Khurram Badar / Archive / Papers / Dubai Autism Center — Data Protection & Child Safety Commitment

Dubai Autism Center — Data Protection & Child Safety Commitment

report · 2026-05-02 · 1740 words · Khurram Badar

Why we publish this The frameworks we follow Children's data — our hard rules Data of children of determination — additional protections.

ai · healthcare · legal · real estate · technology · uae

Dubai Autism Center — Data Protection & Child Safety Commitment

*A public commitment to the families, educators, clinicians, and regulators we serve.*

---

Why we publish this

Most child-focused platforms rely on borrowed US or generic GDPR language and treat UAE data law as an afterthought. We do the opposite. This document is our public, plain-language commitment to how we handle data on the platform — particularly for children, particularly for children of determination, and particularly under UAE law as it stands today.

If anything here ever drifts out of step with the laws or practices it describes, that is a defect we will fix. Please contact our Data Protection Officer at `dpo@drashidalameri.com` *(replace with the real domain at publish time)*.

---

The frameworks we follow

We design and operate the platform to comply with — at minimum — the following UAE federal and emirate-level frameworks:

1. **Federal Decree-Law No. 45 of 2021** on the Protection of Personal Data (UAE PDPL)
2. **UAE Child Digital Safety Federal Law** (effective 1 January 2026, with full implementation by January 2027) for users under the age of 13
3. **Federal Law No. 3 of 2016** on the Rights of the Child (Wadeema's Law), with particular attention to Articles concerning privacy, dignity, and children with disabilities
4. **Federal Law No. 29 of 2006** on the Rights of People of Determination (as amended), covering accessibility, dignity, and non-discrimination in services
5. **Federal Decree-Law on Nurseries** and the data-handling controls determined by the **Federal Agency for Early Education (FAEE)**
6. **Emirate-level education and inclusion regulators**, including:
- Knowledge and Human Development Authority (KHDA) — Dubai, including the Inclusive Education Policy Framework
- Department of Education and Knowledge (ADEK) — Abu Dhabi
- Sharjah Private Education Authority (SPEA)
- Ministry of Education (MOE) for other emirates
7. **DIFC Data Protection Law No. 5 of 2020** and **ADGM Data Protection Regulations 2021** where applicable to free-zone-based partner institutions

We do not invoke COPPA or FERPA. Those are US laws and irrelevant to a UAE platform serving UAE families. We follow the UAE frameworks that actually apply.

---

Children's data — our hard rules

For any user under the age of 18, and most strictly for users under 13:

---

Data of children of determination — additional protections

We treat data relating to a child of determination — including diagnosis indicators, sensory profiles, communication preferences, motor profiles, M-CHAT or screener responses, therapy notes, and any data about additional needs — as **sensitive personal data** under PDPL Article 5 and as protected information under Wadeema's Law and Federal Law No. 29 of 2006.

This means:

---

Our AI — what it does and what it doesn't

We use Anthropic's Claude family of models, accessed via the Anthropic API, to power **NOUR**, the platform's AI assistant. NOUR exists to answer parent and educator questions, surface resources, and assist clinicians with summarising notes — never to act as a clinician or a decision-maker.

**Concrete commitments:**

---

Data we collect, and why

We collect the **minimum** data necessary to deliver each feature. The full inventory:

| Category | Examples | Purpose | Lawful basis (PDPL) |
|---|---|---|---|
| Account data | Parent name, email, phone | Account creation, communication | Contractual necessity |
| Child profile | Name or alias, date of birth, gender, language, child of determination indicator (Yes/No only at signup) | Personalising the experience, age-appropriate content gating | Explicit parental consent |
| Sensitive child data | Diagnosis indicators, sensory profile, communication preferences, screener responses | Personalised support and resource matching | Explicit, separate consent under PDPL Art. 5 |
| Operational telemetry | Page views, error logs, session duration | Keeping the service running | Legitimate interest, limited to first-party |
| Payment data | Card data via a UAE-licensed PSP | Subscription processing | Contractual necessity |

We do not collect: webcam video, biometric data, voice recordings of children, geolocation beyond country level, social-media identifiers, or device-fingerprint data.

---

Where data lives

---

Sub-processors

We name our sub-processors. The current list:

| Sub-processor | Purpose | Region | Legal basis for transfer |
|---|---|---|---|
| Anthropic, PBC | AI / NOUR | US | DPA + standard contractual safeguards |
| Vercel | Web hosting | EU (Frankfurt) | EU-based, no transfer concern |
| Supabase | Database, auth, storage | EU (Frankfurt) | EU-based, no transfer concern |
| \[UAE-licensed PSP, e.g. Network International or Telr\] | Payment processing | UAE | In-region |
| Anthropic-supported transactional email \[provider\] | Account emails | EU | EU-based |

We do not currently use Google Analytics, HubSpot, Microsoft Clarity, Mixpanel, Bugsnag, or Hotjar on child-data surfaces. We commit to publish any future change to this list with at least 30 days' advance notice.

---

Your rights as a parent or guardian

Under UAE PDPL Articles 13–22, parents have the right to:

We respond to all requests within **15 business days**, faster than the PDPL maximum where possible. To exercise any of these rights, contact `dpo@drashidalameri.com` or submit the request from your parent dashboard.

---

How we handle a security incident

If we detect a security incident affecting child data, we will:

1. Contain and investigate within 24 hours of detection
2. Notify the UAE Data Office in accordance with PDPL Article 9 and any executive regulations in force
3. Notify affected parents directly within 72 hours of confirmation, plainly and without legalese
4. Publish a post-incident summary on this page once remediation is complete

We do not claim that incidents are impossible. We claim that we have a documented response plan, regular tabletop exercises, and a public commitment to transparency when something goes wrong.

---

Governance

---

Document control

We will publish any material change to this commitment at least 30 days before it takes effect, and we will email every parent account with a plain-language summary of what has changed and why.

← Dubai Autism Center — Positioning Memo2050PLANET — COMPLETE CONTENT INVENTORY & CATEGORIZATION →
Two years of working thought, indexed.
Ask me to present it in your conference room — WhatsApp +971 55 623 9111
Book Session →