What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Industry

Find Every Copy of a Customer Record.

Customer records sit in loyalty platforms, booking engines, payment systems and building controls. The UAE PDPL covers all of it. Ask for the full list and see how long it takes.

01

What Applies to You

Each one below is dated, named, and set by someone other than us. Read them against what you could show this week, not what you plan to build.

These apply across sectors, not to this industry alone. When a rule specific to this sector exists, it will be added here with its date. We do not list one we cannot name.

DateRegulatorObligationWhat you must show
In forceUAE federal PDPL — extraterritorialLawful basis, DPO appointment, data protection impact assessments; fines AED 100,000 to AED 1,000,000
In forceUAE federal — NESA Information Assurance Standard v239 mandatory Priority One controls; CNI harm penalties from AED 500,000 to AED 3,000,000
In forceDESC (Dubai) Information Security Regulation v3Annual penetration testing, quarterly vulnerability assessment; non-compliance removes you from procurement lists
Rolling out 2026UAE — NCAP Supplier accreditation for critical infrastructureThat your security and cloud suppliers hold the required accreditation
During 2026UAE Cyber Security Council National Encryption Policy — PQC migration planningA cryptographic inventory across the estate
In forceProcurement-driven ISO/IEC 42001 appearing in GCC procurement requirementsCertifiable AI management system, or a defensible path to one
1 Jan 2026DIFC / ADGM Regulation 10 and free-zone data protection regimesAI system inventory, risk assessments, human oversight
ExtraterritorialEU AI Act Applies to MENA multinationals placing systems on the EU marketRisk classification and conformity documentation
02

Three Gaps in Customer Estates

I

Customer Data Sits in More Systems Than the Register Lists.

Loyalty platforms, booking engines, payment estates and property systems all hold records. Ask for the complete list and note how long it takes to assemble - that interval is the finding.

II

Guest-facing AI Arrived Through Marketing, Not Procurement.

Personalisation and chat tools are bought quickly because the commercial case is obvious. Which of them has been reviewed for the data it was given access to?

III

Property and Building Systems were Commissioned by Facilities.

Access control, lifts and building management were installed by teams outside IT. Are they inside your security perimeter, and who holds the credentials?

03

The Assessments

Fixed fee, fixed duration, delivered remotely. We publish the bands so you know before you call whether this is your size of problem.

AssessmentDurationIndicative feeWhat you receive
Control evidence review4–6 weeks USD 30–70K Whether your controls can be evidenced to a third party: what is documented, what is current, what an auditor or correspondent would accept, and what is missing
Third-party & supplier risk review3–4 weeks USD 20–40K Supplier risk assessed against contractual, regulatory and accreditation requirements, ranked by exposure
AI governance gap assessment6 weeks USD 35–75K Shadow-AI discovery, system inventory and a gap report against ISO/IEC 42001 and applicable local obligation
Cryptographic discovery & inventory4–6 weeks USD 40–90K Risk-ranked cryptographic estate inventory and migration-plan skeleton
04

Common Questions

Does the UAE PDPL apply to a hotel group or retailer?

Yes, extraterritorially, wherever the personal data of UAE residents is processed — including by platforms acting on your behalf.

What does a customer data assessment cover?

Every system holding customer or guest records, who administers each one, and which third parties process the data.

Is PCI DSS compliance part of this?

PCI DSS is a payment industry standard rather than a regulator obligation, and Orvix is not a qualified security assessor.

Do you assess building management and property systems?

Yes — access control, lifts and building management are frequently outside the security perimeter and inside the risk.

How quickly can a data subject request be answered today?

That is the question the assessment answers, and the time it takes to assemble the answer is usually the finding.

05

One Method, Different Evidence

Start here

Start With the Evidence.

A fixed-scope assurance review of your AI estate — inventory, control mapping against the frameworks that apply to you, and a written evidence package your board and your regulator can read. Defined price, defined duration, no obligation beyond it.


The people who bring us in are usually the ones who saw it coming.