Retail & Hospitality
Card data. Customer data. Guest data. Covered.
Every till, checkout page and booking engine in the Emirates sits under PCI DSS by contract and the PDPL by law, and the PCI v4 payment-page rules have been mandatory since March 2025. Most merchants found out late. We make the whole stack one quiet program.
We are the GRC and compliance experts who pull it all together and make security look easy, so you can focus on actual security.
of UAE retailers were hit by a cyberattack in a single year
Source: Adyen / Cebr, 2023
the date the new PCI e-commerce anti-skimming requirements became mandatory. If you take cards online, they already apply to you
Source: PCI Security Standards Council
projected Dubai e-commerce market by 2029, three quarters of it on mobile
Source: Digital Commerce 360 / DET
Why it feels harder than it should
Several rulebooks, one business.
Retail obligations arrive from different directions at once: the card schemes and your acquiring bank enforce PCI DSS by contract, the federal PDPL governs the customer and loyalty data you hold, consumer-protection rules apply federally and by emirate, and hotels add passport and guest records to the pile. None of it is optional, and each asks on its own schedule.
What this looks like in practice
One case: a Dubai restaurant group with pay-at-table QR ordering, a delivery-app presence and a loyalty program. The QR checkout pulls the new PCI payment-page controls into scope, the loyalty database is squarely PDPL territory, and every delivery integration is third-party risk. Three obligations most owners have never listed in one place, which is exactly what our assessment does first.
What actually hits retail and hospitality
Retail is the sector where the machines get attacked more than the people: 42% of breaches start with an exploited flaw in a storefront, plugin or POS stack, and 68% involve a third party, the highest vendor exposure Verizon measured outside manufacturing. In the UAE, 44% of retailers reported an attack in a single year. E-skimming on payment pages is the modern till-theft, and the new PCI rules exist because of it.
of retail breaches involve a third party: platforms, plugins, payment stacks
Source: Verizon 2026 DBIR
of UAE retailers hit in a single year
Source: Adyen / Cebr, 2023
How they get in
Source: Verizon 2026 DBIR, Retail breach entry points
The authorities that reach this sector.
Your regulators, sector by sector
Find yourself in the list.
We cover every name on it.
Stores and F&B
- Focus
- POS security, the new payment-page and tamper-detection rules, staff access, customer data under the PDPL.
- Standards
- PCI DSS v4; PDPL.
- Certification
- Annual PCI attestation via your acquirer.
- Rhythm
- Annual, with quarterly scans where connected.
E-commerce and marketplaces
- Focus
- Payment-page script control and tamper detection against e-skimming, API and plugin supply chain, customer accounts at scale.
- Standards
- PCI DSS v4; PDPL.
- Certification
- Annual PCI attestation; level depends on volume.
- Rhythm
- Annual plus mandatory quarterly scans.
Hotels and hospitality
- Focus
- Booking and property systems, card-on-file, passports and IDs as sensitive data, loyalty programs, property-level access control.
- Standards
- PCI DSS v4; PDPL; ISO 27001 increasingly.
- Certification
- PCI attestation appropriate to size.
- Rhythm
- Annual, with impact assessments on change.
Loyalty and CRM-heavy retailers
- Focus
- Large-scale personal data processing, consent, profiling and marketing rules, cross-border transfer, impact assessments.
- Standards
- PDPL first; PCI where cards stored.
- Certification
- PDPL is an attestable program, not a certificate.
- Rhythm
- Continuous, with assessments on change.
These are summary profiles. Behind each one sits a complete obligation map, control set and calendar that AccuSights maintains for clients. Seeing yours is what a demo is for.
One program instead
How we make it one control set.
We assess your card flows and customer data once, hand you the priority list, and keep the program running: PCI attestations prepared before your acquirer asks, PDPL duties handled as routine, and the read-only compliance agent watching your posture continuously. You sell; the program hums.
Cross-mapped controls
One control, mapped to every regulator on this page that it satisfies.
Evidence collected once
Reused across every emirate, free zone, and framework that applies to you.
Always audit-ready
A read-only compliance agent keeps the picture current. You keep the keys.
Global breach figures: Verizon 2026 Data Breach Investigations Report, the 19th edition, analyzing more than 22,000 confirmed breaches across 145 countries. Regional figures: EMEA section of the same report, and UAE public statistics as cited.
Book a demo
See your obligations as one program.
Thirty minutes with an engineer who works in UAE regulation. You leave knowing which rules apply to you, where the gaps are, and how one control set covers them.