We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Retail & Hospitality

Card data. Customer data. Guest data. Covered.

Every till, checkout page and booking engine in the Emirates sits under PCI DSS by contract and the PDPL by law, and the PCI v4 payment-page rules have been mandatory since March 2025. Most merchants found out late. We make the whole stack one quiet program.

We are the GRC and compliance experts who pull it all together and make security look easy, so you can focus on actual security.

44%

of UAE retailers were hit by a cyberattack in a single year

Source: Adyen / Cebr, 2023

Mar 2025

the date the new PCI e-commerce anti-skimming requirements became mandatory. If you take cards online, they already apply to you

Source: PCI Security Standards Council

$13.8B

projected Dubai e-commerce market by 2029, three quarters of it on mobile

Source: Digital Commerce 360 / DET

Why it feels harder than it should

Several rulebooks, one business.

Retail obligations arrive from different directions at once: the card schemes and your acquiring bank enforce PCI DSS by contract, the federal PDPL governs the customer and loyalty data you hold, consumer-protection rules apply federally and by emirate, and hotels add passport and guest records to the pile. None of it is optional, and each asks on its own schedule.

What this looks like in practice

One case: a Dubai restaurant group with pay-at-table QR ordering, a delivery-app presence and a loyalty program. The QR checkout pulls the new PCI payment-page controls into scope, the loyalty database is squarely PDPL territory, and every delivery integration is third-party risk. Three obligations most owners have never listed in one place, which is exactly what our assessment does first.

The threat picture, from the evidence

What actually hits retail and hospitality

Retail is the sector where the machines get attacked more than the people: 42% of breaches start with an exploited flaw in a storefront, plugin or POS stack, and 68% involve a third party, the highest vendor exposure Verizon measured outside manufacturing. In the UAE, 44% of retailers reported an attack in a single year. E-skimming on payment pages is the modern till-theft, and the new PCI rules exist because of it.

68%

of retail breaches involve a third party: platforms, plugins, payment stacks

Source: Verizon 2026 DBIR

44%

of UAE retailers hit in a single year

Source: Adyen / Cebr, 2023

How they get in

Exploited vulnerabilities42%
Stolen credentials14%
Phishing9%

Source: Verizon 2026 DBIR, Retail breach entry points

Your regulators, sector by sector

Find yourself in the list.
We cover every name on it.

Stores and F&B

UAE Data Office
Focus
POS security, the new payment-page and tamper-detection rules, staff access, customer data under the PDPL.
Standards
PCI DSS v4; PDPL.
Certification
Annual PCI attestation via your acquirer.
Rhythm
Annual, with quarterly scans where connected.

E-commerce and marketplaces

UAE Data Office
Focus
Payment-page script control and tamper detection against e-skimming, API and plugin supply chain, customer accounts at scale.
Standards
PCI DSS v4; PDPL.
Certification
Annual PCI attestation; level depends on volume.
Rhythm
Annual plus mandatory quarterly scans.

Hotels and hospitality

UAE Data Office
Focus
Booking and property systems, card-on-file, passports and IDs as sensitive data, loyalty programs, property-level access control.
Standards
PCI DSS v4; PDPL; ISO 27001 increasingly.
Certification
PCI attestation appropriate to size.
Rhythm
Annual, with impact assessments on change.

Loyalty and CRM-heavy retailers

UAE Data Office
Focus
Large-scale personal data processing, consent, profiling and marketing rules, cross-border transfer, impact assessments.
Standards
PDPL first; PCI where cards stored.
Certification
PDPL is an attestable program, not a certificate.
Rhythm
Continuous, with assessments on change.

These are summary profiles. Behind each one sits a complete obligation map, control set and calendar that AccuSights maintains for clients. Seeing yours is what a demo is for.

One program instead

How we make it one control set.

We assess your card flows and customer data once, hand you the priority list, and keep the program running: PCI attestations prepared before your acquirer asks, PDPL duties handled as routine, and the read-only compliance agent watching your posture continuously. You sell; the program hums.

  • Cross-mapped controls

    One control, mapped to every regulator on this page that it satisfies.

  • Evidence collected once

    Reused across every emirate, free zone, and framework that applies to you.

  • Always audit-ready

    A read-only compliance agent keeps the picture current. You keep the keys.

Global breach figures: Verizon 2026 Data Breach Investigations Report, the 19th edition, analyzing more than 22,000 confirmed breaches across 145 countries. Regional figures: EMEA section of the same report, and UAE public statistics as cited.

Book a demo

See your obligations as one program.

Thirty minutes with an engineer who works in UAE regulation. You leave knowing which rules apply to you, where the gaps are, and how one control set covers them.