AW-16 — Data Protection and Information Security Operations
| Workflow ID | AW-16 |
| Pack owner | IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md) |
| Family | K — Facilities, IT, data protection, safety |
| Ownership | Slice of MBRU information governance and Dubai Health data
protection. MBRU and Dubai Health own policy, the data protection
officer function, lawful-basis determination, regulator and data-subject
notification and institutional system security; IoL owns the
departmental data inventory, classification, access and handling
controls, first-line breach response, oversight of the processors it
procures, training and the evidence [IoL to confirm] |
| Governing policy | UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal
Data [IoL to confirm applicability and current text]; Dubai
Health data governance and information security requirements
[IoL to confirm applicability and current text]; MBRU data
protection, information security and acceptable use policies
[IoL to confirm]; ISO 9001:2015 clause 7.5.3; ISO
21001:2018 clause 7.5.3 and its stated principle of data security and
protection |
| Interfaces | WF-25; WF-26; WF-06, WF-14, WF-23; AW-04; AW-15; AW-07 and AW-08; AW-23; AW-24; AW-06 |
| OBEF touchpoint | Every personal-data flow in the academic pack. Graduate contacts (WF-25), supervisor and employer contacts (WF-14), student contacts for surveys (WF-06), attendee names (WF-23), and the raw survey data retained for Appendix B (WF-06, WF-14, WF-25). WF-26 releases none of it until the section 8 controls are met |
| Process owner | ______________ |
| Version | 0.1 draft |
| Effective | |
| Next review |
1. Purpose
To ensure that every item of personal data IoL holds is known, classified, held for a stated purpose on a stated lawful basis, accessible only to the roles that need it, transferred only through approved channels, retained only as long as AW-04 requires, and protected by controls whose operation can be evidenced; and that when something goes wrong it is contained, reported within the required time and learned from.
2. Scope
Scope statement. This procedure manages IoL's handling of personal data from the creation or receipt of a dataset, through classification, access, use, transfer and retention, to disposal, together with the response to data subject requests and to breaches.
Applies to. Personal data held by IoL on learners, applicants, graduates, staff, adjuncts, workplace supervisors, employer contacts, survey respondents, event attendees and contractors, in every system, file, survey platform, mailbox and paper record; and to every IoL role, including adjuncts and student assistants.
Does not apply to. Clinical records of patients, which Dubai Health holds and IoL does not access for education purposes; institutional policy and lawful-basis determination, which are MBRU's and Dubai Health's; institutional infrastructure security, which is MBRU IT's; research data under an approved ethics protocol (WF-15), which follows its data management plan with this procedure as the floor.
Applicable requirements. ISO 9001:2015 clause 7.5.3;
ISO 21001:2018 clause 7.5.3 and its principle of data security and
protection; UAE Federal Decree-Law No. 45 of 2021
[IoL to confirm applicability and current text]; UAE
federal requirements on information technology in health fields, where
any health-related data is handled
[IoL to confirm applicability]; Dubai Health data
governance requirements
[IoL to confirm applicability and current text]; MBRU
policy [IoL to confirm]; the OBEF guide's Appendix B, which
creates a retention obligation for raw survey data.
3. Trigger, boundary and endpoint
| Trigger | A new dataset, system, processor, purpose or transfer; a scheduled review; an access request; a data subject request; a suspected breach; an audit finding |
| First activity | Entry or update of the dataset in the data inventory |
| Last activity | Verified disposal at the end of the AW-04 retention period, or closure of the request or incident |
| Endpoint | Every personal dataset is in the inventory with owner, classification, lawful basis, access roles, processors, transfers and retention class, and each section 8 control can be evidenced |
| Upstream | Every AW and WF that creates personal data; AW-07, AW-08; AW-23; Data Governance |
| Downstream | WF-26 release gate; AW-04; AW-15; AW-24; AW-06; AW-25 |
4. SIPOC
| Element | Content |
|---|---|
| Suppliers | Data subjects; the workflows that create data; Data Governance; MBRU IT; survey and CRM vendors; MoHESR and CHEDS, whose formats shape what is collected |
| Inputs | Personal data at creation; notices and consents; the classification scheme; the AW-15 access matrix; processor contracts; the AW-04 retention schedule |
| Process | Inventory → classify → lawful basis and notice → DPIA where triggered → minimum-necessary access → approved transfer → retain and dispose → answer requests → manage breaches → train → audit |
| Outputs | Data inventory; DPIA records; access approvals; transfer log; disposal records; request and breach logs; training records; annual report |
| Customers | Data subjects; the academic pack; MBRU and Dubai Health data governance; MoHESR and CHEDS; auditors |
| Success criteria | No dataset outside the inventory; no access outside the matrix; no transfer outside the log; no data past its retention date; every breach and request handled within the timeline |
5. Accountability
Process owner. IoL Data Protection Lead, a
departmental role distinct from the institutional data protection
officer, who sits with MBRU or Dubai Health
[IoL to confirm]. The process owner may stop any transfer
or processing that fails the section 8 controls.
| Step | Data Steward | Data Owner | IoL Data Protection Lead | MBRU or Dubai Health Data Governance | MBRU IT |
|---|---|---|---|---|---|
| Maintain the data inventory | R | R | A/R | I | I |
| Classify a dataset | R | A/R | C | I | I |
| Confirm lawful basis, purpose and notice wording | C | R | R | A | I |
| Decide whether a DPIA is required | C | R | A/R | C | I |
| Approve a DPIA | I | R | R | A | C |
| Approve access to a dataset | I | A/R | C | I | I |
| Approve an external transfer | R | A | R | C | I |
| Approve a processor | I | R | R | A | C |
| Respond to a data subject request | R | R | R | A | I |
| Declare, contain and review a breach | R | R | A/R | I | R |
| Notify the regulator and data subjects | I | I | R | A | I |
Data Owner is the process owner of the AW or WF that creates the dataset (the WF-25 owner for graduate data, the WF-06 owner for course evaluations). Data Steward is the named person who operates it. A dataset with no named owner is a non-conformity.
Escalation.
| Condition | Escalates to | Within |
|---|---|---|
| Suspected breach of any kind | IoL Data Protection Lead, then Data Governance | 1 hour of discovery; onward within
[IoL to confirm] |
| Transfer or release requested without a step 8 checklist | IoL Data Protection Lead stops it and informs the Data Owner | Same day |
| Lawful basis unsettled at the point of use | Data Owner to Data Governance; processing does not proceed | Before processing |
6. Procedure
Build and keep the data inventory. The IoL Data Protection Lead holds a register of every dataset containing personal data: owner and steward; subjects; categories; source; purpose; lawful basis; classification; location; access roles; processors; transfers; AW-04 retention class and disposal date; DPIA status. Datasets are entered before collection begins; the inventory is refreshed annually and on every change. [CONTROL] No personal dataset exists outside the inventory; a spreadsheet of names found outside it is a non-conformity under AW-24.
Classify. Four classes. Public. Internal: staff use, business contact details only. Confidential: personal data of learners, graduates, staff, contacts and respondents, for named roles only. Restricted: data whose loss would cause serious harm: health or disability information (AW-19), disciplinary and grievance records (AW-09), identity documents, financial details, and raw per-person survey responses identifying a respondent's views about a named supervisor or employer. Education records and clinical records are distinct categories. IoL staff do not access clinical records for education purposes, and clinical staff do not access education records for clinical purposes. [CONTROL] The class is recorded in the inventory and marked on the document or system; unmarked material is treated as Confidential.
Confirm the lawful basis and purpose for each category, and stop at that purpose. The Data Owner proposes and Data Governance confirms the basis, recorded in the inventory. The categories and the questions to settle
[IoL to confirm each with Data Governance]:Category Created by Purpose Basis to settle Applicant and learner records WF-07, WF-10, AW-18 Programme delivery, progression, regulatory reporting Contract and legal obligation Learner contacts for course evaluation WF-06 KPI 2.6, quality improvement Legitimate interest or consent; notice says raw responses may be inspected by the Ministry Graduate contacts, consent and outcomes WF-25, WF-10 Outcomes, licensure, contacts to MoHESR, substitute-data submissions Consent at clearance, or legal obligation; notice says contacts may go to the Ministry and raw data is retained for Appendix B Supervisor and employer contacts WF-13, WF-14, WF-25 KPIs 2.3 and 2.4 Legitimate interest or consent; business contact details only Staff and adjunct records AW-07, AW-08 Employment, appointment, credentialing Contract and legal obligation Event attendees WF-23, AW-21 Attendance evidence for KPIs 6.1 and 6.2, safety Consent or contract at registration; notice says names are retained as evidence Alumni relationship data AW-22 Communication, engagement Consent, never inferred from the WF-25 outcomes consent [CONTROL] Data collected for one purpose is not used for another without a documented basis and, where required, a fresh notice: graduate contacts captured for outcome tracking are not used for marketing or event invitations unless the notice covered it.
Issue the notice and record consent. Every collection point uses a plain-language notice approved by Data Governance and held under AW-03. Where consent is the basis, the record holds the person, date, notice version and purposes agreed, including onward transfer to MoHESR. [CONTROL] Consent is never inferred from silence, from enrolment alone, or from a consent given for a different purpose.
Screen for a DPIA, and conduct one where triggered. A DPIA is required before: a new system or processor holding Confidential or Restricted data; any transfer outside the UAE; a new Restricted category; large-scale processing of graduate, employer or respondent data; linkage of datasets that could identify individuals not identifiable in either alone; a substitute-data methodology under WF-25; any change of purpose. The Lead screens every new inventory entry. The DPIA, on the MBRU template
[IoL to confirm], covers necessity, proportionality, risks to individuals and measures, and is approved by Data Governance. [CONTROL] Processing that triggers a DPIA does not start until the DPIA is approved.Grant access on the minimum-necessary principle. Access is by role, set in the AW-15 matrix and approved by the Data Owner. A role receives the fields it needs and no more: a survey analyst receives pseudonymised responses, not names; the WF-26 assembly team receives aggregates and the evidence index, not the person-level file. No shared accounts, no personal email, no personal devices for Restricted data
[IoL to confirm MBRU device policy]. [CONTROL] Restricted access is granted only after the person's training record (step 11) is complete.Handle data securely in daily work. Personal data lives only in the locations listed in the inventory; extracts are made only with Data Owner approval and a deletion date. Spreadsheets with personal data are linked, not emailed. WF-26 analysis files are pseudonymised, the key held by the Data Steward apart from the file. Restricted paper is locked away and shredded.
Meet the release gate, then transfer only through approved channels. Before personal data leaves IoL in any form, the Data Steward completes and the Data Owner signs a transfer checklist: lawful basis confirmed; recipient's entitlement confirmed; fields reduced to the minimum the recipient's format requires; DPIA where triggered; channel approved; deletion expectations stated; log entry made. Transfers to MoHESR, CHEDS and Dubai Health use the channel each specifies and MBRU approves
[IoL to confirm channels], otherwise MBRU-approved encrypted transfer; never unencrypted email, consumer file-sharing or removable media. The log records date, sender, recipient, dataset, fields, record count and acknowledgement. Where a CHEDS template carries person-level identifiers[IoL to confirm which fields], the Data Owner confirms each is required before it is populated. [CONTROL] WF-26 does not release any personal data, or any file containing it, to the MBRU institutional OBEF process without a signed checklist for that release: graduate contact extracts, substitute-data packs, employer lists and attendee lists alike.Control processors and third parties. Survey platforms, CRM, cloud storage, event registration tools and any vendor touching personal data are processors. Before use: due diligence on security and data location; an AW-23 contract covering purpose limitation, confidentiality, sub-processors, data location, breach notification to IoL, audit rights and deletion at end of contract; a register entry; DPIA where triggered. Processors are reviewed annually. [CONTROL] No personal data enters a tool without a processor contract and register entry; free-tier survey and form tools are not used for personal data.
Retain and dispose in line with AW-04. Every dataset carries its AW-04 retention class from creation. Raw per-person survey and outcome data retained for Appendix B is held for the period WF-25 and AW-04 specify, seven years minimum for substitute-data records, in a Restricted location open to the Data Steward only, its retention justified in the inventory as evidentiary. At the disposal date the Data Steward disposes by the AW-04 method and records it. [CONTROL] No personal data is retained past its disposal date without a documented Data Owner decision and a new date.
Train and keep awareness. Every joiner completes data protection training at AW-07 or AW-08 induction, before any Confidential access; Data Stewards and Restricted-data handlers complete role-specific training; refreshers are annual; a briefing follows any breach. [CONTROL] A person without a current training record does not hold Restricted access; AW-15 removes it at the quarterly review where the record has lapsed.
Answer data subject requests. Requests to access, correct, delete, restrict or object, and consent withdrawals, are logged the same day wherever they arrive and routed to the Lead, who confirms identity, finds every dataset holding the person's data from the inventory, and coordinates the response with Data Governance, which is accountable for the answer and the timeline
[IoL to confirm under UAE law and MBRU policy]. Withdrawal of graduate outcome consent is actioned in WF-25 within 5 working days. [CONTROL] Deletion requests are checked against AW-04 legal holds and Appendix B exposure before anything is destroyed.Identify, contain, report and learn from breaches. A breach is any loss, unauthorised access, disclosure, alteration or unavailability of personal data: a misdirected email, a lost device, a survey link exposing responses, a leaver's live account. Whoever suspects one reports it to the Lead within 1 hour, without first investigating. The Lead contains it (recall, revoke, isolate, with MBRU IT where needed), logs what is known, assesses data, subjects, likely harm and cause, and notifies Data Governance within the internal timeline
[IoL to confirm]. Data Governance decides on and makes any notification to the regulator and data subjects within the statutory timeline[IoL to confirm against UAE and Dubai Health requirements]; IoL supplies the facts and never notifies externally on its own account. Within 20 working days the Lead completes a post-incident review: timeline, root cause, control failure, corrective action through AW-24, changes to inventory, DPIA or training. [CONTROL] Every breach and near-miss is logged; a breach found in an audit that was not logged at the time is itself a non-conformity.Audit access logs, report and review. Quarterly, the Lead samples access logs for Restricted datasets and the survey, alumni and student records systems where logs exist
[IoL to confirm], for access outside the matrix, unusual times, bulk exports and dormant accounts, reconciled with the AW-15 review; anomalies are suspected breaches until shown otherwise. Annually the Lead reports to AW-25 on inventory completeness, DPIAs, transfers, requests, breaches, training and audit findings, with the risk position for AW-06. AW-24 audits this procedure at least every two years.
7. Information handled and interfaces
| Data category | Subjects | Created by | Classification | Flows to |
|---|---|---|---|---|
| Learner records and contacts | Learners, applicants | WF-07, WF-10, WF-06 | Confidential | WF-26 aggregates; CHEDS via MBRU |
| Graduate contact, consent and outcome records | Graduates | WF-25 | Confidential; raw outcome data Restricted | MoHESR contact extract via MBRU; substitute-data packs; WF-14 employer population |
| Supervisor and employer contacts | Supervisors, employer contacts | WF-13, WF-14, WF-25 | Confidential | Survey platform (processor); WF-26 aggregates |
| Raw per-person survey responses | Learners, graduates, supervisors, employers | WF-06, WF-14, WF-25 | Restricted | Appendix B evidence on request, via WF-26 and MBRU only |
| Staff and adjunct records | Staff, adjuncts | AW-07, AW-08 | Confidential; health, disciplinary and identity documents Restricted | MBRU HR; WF-08 |
| Event attendee lists | Attendees, visitors | WF-23, AW-21 | Confidential | WF-23 attendance evidence; AW-22 only where consented |
| Adjustment and wellbeing records | Learners, staff | AW-19, AW-09 | Restricted | Nowhere outside the owning procedure |
Interfaces stated as obligations. WF-25 captures consent under the step 4 notice; WF-06, WF-14 and WF-23 collect only through registered processors; WF-26 releases nothing containing personal data without the step 8 checklist; AW-04 sets retention; AW-15 provisions and reviews access; AW-07 and AW-08 deliver induction training and notify leavers.
8. Controls
Stated as assertions an auditor can test.
| # | Control | Evidence |
|---|---|---|
| C1 | Every personal dataset is in the inventory with owner, classification, lawful basis, access roles, processors, transfers and retention class | Inventory against a sample of systems and drives |
| C2 | Every category has a lawful basis confirmed by Data Governance and a notice at the collection point | Inventory; notice versions in AW-03; consent records |
| C3 | IoL staff hold no access to clinical records for education purposes, and no education dataset is linked to a clinical record | Access matrix; inventory; access log sample |
| C4 | Access to each dataset matches the AW-15 matrix and the Data Owner's approvals; Restricted access requires a current training record | AW-15 quarterly review; training register |
| C5 | Every external transfer of personal data has a signed checklist and a log entry | Transfer log against WF-26 release records and MBRU submission records |
| C6 | Every processor has a contract with the required terms and a register entry before use | Processor register; AW-23 contracts |
| C7 | Every DPIA trigger identified at inventory entry results in an approved DPIA before processing | Screening record; DPIA register |
| C8 | No personal data is held past its AW-04 disposal date without a documented decision | Inventory; disposal records |
| C9 | Every suspected breach is logged within 1 hour and reported to Data Governance within the internal timeline | Breach log; notification records |
| C10 | Every data subject request is logged the same day and answered within the timeline | Request log |
| C11 | Every person with Confidential access has induction training and a refresher within 12 months | Training register against AW-15 access list |
| C12 | Quarterly access log audits are performed and anomalies followed up | Audit records |
9. Exceptions and escalation
| Exception | Authorised by | Rationale required | Recorded where |
|---|---|---|---|
| Transfer without a completed checklist under urgent regulatory demand | Senior Director, IoL, with Data Governance informed the same day | The demand, the deadline, the fields released; checklist completed within 2 working days | Transfer log, marked EXCEPTION |
| Retention beyond disposal date | Data Owner with Data Governance | Legal hold, regulator request, live dispute or Appendix B exposure; new date | Inventory; AW-04 hold register |
| Use of a processor before contract completion | Data Governance | Why the delay is unavoidable; interim safeguards; expiry not exceeding 60 days | Processor register, marked INTERIM |
This procedure must never: allow IoL staff access to clinical records for education purposes, or link an education record to a clinical one; release personal data through WF-26 or otherwise without the step 8 checklist; infer consent from enrolment, silence or a consent given for another purpose; use contacts for a purpose the notice did not cover; place personal data in a tool without a processor contract; notify a regulator or data subject on IoL's own account; delay a breach report while the facts are investigated; or destroy data under a legal hold or Appendix B exposure.
10. Service standards
| Service | Standard |
|---|---|
| New dataset entered in the inventory | Before collection begins |
| DPIA screening of a new inventory entry | 5 working days |
| Transfer checklist signed | Before release, within 3 working days of request |
| Consent withdrawal actioned | 5 working days |
| Data subject request logged and routed | Same day; answered within the statutory or policy timeline
[IoL to confirm] |
| Suspected breach reported to the IoL Data Protection Lead | Within 1 hour of discovery |
| Breach reported to Data Governance | Within [IoL to confirm] hours of discovery |
| Access log audit | Quarterly, within 20 working days of quarter end |
11. Records and retention
| Record | System | Retention | Owner |
|---|---|---|---|
| Data inventory | Controlled register under AW-03 | Permanent, versioned | IoL Data Protection Lead |
| Privacy notices and consent records | AW-03 for notices; the owning dataset's system for consents | Life of the data plus 7 years | Data Owner |
| DPIA records | Controlled repository | Life of the processing plus 7 years | IoL Data Protection Lead |
| Transfer log and checklists | IoL data protection log | 7 years; permanent for OBEF submissions | Data Owner |
| Data subject request log | IoL data protection log | 7 years | IoL Data Protection Lead |
| Breach log, notifications and post-incident reviews | IoL data protection log and AW-24 | 10 years | IoL Data Protection Lead |
| Training records and access log audits | IoL training register; IoL data protection log | Employment plus 7 years; 7 years | IoL Data Protection Lead |
12. Risks and controls
| # | Risk | Consequence | Control | Owner |
|---|---|---|---|---|
| 1 | Graduate contacts supplied to MoHESR without a settled lawful basis or notice | Unlawful processing; mass consent withdrawal; KPI 1.1 collapse | Step 3 settled before WF-25 clearance capture begins; C2 | WF-25 owner |
| 2 | Raw per-person survey data retained for Appendix B is accessed beyond the Data Steward | Respondent views about named supervisors disclosed | Restricted class; C4; step 14 audit | Data Owner |
| 3 | Personal data assembled for WF-26 in working spreadsheets outside approved systems | Uncontrolled copies; breach on a lost device | Step 7; C1; pseudonymised analysis files | WF-26 owner |
| 4 | A survey platform on free or unreviewed terms | Data location unknown; no breach notification; no deletion | Step 9; C6 | IoL Data Protection Lead |
| 5 | Breach reported late because staff investigate first | Statutory timeline missed; harm compounds | Step 13; the 1-hour rule; training | IoL Data Protection Lead |
| 6 | Lawful bases and timelines assumed rather than confirmed | Defensible on paper, not in law | Every [IoL to confirm] resolved with Data Governance
before version 1.0 |
Process owner |
13. Performance measures
| Dimension | Measure | Target |
|---|---|---|
| Compliance | Personal datasets found outside the inventory per audit | 0 |
| Compliance | External transfers with a signed checklist and log entry | 100% |
| Compliance | Processors with a contract and register entry before use | 100% |
| Timeliness | Suspected breaches reported to the Lead within 1 hour | 100% |
| Timeliness | Data subject requests answered within the timeline | 100% |
| Capability | Staff with current training, as a share of those holding Confidential access | 100% |
| Experience | Complaints about IoL data handling per year | Tracked; each reviewed |
| Touchpoint | WF-26 releases containing personal data made without a checklist | 0 |
14. Change control
| Date | Version | Change | Reason | Approved by |
|---|---|---|---|---|
| 2026-09-02 | 0.1 | Initial draft | IoL administrative pack | draft, unapproved |