJECTS without undue delay where the breach is likely to result in a HIGH RISK to their rights + freedoms; the notification to data subjects should be in clear + plain language. Records of breaches must be maintained + the controller must document the facts + effects + remedial action taken.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.