UAE PDPL readiness checklist (v3)
Updated for the 2026 executive regulations: lawful basis, cross-border transfer assessments, DPO appointment and breach notification timelines.
Updated for the 2026 executive regulations: lawful basis, cross-border transfer assessments, DPO appointment and breach notification timelines.
Written by Layla Ibrahim and pressure-tested on live data privacy engagements before publication, this checklist is designed to move a programme forward the same week you open it.
Every section is annotated with the decision it should unblock, the owner it should sit with, and the evidence it should leave behind — so the artefact still holds up under audit twelve months later.
- Field-tested against real Stage 1 and Stage 2 audit findings
- Mapped to the controls and cadences the Data Privacy faculty deploy in cohort work
- Editable, credit-line optional — use it inside your organisation without attribution
- Includes evidence pointers, owner fields and a first-90-days cadence
- Heads of GRC, CISOs, DPOs and internal audit leads
- Lead Implementers and Lead Auditors preparing for cert cycles
- Consulting teams standing up client programmes
Book a demo with the faculty who wrote this.
Walk through the checklist with a MAST practitioner — mapped against your controls, your evidence and your next audit window.
Privacy-by-design in a national health programme
How a public-sector health platform embedded DPIAs, consent and data minimisation into product delivery without slowing release cadence.
GDPR × UAE PDPL × KSA PDPL — a comparative controls map
Side-by-side mapping of lawful bases, DSR timelines, transfer mechanisms and breach thresholds across three regimes, with a single unified control set.
DPIA quick-start — 12 questions before you approve
A one-page screening tool product managers can run in ten minutes to decide whether a full DPIA is required — and what evidence to gather either way.
