Practice 02

Privacy & data protection

A regulator does not assess your policy document. It assesses whether what the policy describes is what the business actually does — which is why we build compliance from the data outward: what you hold, why you are allowed to hold it, where it goes, and who can show that on the day someone asks.

Frameworks
Two
UAE PDPL and the EU & UK GDPR
Businesses guided
Hundreds
Through governance, risk and implementation
Typical build
8–14 wk
Gap assessment to an operating framework
Practice lead
The Director
Saeed Hasan Khan, Privacy & Taxation
The discipline

Compliance is a record, not a document

Most privacy programmes fail the same way. A set of policies is drafted, approved and circulated; the business carries on collecting, sharing and exporting personal data exactly as it did before; and eighteen months later a subject access request, a vendor's security questionnaire or a regulator's enquiry asks the one question the policies never answered — where is this data, and on what basis do you hold it?

We work in the opposite order. The data estate is mapped first: what is collected, by which system, on what lawful basis, shared with whom, held for how long, and moved across which borders. Everything else — the records of processing, the notices, the retention schedule, the transfer mechanism, the impact assessments — is then a description of something that is true, which is the only kind of compliance that survives an audit.

The two regimes we run are the UAE PDPL and the GDPR in its EU and UK forms, and most of our clients are subject to both at once. That overlap is where the practice lives: a group operating between the Gulf and Europe does not need two programmes, it needs one framework that satisfies the stricter test in each place it applies — and a clear account of where the two genuinely diverge.

Call us when

  • The business has come into scope of the UAE PDPL and nothing has been done yet.
  • Personal data moves between group companies across borders without a documented mechanism.
  • A customer, investor or acquirer has sent a compliance questionnaire you cannot answer.
  • A subject access request or a complaint has arrived with a statutory clock on it.
  • You are appointing processors and cannot tell whether the contracts do what they need to.
  • A new product, market or AI deployment changes what personal data the business touches.
What we cover

Four areas of the practice

A first mandate is usually the whole of the first area. The other three are where the programme is kept true after it goes live.

  • 01

    Assessment & data mapping

    The foundation everything else rests on: what personal data the business actually holds, in which systems, on what basis, and for how long — measured against the regimes that apply to it.

    • Applicability and scoping across group entities
    • Gap assessment against the UAE PDPL and the GDPR
    • Data inventory and processing-activity records
    • Lawful basis, consent and retention analysis
  • 02

    Governance frameworks

    The policies, notices and contracts that describe the mapped estate — drafted to be operable by the people who will have to run them, rather than to be comprehensive on paper.

    • Privacy policies, notices and consent mechanics
    • Controller and processor agreements, vendor terms
    • Roles, accountability and DPO arrangements
    • Retention schedules and deletion routines
  • 03

    Cross-border transfers

    The half of the work that most often goes undocumented. Where data leaves a jurisdiction, the mechanism has to exist before the transfer does — and it has to match how the group actually operates.

    • Transfer mapping across entities, vendors and regions
    • Adequacy analysis and transfer mechanisms
    • Standard clauses and intra-group agreements
    • Transfer impact assessments and supplementary measures
  • 04

    Risk, incidents & assurance

    What happens when the framework is tested. Impact assessments before a risk is taken, a rehearsed response when something goes wrong, and periodic audit so the record stays true as the business changes.

    • DPIAs and legitimate-interest assessments
    • Breach response, notification and regulator liaison
    • Data subject request handling and escalation
    • Compliance audits, training and annual review
How a mandate runs

Six stages, in this order

The order matters more than the pace. A framework written before the estate is mapped describes a business that does not exist, and that is the failure mode we are hired to undo most often.

  1. 01

    Scope & gap assessment

    Which regimes reach which entities, and where you stand against each of them today. The output is a ranked list of exposures with the regulatory consequence attached — not a score out of a hundred.

    Week 1–2

  2. 02

    Data mapping

    Interviews with the teams that actually handle the data, system by system, until the inventory reflects practice rather than intention. This is the longest stage and the one that determines whether everything after it is worth anything.

    Week 2–5

  3. 03

    Lawful basis & transfers

    Each processing activity assigned a basis that can be defended, and each border crossing given a mechanism. Where a flow cannot be justified, it is flagged as something to change rather than something to document.

    Week 4–7

  4. 04

    Framework build

    Policies, notices, records of processing, retention schedule, processor terms and the request and breach procedures — drafted against the mapped estate and written to be followed by non-lawyers.

    Week 6–10

  5. 05

    Implementation & training

    Owners named, routines placed in the systems that will run them, and the teams trained on the parts they touch. A framework nobody has been shown is a framework that will be contradicted within a quarter.

    Week 8–14

  6. 06

    Assurance & review

    Periodic audit against the record, DPIAs as new processing is proposed, and a stated review cycle — plus a rehearsed path for the two things that arrive without warning: a data subject request and a breach.

    Ongoing

Regimes we run

Named, not implied

Most of our clients are subject to more than one of these at once. The framework is built to satisfy the stricter test wherever they overlap.

UAE PDPL

  • Applicability and scoping
  • Controller and processor obligations
  • Consent and lawful processing
  • Data subject rights handling
  • Cross-border transfer conditions
  • Breach notification

GDPR — EU & UK

  • Records of processing (Article 30)
  • Lawful basis and legitimate interests
  • Data protection impact assessments
  • Processor and sub-processor terms
  • Representative and DPO arrangements
  • 72-hour breach notification

Transfers

  • Adequacy analysis
  • Standard contractual clauses
  • Intra-group transfer agreements
  • Transfer impact assessments
  • Supplementary technical measures

Sitting between the Gulf and Europe is the common case, not the exception — and it is the case this practice was built for.

See the jurisdictions
Common questions

What clients ask before they start

Answers here are general. Which of them applies to your business depends on where it operates and what it holds — that is what the assessment establishes.

We are based in the UAE. Does the GDPR reach us at all?

It can, and frequently does. The GDPR follows the data subject rather than the company — offering goods or services to people in the EU or the UK, or monitoring their behaviour, brings a business within scope regardless of where it is established. A UAE group with European customers, European staff or a European group entity is usually subject to both regimes at once.

Establishing exactly which entities are in scope of which regime is the first stage of the mandate, not an assumption we make.

We already have a privacy policy. Is that not most of it?

It is the visible part and rarely the substantive one. A regulator's questions are about the estate behind the policy: which systems hold personal data, on what basis, shared with whom, retained how long, transferred where. A policy that describes a business accurately is valuable; one drafted before anyone looked is a statement you can be held to and cannot evidence.

How long does a first programme take, realistically?

Eight to fourteen weeks from gap assessment to an operating framework, for a single business of moderate complexity. The variable is almost never the drafting — it is how quickly the people who actually handle the data can be sat down and asked what they do with it.

Groups with multiple entities and shared systems run longer, and are scoped by entity so the first one is live while the rest are still being mapped.

A data subject request has arrived and the clock is running.

Say so in the first line of your message. Requests and breaches both run on statutory clocks measured in days, and they are triaged ahead of programme work. We will deal with the response in front of you first, then be honest about whether the fact that it caught you unprepared is itself worth addressing.

Do we need to appoint a Data Protection Officer?

It depends on what you process and at what scale, and the tests differ between the PDPL and the GDPR. Where an appointment is required we say so plainly; where it is not, we say that too rather than selling a role you do not need. What every business does need is a named person accountable for the framework — that is a governance point, not a statutory one.

Can you work with our IT team and existing vendors?

That is how the mapping stage works — it is conducted with the people who run the systems, not around them. On the vendor side we review the contracts you already have and tell you which ones do the job, which need amending, and which represent a transfer with no mechanism behind it.

Practice 01

Anti-dumping & trade remedy

The same craft against a different regime: anti-dumping, countervailing and safeguard proceedings run from the notice of initiation through to the determination and the reviews that follow it.

Explore trade remedy

Start with the estate.

Tell us what the business holds and where it operates. The Director tells you which regimes reach you and what the real exposure is — within one business day.