Which Standards Apply to a UAE Business
This is the question worth answering first, because the cost of the whole programme depends on it. Several frameworks operate in the UAE and most businesses are subject to fewer than they fear.
- 01UAE PDPL, the federal personal data protection law, applies broadly to businesses handling personal data
- 02Sector rules can override: DIFC and ADGM operate their own data protection regimes for entities registered there
- 03ISO 27001 is not legally required but is frequently demanded contractually by enterprise and government clients
- 04PCI DSS applies if you store, process or transmit cardholder data, and its scope depends heavily on how you take payment
- 05Healthcare, government and critical infrastructure carry additional sector-specific requirements
- 06The honest starting point is usually a client contract or a tender, not a regulator