The supervisory authority can ask for your processing record. There is no preparation time built in.
Article 30 requires the record to be in writing and to be made available to the supervisory authority on request. For UAE businesses offering goods or services to people in the Union, that obligation travels with the customers rather than with the office.

- 7 elementsRequired in a controller record
- 4 elementsRequired in a processor record
- On requestNo notice period before it must be produced
- Under 250A derogation with three broad exceptions
GDPR follows the data subjects, not the office address.
The territorial scope provision is what brings UAE organisations into an EU regulation without any EU establishment.
- The Regulation applies to controllers and processors not established in the Union where the processing relates to offering goods or services to data subjects in the Union, whether or not payment is required, or to monitoring their behaviour within the Union.
- For a UAE business that typically means a website selling into Europe, a mobile application with European users, analytics or advertising that tracks European visitors, or a services business with European clients whose employee data it processes.
- It also reaches processors. A UAE company providing software, hosting, support or business process services to a European controller is processing on their behalf, and it carries its own Article 30 processor record obligation separately from the controller.
- None of this depends on having an entity, a server or a bank account in Europe. The connecting factor is the data subjects, which is why organisations are routinely surprised to find themselves in scope after an EU customer asks for their processing record.
Eight things the record has to establish.
Purposes, in the plural
The record states the purposes of the processing. Not a single purpose statement for the organisation, but the purpose behind each processing activity, which is where organisations first discover how many separate purposes they are actually operating.
Categories of data subjects and personal data
A description of the categories of data subjects and of the categories of personal data. Employees, customers, candidates, suppliers and visitors are different categories with different expectations, and treating them as one obscures most of the risk.
Recipients, including in third countries
The categories of recipients to whom the data have been or will be disclosed, including recipients in third countries or international organisations. That includes your processors and their subprocessors, which is where most records turn out to be incomplete.
Transfers with their safeguards documented
Where applicable, transfers to a third country or an international organisation, identifying that country or organisation and, for transfers under the second subparagraph of Article 49(1), documenting the suitable safeguards relied upon.
Retention periods where possible
Where possible, the envisaged time limits for erasure of the different categories of data. The qualifier gives some latitude and it is not a licence to leave the field blank across the whole record, which is the most common shortcut taken.
A description of the security measures
Where possible, a general description of the technical and organisational security measures referred to in Article 32(1). General is the operative word, but it still requires knowing what those measures are for each processing activity.
Processors keep a different record
A processor record names the processor and each controller it acts for, describes the categories of processing carried out on behalf of each controller, documents transfers, and gives a general description of security measures. Shorter, and often forgotten entirely.
In writing, including electronic form
The records must be in writing, including in electronic form, and must be made available to the supervisory authority on request. A record that exists as institutional knowledge in three people heads does not meet either requirement.
Controller record against processor record.
| Element | Controller record | Processor record | |
|---|---|---|---|
| Name and contact details | Controller, joint controller, representative, DPO | Processor, each controller, representatives, DPO | |
| Purposes of processing | Required | Not required in this form | |
| Categories of data subjects | Required | Not required in this form | |
| Categories of personal data | Required | Not required in this form | |
| Categories of processing | Not required in this form | Required, per controller | |
| Categories of recipients | Required, including third countries | Not required in this form | |
| Third country transfers | Required with safeguards documented | Required with safeguards documented | |
| Envisaged erasure time limits | Where possible | Not required in this form | |
| Security measures description | Where possible, general | Where possible, general | |
| Form and availability | In writing, available on request | In writing, available on request |
Four things that make a processing record worth having.
We build it from the business, not from the systems list
Processing activities are business activities. Starting from an application inventory produces a technical document that misses purposes, data subject categories and the paper based processing that still exists in HR and finance in most organisations.
We chase recipients through to subprocessors
The record covers categories of recipients including those in third countries. Suppliers use their own suppliers, and a record that stops at the direct contract understates where the data actually goes, which is exactly what a customer audit tests.
We treat retention as work rather than a blank field
Envisaged erasure time limits are required where possible, and where possible is not the same as never. Establishing them forces useful decisions about what is kept and why, which is valuable independently of the compliance obligation.
We make it maintainable before we hand it over
A record accurate on the day it was written and stale six months later is worse than none, because it is a written and dated statement that contradicts reality. Named ownership and defined update triggers are part of the deliverable.
Three phases across roughly five to eight weeks.
- 01Weeks 1 to 3
Identify the processing activities
Function by function across the organisation, since processing happens in HR, sales, marketing, finance, support and operations rather than in a single place. Each activity gets a purpose, which is the anchor for everything else in the record.
- Processing activities identified per business function
- Purposes articulated separately per activity
- Categories of data subjects and personal data described
- Controller and processor roles distinguished per activity
- 02Weeks 4 to 6
Map recipients, transfers and retention
Where the data goes, including processors and their subprocessors, which third countries are involved and what safeguards are relied upon. Then retention, where possible, which is the field most organisations cannot complete without doing the work.
- Recipient categories documented including third countries
- Transfers identified with safeguards recorded
- Envisaged erasure time limits established where possible
- Security measures described per activity in general terms
- 03Weeks 7 to 8
Assemble, review and make it maintainable
The record produced in electronic form, reviewed for gaps and internal contradictions, and handed over with a maintenance process. A record that is accurate on the day it is finished and never updated is a liability rather than an asset.
- Controller and processor records completed in writing
- Internal review completed and gaps closed
- Maintenance process defined with a named owner
- Trigger events agreed for updating the record
Six situations that make the record urgent.
A UAE company selling online into Europe
Offering goods or services to data subjects in the Union brings the Regulation into play regardless of establishment. The processing record is one of the first documents an EU customer or a supervisory authority asks about.
A service provider processing on behalf of EU clients
Processors carry their own Article 30 obligation, naming each controller they act for and describing the categories of processing carried out on behalf of each. That record is separate from any record the client maintains.
An organisation responding to a data subject request
Finding every place a person data is held is far easier where processing activities, recipients and retention have already been mapped. Organisations without a record spend the response window discovering their own estate.
A company assessing a personal data breach
Breach assessment depends on knowing what categories of data and data subjects are affected and who the data was disclosed to. That is exactly what the record contains, which is why it becomes valuable at the worst possible moment.
A business under customer security due diligence
Enterprise buyers increasingly ask for the processing record, the subprocessor list and the transfer safeguards. Having them assembled shortens a security review considerably and signals a level of maturity that questionnaires alone do not.
An organisation relying on the small enterprise derogation
The under 250 derogation is removed where processing is likely to risk rights and freedoms, is not occasional, or includes special categories or criminal conviction data. Most organisations that want to rely on it meet at least one exception.
How UAE organisations stand on processing records.
| Feature | Maintained record | Written once, never updated | No record |
|---|---|---|---|
Producible on request | Yes, today | Yes, but inaccurate | No |
Reflects current systems | Yes | No | Not applicable |
Includes recent suppliers | Yes | No | No |
Third country transfers current | Yes | Stale | Unknown |
Retention periods stated | Where possible | Usually blank | None |
Processor record exists where needed | Yes | Rarely | No |
Useful for answering customer due diligence | Directly | Partly | Not at all |
Supports breach assessment | Yes, scope is known | Slows it down | Materially delays it |
Effort to reach | Weeks, then maintenance | Weeks, once | None |
Position with a supervisory authority | Defensible | Weak | An admission |
Fewer than 250 employees is not an exemption. It has three exceptions that swallow it.
The derogation is read as a small business carve out, and the qualifying language removes it for most organisations that would want to rely on it.
- The obligations do not apply to an enterprise employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects. Risk is not a high threshold, and a great deal of ordinary commercial processing meets it.
- The second exception removes the derogation where the processing is not occasional. Any processing that happens routinely, which describes customer records, employee records, marketing and support, is not occasional in any ordinary reading of the word.
- The third removes it where the processing includes special categories of data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10. Health data, biometric data and background screening all fall inside that.
- In practice an organisation of fewer than 250 people processing customer or employee data routinely will meet at least one exception. The safer position is to keep the record, which is useful internally regardless of whether it is strictly required.
Five steps, built around interviews rather than tooling.
- 1
Establish scope and role
Whether the Regulation applies through offering goods or services to data subjects in the Union or monitoring their behaviour, and whether the organisation acts as controller, processor or both. The two roles produce different records with different contents.
- 2
Identify processing activities by function
HR, finance, sales, marketing, support, operations and IT. Each activity described with its purpose, the categories of data subjects and the categories of personal data involved, which is the core of the controller record.
- 3
Map recipients, transfers and safeguards
Categories of recipients including those in third countries or international organisations, the transfers themselves with the destination identified, and documentation of the suitable safeguards relied upon where the transfer depends on them.
- 4
Establish retention and describe security measures
Envisaged erasure time limits for the different categories of data where possible, and a general description of the technical and organisational security measures. Both are qualified by where possible, and both should still be attempted seriously.
- 5
Produce it in writing and make it maintainable
The record delivered in electronic form so it can be made available to a supervisory authority on request, with a named owner, defined update triggers and a link into procurement so new processors reach the record without anybody remembering to add them.
What UAE organisations ask about processing records.
Fifteen questions to ask of an existing record.
Completeness
- Does every activity have a stated purpose?Not one purpose for all.
- Are data subject categories distinguished?Staff, customers, candidates.
- Are all recipients listed?Including subprocessors.
- Are third country transfers identified?With the country named.
- Are safeguards documented?Where transfers rely on them.
Quality
- Are retention periods stated?Where possible, not never.
- Are security measures described?Generally, per activity.
- Do we have a processor record too?Where we act as processor.
- Is it in writing or electronic form?A stated requirement.
- Could we produce it today?On request means today.
Maintenance
- When was it last updated?Most answers are years.
- Who owns it?Name a person.
- What triggers an update?New system, supplier, purpose.
- Does procurement feed into it?New processors appear there.
- Is it consistent with our privacy notice?They contradict surprisingly often.
Ask whether your organisation could produce a complete processing record this afternoon.
The obligation is to make it available on request, with no preparation period built in. Hesitation about that question is the finding, and it is a common one.
Related Services
Explore more solutions that work great with this service
DPO as a service
An independent data protection officer without the conflict.
GDPR for UAE Businesses
When EU law actually reaches a UAE business, and when it does not
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Data Discovery Audit
Where the sensitive data is, and who can reach it
Privacy Impact Assessment
DPIA done at design stage, necessity tested properly
Data Lifecycle Management
Retention policies, labels and defensible deletion
Third Party Risk Audit
Who can actually reach your systems, and what to do about it
Compliance as a Service
Keeping the position true between assessments