IoL Workflows
Administrative   Family K · Facilities, IT, data protection, safety  ·  IoL Administrative Affairs

AW-16 · Data Protection and Information Security Operations

Primary KPIsnone
Contributes to
TriggerA new dataset, system, processor, purpose or transfer; a scheduled review; an access request; a data subject request; a suspected breach; an audit finding
EndpointEvery personal dataset is in the inventory with owner, classification, lawful basis, access roles, processors, transfers and retention class, and each section 8 control can be evidenced
OBEF touchpoint**Every personal-data flow in the academic pack.** Graduate contacts (WF-25), supervisor and employer contacts (WF-14), student contacts for surveys (WF-06), attendee names (WF-23), and the raw survey data retained for Appendix B (WF-06, WF-14, WF-25). WF-26 releases none of it until the section 8 controls are met

BPMN 2.0 (ISO/IEC 19510), generated from the procedure section of this document. Lanes are the roles in the RACI; a cylinder marks a capture point and the KPI it feeds; a diamond is a decision point. Click a task to jump to its step. Scroll to zoom, drag to pan.

AW-16 — Data Protection and Information Security Operations

Workflow ID AW-16
Pack owner IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md)
Family K — Facilities, IT, data protection, safety
Ownership Slice of MBRU information governance and Dubai Health data protection. MBRU and Dubai Health own policy, the data protection officer function, lawful-basis determination, regulator and data-subject notification and institutional system security; IoL owns the departmental data inventory, classification, access and handling controls, first-line breach response, oversight of the processors it procures, training and the evidence [IoL to confirm]
Governing policy UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data [IoL to confirm applicability and current text]; Dubai Health data governance and information security requirements [IoL to confirm applicability and current text]; MBRU data protection, information security and acceptable use policies [IoL to confirm]; ISO 9001:2015 clause 7.5.3; ISO 21001:2018 clause 7.5.3 and its stated principle of data security and protection
Interfaces WF-25; WF-26; WF-06, WF-14, WF-23; AW-04; AW-15; AW-07 and AW-08; AW-23; AW-24; AW-06
OBEF touchpoint Every personal-data flow in the academic pack. Graduate contacts (WF-25), supervisor and employer contacts (WF-14), student contacts for surveys (WF-06), attendee names (WF-23), and the raw survey data retained for Appendix B (WF-06, WF-14, WF-25). WF-26 releases none of it until the section 8 controls are met
Process owner ______________
Version 0.1 draft
Effective
Next review

1. Purpose

To ensure that every item of personal data IoL holds is known, classified, held for a stated purpose on a stated lawful basis, accessible only to the roles that need it, transferred only through approved channels, retained only as long as AW-04 requires, and protected by controls whose operation can be evidenced; and that when something goes wrong it is contained, reported within the required time and learned from.

2. Scope

Scope statement. This procedure manages IoL's handling of personal data from the creation or receipt of a dataset, through classification, access, use, transfer and retention, to disposal, together with the response to data subject requests and to breaches.

Applies to. Personal data held by IoL on learners, applicants, graduates, staff, adjuncts, workplace supervisors, employer contacts, survey respondents, event attendees and contractors, in every system, file, survey platform, mailbox and paper record; and to every IoL role, including adjuncts and student assistants.

Does not apply to. Clinical records of patients, which Dubai Health holds and IoL does not access for education purposes; institutional policy and lawful-basis determination, which are MBRU's and Dubai Health's; institutional infrastructure security, which is MBRU IT's; research data under an approved ethics protocol (WF-15), which follows its data management plan with this procedure as the floor.

Applicable requirements. ISO 9001:2015 clause 7.5.3; ISO 21001:2018 clause 7.5.3 and its principle of data security and protection; UAE Federal Decree-Law No. 45 of 2021 [IoL to confirm applicability and current text]; UAE federal requirements on information technology in health fields, where any health-related data is handled [IoL to confirm applicability]; Dubai Health data governance requirements [IoL to confirm applicability and current text]; MBRU policy [IoL to confirm]; the OBEF guide's Appendix B, which creates a retention obligation for raw survey data.

3. Trigger, boundary and endpoint

Trigger A new dataset, system, processor, purpose or transfer; a scheduled review; an access request; a data subject request; a suspected breach; an audit finding
First activity Entry or update of the dataset in the data inventory
Last activity Verified disposal at the end of the AW-04 retention period, or closure of the request or incident
Endpoint Every personal dataset is in the inventory with owner, classification, lawful basis, access roles, processors, transfers and retention class, and each section 8 control can be evidenced
Upstream Every AW and WF that creates personal data; AW-07, AW-08; AW-23; Data Governance
Downstream WF-26 release gate; AW-04; AW-15; AW-24; AW-06; AW-25

4. SIPOC

Element Content
Suppliers Data subjects; the workflows that create data; Data Governance; MBRU IT; survey and CRM vendors; MoHESR and CHEDS, whose formats shape what is collected
Inputs Personal data at creation; notices and consents; the classification scheme; the AW-15 access matrix; processor contracts; the AW-04 retention schedule
Process Inventory → classify → lawful basis and notice → DPIA where triggered → minimum-necessary access → approved transfer → retain and dispose → answer requests → manage breaches → train → audit
Outputs Data inventory; DPIA records; access approvals; transfer log; disposal records; request and breach logs; training records; annual report
Customers Data subjects; the academic pack; MBRU and Dubai Health data governance; MoHESR and CHEDS; auditors
Success criteria No dataset outside the inventory; no access outside the matrix; no transfer outside the log; no data past its retention date; every breach and request handled within the timeline

5. Accountability

Process owner. IoL Data Protection Lead, a departmental role distinct from the institutional data protection officer, who sits with MBRU or Dubai Health [IoL to confirm]. The process owner may stop any transfer or processing that fails the section 8 controls.

Step Data Steward Data Owner IoL Data Protection Lead MBRU or Dubai Health Data Governance MBRU IT
Maintain the data inventory R R A/R I I
Classify a dataset R A/R C I I
Confirm lawful basis, purpose and notice wording C R R A I
Decide whether a DPIA is required C R A/R C I
Approve a DPIA I R R A C
Approve access to a dataset I A/R C I I
Approve an external transfer R A R C I
Approve a processor I R R A C
Respond to a data subject request R R R A I
Declare, contain and review a breach R R A/R I R
Notify the regulator and data subjects I I R A I

Data Owner is the process owner of the AW or WF that creates the dataset (the WF-25 owner for graduate data, the WF-06 owner for course evaluations). Data Steward is the named person who operates it. A dataset with no named owner is a non-conformity.

Escalation.

Condition Escalates to Within
Suspected breach of any kind IoL Data Protection Lead, then Data Governance 1 hour of discovery; onward within [IoL to confirm]
Transfer or release requested without a step 8 checklist IoL Data Protection Lead stops it and informs the Data Owner Same day
Lawful basis unsettled at the point of use Data Owner to Data Governance; processing does not proceed Before processing

6. Procedure

  1. Build and keep the data inventory. The IoL Data Protection Lead holds a register of every dataset containing personal data: owner and steward; subjects; categories; source; purpose; lawful basis; classification; location; access roles; processors; transfers; AW-04 retention class and disposal date; DPIA status. Datasets are entered before collection begins; the inventory is refreshed annually and on every change. [CONTROL] No personal dataset exists outside the inventory; a spreadsheet of names found outside it is a non-conformity under AW-24.

  2. Classify. Four classes. Public. Internal: staff use, business contact details only. Confidential: personal data of learners, graduates, staff, contacts and respondents, for named roles only. Restricted: data whose loss would cause serious harm: health or disability information (AW-19), disciplinary and grievance records (AW-09), identity documents, financial details, and raw per-person survey responses identifying a respondent's views about a named supervisor or employer. Education records and clinical records are distinct categories. IoL staff do not access clinical records for education purposes, and clinical staff do not access education records for clinical purposes. [CONTROL] The class is recorded in the inventory and marked on the document or system; unmarked material is treated as Confidential.

  3. Confirm the lawful basis and purpose for each category, and stop at that purpose. The Data Owner proposes and Data Governance confirms the basis, recorded in the inventory. The categories and the questions to settle [IoL to confirm each with Data Governance]:

    Category Created by Purpose Basis to settle
    Applicant and learner records WF-07, WF-10, AW-18 Programme delivery, progression, regulatory reporting Contract and legal obligation
    Learner contacts for course evaluation WF-06 KPI 2.6, quality improvement Legitimate interest or consent; notice says raw responses may be inspected by the Ministry
    Graduate contacts, consent and outcomes WF-25, WF-10 Outcomes, licensure, contacts to MoHESR, substitute-data submissions Consent at clearance, or legal obligation; notice says contacts may go to the Ministry and raw data is retained for Appendix B
    Supervisor and employer contacts WF-13, WF-14, WF-25 KPIs 2.3 and 2.4 Legitimate interest or consent; business contact details only
    Staff and adjunct records AW-07, AW-08 Employment, appointment, credentialing Contract and legal obligation
    Event attendees WF-23, AW-21 Attendance evidence for KPIs 6.1 and 6.2, safety Consent or contract at registration; notice says names are retained as evidence
    Alumni relationship data AW-22 Communication, engagement Consent, never inferred from the WF-25 outcomes consent

    [CONTROL] Data collected for one purpose is not used for another without a documented basis and, where required, a fresh notice: graduate contacts captured for outcome tracking are not used for marketing or event invitations unless the notice covered it.

  4. Issue the notice and record consent. Every collection point uses a plain-language notice approved by Data Governance and held under AW-03. Where consent is the basis, the record holds the person, date, notice version and purposes agreed, including onward transfer to MoHESR. [CONTROL] Consent is never inferred from silence, from enrolment alone, or from a consent given for a different purpose.

  5. Screen for a DPIA, and conduct one where triggered. A DPIA is required before: a new system or processor holding Confidential or Restricted data; any transfer outside the UAE; a new Restricted category; large-scale processing of graduate, employer or respondent data; linkage of datasets that could identify individuals not identifiable in either alone; a substitute-data methodology under WF-25; any change of purpose. The Lead screens every new inventory entry. The DPIA, on the MBRU template [IoL to confirm], covers necessity, proportionality, risks to individuals and measures, and is approved by Data Governance. [CONTROL] Processing that triggers a DPIA does not start until the DPIA is approved.

  6. Grant access on the minimum-necessary principle. Access is by role, set in the AW-15 matrix and approved by the Data Owner. A role receives the fields it needs and no more: a survey analyst receives pseudonymised responses, not names; the WF-26 assembly team receives aggregates and the evidence index, not the person-level file. No shared accounts, no personal email, no personal devices for Restricted data [IoL to confirm MBRU device policy]. [CONTROL] Restricted access is granted only after the person's training record (step 11) is complete.

  7. Handle data securely in daily work. Personal data lives only in the locations listed in the inventory; extracts are made only with Data Owner approval and a deletion date. Spreadsheets with personal data are linked, not emailed. WF-26 analysis files are pseudonymised, the key held by the Data Steward apart from the file. Restricted paper is locked away and shredded.

  8. Meet the release gate, then transfer only through approved channels. Before personal data leaves IoL in any form, the Data Steward completes and the Data Owner signs a transfer checklist: lawful basis confirmed; recipient's entitlement confirmed; fields reduced to the minimum the recipient's format requires; DPIA where triggered; channel approved; deletion expectations stated; log entry made. Transfers to MoHESR, CHEDS and Dubai Health use the channel each specifies and MBRU approves [IoL to confirm channels], otherwise MBRU-approved encrypted transfer; never unencrypted email, consumer file-sharing or removable media. The log records date, sender, recipient, dataset, fields, record count and acknowledgement. Where a CHEDS template carries person-level identifiers [IoL to confirm which fields], the Data Owner confirms each is required before it is populated. [CONTROL] WF-26 does not release any personal data, or any file containing it, to the MBRU institutional OBEF process without a signed checklist for that release: graduate contact extracts, substitute-data packs, employer lists and attendee lists alike.

  9. Control processors and third parties. Survey platforms, CRM, cloud storage, event registration tools and any vendor touching personal data are processors. Before use: due diligence on security and data location; an AW-23 contract covering purpose limitation, confidentiality, sub-processors, data location, breach notification to IoL, audit rights and deletion at end of contract; a register entry; DPIA where triggered. Processors are reviewed annually. [CONTROL] No personal data enters a tool without a processor contract and register entry; free-tier survey and form tools are not used for personal data.

  10. Retain and dispose in line with AW-04. Every dataset carries its AW-04 retention class from creation. Raw per-person survey and outcome data retained for Appendix B is held for the period WF-25 and AW-04 specify, seven years minimum for substitute-data records, in a Restricted location open to the Data Steward only, its retention justified in the inventory as evidentiary. At the disposal date the Data Steward disposes by the AW-04 method and records it. [CONTROL] No personal data is retained past its disposal date without a documented Data Owner decision and a new date.

  11. Train and keep awareness. Every joiner completes data protection training at AW-07 or AW-08 induction, before any Confidential access; Data Stewards and Restricted-data handlers complete role-specific training; refreshers are annual; a briefing follows any breach. [CONTROL] A person without a current training record does not hold Restricted access; AW-15 removes it at the quarterly review where the record has lapsed.

  12. Answer data subject requests. Requests to access, correct, delete, restrict or object, and consent withdrawals, are logged the same day wherever they arrive and routed to the Lead, who confirms identity, finds every dataset holding the person's data from the inventory, and coordinates the response with Data Governance, which is accountable for the answer and the timeline [IoL to confirm under UAE law and MBRU policy]. Withdrawal of graduate outcome consent is actioned in WF-25 within 5 working days. [CONTROL] Deletion requests are checked against AW-04 legal holds and Appendix B exposure before anything is destroyed.

  13. Identify, contain, report and learn from breaches. A breach is any loss, unauthorised access, disclosure, alteration or unavailability of personal data: a misdirected email, a lost device, a survey link exposing responses, a leaver's live account. Whoever suspects one reports it to the Lead within 1 hour, without first investigating. The Lead contains it (recall, revoke, isolate, with MBRU IT where needed), logs what is known, assesses data, subjects, likely harm and cause, and notifies Data Governance within the internal timeline [IoL to confirm]. Data Governance decides on and makes any notification to the regulator and data subjects within the statutory timeline [IoL to confirm against UAE and Dubai Health requirements]; IoL supplies the facts and never notifies externally on its own account. Within 20 working days the Lead completes a post-incident review: timeline, root cause, control failure, corrective action through AW-24, changes to inventory, DPIA or training. [CONTROL] Every breach and near-miss is logged; a breach found in an audit that was not logged at the time is itself a non-conformity.

  14. Audit access logs, report and review. Quarterly, the Lead samples access logs for Restricted datasets and the survey, alumni and student records systems where logs exist [IoL to confirm], for access outside the matrix, unusual times, bulk exports and dormant accounts, reconciled with the AW-15 review; anomalies are suspected breaches until shown otherwise. Annually the Lead reports to AW-25 on inventory completeness, DPIAs, transfers, requests, breaches, training and audit findings, with the risk position for AW-06. AW-24 audits this procedure at least every two years.

7. Information handled and interfaces

Data category Subjects Created by Classification Flows to
Learner records and contacts Learners, applicants WF-07, WF-10, WF-06 Confidential WF-26 aggregates; CHEDS via MBRU
Graduate contact, consent and outcome records Graduates WF-25 Confidential; raw outcome data Restricted MoHESR contact extract via MBRU; substitute-data packs; WF-14 employer population
Supervisor and employer contacts Supervisors, employer contacts WF-13, WF-14, WF-25 Confidential Survey platform (processor); WF-26 aggregates
Raw per-person survey responses Learners, graduates, supervisors, employers WF-06, WF-14, WF-25 Restricted Appendix B evidence on request, via WF-26 and MBRU only
Staff and adjunct records Staff, adjuncts AW-07, AW-08 Confidential; health, disciplinary and identity documents Restricted MBRU HR; WF-08
Event attendee lists Attendees, visitors WF-23, AW-21 Confidential WF-23 attendance evidence; AW-22 only where consented
Adjustment and wellbeing records Learners, staff AW-19, AW-09 Restricted Nowhere outside the owning procedure

Interfaces stated as obligations. WF-25 captures consent under the step 4 notice; WF-06, WF-14 and WF-23 collect only through registered processors; WF-26 releases nothing containing personal data without the step 8 checklist; AW-04 sets retention; AW-15 provisions and reviews access; AW-07 and AW-08 deliver induction training and notify leavers.

8. Controls

Stated as assertions an auditor can test.

# Control Evidence
C1 Every personal dataset is in the inventory with owner, classification, lawful basis, access roles, processors, transfers and retention class Inventory against a sample of systems and drives
C2 Every category has a lawful basis confirmed by Data Governance and a notice at the collection point Inventory; notice versions in AW-03; consent records
C3 IoL staff hold no access to clinical records for education purposes, and no education dataset is linked to a clinical record Access matrix; inventory; access log sample
C4 Access to each dataset matches the AW-15 matrix and the Data Owner's approvals; Restricted access requires a current training record AW-15 quarterly review; training register
C5 Every external transfer of personal data has a signed checklist and a log entry Transfer log against WF-26 release records and MBRU submission records
C6 Every processor has a contract with the required terms and a register entry before use Processor register; AW-23 contracts
C7 Every DPIA trigger identified at inventory entry results in an approved DPIA before processing Screening record; DPIA register
C8 No personal data is held past its AW-04 disposal date without a documented decision Inventory; disposal records
C9 Every suspected breach is logged within 1 hour and reported to Data Governance within the internal timeline Breach log; notification records
C10 Every data subject request is logged the same day and answered within the timeline Request log
C11 Every person with Confidential access has induction training and a refresher within 12 months Training register against AW-15 access list
C12 Quarterly access log audits are performed and anomalies followed up Audit records

9. Exceptions and escalation

Exception Authorised by Rationale required Recorded where
Transfer without a completed checklist under urgent regulatory demand Senior Director, IoL, with Data Governance informed the same day The demand, the deadline, the fields released; checklist completed within 2 working days Transfer log, marked EXCEPTION
Retention beyond disposal date Data Owner with Data Governance Legal hold, regulator request, live dispute or Appendix B exposure; new date Inventory; AW-04 hold register
Use of a processor before contract completion Data Governance Why the delay is unavoidable; interim safeguards; expiry not exceeding 60 days Processor register, marked INTERIM

This procedure must never: allow IoL staff access to clinical records for education purposes, or link an education record to a clinical one; release personal data through WF-26 or otherwise without the step 8 checklist; infer consent from enrolment, silence or a consent given for another purpose; use contacts for a purpose the notice did not cover; place personal data in a tool without a processor contract; notify a regulator or data subject on IoL's own account; delay a breach report while the facts are investigated; or destroy data under a legal hold or Appendix B exposure.

10. Service standards

Service Standard
New dataset entered in the inventory Before collection begins
DPIA screening of a new inventory entry 5 working days
Transfer checklist signed Before release, within 3 working days of request
Consent withdrawal actioned 5 working days
Data subject request logged and routed Same day; answered within the statutory or policy timeline [IoL to confirm]
Suspected breach reported to the IoL Data Protection Lead Within 1 hour of discovery
Breach reported to Data Governance Within [IoL to confirm] hours of discovery
Access log audit Quarterly, within 20 working days of quarter end

11. Records and retention

Record System Retention Owner
Data inventory Controlled register under AW-03 Permanent, versioned IoL Data Protection Lead
Privacy notices and consent records AW-03 for notices; the owning dataset's system for consents Life of the data plus 7 years Data Owner
DPIA records Controlled repository Life of the processing plus 7 years IoL Data Protection Lead
Transfer log and checklists IoL data protection log 7 years; permanent for OBEF submissions Data Owner
Data subject request log IoL data protection log 7 years IoL Data Protection Lead
Breach log, notifications and post-incident reviews IoL data protection log and AW-24 10 years IoL Data Protection Lead
Training records and access log audits IoL training register; IoL data protection log Employment plus 7 years; 7 years IoL Data Protection Lead

12. Risks and controls

# Risk Consequence Control Owner
1 Graduate contacts supplied to MoHESR without a settled lawful basis or notice Unlawful processing; mass consent withdrawal; KPI 1.1 collapse Step 3 settled before WF-25 clearance capture begins; C2 WF-25 owner
2 Raw per-person survey data retained for Appendix B is accessed beyond the Data Steward Respondent views about named supervisors disclosed Restricted class; C4; step 14 audit Data Owner
3 Personal data assembled for WF-26 in working spreadsheets outside approved systems Uncontrolled copies; breach on a lost device Step 7; C1; pseudonymised analysis files WF-26 owner
4 A survey platform on free or unreviewed terms Data location unknown; no breach notification; no deletion Step 9; C6 IoL Data Protection Lead
5 Breach reported late because staff investigate first Statutory timeline missed; harm compounds Step 13; the 1-hour rule; training IoL Data Protection Lead
6 Lawful bases and timelines assumed rather than confirmed Defensible on paper, not in law Every [IoL to confirm] resolved with Data Governance before version 1.0 Process owner

13. Performance measures

Dimension Measure Target
Compliance Personal datasets found outside the inventory per audit 0
Compliance External transfers with a signed checklist and log entry 100%
Compliance Processors with a contract and register entry before use 100%
Timeliness Suspected breaches reported to the Lead within 1 hour 100%
Timeliness Data subject requests answered within the timeline 100%
Capability Staff with current training, as a share of those holding Confidential access 100%
Experience Complaints about IoL data handling per year Tracked; each reviewed
Touchpoint WF-26 releases containing personal data made without a checklist 0

14. Change control

Date Version Change Reason Approved by
2026-09-02 0.1 Initial draft IoL administrative pack draft, unapproved