Article 9 imposes the DATA-BREACH-NOTIFICATION regime. Controllers must NOTIFY the UAE Data Office of any personal data breach that may pose a risk to the privacy + confidentiality + security of the data subjects WITHOUT UNDUE DELAY (the UAE PDPL does not specify the GDPR 72-hour timeline; the Data Office guidance recommends prompt notification). The notification must include: (a) NATURE of the breach (categories of data + data subjects affected + approximate numbers); (b) NAME + contact details of the DPO or other contact point; (c) LIKELY CONSEQUENCES of the breach; (d) MEASURES taken or proposed to address the breach + mitigate adverse effects. Article 9 also requires controllers to NOTIFY DATA SUBJECTS without undue delay where the breach is likely to result in a HIGH RISK to their rights + freedoms; the notification to data subjects should be in clear + plain language. Records of breaches must be maintained + the controller must document the facts + effects + remedial action taken.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.