Which compliance applies to your UAE business? It depends on where you are licensed and what you do.
There is no single UAE IT compliance checklist, and anyone selling you one is selling a template. Your obligations come from three directions at once: where your licence sits (mainland, DIFC, ADGM, or another free zone), what sector you operate in, and who your customers are. This page maps every regulation and framework we cover, tells you in one line who each applies to, and links to the detailed page for each. If you already know your regulator, jump straight to it. If you do not, the decision section below gets you there in a minute.

- Licence-ledScoped to your obligations
- 28Frameworks and services covered
- 5 minP1 remote response
- FreeInitial scoping call
Six things every framework asks for, whatever the acronym.
Know what data you hold and where it lives
Every data protection regime starts here: what personal or regulated data you process, why, where it is stored, who can reach it, and where the copies sit including backups and replicas. Most businesses cannot answer this on day one, and most findings trace back to that gap. A data inventory and records of processing turn the question into an export.
Access control that survives an audit
Multi-factor authentication enforced rather than merely available, administrator accounts separated from daily accounts, joiner and leaver processes documented and followed, and dormant accounts removed. Auditors under every framework check this first because it is where breaches actually start.
Monitoring and the ability to detect an incident
Regulations increasingly assume you will detect your own incidents rather than hear about them from a customer. That means logging that is retained, alerting that a human reviews, and an answer to the question of who noticed and when. Frameworks from the UAE information assurance standards to DORA make this explicit.
A breach response you have rehearsed
Most modern regimes carry notification duties with short clocks attached. The difference between a controlled notification and a scramble is a written plan, named owners, and at least one rehearsal before the real event. We build and test the plan so the clock starts on a process rather than a panic.
Evidence, kept current, not assembled under deadline
Having controls and having proof of controls are different things, and reviews fail on the second one as often as the first. Policies, configurations, test results, training records and restore evidence maintained continuously turn a regulator, bank or enterprise customer request into an export rather than a fortnight of archaeology.
People who know what the rules require of them
Awareness training, an acceptable use policy people have actually read, and clear ownership of compliance duties inside the business. Several regimes expect a named responsible person, and some sectors expect a formally appointed data protection officer, which can be provided as a service rather than a hire.
Find your regulation, grouped by who enforces it.
UAE federal and emirate rules
Rules made in the UAE that apply based on where you operate and what sector you are in, from the federal data protection law to emirate-level security standards.
- UAE PDPL complianceThe federal data protection law. Broadly relevant to businesses processing personal data in the UAE.
- NESA complianceUAE information assurance standards, relevant to critical sectors and entities connected to them.
- DESC ISR complianceDubai government information security regulation, relevant to Dubai government entities and their suppliers.
- ADHICS complianceAbu Dhabi healthcare information and cyber security standard for healthcare entities in the emirate.
- Central Bank IT requirementsIT and security expectations for banks, exchange houses and finance firms under Central Bank supervision.
- IT asset disposal complianceCompliant destruction and disposal of data-bearing hardware for any UAE business retiring equipment.
Financial free zone regulators
DIFC and ADGM are financial free zones with their own legal systems, their own data protection regimes and their own financial regulators. If your licence sits in one of them, these pages are yours.
- DIFC Data Protection LawThe DIFC data protection regime, applying to entities established in or processing through the DIFC.
- DFSA IT complianceIT, cyber and operational resilience expectations for DFSA-regulated financial firms in the DIFC.
- ADGM IT complianceControls and evidence for Abu Dhabi Global Market entities under their regulatory framework.
International frameworks
Standards you adopt by choice or by contract rather than by law. Customers, banks and tenders increasingly require them, and some UAE regulators reference them as the expected baseline.
- ISO 27001 certificationThe international information security management standard. Voluntary, and the one most often demanded by contract.
- PCI DSS complianceRequired by the card schemes for any business that stores, processes or transmits cardholder data.
- NIST CSF assessmentA structured cybersecurity maturity assessment, useful as a baseline for boards and insurers.
- GDPR for UAE businessesThe EU data protection regulation, which can reach UAE firms serving or monitoring people in the EU.
- CSA STAR certificationCloud security assurance for providers and SaaS businesses selling into security-conscious customers.
- SOX ITGC complianceIT general controls for UAE subsidiaries of US-listed groups and businesses preparing for listing.
- COBIT IT governanceAn IT governance framework for organisations formalising how IT is directed and controlled.
EU rules reaching UAE firms
European regulations with reach beyond Europe. If you serve EU financial institutions, EU markets or EU users, these can apply to you contractually or directly even though your licence is in the UAE.
- DORA complianceEU digital operational resilience rules that reach UAE firms serving EU financial entities.
- NIS2 complianceEU network and information security rules that can reach UAE suppliers to in-scope EU organisations.
- EU AI Act complianceEU rules on AI systems, relevant to UAE businesses placing AI products or outputs into the EU market.
Compliance delivery services
The frameworks above say what must be true. These services are how we make it true and keep it true, from a one-off audit to a standing programme with a named officer.
- Compliance as a serviceThe full programme run for you: scoping, remediation, evidence and audit support as a subscription.
- Continuous compliance monitoringControls checked continuously rather than annually, so drift is caught before an auditor catches it.
- DPO as a serviceA named data protection officer for businesses that need one without making a full-time hire.
- Records of processing activitiesThe processing register that data protection regimes expect, built and kept current for you.
- Privacy impact assessmentsStructured assessments for new systems and higher-risk processing, documented to regulator standard.
- Breach notification readinessThe plan, the templates and the rehearsal, so a notification clock starts on a process, not a panic.
- Communication complianceRetention and supervision of business communications for regulated firms and disciplined ones.
- Open source licence complianceFor software businesses: knowing what open source you ship and what its licences oblige you to do.
- Cybersecurity audit and complianceThe audit that starts most engagements: where you stand today, in writing, against the frameworks that apply.
Four reasons this works better than a policy pack.
We map obligations before we quote controls
The first conversation is about your licence location, your sector, and your customers, because that is what determines which regimes reach you. Scoping by company size alone is how providers sell an ISO project to a business whose actual deadline is a Central Bank review. You get the map in writing, including the regimes we think do not apply to you and why.
We implement, not just document
A policy that says MFA is enforced while the tenant says otherwise fails the audit and, worse, fails the breach. We are an IT and security provider first, so the controls get built in your actual environment: identity, endpoints, logging, backup, mail authentication. The documents describe a real state instead of an aspiration.
One control set, mapped to every framework you face
Most of our compliance clients answer to more than one regime at once: a data protection law, a sector regulator, and a contractual framework a customer imposed. We build the control set once and maintain a mapping to each framework, so an ISO audit, a bank review and a regulator query all draw from the same living evidence.
We stand next to you at the review
Audits and regulator interactions go better with the people who built the controls in the room. We prepare the evidence pack, sit in the sessions where you want us, handle the technical questions, and turn findings into a remediation plan with owners and dates rather than a PDF that gets filed.
Narrow it down by where you are licensed and what you do.
By where your licence sits
- Mainland UAEThe federal data protection law is your starting point for personal data, with sector rules layered on top depending on your industry. If you retire hardware, disposal compliance applies to everyone.
- DIFCThe DIFC has its own data protection law and its own commissioner. If you are also DFSA-regulated, DFSA IT and resilience expectations sit alongside it. The federal regime generally is not your primary data law here.
- ADGMADGM likewise operates its own data protection framework, with financial firms answering to the financial regulator on top. Treat it as its own jurisdiction for data purposes.
- Other free zones (DMCC, Jafza, Meydan and the rest)Non-financial free zones generally sit under the federal regime for data protection. Your zone authority rarely adds IT rules directly; your licence category and sector regulator are what matter.
By what you do
- Banking, finance and insurance (BFSI)Central Bank supervision on the mainland, DFSA in the DIFC, the ADGM regulator in ADGM. Expect explicit IT, outsourcing and resilience requirements, plus communication retention. Serving EU financial institutions can pull DORA obligations into your contracts.
- HealthcareHealth data is regulated more tightly than general personal data. In Abu Dhabi, ADHICS applies to healthcare entities. Across the UAE, health-sector rules on patient data sit on top of general data protection law.
- Government suppliersSupplying Dubai government entities brings DESC ISR requirements into your contracts. Critical-sector work can bring the UAE information assurance standards. Both are commonly flowed down to suppliers through procurement.
- Retail, ecommerce and hospitalityTaking card payments puts PCI DSS in scope through your acquirer, whatever your size. Customer databases put you under data protection law. Neither depends on having an office.
- Selling to or monitoring people in the EUGDPR can apply to a UAE business that offers goods or services to people in the EU or monitors their behaviour, regardless of where the company is licensed. An EU-facing website with EU customers is the classic trigger.
- Technology, SaaS and AI productsEnterprise customers will ask for ISO 27001 or CSA STAR before regulators ask for anything. Shipping software brings open source licence obligations. Placing AI systems into the EU market brings the EU AI Act into view.
The six situations that bring businesses here.
Financial firms with a regulator letter
A DFSA, ADGM or Central Bank supervisory request with a response date attached. The work is mapping the request to controls, closing the genuine gaps fast, and presenting the rest honestly with a dated plan.
Healthcare providers handling patient data
Clinics, pharmacies and health-tech businesses whose data is regulated more tightly than general personal data, and who in Abu Dhabi face ADHICS specifically. The controls and the evidence both have to reflect health-sector expectations.
Retail and ecommerce taking card payments
The acquirer asks for PCI DSS evidence and the honest answer is nobody has looked. Scoping down what actually touches card data usually shrinks the problem dramatically before any control work starts.
Suppliers bidding for government work
A tender or contract flows DESC ISR or information assurance requirements down to you, sometimes mid-relationship. Meeting them is increasingly the price of staying on the vendor list.
Firms whose bank or big customer is asking questions
Enhanced due diligence and supplier security assessments impose more compliance work on UAE SMEs in practice than regulators do. The questionnaire is long, the deadline is short, and the answers have to be true.
SaaS and technology businesses selling upmarket
The deal is waiting on a security review. ISO 27001 or CSA STAR is the unlock, GDPR readiness is the follow-up question, and if the product ships AI into the EU market the AI Act is the one after that.
PDPL, ISO 27001, PCI DSS, GDPR and DIFC data protection, side by side.
| Feature | UAE PDPL | ISO 27001 | PCI DSS | GDPR | DIFC DP Law |
|---|---|---|---|---|---|
What it is | UAE federal data protection law | International security management standard | Card industry security standard | EU data protection regulation | DIFC data protection regime |
Generally applies to | Businesses processing personal data in the UAE | Anyone who chooses or is contractually required to certify | Any business handling cardholder data | EU-facing processing, wherever the business sits | Entities established in or processing through the DIFC |
Mandatory or voluntary | Law | Voluntary standard, often required by contract | Contractual, via the card schemes and your acquirer | Law, where its reach applies | Law, within its jurisdiction |
Overseen or enforced by | Federal authorities | Accredited certification bodies | Card schemes, via acquirers and assessors | EU data protection authorities | The DIFC data protection commissioner |
Deadline style | Ongoing legal duty | Certification cycle with periodic surveillance audits | Annual validation plus quarterly requirements | Ongoing duty with short breach notification clocks | Ongoing duty with notification obligations |
Typical trigger for a UAE business | Holding customer or employee data at all | An enterprise customer or tender demands it | Your acquirer or payment provider requires evidence | EU customers, EU users or EU-facing marketing | Taking a DIFC licence |
Consequence style, described without figures | Administrative penalties and orders to change processing | Failed or suspended certification, lost contracts | Fines via the schemes, higher fees, loss of card acceptance | Administrative fines scaled to severity, processing bans | Fines, directions and compensation claims |
What IT must show | Lawful basis, security measures, breach response, records | A working ISMS with evidence across every control area | Segmented card data, hardening, logging, testing | Security of processing, rights handling, transfer controls | Security measures, records, notification readiness |
Treating compliance as a document rather than a running state.
The pattern we see most is a business that bought a policy pack, passed one review, and changed nothing operationally. A year later the controls have drifted, the evidence is stale, and the next request lands as a crisis. Three habits prevent it.
- Map obligations once, properly. Most businesses are in scope of fewer regimes than they fear and more than they know. An hour of scoping against your licence, sector and customer base beats a year of guessing.
- Build controls once, map them to every framework that applies. MFA, logging, backup, joiner-leaver discipline and breach response serve PDPL, ISO 27001, PCI DSS and the sector rules simultaneously. Doing the work per-framework doubles the cost for no gain.
- Keep evidence continuously. The regimes that matter all assume you can show your state on demand. If proof takes two weeks to assemble, the controls may be fine but the review will not go well.
Four steps from unsure to evidenced.
- 1
Obligation mapping
Week 1
Licence location, sector, customers, contracts and card flows. Out the other side comes a written map: which regimes apply, which do not and why, and which one has the nearest deadline. This is the step most businesses have never done and it changes everything after it.
- 2
Gap assessment against what applies
Weeks 1 to 3
Your actual environment, assessed against the frameworks from the map. Every finding is verified in the tenant, on the endpoint or in the configuration rather than taken from an interview, and severity reflects your real exposure, not a generic score.
- 3
Remediation, worst first
Weeks 2 to 8, scope dependent
Close the gaps in risk order: identity and access first, then logging and backup, then the framework-specific items. Policies are written to describe the state we built, and staff get the training the regime expects.
- 4
Evidence and maintenance
Ongoing
The evidence pack goes live and stays current: control status, test results, training records, restore proofs, processing records. Audits, bank reviews and regulator queries become exports. Continuous monitoring catches drift before the next review does.
The questions that decide what you actually need.
Where to go next.
Cybersecurity audit and compliance
The audit that starts most engagements: your current state, in writing, against the frameworks that apply to you.
Compliance as a service
The whole programme run for you as a subscription: scoping, remediation, evidence and audit support.
Free zone IT services
The licence-led view of IT for free zone companies, including which regulators sit behind which zones.
Tell us where you are licensed and what you do, and we will tell you which regulations actually apply.
A short call covering your licence location, your sector, your customers and any deadline already running. You get a written obligation map, including the regimes we believe do not apply to you and why. No charge for the scoping, and no programme sold before the map exists.
Related Services
Explore more solutions that work great with this service
Cybersecurity Audit
Security assessment and compliance audit
Compliance as a Service
Keeping the position true between assessments
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
DPO as a service
An independent data protection officer without the conflict.
Continuous Compliance Monitoring
Control state tested daily, not annually
Free Zone IT Services
Scoped by licence category, not postcode