Compliance is a record, not a document
Most privacy programmes fail the same way. A set of policies is drafted, approved and circulated; the business carries on collecting, sharing and exporting personal data exactly as it did before; and eighteen months later a subject access request, a vendor's security questionnaire or a regulator's enquiry asks the one question the policies never answered — where is this data, and on what basis do you hold it?
We work in the opposite order. The data estate is mapped first: what is collected, by which system, on what lawful basis, shared with whom, held for how long, and moved across which borders. Everything else — the records of processing, the notices, the retention schedule, the transfer mechanism, the impact assessments — is then a description of something that is true, which is the only kind of compliance that survives an audit.
The two regimes we run are the UAE PDPL and the GDPR in its EU and UK forms, and most of our clients are subject to both at once. That overlap is where the practice lives: a group operating between the Gulf and Europe does not need two programmes, it needs one framework that satisfies the stricter test in each place it applies — and a clear account of where the two genuinely diverge.
Call us when
- The business has come into scope of the UAE PDPL and nothing has been done yet.
- Personal data moves between group companies across borders without a documented mechanism.
- A customer, investor or acquirer has sent a compliance questionnaire you cannot answer.
- A subject access request or a complaint has arrived with a statutory clock on it.
- You are appointing processors and cannot tell whether the contracts do what they need to.
- A new product, market or AI deployment changes what personal data the business touches.