Search all 478 artefacts by title, document ID or content.
Contract | Family 14, Jurisdiction Variant Sets
This Agreement is entered into between Edsol Edtech Pvt. Ltd. ("Pensieve") and the hospital ("the Customer"), and takes effect on this document.
This document is the source of truth for: ae-processor-obligations, ae-localisation-covenant, article-13-permission-protocol
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
DPA-AE-001)This Agreement is entered into between Edsol Edtech Pvt. Ltd. ("Pensieve") and
Customer legal name ("the Customer"), and takes effect on 01 August 2026.
DM-1 Dedicated |
DM-2 Shared |
DM-3 Customer Cloud |
DM-4 On-Premise |
|---|---|---|---|
Only on a UAE-resident cloud region (DIS-AE-008 Section 4.1) |
Only on a UAE-resident shared estate (DIS-AE-008 Section 4.2) |
With ADD-GL-009 |
With ADD-GL-008 |
A Deployment Model that DIS-AE-008 records as unavailable in this market cannot be selected on the Order
Form. This Agreement does not authorise one.
To record the Parties' respective obligations in respect of Personal Data and Health Data processed through the Platform for health services provided in the United Arab Emirates, under Federal Law No. 2 of 2019 Concerning the Use of Information and Communication Technology in Health Fields and Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
1.1 The Data Processing Agreement DPA-GL-001, including its Annexures I (Details of the
Processing), II (Technical and Organisational Measures) and III (Sub-processors), is incorporated into this
Agreement in full and forms part of it.
1.2 This Agreement replaces Annexure VII of DPA-GL-001 in its entirety for an engagement in which
Customer jurisdiction is AE. Annexure VII remains the summary position published for readers who are
not contracting; this Agreement is the operative instrument.
1.3 Order of precedence. Where a conflict arises, the following order applies, highest first:
ORD-GL-001), as to the Deployment Model, the deployment location and the infrastructure
provider;DPA-GL-001 and its Annexures I to III;MSA-AE-001);ADD-GL-001) and, as applicable, ADD-GL-008 or ADD-GL-009;1.4 Terms defined in DPA-GL-001 have the same meaning here. In addition:
1.5 Roles. The Customer is the Controller. Pensieve is the Processor. Pensieve processes Health Data and Personal Data only on the Customer's documented instructions, of which this Agreement, the Order Form and the Statement of Work are the initial and complete set.
This clause is the substantive UAE-specific obligation and is drafted to be enforceable rather than aspirational.
2.1 The covenant. Pensieve shall not store, process, generate or transfer Health Data outside the Territory, and shall not permit any Sub-processor to do so.
2.2 The four activities are addressed separately, because the Localisation Law names four:
(a) Storage: all primary data, replicas, snapshots, backups, archives, exports, search indices, caches and object storage holding Health Data reside on infrastructure physically located in the Territory.
(b) Processing: all application compute, background and batch processing, reporting, indexing, document generation and any inference or analytical computation over Health Data is executed on infrastructure physically located in the Territory.
(c) Generation: Health Data created by the Platform, including derived records, computed indicators, audit events and generated documents, is created on infrastructure physically located in the Territory and is not created elsewhere and imported.
(d) Transfer: no Health Data is transmitted to any system, person or storage location outside the Territory, including for support, diagnostics, testing, quality assurance, analytics, benchmarking, machine learning or product development.
2.3 No mitigating instrument substitutes for the covenant. The Parties record that encryption, pseudonymisation, key custody arrangements, contractual safeguards, standard contractual clauses and this Agreement itself do not satisfy the Localisation Law, which imposes a territorial and not a risk-based obligation.
2.4 Deployment record. The Deployment Model, the infrastructure provider, the region or physical site, and the identity of every Sub-processor holding Health Data are recorded in Schedule 1 and on the Order Form. Schedule 1 is a statement of fact, not a design intention, and is completed before this Agreement is executed.
2.5 Configuration commitments. For the Deployment Model recorded in Schedule 1, Pensieve shall:
(a) disable cross-region replication of data stores, backups and object storage; (b) configure logging to a regional log destination inside the Territory, and not to a multi-region or global destination; (c) hold encryption keys in a key management service inside the Territory; (d) enable data-access audit logging, which is not enabled by default; and (e) maintain the above as infrastructure-as-code, so that a change to any of them is a reviewed change and not a console action.
Under DM-3 and DM-4 items (a) to (d) are configured by Pensieve within infrastructure the Customer owns,
and the Customer may verify each of them directly at any time without notice to Pensieve.
2.6 Verification. The Customer may, at any time and without cause, require Pensieve to evidence
compliance with 2.5 by producing the current configuration state. Pensieve shall respond
within five working days. This right is in addition to the audit rights in DPA-GL-001 clause 15 and is not
subject to their frequency limits, because a residency breach is not an audit finding; it is a statutory
breach of the Customer's own obligation.
2.7 Notification of breach of the covenant. If Pensieve becomes aware that Health Data has been stored,
processed, generated or transferred outside the Territory, it shall notify the Customer within four hours
of becoming aware, in the form required by DPA-GL-001 clause 10, and shall state: what left, when, to
where, on whose instruction, whether it has been deleted, and what prevents recurrence. This notification is
required whether or not the event is also a Personal Data Breach.
2.8 Remedy at Pensieve's cost. A breach of 2.1 is a material breach. Pensieve shall remedy it at its own cost, including the cost of re-establishing the deployment inside the Territory, and shall not charge the Customer for work arising from it.
2.9 The Customer's own obligation is not assumed. Pensieve does not assume, and cannot discharge, the Customer's obligations to the Health Authority under the Localisation Law or under its facility licence. Pensieve's obligation is to make compliance possible and to evidence it.
3.1 The Parties record that the Localisation Law restricts processing outside the Territory and that
no regulator guidance has been identified resolving whether viewing Health Data from outside the
Territory constitutes such processing. [UNVERIFIED]
3.2 Pensieve adopts the strict reading. Accordingly:
(a) support requiring sight of Health Data is performed by personnel located in the Territory, or is not performed; (b) no diagnostic export, memory dump, database extract or log bundle containing Health Data is taken out of the Territory, for any purpose including debugging; (c) support correspondence carries identifiers and error references, not record content. Attachments containing Health Data are refused and, where received, deleted with the deletion recorded; and (d) Pensieve's engineering and support function is operated from India, which is the reason for (a) and is a present constraint on the scope of support available in this market.
3.3 The exception, and its conditions. Where a remote session from outside the Territory is unavoidable, it may be conducted only if all of the following are satisfied:
Pensieve does not represent that a session under 3.3 complies with the Localisation Law. Condition 5 exists because the Customer, not Pensieve, holds the facility licence.
3.4 Under DM-3 and DM-4 access exists only while the Customer opens it. The Customer's own identity
and access management, and its own network controls, are the operative control and Pensieve does not seek to
displace them.
3.5 DIS-GL-033 records Pensieve's global remote-access model. For this market it is read subject to
this clause, which is more restrictive.
4.1 The Customer is the Controller and Pensieve is the Processor for the purposes of the PDPL.
4.2 [UNVERIFIED as at 01 August 2026] The most authoritative source available indicates that
the Executive Regulations to the PDPL had not been issued, so the registration, data protection officer
threshold, breach mechanics and cross-border adequacy machinery are not yet operational. Commercial sources
asserting that the Regulations have been issued are mutually inconsistent and are not relied on. On issue of
the Executive Regulations, the Parties shall review this clause under DPA-GL-001 clause 20.3.
4.3 Pensieve does not operate a separate PDPL compliance programme. It operates one programme, the
technical and organisational measures at DPA-GL-001 Annexure II, and maps it. The mapping is
Schedule 3.
4.4 Breach chain. On becoming aware of a Personal Data Breach, Pensieve notifies the Customer within
four hours under DPA-GL-001 clause 10.2. The Customer notifies the UAE Data Office and affected data
subjects without undue delay on becoming aware, as required of a Controller. Pensieve supplies the
content the Customer's notification requires and does not itself notify the regulator, because it is not the
Controller.
4.5 Cross-border transfer under the PDPL is not engaged. The PDPL permits transfer on adequacy or
appropriate safeguards, in shapes comparable to the European regime. Because 2.1 means Health
Data does not leave the Territory, no PDPL transfer mechanism is relied on for Health Data. Where Personal
Data that is not Health Data crosses a border, the three categories exhaustively listed at
DIS-AE-008 Section 3.2. DPA-GL-001 clause 12 governs.
4.6 Financial free zones. Where the Customer is established in the DIFC or in ADGM, that free zone's own data protection law applies in place of the PDPL, and references in this clause to the PDPL are read as references to that law and to its supervisory authority. 2 is unaffected, because the Localisation Law applies in the free zones.
Stated so that no obligation is assumed by silence.
| Obligation | Whose |
|---|---|
| Holding and maintaining the facility licence | Customer |
| Any application for a Health Authority decision permitting an activity outside the Territory | Customer (Schedule 2) |
| Determining the lawful basis and the consent position for the Customer's own processing of Health Data | Customer |
| Determining retention periods for Health Data under the Customer's licence conditions and Health Authority requirements | Customer (7) |
| Participation in the emirate's health information exchange and in the federal platform | Customer: DIS-AE-029 |
| Configuring, operating and evidencing the deployment so that Health Data remains inside the Territory | Pensieve (2) |
| Notifying the Customer of any departure from 2.1 | Pensieve (2.7) |
| Notifying the Health Authority and the UAE Data Office | Customer |
6.1 DPA-GL-001 clause 8 and its Annexure III govern. This clause adds two UAE-specific rules.
6.2 No Sub-processor may hold Health Data outside the Territory. Pensieve shall not engage a
Sub-processor that would hold, process or generate Health Data outside the Territory, and shall not rely on
the general notification-and-objection mechanism in POL-GL-055 to introduce one. A Sub-processor change
that would place Health Data outside the Territory requires the Customer's prior written consent, which
the Customer may withhold without giving reasons.
6.3 The infrastructure Sub-processor is market-specific. The provider of the infrastructure on which a
UAE deployment runs is not the provider named in DIS-GL-009 for other markets. It is named in
Schedule 1 and recorded as a separate market entry in DIS-GL-009. Under DM-3 the provider is the
Customer's own supplier under DPA-GL-001 clause 8.7 and is not a Sub-processor of Pensieve. Under DM-4
there is no cloud infrastructure Sub-processor.
7.1 Retention periods for Health Data are set by the Customer, having regard to its licence conditions
and the requirements of the Health Authority. Annexure I Section I-9 of DPA-GL-001, which records Indian
statutory retention defaults, does not apply to this engagement.
7.2 The Platform implements a configurable per-record-class retention schedule. Pensieve implements the periods the Customer sets and does not select them.
7.3 On termination, DIS-GL-023 governs export, deletion and the Certificate of Deletion, with one
modification: the export is produced, staged and delivered inside the Territory, and no copy of it is
held outside the Territory at any point, including in transit through a support channel. Delivery is by a
mechanism that does not route Health Data outside the Territory; the mechanism is agreed in the Transition
Services Agreement (ADD-GL-018) where one is entered into.
8.1 DPA-GL-001 clause 15 governs, with the addition of the verification right at 2.6.
8.2 Pensieve holds no certification, accreditation or assessed compliance status against any
information security standard, in this market or any other. Where the Customer's licence or its own
regulator requires supplier conformance, Pensieve supplies the control mapping at DPA-GL-001 Annexure II
and the position at STM-AE-001, participates in the Customer's own assessment, and states which
requirements it meets and which it does not. It does not represent that it is certified, assessed or
approved.
Participation in the emirate's health information exchange, in the federal record platform and in the
electronic claims platform is a condition of the Customer's facility licence. The Customer is the
participant. Pensieve is not, and does not represent that it holds any onboarding status, certification or
approval in any of those programmes. The Platform integrates using the Customer's own credentials on the
Customer's authority under DPA-GL-001 clause 8.6 and ADD-GL-007. The allocation of responsibility is at
DIS-AE-029 Section 5; the credential-handling model is at DIS-GL-025.
This Agreement is governed by the law stated in MSA-AE-001 Section 4, which replaces clause 26 of MSA-IN-001,
and is subject to the same forum.
Nothing in the choice of law displaces the Localisation Law or the PDPL, which apply by their own terms.
This Agreement takes effect on 01 August 2026, continues for so long as Pensieve processes Health
Data or Personal Data for the Customer, and survives termination of the MSA to the extent necessary to
complete the obligations at 7.
| Disclosure | Subject |
|---|---|
DIS-AE-008 |
Data residency and localisation, per Deployment Model |
DIS-AE-029 |
Health information exchange, claims and terminology position |
DIS-AE-028 |
Clinical safety boundary and the medical device position |
STM-AE-001 |
Information assurance standards position |
DIS-GL-009 |
Sub-processors, including the UAE market entry |
DIS-GL-011, DIS-GL-013, DIS-GL-016, DIS-GL-023, DIS-GL-025, DIS-GL-033 |
Encryption; audit logging; incident response; deletion and return; credential handling; remote access |
Pensieve warrants that each disclosure listed above is accurate as at 01 August 2026 in the same
terms as MSA-AE-001 clause 15.
Completed before execution. A blank field blocks execution; it is not completed later.
| Item | Value |
|---|---|
| Deployment Model | DM-1 |
| Infrastructure provider | |
| Region or physical site, inside the Territory | |
| Country of the site | United Arab Emirates |
| Emirate | |
| Cross-region replication disabled | Confirmed |
| Log destination: regional, inside the Territory | |
| Key management service location | |
| Data-access audit logging enabled | Confirmed |
| Backup location and custodian | |
| Sub-processors holding Health Data | |
| Customer's named approver for 3.3 sessions | |
| Countries from which support personnel may access the deployment | |
This Schedule applies only if the Customer decides to seek a Health Authority decision permitting an activity outside the Territory. Pensieve's delivery plan does not depend on one and Pensieve does not initiate one.
The application is made by the Customer, as the licensed facility. Pensieve has no standing to apply in respect of the Customer's Health Data and will not purport to.
[UNVERIFIED] No published application form, fee, channel or service standard for a decision under
Article 13 was identified. The route understood to apply is a bespoke application to the Health Authority
having jurisdiction over the Customer's facility, in coordination with the Ministry of Health and
Prevention. The Customer should obtain UAE regulatory advice before relying on any timeline.
| Artefact | Content |
|---|---|
| Data-flow description | Every flow of Health Data in the proposed architecture, with source, destination, transport, frequency and volume |
| Processing description | The nature, purpose, categories and duration of processing (DPA-GL-001 Annexure I, restated for the proposed architecture) |
| Technical and organisational measures | DPA-GL-001 Annexure II, with the measures specific to the proposed architecture identified |
| Sub-processor schedule | Every party that would hold Health Data outside the Territory, its location, its role and its safeguards |
| Access model | Who could reach the data, from where, under what approval and with what logging |
| Deletion and repatriation plan | How Health Data outside the Territory would be deleted or returned if the decision were refused, withdrawn or expired |
(a) The Customer provides Pensieve with a copy and with its terms, conditions, scope and expiry.
(b) The Parties execute an amendment under DPA-GL-001 clause 20.3 recording the permitted activity, its
scope and its limits. 2.1 is not varied by anything less than that amendment.
(c) Schedule 1 is reissued.
(d) DIS-GL-009 is updated and notice given under POL-GL-055.
Pensieve returns the deployment to full compliance with 2.1 within the period stated in the
amendment or, if none, within thirty days, and issues a Certificate of Deletion under DIS-GL-023 for
every copy of Health Data held outside the Territory.
One programme, mapped. Not a second programme.
| PDPL topic | Where it is discharged |
|---|---|
| Roles: Controller and Processor | 1.5 |
| Processing on documented instructions only | DPA-GL-001 clause 5 |
| Confidentiality of personnel | DPA-GL-001 clause 6 |
| Security of processing | DPA-GL-001 clause 7 and Annexure II; ADD-GL-001 |
| Engagement of Sub-processors | DPA-GL-001 clause 8; 6 |
| Assistance with data subject rights | DPA-GL-001 clause 9 |
| Breach notification to the Controller | DPA-GL-001 clause 10.2 (four hours) |
| Breach notification to the UAE Data Office and data subjects | 4.4, the Customer's obligation |
| Records of processing | DPA-GL-001 Annexure I, which doubles as the processor record |
| Assistance with impact assessment | DPA-GL-001 clause 11 |
| Deletion or return on termination | 7; DIS-GL-023 |
| Audit and information | DPA-GL-001 clause 15; 2.6 |
| Cross-border transfer | 4.5, not engaged for Health Data |
This Agreement is executed by the Parties' authorised representatives. Schedules 1 to 3 form part of it. Schedule 1 must be complete.
For and on behalf of
Edsol Edtech Pvt. Ltd.
For and on behalf of
Customer legal name
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Legal | First issue. Operative UAE processor agreement replacing DPA-GL-001 Annexure VII for AE engagements. Localisation covenant with per-activity drafting, configuration commitments, verification right and four-hour covenant-breach notification. Support restricted on the strict reading of the Localisation Law. Article 13 Permission Protocol published as Schedule 2. PDPL mapped rather than duplicated. |
Drafted against 01-research/international/02-norway-uae.md Part B, which carries the primary citations for
Federal Law No. 2 of 2019 Articles 2 and 13 and its penalty range, the absence of a cloud region inside the
Territory, the PDPL and the status of its Executive Regulations, and the free-zone data protection regimes.
Points marked [UNVERIFIED] are unresolved in that research and are carried forward as unresolved. They are
re-tested at each review.