Obligations Finder · 2 minutes · 3 questions
Which UAE regulators and frameworks apply to your business, and what each one demands?
Three taps and you see your regulators drawn by weight, the rulebook and notification rule for each, and the three protections that answer most of it. Complicated made simple. The precise map, with every control and date, comes in thirty minutes with an engineer.
No email needed to see it.
1. What does your organization do?
2. Where do you operate?(choose all that apply)
3. Which of these describe your business? Choose all that apply.(choose all that apply)
Answer the first two questions to see your map.
Questions about scope
Which rules apply, where the free zones differ, and what moves data across the border.
Which cybersecurity regulations apply in the UAE?
Sector and location decide it. Everyone answers to the Cybercrime Law (Federal Decree-Law 34 of 2021) and the PDPL (Federal Decree-Law 45 of 2021). Healthcare adds ADHICS in Abu Dhabi, DHA and NABIDH in Dubai and the federal health data law. Finance adds CBUAE, DFSA, FSRA or VARA. Government and critical infrastructure add the IA Standard v2 and, in Dubai, DESC ISR. DIFC and ADGM run their own privacy laws. Most businesses face three or more at once.
Does the UAE PDPL apply inside DIFC and ADGM?
No. Both financial free zones are carved out of the federal PDPL and run their own regulators: the DIFC Commissioner of Data Protection under DIFC Law No. 5 of 2020, and the ADGM Office of Data Protection under the ADGM Data Protection Regulations 2021. A group with entities in DIFC and onshore Dubai must satisfy both regimes. The laws are similar enough that one programme with a few zone-specific add-ons usually covers all of them.
Do I need a data protection officer in the UAE?
The PDPL requires a DPO when processing is high-risk, involves large-scale sensitive data or involves systematic monitoring, with the thresholds to be detailed in the executive regulations. A DPO can be an employee or an external appointment and can sit outside the UAE. Most SMEs do not need one, but every business still needs a named person responsible for privacy.
Can I transfer personal data outside the UAE?
Yes, to countries the UAE Data Office deems adequate, or otherwise with safeguards such as contractual clauses, or with the individual’s consent. Health data is a separate case: Federal Law No. 2 of 2019 restricts storing or transferring health information outside the UAE except where permitted. Check both laws before a foreign cloud service holds patient or customer data.
Do fintech start-ups need cybersecurity compliance before they are licensed?
Yes, from the application onward. Whether you sit under CBUAE, DFSA, FSRA or VARA, the licence application itself asks for cyber governance, policies, testing and incident response evidence, and weak cybersecurity is a common reason applications stall. Building the programme before applying is faster and cheaper than retrofitting it.
Is ISO 27001 required for UAE financial firms?
No regulator mandates the certificate itself, but every UAE financial regulator’s framework maps closely to ISO 27001, and many banks require it of their vendors and fintech partners. Certification is the fastest way to evidence compliance across CBUAE, DFSA and FSRA at once, and counterparties increasingly expect it.
How fast do UAE financial firms have to report a cyber incident?
It depends on the regulator. VARA’s rulebook and the FSRA rules effective January 31, 2026 require notification of material incidents within 24 hours; DFSA’s Cyber Risk Management rules, mandatory since January 1, 2024, allow up to 72 hours; CBUAE requires prompt reporting under its Information Assurance framework. A firm regulated by more than one body meets the shortest clock.
Book a demo
See your obligations as one program.
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.
Prefer we come to you? Leave your details below and an engineer replies within one business day.