PDPL
Your client sent a PDPL questionnaire. These are the documents they expect
Updated 2026-09-25
For many small UAE businesses, the first contact with the PDPL is not a regulator. It is a procurement questionnaire from a larger client. The questions vary, but they cluster around a small set of documents. Having these ready turns a week of back-and-forth into an afternoon.
The questions, and the document that answers each
- 'Do you maintain a record of processing activities?' The ROPA required by Articles 7 and 8: what data, for what purpose, on what legal basis, shared with whom, kept how long.
- 'Please provide your privacy notice.' A notice written for the PDPL, naming the UAE Data Office and the correct legal grounds.
- 'Who is responsible for data protection?' A named DPO where Article 10 requires one, otherwise a named privacy lead.
- 'Do you use sub-processors? Where is data stored?' Your list of providers and their hosting regions, and the contracts that bind them (Article 8).
- 'How would you handle a personal data breach?' A written breach procedure covering the notification in Article 9, ideally with evidence it has been rehearsed.
- 'What security measures do you apply?' MFA, encryption, access control, backups, logging: the technical and organisational measures of Article 20.
- 'How do you handle data subject requests?' A procedure for access, correction, erasure and objection (Articles 13 to 18).
What reviewers actually look for
Consistency. The privacy notice, the ROPA and the vendor list should tell the same story. A notice that mentions no transfers abroad, next to a vendor list full of US SaaS tools, is the kind of contradiction that triggers follow-up questions.
Specifics over boilerplate. 'We take security seriously' earns nothing. 'MFA is enforced on email and admin accounts; laptops use full-disk encryption' answers the question.
Getting the set together
Our PDPL kit produces all of these from one questionnaire, already consistent with each other because they are generated from the same answers: gap report, privacy notice, ROPA, request and breach procedures, a DPA for vendors, a DPIA and a retention schedule.
Where does your company stand on PDPL?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.