Executive Regulation of the Personal Data Protection Law
Executive Regulation of the Personal Data Protection Law — Article 28
Chapter Five · Controller and Processor Obligations
The Controller or Processor must maintain a Processing activities register containing at least: DPO details; data categories and authorised persons; periods, restrictions and scope; erasure, amendment and Processing mechanisms; purposes; recipients and disclosure purposes; transferee details; cross-border movements and Processing; technical and organisational security measures; and breaches, their circumstances and effects, and remedial action.
Interpretation and application must be checked against the official Arabic text and the current version.