Compliance conversations in the UAE usually start in one of two places: a client contract that mentions a standard, or a tender that requires one. Rarely does a regulator arrive first. That matters, because it means the honest first question is not what is best practice but what someone is actually asking you for.
Get this confirmed properly
This is an orientation guide, not legal advice. Confirm your specific obligations with a qualified legal or compliance advisor, because they turn on your sector, your jurisdiction and your contracts.
Start with jurisdiction
Where your entity is registered changes which data protection regime applies, and this catches out businesses that assume one federal rule covers everything.
| Where you are registered | Data protection regime |
|---|---|
| UAE mainland | Federal personal data protection law (PDPL) |
| DIFC | DIFC's own data protection regulations |
| ADGM | ADGM's own data protection regulations |
| Other free zones | Generally the federal regime, but confirm with the zone authority |
DIFC and ADGM operate their own frameworks rather than deferring to the federal law. If you are registered there, that is your starting point, and advice written for mainland businesses may not apply cleanly.
Then ask what you actually handle
- Personal data of individuals: a data protection regime applies, and which one depends on jurisdiction above
- Cardholder data that you store, process or transmit: PCI DSS applies, and its scope depends heavily on how payments are taken
- Health information in Abu Dhabi: sector-specific healthcare requirements apply on top
- Government or critical infrastructure contracts: expect additional sector requirements in the contract itself
- None of the above, but enterprise clients: you are probably being asked for ISO 27001
ISO 27001 is contractual, not legal
This is the one businesses most often misunderstand. ISO 27001 is not required by UAE law. It is demanded by clients, particularly large enterprises and government buyers, as a condition of doing business. That makes it a commercial decision rather than a regulatory one, and it should be evaluated as such.
If one client is asking and the contract is large enough to justify it, pursue it. If nobody is asking, the money is usually better spent on the controls themselves than on certifying them.
PCI DSS scope is the whole game
PCI DSS applies if you touch cardholder data, and the amount of work depends enormously on how you take payment. A business using a hosted payment page where card details never reach its systems carries a fraction of the obligation of one storing card numbers. Reducing scope is almost always cheaper than complying with a large one.
The practical order to work through
- 1Read your client contracts and tender documents. Most compliance requirements arrive there first
- 2Confirm your registration jurisdiction and which data protection regime follows from it
- 3Map what categories of data you actually hold, rather than what you assume you hold
- 4Establish whether payments bring you into PCI scope, and whether that scope can be reduced
- 5Only then decide whether a certification such as ISO 27001 is commercially worth pursuing
What compliance work actually looks like
Whichever standard applies, the work divides into the same three parts: a gap assessment measuring where you are, technical remediation fixing what is missing, and building an evidence trail that shows controls operating over time. Most first-time audits struggle on the third, not the second.
Not sure which applies to you?
Tell us your sector, where you are registered and what your clients are asking for. We will help establish the applicable standard before anyone quotes you a programme.
Frequently asked questions
Is ISO 27001 mandatory in the UAE?
No. It is not required by law. It is frequently required by clients, particularly large enterprises and government buyers, as a condition of contract. That makes pursuing it a commercial decision about winning business rather than a regulatory obligation.
Does UAE PDPL apply to us?
If you are a mainland entity handling personal data, generally yes. If you are registered in DIFC or ADGM, those free zones operate their own data protection regimes instead. Confirm your position with a qualified advisor, since jurisdiction is the deciding factor.
How do we reduce PCI DSS scope?
By ensuring cardholder data never touches your systems, typically through a hosted payment page or a fully outsourced payment provider. Scope reduction is almost always cheaper than complying with a large scope, and it is the first thing worth examining.
Can our IT provider certify us?
No, and be wary of anyone who says otherwise. Certification must come from an accredited certification body independent of the people who implemented your controls. An IT provider can run the gap assessment, remediate findings and prepare your evidence.
What do auditors actually ask for?
Evidence that controls operated over a period, not merely that they exist. Typically access review records, patch reports, backup restore tests, training records and incident logs spanning months. Building that trail as you go is far easier than reconstructing it later.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for IT Compliance Consulting Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.