Skip to content

Evidence request lists

Bahrain PDPL

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Bahrain PDPL: Accountability & Compliance

BH-PDPL-25
Compliance monitoring and auditing

Compliance monitoring and auditing. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BH-PDPL-26
Training and awareness programs

Training and awareness programs. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BH-PDPL-27
Regulatory reporting and cooperation

Regulatory reporting and cooperation. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BH-PDPL-28
Complaints handling and resolution

Complaints handling and resolution. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BH-PDPL-29
Enforcement and penalties awareness

Enforcement and penalties awareness. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs

Bahrain PDPL: Data Collection & Consent

BH-PDPL-01
Notice and transparency requirements

Notice and transparency requirements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-02
Consent management and withdrawal

Consent management and withdrawal. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-03
Lawful basis for processing

Lawful basis for processing. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-04
Purpose limitation and specification

Purpose limitation and specification. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-05
Data minimization requirements

Data minimization requirements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome

Bahrain PDPL: Data Governance

BH-PDPL-19
Data protection officer designation

Data protection officer designation. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPO appointment letter and reporting line
  • Records of processing activities
  • DPIA register and templates
  • Privacy by design checklist for projects
  • Privacy training records
Where this commonly fails
  • ROPA incomplete or stale
  • DPIAs not triggered for high-risk processing
  • DPO independence not documented
  • Privacy by design treated as afterthought
BH-PDPL-20
Records of processing activities

Records of processing activities. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPO appointment letter and reporting line
  • Records of processing activities
  • DPIA register and templates
  • Privacy by design checklist for projects
  • Privacy training records
Where this commonly fails
  • ROPA incomplete or stale
  • DPIAs not triggered for high-risk processing
  • DPO independence not documented
  • Privacy by design treated as afterthought
BH-PDPL-21
Data protection impact assessments

Data protection impact assessments. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPO appointment letter and reporting line
  • Records of processing activities
  • DPIA register and templates
  • Privacy by design checklist for projects
  • Privacy training records
Where this commonly fails
  • ROPA incomplete or stale
  • DPIAs not triggered for high-risk processing
  • DPO independence not documented
  • Privacy by design treated as afterthought
BH-PDPL-22
Privacy by design and default

Privacy by design and default. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPO appointment letter and reporting line
  • Records of processing activities
  • DPIA register and templates
  • Privacy by design checklist for projects
  • Privacy training records
Where this commonly fails
  • ROPA incomplete or stale
  • DPIAs not triggered for high-risk processing
  • DPO independence not documented
  • Privacy by design treated as afterthought
BH-PDPL-23
Data processing agreements

Data processing agreements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • Approved information security policy
  • Policy review and approval history
  • Roles and responsibilities matrix
  • Management commitment statement
  • Policy communication evidence
Where this commonly fails
  • Policies outdated or unsigned
  • No defined review cadence
  • Roles unclear or duplicated
  • Management commitment not visible
BH-PDPL-24
Cross-border transfer safeguards

Cross-border transfer safeguards. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Governance.

Artefacts an auditor will ask for
  • Transfer impact assessment documents
  • Standard contractual clauses register
  • Binding corporate rules approval
  • Adequacy decision references
  • Vendor transfer mapping
Where this commonly fails
  • No transfer impact assessment performed
  • SCCs not updated to current versions
  • Sub-processor transfers untracked
  • Reliance on adequacy without supplementary measures

Bahrain PDPL: Data Security

BH-PDPL-13
Encryption of personal data

Encryption of personal data. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Cryptographic standards and algorithm catalogue
  • Key management policy and KMS configuration
  • TLS configuration and inventory
  • Encryption at rest evidence per system
  • Key rotation and escrow records
Where this commonly fails
  • Use of deprecated ciphers or self-signed certificates
  • Keys stored alongside encrypted data
  • No documented rotation schedule
  • Inconsistent encryption coverage across data stores
BH-PDPL-14
Pseudonymization techniques

Pseudonymization techniques. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
Where this commonly fails
  • Policy not aligned to control statement
  • Procedure undocumented
  • No periodic monitoring
  • Evidence not retained
BH-PDPL-15
Access control for personal data

Access control for personal data. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BH-PDPL-16
Data breach notification requirements

Data breach notification requirements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BH-PDPL-17
Security incident response procedures

Security incident response procedures. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BH-PDPL-18
Regular security testing and assessment

Regular security testing and assessment. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.

Artefacts an auditor will ask for
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
Where this commonly fails
  • Policy not aligned to control statement
  • Procedure undocumented
  • No periodic monitoring
  • Evidence not retained

Bahrain PDPL: Data Subject Rights

BH-PDPL-06
Right of access to personal data

Right of access to personal data. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-07
Right to rectification of inaccurate data

Right to rectification of inaccurate data. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-08
Right to erasure and deletion

Right to erasure and deletion. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-09
Right to data portability

Right to data portability. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-10
Right to restrict processing

Right to restrict processing. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-11
Right to object to processing

Right to object to processing. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BH-PDPL-12
Automated decision-making protections

Automated decision-making protections. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Bahrain PDPL framework page.