For schools

Child digital safety is now regulated by law. Aman delivers your institution’s compliance.

Policy, controls and a verifiable evidentiary record — implemented and operated on your behalf, with all data retained within the United Arab Emirates.

The regulatory requirement

The expected standard is demonstrable compliance.

Federal Decree-Law No. 26 of 2025 established child digital safety as a matter of UAE law, effective January 2026. It imposes binding obligations across the digital ecosystem and raises the standard of care expected of every institution responsible for minors.

Schools occupy a position of accountability. Alongside the requirements of ADEK, the KHDA and the UAE Personal Data Protection Law, an institution is expected to evidence the controls it has in place. In the event of an incident, the institution must be able to produce a complete and contemporaneous record of those controls.

Review how Aman delivers compliance

Institutional obligations

Four requirements every institution must now meet.

Aman addresses each of these obligations as a single managed engagement, and maintains them on a continuing basis.

01

Documented policy

A published safeguarding and digital-safety policy, aligned to the Child Digital Safety Law and the ADEK and KHDA frameworks.

02

Effective controls

Age-appropriate protections applied consistently across all students, maintained continuously rather than configured once.

03

Identification and escalation

A defined process for recognising safeguarding concerns and directing them to the designated lead with appropriate context.

04

Evidentiary record

A complete, time-stamped audit trail demonstrating the controls in operation, available to regulators and inspectors on request.

Safeguarding governance

Compliance is the requirement; safeguarding is its purpose.

Regulatory compliance establishes the baseline; the objective is the effective protection of students. Where indicators of harm arise, the relevant information is directed to the designated safeguarding lead with appropriate context — supporting professional judgement rather than replacing it. The institution retains oversight throughout, and the privacy of students is preserved in accordance with the applicable data-protection requirements.

Frequently asked questions

Is our institution legally required to implement this?+

Federal Decree-Law No. 26 of 2025 places its obligations directly on digital platforms and internet service providers rather than on schools by name. However, as the institution responsible for minors in its care, a school is expected to implement appropriate safeguards and to evidence them. Together with the requirements of ADEK, the KHDA and the UAE Personal Data Protection Law, the standard expected of institutions is clear: effective controls, demonstrably in place, with a record that can be produced on request. Aman delivers and evidences that compliance.

How is compliance demonstrated to a regulator, inspector or parent?+

Aman maintains a continuous, time-stamped record of every control in operation and every safeguarding action taken. Rather than assembling documentation retrospectively, your institution can produce a complete and contemporaneous account on request.

Will the service disrupt teaching or existing institutional systems?+

No. The service operates alongside your institution's existing environment and is managed on your behalf — there is nothing for your staff to configure, learn or maintain. Controls apply consistently in the background, without impeding teaching.

Does the institution have visibility of student activity outside school?+

Not by default. Where protection extends to a student's personal device beyond the school perimeter, the privacy boundary is preserved in accordance with applicable data-protection requirements: the institution does not have visibility of private out-of-school activity. This boundary is deliberate and is not relaxed.

Where is institutional data retained?+

Within the United Arab Emirates. All records remain in the country, under the institution's control, and are never sold, shared or transferred abroad. This applies whether the service is delivered via cloud, managed service, on-premise or virtual deployment — each is sovereign.

What is the timeline to achieving compliance?+

Engagement begins with a structured compliance review that establishes your institution's current position against the regulatory requirements. From there, the required policy and controls are implemented and operated on your behalf, bringing the institution into a demonstrably compliant state within a short timeframe.

Establish your institution’s compliance position.

A structured compliance review assesses your institution against the current regulatory requirements and defines the path to achieving and evidencing compliance.