Data Protection & Compliance
AlMiqyas is committed to the highest standards of data protection. This document outlines our compliance framework, data governance practices, and the safeguards we apply to protect school and student data.
1 Compliance Framework
AlMiqyas operates within a multi-jurisdictional data protection compliance framework, recognising that our partner schools are located across the UAE, GCC, and internationally. Our compliance programme is built on the following regulatory foundations:
| Regulation | Jurisdiction | Applicability |
|---|---|---|
| UAE PDPL Federal Decree-Law No. 45 of 2021 |
United Arab Emirates | All UAE-based schools and data subjects |
| GDPR EU Regulation 2016/679 |
European Union / EEA | Schools serving EU-based students or operating under EU curricula |
| ADGM Data Protection Regulations 2021 | Abu Dhabi Global Market | Schools operating within ADGM jurisdiction |
| DIFC Data Protection Law 2020 | Dubai International Financial Centre | Schools operating within DIFC jurisdiction |
2 Data Controller & Processor Roles
Understanding the distinction between data controller and data processor is fundamental to our compliance approach:
| Role | Party | Responsibility |
|---|---|---|
| Data Controller | The School | Determines the purposes and means of processing student personal data. Responsible for obtaining consent, managing data subject rights, and ensuring lawful processing. |
| Data Processor | AlMiqyas | Processes student data solely on the School's instructions for the purpose of delivering assessment services. Bound by a Data Processing Agreement (DPA). |
| Sub-Processor | AlMiqyas's service providers | Third-party providers (e.g. cloud infrastructure) engaged by AlMiqyas under equivalent data protection obligations. |
AlMiqyas maintains a current register of all sub-processors and will notify Schools of any material changes to sub-processor arrangements with at least 30 days' notice.
3 Lawful Basis for Processing
AlMiqyas processes personal data on the following lawful bases:
- Contractual necessity: Processing required to deliver the assessment services contracted by the School.
- Legitimate interests: Platform security, fraud prevention, and service improvement using anonymised analytics.
- Legal obligation: Compliance with UAE law, regulatory requirements, and lawful authority requests.
- Consent: Where required (e.g. marketing communications), we obtain explicit, freely given consent that can be withdrawn at any time.
4 Data Governance
Our data governance programme includes the following key elements:
- Data Inventory & Mapping: We maintain a comprehensive record of all personal data processed, including data flows, storage locations, and retention schedules.
- Privacy by Design: Data protection principles are embedded into all new platform features and processes from the outset.
- Data Minimisation: We collect only the minimum data necessary to deliver our services.
- Purpose Limitation: Data collected for assessment purposes is never repurposed for unrelated activities.
- Data Quality: We implement controls to ensure data accuracy and provide mechanisms for correction.
- Staff Training: All AlMiqyas staff with access to personal data receive regular data protection training.
5 Security Measures
AlMiqyas implements a comprehensive set of technical and organisational security measures (TOMs) to protect personal data:
Technical Controls
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- Web Application Firewall (WAF) and DDoS protection
- Role-based access control (RBAC) with principle of least privilege
- Multi-factor authentication (MFA) for all administrative access
- Automated vulnerability scanning and patch management
- Intrusion detection and security information and event management (SIEM)
- Regular penetration testing by independent security firms
Organisational Controls
- Documented information security policies and procedures
- Background checks for all staff with access to personal data
- Confidentiality agreements for all employees and contractors
- Incident response plan with defined escalation procedures
- Regular security awareness training for all staff
- Vendor due diligence process for all sub-processors
6 International Data Transfers
AlMiqyas primarily stores and processes data within the UAE. Where data is transferred internationally (e.g. to cloud infrastructure providers), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) for transfers to countries without an adequacy decision
- Adequacy assessments for all international transfer destinations
- Contractual obligations on sub-processors to maintain equivalent data protection standards
7 Data Breach Response
AlMiqyas maintains a documented Data Breach Response Plan. In the event of a personal data breach:
- The incident will be contained and assessed within 24 hours of discovery.
- Affected Schools will be notified within 48 hours of confirmed breach identification.
- Regulatory notification will be made within 72 hours where required by applicable law.
- A full incident report will be provided to affected Schools within 14 days.
- Remediation measures will be implemented and documented.
Schools are required to notify AlMiqyas immediately upon becoming aware of any suspected breach involving Platform data.
8 Data Processing Agreement (DPA)
A Data Processing Agreement is incorporated into the School's service contract with AlMiqyas. The DPA covers:
- The subject matter, duration, nature, and purpose of processing
- The type of personal data and categories of data subjects
- AlMiqyas's obligations as data processor
- Sub-processor management and notification requirements
- Data subject rights assistance obligations
- Security measures and breach notification procedures
- Data return and deletion obligations upon contract termination
Schools requiring a standalone DPA document for their records may request one from dpo@almiqyas.com.
9 School Responsibilities as Data Controller
As the data controller for student personal data, Schools are responsible for:
- Maintaining a lawful basis for processing student data through the Platform
- Providing students and parents/guardians with appropriate privacy notices
- Obtaining parental consent for students under the applicable age threshold in their jurisdiction
- Responding to data subject access requests from students and parents
- Ensuring that only authorised staff are granted access to the Platform
- Promptly deactivating accounts of staff who leave the school
- Reporting any suspected data breaches to AlMiqyas without undue delay
10 Audits & Certifications
AlMiqyas is committed to demonstrating compliance through independent verification:
- Annual third-party security audits and penetration testing
- Regular internal data protection impact assessments (DPIAs) for high-risk processing activities
- Compliance reviews aligned with UAE PDPL requirements
- Schools may request a summary of our most recent security audit findings under NDA
We are actively working towards ISO 27001 certification and will update this page upon achievement.
11 Contact Our Data Protection Officer
For all data protection enquiries, DPA requests, data subject rights requests, or to report a suspected breach:
Email: dpo@almiqyas.com
Phone: +971 56 896-5663
Address: ABC Street, ABC Venue, Dubai, UAE
Response time: Within 5 business days for general enquiries; within 30 days for formal data subject rights requests.