We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance and regulation
UAE IT compliance hub

Which compliance applies to your UAE business? It depends on where you are licensed and what you do.

There is no single UAE IT compliance checklist, and anyone selling you one is selling a template. Your obligations come from three directions at once: where your licence sits (mainland, DIFC, ADGM, or another free zone), what sector you operate in, and who your customers are. This page maps every regulation and framework we cover, tells you in one line who each applies to, and links to the detailed page for each. If you already know your regulator, jump straight to it. If you do not, the decision section below gets you there in a minute.

Get a compliance scopeFind your regulation
UAE business districts governed by federal, emirate and free zone regulators
  • Licence-ledScoped to your obligations
  • 28Frameworks and services covered
  • 5 minP1 remote response
  • FreeInitial scoping call
What compliance actually demands from IT

Six things every framework asks for, whatever the acronym.

The frameworks differ in scope, language and enforcement, but the technical substance overlaps heavily. Whichever regulation applies to you, the work lands in the same six places, which is why one well-built control set can serve several frameworks at once.

Know what data you hold and where it lives

Every data protection regime starts here: what personal or regulated data you process, why, where it is stored, who can reach it, and where the copies sit including backups and replicas. Most businesses cannot answer this on day one, and most findings trace back to that gap. A data inventory and records of processing turn the question into an export.

Access control that survives an audit

Multi-factor authentication enforced rather than merely available, administrator accounts separated from daily accounts, joiner and leaver processes documented and followed, and dormant accounts removed. Auditors under every framework check this first because it is where breaches actually start.

Monitoring and the ability to detect an incident

Regulations increasingly assume you will detect your own incidents rather than hear about them from a customer. That means logging that is retained, alerting that a human reviews, and an answer to the question of who noticed and when. Frameworks from the UAE information assurance standards to DORA make this explicit.

A breach response you have rehearsed

Most modern regimes carry notification duties with short clocks attached. The difference between a controlled notification and a scramble is a written plan, named owners, and at least one rehearsal before the real event. We build and test the plan so the clock starts on a process rather than a panic.

Evidence, kept current, not assembled under deadline

Having controls and having proof of controls are different things, and reviews fail on the second one as often as the first. Policies, configurations, test results, training records and restore evidence maintained continuously turn a regulator, bank or enterprise customer request into an export rather than a fortnight of archaeology.

People who know what the rules require of them

Awareness training, an acceptable use policy people have actually read, and clear ownership of compliance duties inside the business. Several regimes expect a named responsible person, and some sectors expect a formally appointed data protection officer, which can be provided as a service rather than a hire.

Every regulation and framework we cover

Find your regulation, grouped by who enforces it.

One line on who each applies to, and a dedicated page behind each link with the detail. If you are not sure which of these reaches you, the decision section further down this page narrows it by licence location and industry, and the scoping call settles it for free.

UAE federal and emirate rules

Rules made in the UAE that apply based on where you operate and what sector you are in, from the federal data protection law to emirate-level security standards.

  • UAE PDPL complianceThe federal data protection law. Broadly relevant to businesses processing personal data in the UAE.
  • NESA complianceUAE information assurance standards, relevant to critical sectors and entities connected to them.
  • DESC ISR complianceDubai government information security regulation, relevant to Dubai government entities and their suppliers.
  • ADHICS complianceAbu Dhabi healthcare information and cyber security standard for healthcare entities in the emirate.
  • Central Bank IT requirementsIT and security expectations for banks, exchange houses and finance firms under Central Bank supervision.
  • IT asset disposal complianceCompliant destruction and disposal of data-bearing hardware for any UAE business retiring equipment.

Financial free zone regulators

DIFC and ADGM are financial free zones with their own legal systems, their own data protection regimes and their own financial regulators. If your licence sits in one of them, these pages are yours.

  • DIFC Data Protection LawThe DIFC data protection regime, applying to entities established in or processing through the DIFC.
  • DFSA IT complianceIT, cyber and operational resilience expectations for DFSA-regulated financial firms in the DIFC.
  • ADGM IT complianceControls and evidence for Abu Dhabi Global Market entities under their regulatory framework.

International frameworks

Standards you adopt by choice or by contract rather than by law. Customers, banks and tenders increasingly require them, and some UAE regulators reference them as the expected baseline.

  • ISO 27001 certificationThe international information security management standard. Voluntary, and the one most often demanded by contract.
  • PCI DSS complianceRequired by the card schemes for any business that stores, processes or transmits cardholder data.
  • NIST CSF assessmentA structured cybersecurity maturity assessment, useful as a baseline for boards and insurers.
  • GDPR for UAE businessesThe EU data protection regulation, which can reach UAE firms serving or monitoring people in the EU.
  • CSA STAR certificationCloud security assurance for providers and SaaS businesses selling into security-conscious customers.
  • SOX ITGC complianceIT general controls for UAE subsidiaries of US-listed groups and businesses preparing for listing.
  • COBIT IT governanceAn IT governance framework for organisations formalising how IT is directed and controlled.

EU rules reaching UAE firms

European regulations with reach beyond Europe. If you serve EU financial institutions, EU markets or EU users, these can apply to you contractually or directly even though your licence is in the UAE.

  • DORA complianceEU digital operational resilience rules that reach UAE firms serving EU financial entities.
  • NIS2 complianceEU network and information security rules that can reach UAE suppliers to in-scope EU organisations.
  • EU AI Act complianceEU rules on AI systems, relevant to UAE businesses placing AI products or outputs into the EU market.

Compliance delivery services

The frameworks above say what must be true. These services are how we make it true and keep it true, from a one-off audit to a standing programme with a named officer.

  • Compliance as a serviceThe full programme run for you: scoping, remediation, evidence and audit support as a subscription.
  • Continuous compliance monitoringControls checked continuously rather than annually, so drift is caught before an auditor catches it.
  • DPO as a serviceA named data protection officer for businesses that need one without making a full-time hire.
  • Records of processing activitiesThe processing register that data protection regimes expect, built and kept current for you.
  • Privacy impact assessmentsStructured assessments for new systems and higher-risk processing, documented to regulator standard.
  • Breach notification readinessThe plan, the templates and the rehearsal, so a notification clock starts on a process, not a panic.
  • Communication complianceRetention and supervision of business communications for regulated firms and disciplined ones.
  • Open source licence complianceFor software businesses: knowing what open source you ship and what its licences oblige you to do.
  • Cybersecurity audit and complianceThe audit that starts most engagements: where you stand today, in writing, against the frameworks that apply.
Why businesses run compliance through us

Four reasons this works better than a policy pack.

We map obligations before we quote controls

The first conversation is about your licence location, your sector, and your customers, because that is what determines which regimes reach you. Scoping by company size alone is how providers sell an ISO project to a business whose actual deadline is a Central Bank review. You get the map in writing, including the regimes we think do not apply to you and why.

We implement, not just document

A policy that says MFA is enforced while the tenant says otherwise fails the audit and, worse, fails the breach. We are an IT and security provider first, so the controls get built in your actual environment: identity, endpoints, logging, backup, mail authentication. The documents describe a real state instead of an aspiration.

One control set, mapped to every framework you face

Most of our compliance clients answer to more than one regime at once: a data protection law, a sector regulator, and a contractual framework a customer imposed. We build the control set once and maintain a mapping to each framework, so an ISO audit, a bank review and a regulator query all draw from the same living evidence.

We stand next to you at the review

Audits and regulator interactions go better with the people who built the controls in the room. We prepare the evidence pack, sit in the sessions where you want us, handle the technical questions, and turn findings into a remediation plan with owners and dates rather than a PDF that gets filed.

Which applies to me?

Narrow it down by where you are licensed and what you do.

Start with your licence location, then add your sector, then add your customers. Most businesses end up with one primary regime, one or two sector overlays, and one contractual framework. The combinations below cover the common cases; the scoping call covers yours specifically.

By where your licence sits

  • Mainland UAE
    The federal data protection law is your starting point for personal data, with sector rules layered on top depending on your industry. If you retire hardware, disposal compliance applies to everyone.
  • DIFC
    The DIFC has its own data protection law and its own commissioner. If you are also DFSA-regulated, DFSA IT and resilience expectations sit alongside it. The federal regime generally is not your primary data law here.
  • ADGM
    ADGM likewise operates its own data protection framework, with financial firms answering to the financial regulator on top. Treat it as its own jurisdiction for data purposes.
  • Other free zones (DMCC, Jafza, Meydan and the rest)
    Non-financial free zones generally sit under the federal regime for data protection. Your zone authority rarely adds IT rules directly; your licence category and sector regulator are what matter.

By what you do

  • Banking, finance and insurance (BFSI)
    Central Bank supervision on the mainland, DFSA in the DIFC, the ADGM regulator in ADGM. Expect explicit IT, outsourcing and resilience requirements, plus communication retention. Serving EU financial institutions can pull DORA obligations into your contracts.
  • Healthcare
    Health data is regulated more tightly than general personal data. In Abu Dhabi, ADHICS applies to healthcare entities. Across the UAE, health-sector rules on patient data sit on top of general data protection law.
  • Government suppliers
    Supplying Dubai government entities brings DESC ISR requirements into your contracts. Critical-sector work can bring the UAE information assurance standards. Both are commonly flowed down to suppliers through procurement.
  • Retail, ecommerce and hospitality
    Taking card payments puts PCI DSS in scope through your acquirer, whatever your size. Customer databases put you under data protection law. Neither depends on having an office.
  • Selling to or monitoring people in the EU
    GDPR can apply to a UAE business that offers goods or services to people in the EU or monitors their behaviour, regardless of where the company is licensed. An EU-facing website with EU customers is the classic trigger.
  • Technology, SaaS and AI products
    Enterprise customers will ask for ISO 27001 or CSA STAR before regulators ask for anything. Shipping software brings open source licence obligations. Placing AI systems into the EU market brings the EU AI Act into view.
Who this hub is for

The six situations that bring businesses here.

Financial firms with a regulator letter

A DFSA, ADGM or Central Bank supervisory request with a response date attached. The work is mapping the request to controls, closing the genuine gaps fast, and presenting the rest honestly with a dated plan.

Healthcare providers handling patient data

Clinics, pharmacies and health-tech businesses whose data is regulated more tightly than general personal data, and who in Abu Dhabi face ADHICS specifically. The controls and the evidence both have to reflect health-sector expectations.

Retail and ecommerce taking card payments

The acquirer asks for PCI DSS evidence and the honest answer is nobody has looked. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.

Suppliers bidding for government work

A tender or contract flows DESC ISR or information assurance requirements down to you, sometimes mid-relationship. Meeting them is increasingly the price of staying on the vendor list.

Firms whose bank or big customer is asking questions

Enhanced due diligence and supplier security assessments impose more compliance work on UAE SMEs in practice than regulators do. The questionnaire is long, the deadline is short, and the answers have to be true.

SaaS and technology businesses selling upmarket

The deal is waiting on a security review. ISO 27001 or CSA STAR is the unlock, GDPR readiness is the follow-up question, and if the product ships AI into the EU market the AI Act is the one after that.

The five we get asked about most

PDPL, ISO 27001, PCI DSS, GDPR and DIFC data protection, side by side.

These five come up in almost every scoping call. The table shows how differently they behave: who they reach, who enforces them, and what kind of deadline they carry. Penalties are described in kind rather than in figures, because the figures change and the useful question is what category of consequence you are exposed to.
What it is
UAE PDPLUAE federal data protection law
ISO 27001International security management standard
PCI DSSCard industry security standard
GDPREU data protection regulation
DIFC DP LawDIFC data protection regime
Generally applies to
UAE PDPLBusinesses processing personal data in the UAE
ISO 27001Anyone who chooses or is contractually required to certify
PCI DSSAny business handling cardholder data
GDPREU-facing processing, wherever the business sits
DIFC DP LawEntities established in or processing through the DIFC
Mandatory or voluntary
UAE PDPLLaw
ISO 27001Voluntary standard, often required by contract
PCI DSSContractual, via the card schemes and your acquirer
GDPRLaw, where its reach applies
DIFC DP LawLaw, within its jurisdiction
Overseen or enforced by
UAE PDPLFederal authorities
ISO 27001Accredited certification bodies
PCI DSSCard schemes, via acquirers and assessors
GDPREU data protection authorities
DIFC DP LawThe DIFC data protection commissioner
Deadline style
UAE PDPLOngoing legal duty
ISO 27001Certification cycle with periodic surveillance audits
PCI DSSAnnual validation plus quarterly requirements
GDPROngoing duty with short breach notification clocks
DIFC DP LawOngoing duty with notification obligations
Typical trigger for a UAE business
UAE PDPLHolding customer or employee data at all
ISO 27001An enterprise customer or tender demands it
PCI DSSYour acquirer or payment provider requires evidence
GDPREU customers, EU users or EU-facing marketing
DIFC DP LawTaking a DIFC licence
Consequence style, described without figures
UAE PDPLAdministrative penalties and orders to change processing
ISO 27001Failed or suspended certification, lost contracts
PCI DSSFines via the schemes, higher fees, loss of card acceptance
GDPRAdministrative fines scaled to severity, processing bans
DIFC DP LawFines, directions and compensation claims
What IT must show
UAE PDPLLawful basis, security measures, breach response, records
ISO 27001A working ISMS with evidence across every control area
PCI DSSSegmented card data, hardening, logging, testing
GDPRSecurity of processing, rights handling, transfer controls
DIFC DP LawSecurity measures, records, notification readiness
Feature
UAE PDPL
ISO 27001
PCI DSS
GDPR
DIFC DP Law
What it is
UAE federal data protection lawInternational security management standardCard industry security standardEU data protection regulationDIFC data protection regime
Generally applies to
Businesses processing personal data in the UAEAnyone who chooses or is contractually required to certifyAny business handling cardholder dataEU-facing processing, wherever the business sitsEntities established in or processing through the DIFC
Mandatory or voluntary
LawVoluntary standard, often required by contractContractual, via the card schemes and your acquirerLaw, where its reach appliesLaw, within its jurisdiction
Overseen or enforced by
Federal authoritiesAccredited certification bodiesCard schemes, via acquirers and assessorsEU data protection authoritiesThe DIFC data protection commissioner
Deadline style
Ongoing legal dutyCertification cycle with periodic surveillance auditsAnnual validation plus quarterly requirementsOngoing duty with short breach notification clocksOngoing duty with notification obligations
Typical trigger for a UAE business
Holding customer or employee data at allAn enterprise customer or tender demands itYour acquirer or payment provider requires evidenceEU customers, EU users or EU-facing marketingTaking a DIFC licence
Consequence style, described without figures
Administrative penalties and orders to change processingFailed or suspended certification, lost contractsFines via the schemes, higher fees, loss of card acceptanceAdministrative fines scaled to severity, processing bansFines, directions and compensation claims
What IT must show
Lawful basis, security measures, breach response, recordsA working ISMS with evidence across every control areaSegmented card data, hardening, logging, testingSecurity of processing, rights handling, transfer controlsSecurity measures, records, notification readiness
The most common mistake

Treating compliance as a document rather than a running state.

The pattern we see most is a business that bought a policy pack, passed one review, and changed nothing operationally. A year later the controls have drifted, the evidence is stale, and the next request lands as a crisis. Three habits prevent it.

  • Map obligations once, properly. Most businesses are in scope of fewer regimes than they fear and more than they know. An hour of scoping against your licence, sector and customer base beats a year of guessing.
  • Build controls once, map them to every framework that applies. MFA, logging, backup, joiner-leaver discipline and breach response serve PDPL, ISO 27001, PCI DSS and the sector rules simultaneously. Doing the work per-framework doubles the cost for no gain.
  • Keep evidence continuously. The regimes that matter all assume you can show your state on demand. If proof takes two weeks to assemble, the controls may be fine but the review will not go well.
Get your obligations mapped
How a compliance engagement runs

Four steps from unsure to evidenced.

  1. 1

    Obligation mapping

    Week 1

    Licence location, sector, customers, contracts and card flows. Out the other side comes a written map: which regimes apply, which do not and why, and which one has the nearest deadline. This is the step most businesses have never done and it changes everything after it.

  2. 2

    Gap assessment against what applies

    Weeks 1 to 3

    Your actual environment, assessed against the frameworks from the map. Every finding is verified in the tenant, on the endpoint or in the configuration rather than taken from an interview, and severity reflects your real exposure, not a generic score.

  3. 3

    Remediation, worst first

    Weeks 2 to 8, scope dependent

    Close the gaps in risk order: identity and access first, then logging and backup, then the framework-specific items. Policies are written to describe the state we built, and staff get the training the regime expects.

  4. 4

    Evidence and maintenance

    Ongoing

    The evidence pack goes live and stays current: control status, test results, training records, restore proofs, processing records. Audits, bank reviews and regulator queries become exports. Continuous monitoring catches drift before the next review does.

UAE compliance FAQ

The questions that decide what you actually need.

It can, and the honest answer is that it depends on how you face the EU rather than on where your licence sits. GDPR is written to reach organisations outside the EU when they offer goods or services to people in the EU or monitor their behaviour, so a UAE company with an EU customer base, EU-targeted marketing, or analytics tracking EU visitors can be in scope even with no European entity. A UAE company that merely has an occasional EU customer who found them is in a much greyer area. The practical move is a short scoping exercise: how you market, who your customers are, what data you collect and what tracking you run. If GDPR does apply, the good news is that the control work overlaps heavily with UAE data protection law, so you are mostly extending one programme rather than running two.

They are separate regimes with separate regulators, and which one covers you follows your establishment. The DIFC is a financial free zone with its own legal system, and it operates its own data protection law overseen by its own commissioner. Entities established in the DIFC, or processing personal data through it, generally look to that regime as their data protection law. Businesses on the mainland and in ordinary free zones generally look to the federal law instead. ADGM works the same way with its own framework. Groups that span both, a DIFC entity and a mainland entity for example, need to know which entity processes what, because the answer differs per entity. That mapping exercise is short and it prevents the common mistake of writing one privacy notice that cites the wrong law for half the group.

No. ISO 27001 is a voluntary international standard, not a law, and no general rule requires UAE businesses to certify. In practice it becomes mandatory through the back door: enterprise customers require it in supplier contracts, tenders list it as a qualification, banks reference it in due diligence, and some regulators treat it as the expected baseline for how a serious organisation manages security. So the real question is not whether the law requires it but whether the deals you want require it. If they do, certification is a defined project with a defined audit at the end. If they do not, the sensible move is often to build the same controls without the certificate and add the audit only when a contract makes it worth the cost.

It depends on the regime, and we deliberately describe consequences in kind rather than quoting figures, because figures change and the category of exposure is what should drive your decisions. Data protection laws carry administrative fines that scale with severity, plus orders to stop or change processing, which for a data-driven business can hurt more than the fine. Sector regulators can impose penalties, restrict activities and, at the extreme end, affect the licence a business operates under. PCI DSS failures arrive as fines passed through your acquirer, higher processing fees, and ultimately loss of the ability to take cards. And across all of them sits the commercial penalty: failed due diligence, lost enterprise deals and strained banking relationships, which for most SMEs bite earlier and harder than any regulator does.

Generally yes for ordinary free zones, with the financial free zones as the exception. The federal data protection framework is written to cover businesses processing personal data in the UAE, and a DMCC, Jafza or Meydan licence does not exempt you from it. The DIFC and ADGM are different because they operate their own data protection regimes, so entities established there look to those laws instead. What ordinary free zones add is rarely a data rule of their own; it is the sector regulator behind your licence category, a virtual assets regulator, a health authority, that layers additional requirements on top of the federal baseline. This is why we scope by licence rather than by address.

Yes, and it should, because running separate programmes per entity doubles cost and creates contradictions. The structure that works is one control set, one evidence system and one owner, with a per-entity mapping that records which regimes each entity answers to and any deltas, a DIFC entity following its own data law while the mainland entity follows the federal one, for example. The controls themselves, identity, logging, backup, breach response, training, barely differ between regimes, so most of the programme is genuinely shared. The mapping layer is where the legal differences live, and keeping it explicit is what lets one audit serve several reviewers without anyone being told something untrue.

Usually only through your customers, and for most private businesses the honest answer is not directly. The UAE information assurance standards are aimed at critical sectors and the entities connected to them, and the Dubai government information security regulation is aimed at Dubai government entities. Where private companies meet them is supply: if you supply a government entity or operate in or around a critical sector, the requirements are commonly flowed down to you through contracts and procurement conditions. If that is you, the requirement is real regardless of the fact that you are private, and meeting it is increasingly the price of staying on the vendor list. If it is not you, do not let anyone sell you a critical-infrastructure programme you do not need.

Scoping and gap assessment typically fit inside the first three weeks, and the critical remediation items usually close within the first two months for an SME estate. Beyond that it depends on the finish line: readiness for a bank review is measured in weeks, while an ISO 27001 certification is usually measured in months because the management system needs to run before it can be audited. Two honest cautions: any provider quoting one timeline before seeing your environment is guessing, and compliance is not a project that ends. The regimes that matter all assume a maintained state, which is why the evidence and monitoring step is ongoing rather than final.

It depends on your regime and your processing rather than on your size. Data protection frameworks in this region expect a designated responsible person in some circumstances, typically tied to the scale and sensitivity of processing rather than headcount, and DIFC and ADGM have their own expectations for entities established there. Many businesses need the function without needing the hire, which is what DPO as a service exists for: a named, qualified officer who maintains your processing records, handles rights requests and breach notifications, and fronts regulator contact. The scoping call establishes whether your processing triggers the requirement at all; if it does not, we say so rather than selling you an officer you do not need.
Related pages

Where to go next.

Cybersecurity audit and compliance

The audit that starts most engagements: your current state, in writing, against the frameworks that apply to you.

Learn more

Compliance as a service

The whole programme run for you as a subscription: scoping, remediation, evidence and audit support.

Learn more

Free zone IT services

The licence-led view of IT for free zone companies, including which regulators sit behind which zones.

Learn more
Compliance scoping

Tell us where you are licensed and what you do, and we will tell you which regulations actually apply.

A short call covering your licence location, your sector, your customers and any deadline already running. You get a written obligation map, including the regimes we believe do not apply to you and why. No charge for the scoping, and no programme sold before the map exists.

Get a compliance scopeCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Cybersecurity Audit

Security assessment and compliance audit

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

DPO as a service

An independent data protection officer without the conflict.

Learn more

Continuous Compliance Monitoring

Control state tested daily, not annually

Learn more

Free Zone IT Services

Scoped by licence category, not postcode

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy