The Controller must establish controls and procedures to be followed when Processing Personal Data. They must include in particular: (a) identification of risks to which the Data Subject may be exposed as a result of Processing; (b) procedures and controls for transporting and transferring Personal Data; (c) technical and procedural measures ensuring that Processing is carried out in accordance with this Law; (d) any other controls or procedures prescribed by the Regulation.
This article belongs to the source version of Royal Decree 6/2022. Amendment 68/2026 has not yet been incorporated into the published article-by-article text. Interpretation and application must be checked against the official Arabic text and the current version.
