We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. Records of processing activities
Records of processing, UAE

The supervisory authority can ask for your processing record. There is no preparation time built in.

Article 30 requires the record to be in writing and to be made available to the supervisory authority on request. For UAE businesses offering goods or services to people in the Union, that obligation travels with the customers rather than with the office.

Book a processing record reviewSee what it must contain
Records of processing activities for UAE organisations
  • 7 elementsRequired in a controller record
  • 4 elementsRequired in a processor record
  • On requestNo notice period before it must be produced
  • Under 250A derogation with three broad exceptions
Why a UAE company has this obligation

GDPR follows the data subjects, not the office address.

The territorial scope provision is what brings UAE organisations into an EU regulation without any EU establishment.

  • The Regulation applies to controllers and processors not established in the Union where the processing relates to offering goods or services to data subjects in the Union, whether or not payment is required, or to monitoring their behaviour within the Union.
  • For a UAE business that typically means a website selling into Europe, a mobile application with European users, analytics or advertising that tracks European visitors, or a services business with European clients whose employee data it processes.
  • It also reaches processors. A UAE company providing software, hosting, support or business process services to a European controller is processing on their behalf, and it carries its own Article 30 processor record obligation separately from the controller.
  • None of this depends on having an entity, a server or a bank account in Europe. The connecting factor is the data subjects, which is why organisations are routinely surprised to find themselves in scope after an EU customer asks for their processing record.
Ask us whether you are in scope
What Article 30 requires

Eight things the record has to establish.

The record of processing activities is treated as a documentation exercise and it is closer to an inventory. It is the only document that describes, in one place, every purpose for which your organisation processes personal data and where that data goes.

Purposes, in the plural

The record states the purposes of the processing. Not a single purpose statement for the organisation, but the purpose behind each processing activity, which is where organisations first discover how many separate purposes they are actually operating.

Categories of data subjects and personal data

A description of the categories of data subjects and of the categories of personal data. Employees, customers, candidates, suppliers and visitors are different categories with different expectations, and treating them as one obscures most of the risk.

Recipients, including in third countries

The categories of recipients to whom the data have been or will be disclosed, including recipients in third countries or international organisations. That includes your processors and their subprocessors, which is where most records turn out to be incomplete.

Transfers with their safeguards documented

Where applicable, transfers to a third country or an international organisation, identifying that country or organisation and, for transfers under the second subparagraph of Article 49(1), documenting the suitable safeguards relied upon.

Retention periods where possible

Where possible, the envisaged time limits for erasure of the different categories of data. The qualifier gives some latitude and it is not a licence to leave the field blank across the whole record, which is the most common shortcut taken.

A description of the security measures

Where possible, a general description of the technical and organisational security measures referred to in Article 32(1). General is the operative word, but it still requires knowing what those measures are for each processing activity.

Processors keep a different record

A processor record names the processor and each controller it acts for, describes the categories of processing carried out on behalf of each controller, documents transfers, and gives a general description of security measures. Shorter, and often forgotten entirely.

In writing, including electronic form

The records must be in writing, including in electronic form, and must be made available to the supervisory authority on request. A record that exists as institutional knowledge in three people heads does not meet either requirement.

Two records

Controller record against processor record.

Organisations are frequently both, in different relationships, and need both records. Maintaining only the controller one is the usual gap.
ElementController recordProcessor record
Name and contact detailsController, joint controller, representative, DPOProcessor, each controller, representatives, DPO
Purposes of processingRequiredNot required in this form
Categories of data subjectsRequiredNot required in this form
Categories of personal dataRequiredNot required in this form
Categories of processingNot required in this formRequired, per controller
Categories of recipientsRequired, including third countriesNot required in this form
Third country transfersRequired with safeguards documentedRequired with safeguards documented
Envisaged erasure time limitsWhere possibleNot required in this form
Security measures descriptionWhere possible, generalWhere possible, general
Form and availabilityIn writing, available on requestIn writing, available on request
How we approach it

Four things that make a processing record worth having.

The record is genuinely useful when it is accurate, and it is a liability when it is not, because it is a written statement about your own processing that you have offered to a regulator.

We build it from the business, not from the systems list

Processing activities are business activities. Starting from an application inventory produces a technical document that misses purposes, data subject categories and the paper based processing that still exists in HR and finance in most organisations.

We chase recipients through to subprocessors

The record covers categories of recipients including those in third countries. Suppliers use their own suppliers, and a record that stops at the direct contract understates where the data actually goes, which is exactly what a customer audit tests.

We treat retention as work rather than a blank field

Envisaged erasure time limits are required where possible, and where possible is not the same as never. Establishing them forces useful decisions about what is kept and why, which is valuable independently of the compliance obligation.

We make it maintainable before we hand it over

A record accurate on the day it was written and stale six months later is worse than none, because it is a written and dated statement that contradicts reality. Named ownership and defined update triggers are part of the deliverable.

How an engagement runs

Three phases across roughly five to eight weeks.

The interviews take most of the elapsed time. The record itself is quick to assemble once the processing activities have actually been identified.
  1. 01
    Weeks 1 to 3

    Identify the processing activities

    Function by function across the organisation, since processing happens in HR, sales, marketing, finance, support and operations rather than in a single place. Each activity gets a purpose, which is the anchor for everything else in the record.

    • Processing activities identified per business function
    • Purposes articulated separately per activity
    • Categories of data subjects and personal data described
    • Controller and processor roles distinguished per activity
  2. 02
    Weeks 4 to 6

    Map recipients, transfers and retention

    Where the data goes, including processors and their subprocessors, which third countries are involved and what safeguards are relied upon. Then retention, where possible, which is the field most organisations cannot complete without doing the work.

    • Recipient categories documented including third countries
    • Transfers identified with safeguards recorded
    • Envisaged erasure time limits established where possible
    • Security measures described per activity in general terms
  3. 03
    Weeks 7 to 8

    Assemble, review and make it maintainable

    The record produced in electronic form, reviewed for gaps and internal contradictions, and handed over with a maintenance process. A record that is accurate on the day it is finished and never updated is a liability rather than an asset.

    • Controller and processor records completed in writing
    • Internal review completed and gaps closed
    • Maintenance process defined with a named owner
    • Trigger events agreed for updating the record
Where this comes up

Six situations that make the record urgent.

The record is rarely built because somebody read the Regulation. It is built because somebody asked for it.

A UAE company selling online into Europe

Offering goods or services to data subjects in the Union brings the Regulation into play regardless of establishment. The processing record is one of the first documents an EU customer or a supervisory authority asks about.

A service provider processing on behalf of EU clients

Processors carry their own Article 30 obligation, naming each controller they act for and describing the categories of processing carried out on behalf of each. That record is separate from any record the client maintains.

An organisation responding to a data subject request

Finding every place a person data is held is far easier where processing activities, recipients and retention have already been mapped. Organisations without a record spend the response window discovering their own estate.

A company assessing a personal data breach

Breach assessment depends on knowing what categories of data and data subjects are affected and who the data was disclosed to. That is exactly what the record contains, which is why it becomes valuable at the worst possible moment.

A business under customer security due diligence

Enterprise buyers increasingly ask for the processing record, the subprocessor list and the transfer safeguards. Having them assembled shortens a security review considerably and signals a level of maturity that questionnaires alone do not.

An organisation relying on the small enterprise derogation

The under 250 derogation is removed where processing is likely to risk rights and freedoms, is not occasional, or includes special categories or criminal conviction data. Most organisations that want to rely on it meet at least one exception.

Three positions

How UAE organisations stand on processing records.

The middle column is the most common. It satisfies a checklist and it does not survive a follow up question about a specific system or supplier.
Producible on request
Maintained recordYes, today
Written once, never updatedYes, but inaccurate
No recordNo
Reflects current systems
Maintained recordYes
Written once, never updatedNo
No recordNot applicable
Includes recent suppliers
Maintained recordYes
Written once, never updatedNo
No recordNo
Third country transfers current
Maintained recordYes
Written once, never updatedStale
No recordUnknown
Retention periods stated
Maintained recordWhere possible
Written once, never updatedUsually blank
No recordNone
Processor record exists where needed
Maintained recordYes
Written once, never updatedRarely
No recordNo
Useful for answering customer due diligence
Maintained recordDirectly
Written once, never updatedPartly
No recordNot at all
Supports breach assessment
Maintained recordYes, scope is known
Written once, never updatedSlows it down
No recordMaterially delays it
Effort to reach
Maintained recordWeeks, then maintenance
Written once, never updatedWeeks, once
No recordNone
Position with a supervisory authority
Maintained recordDefensible
Written once, never updatedWeak
No recordAn admission
Feature
Maintained record
Written once, never updated
No record
Producible on request
Yes, todayYes, but inaccurateNo
Reflects current systems
YesNoNot applicable
Includes recent suppliers
YesNoNo
Third country transfers current
YesStaleUnknown
Retention periods stated
Where possibleUsually blankNone
Processor record exists where needed
YesRarelyNo
Useful for answering customer due diligence
DirectlyPartlyNot at all
Supports breach assessment
Yes, scope is knownSlows it downMaterially delays it
Effort to reach
Weeks, then maintenanceWeeks, onceNone
Position with a supervisory authority
DefensibleWeakAn admission
The exemption most companies get wrong

Fewer than 250 employees is not an exemption. It has three exceptions that swallow it.

The derogation is read as a small business carve out, and the qualifying language removes it for most organisations that would want to rely on it.

  • The obligations do not apply to an enterprise employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects. Risk is not a high threshold, and a great deal of ordinary commercial processing meets it.
  • The second exception removes the derogation where the processing is not occasional. Any processing that happens routinely, which describes customer records, employee records, marketing and support, is not occasional in any ordinary reading of the word.
  • The third removes it where the processing includes special categories of data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10. Health data, biometric data and background screening all fall inside that.
  • In practice an organisation of fewer than 250 people processing customer or employee data routinely will meet at least one exception. The safer position is to keep the record, which is useful internally regardless of whether it is strictly required.
Ask us to check the derogation for you
How an engagement runs

Five steps, built around interviews rather than tooling.

Processing happens where people work. The record has to be assembled from those conversations, then verified against systems rather than derived from them.
  1. 1

    Establish scope and role

    Whether the Regulation applies through offering goods or services to data subjects in the Union or monitoring their behaviour, and whether the organisation acts as controller, processor or both. The two roles produce different records with different contents.

  2. 2

    Identify processing activities by function

    HR, finance, sales, marketing, support, operations and IT. Each activity described with its purpose, the categories of data subjects and the categories of personal data involved, which is the core of the controller record.

  3. 3

    Map recipients, transfers and safeguards

    Categories of recipients including those in third countries or international organisations, the transfers themselves with the destination identified, and documentation of the suitable safeguards relied upon where the transfer depends on them.

  4. 4

    Establish retention and describe security measures

    Envisaged erasure time limits for the different categories of data where possible, and a general description of the technical and organisational security measures. Both are qualified by where possible, and both should still be attempted seriously.

  5. 5

    Produce it in writing and make it maintainable

    The record delivered in electronic form so it can be made available to a supervisory authority on request, with a named owner, defined update triggers and a link into procurement so new processors reach the record without anybody remembering to add them.

Straight answers

What UAE organisations ask about processing records.

If the Regulation applies to it, yes. It reaches controllers and processors not established in the Union where the processing relates to offering goods or services to data subjects in the Union or to monitoring their behaviour within the Union.

Contact details for the controller and where applicable joint controller, representative and data protection officer, the purposes of processing, categories of data subjects and personal data, categories of recipients including in third countries, transfers with safeguards, envisaged erasure time limits where possible, and a general description of security measures where possible.

It names the processor and each controller it acts for with any representatives and the data protection officer, describes the categories of processing carried out on behalf of each controller, documents third country transfers with safeguards, and gives a general description of security measures where possible.

Rarely in practice. The derogation falls away where the processing is likely to result in a risk to rights and freedoms, where it is not occasional, or where it includes special categories of data or data relating to criminal convictions and offences.

Yes, and that is why the derogation is narrower than it appears. Routine processing of customer or employee data is not occasional by any ordinary reading, and routine processing is what most organisations do every day.

It must be in writing, including in electronic form. There is no prescribed template, so a well structured spreadsheet or a purpose built tool both satisfy the requirement provided the content is complete and it can be produced when asked.

None is specified. The controller or processor shall make the record available to the supervisory authority on request, which means the practical test is whether you could produce an accurate record today rather than within a reasonable period.

The requirement is categories of recipients, though naming them is common and is often what customers actually want. What matters more is that subprocessors are not missed, since that is where records most frequently understate where data travels.

The requirement is qualified by where possible, so a genuine inability is accommodated. Leaving the field blank across the entire record is a different matter, and it is usually a sign that the retention work was avoided rather than attempted.

A general description of the technical and organisational measures. General is explicitly the standard, so this is not a control matrix, but it does require knowing what measures apply to each processing activity rather than describing the organisation as a whole.

Partly, and not entirely. Tools find where data lives, which helps with recipients and categories. They cannot state purposes, and purpose is the anchor of the whole record, so interviews with the business remain necessary.

Whenever a processing activity, system, supplier or purpose changes, and on a scheduled review regardless. The most reliable approach ties it to procurement, so new processors reach the record as part of onboarding rather than by somebody remembering.

Related but not identical. A data inventory usually describes where data sits. The processing record describes why the organisation processes data, for whom, with whom it is shared, where it goes and for how long. The purpose dimension is what makes it different.

Considerably. It shortens data subject request responses, speeds up breach assessment, answers a large part of customer security due diligence, and frequently surfaces processing that no longer serves any purpose and can be stopped.

We scope by the number of business functions and processing activities. The free first step: ask whether your organisation could produce a complete and accurate processing record this afternoon. The hesitation is usually the answer.

Somewhere it can be maintained rather than somewhere it looks impressive. A well structured spreadsheet that gets updated beats a purpose built tool that nobody has logged into since the implementation project finished.

The requirement is categories of recipients, and naming them is common because customers and auditors usually want the names. The more important point is completeness through to subprocessors rather than the level of naming detail.

The controller record names the controller and, where applicable, the joint controller, along with representatives and the data protection officer. Establishing which relationships are genuinely joint controllership is a legal question worth resolving before the record is written.

Record it as one activity with one purpose, and list the systems and recipients involved. Building the record around systems rather than activities produces a technical inventory that omits purposes, which is the element the Regulation actually requires.

No. It is made available to the supervisory authority on request, and it is frequently shared in whole or in part with customers during due diligence. It is not a public document in the way a privacy notice is.

They describe the same processing to different audiences, which is why they should agree. Where a privacy notice describes purposes the record does not contain, or the record contains purposes the notice never mentions, one of the two is wrong.

A small team drawing on each business function, because the purposes live with the people doing the processing. Attempting it entirely from within IT or entirely from within legal produces a record that is either purposeless or systemless.
Record health check

Fifteen questions to ask of an existing record.

Most organisations that have a record have one that was written once during a compliance project and has not been touched since. These questions find that quickly.

Completeness

  • Does every activity have a stated purpose?
    Not one purpose for all.
  • Are data subject categories distinguished?
    Staff, customers, candidates.
  • Are all recipients listed?
    Including subprocessors.
  • Are third country transfers identified?
    With the country named.
  • Are safeguards documented?
    Where transfers rely on them.

Quality

  • Are retention periods stated?
    Where possible, not never.
  • Are security measures described?
    Generally, per activity.
  • Do we have a processor record too?
    Where we act as processor.
  • Is it in writing or electronic form?
    A stated requirement.
  • Could we produce it today?
    On request means today.

Maintenance

  • When was it last updated?
    Most answers are years.
  • Who owns it?
    Name a person.
  • What triggers an update?
    New system, supplier, purpose.
  • Does procurement feed into it?
    New processors appear there.
  • Is it consistent with our privacy notice?
    They contradict surprisingly often.
Related reading

The pages around this one.

GDPR for UAE businesses

The wider obligation this record sits inside.

Learn more

UAE PDPL compliance

The domestic personal data position.

Learn more

Data discovery and classification audit

Finding the data the record describes.

Learn more
Next step

Ask whether your organisation could produce a complete processing record this afternoon.

The obligation is to make it available on request, with no preparation period built in. Hesitation about that question is the finding, and it is a common one.

Book a processing record reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

DPO as a service

An independent data protection officer without the conflict.

Learn more

GDPR for UAE Businesses

When EU law actually reaches a UAE business, and when it does not

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

Data Discovery Audit

Where the sensitive data is, and who can reach it

Learn more

Privacy Impact Assessment

DPIA done at design stage, necessity tested properly

Learn more

Data Lifecycle Management

Retention policies, labels and defensible deletion

Learn more

Third Party Risk Audit

Who can actually reach your systems, and what to do about it

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy