Customer Data Sits in More Systems Than the Register Lists.
Loyalty platforms, booking engines, payment estates and property systems all hold records. Ask for the complete list and note how long it takes to assemble - that interval is the finding.
Customer records sit in loyalty platforms, booking engines, payment systems and building controls. The UAE PDPL covers all of it. Ask for the full list and see how long it takes.
Each one below is dated, named, and set by someone other than us. Read them against what you could show this week, not what you plan to build.
These apply across sectors, not to this industry alone. When a rule specific to this sector exists, it will be added here with its date. We do not list one we cannot name.
| Date | Regulator | Obligation | What you must show |
|---|---|---|---|
| In force | UAE federal | PDPL — extraterritorial | Lawful basis, DPO appointment, data protection impact assessments; fines AED 100,000 to AED 1,000,000 |
| In force | UAE federal — NESA | Information Assurance Standard v2 | 39 mandatory Priority One controls; CNI harm penalties from AED 500,000 to AED 3,000,000 |
| In force | DESC (Dubai) | Information Security Regulation v3 | Annual penetration testing, quarterly vulnerability assessment; non-compliance removes you from procurement lists |
| Rolling out 2026 | UAE — NCAP | Supplier accreditation for critical infrastructure | That your security and cloud suppliers hold the required accreditation |
| During 2026 | UAE Cyber Security Council | National Encryption Policy — PQC migration planning | A cryptographic inventory across the estate |
| In force | Procurement-driven | ISO/IEC 42001 appearing in GCC procurement requirements | Certifiable AI management system, or a defensible path to one |
| 1 Jan 2026 | DIFC / ADGM | Regulation 10 and free-zone data protection regimes | AI system inventory, risk assessments, human oversight |
| Extraterritorial | EU AI Act | Applies to MENA multinationals placing systems on the EU market | Risk classification and conformity documentation |
No instrument for this jurisdiction is listed on this page. Federal and cross-border obligations under Show all still apply.
Loyalty platforms, booking engines, payment estates and property systems all hold records. Ask for the complete list and note how long it takes to assemble - that interval is the finding.
Personalisation and chat tools are bought quickly because the commercial case is obvious. Which of them has been reviewed for the data it was given access to?
Access control, lifts and building management were installed by teams outside IT. Are they inside your security perimeter, and who holds the credentials?
Fixed fee, fixed duration, delivered remotely. We publish the bands so you know before you call whether this is your size of problem.
| Assessment | Duration | Indicative fee | What you receive |
|---|---|---|---|
| Control evidence review | 4–6 weeks | USD 30–70K | Whether your controls can be evidenced to a third party: what is documented, what is current, what an auditor or correspondent would accept, and what is missing |
| Third-party & supplier risk review | 3–4 weeks | USD 20–40K | Supplier risk assessed against contractual, regulatory and accreditation requirements, ranked by exposure |
| AI governance gap assessment | 6 weeks | USD 35–75K | Shadow-AI discovery, system inventory and a gap report against ISO/IEC 42001 and applicable local obligation |
| Cryptographic discovery & inventory | 4–6 weeks | USD 40–90K | Risk-ranked cryptographic estate inventory and migration-plan skeleton |
Yes, extraterritorially, wherever the personal data of UAE residents is processed — including by platforms acting on your behalf.
Every system holding customer or guest records, who administers each one, and which third parties process the data.
PCI DSS is a payment industry standard rather than a regulator obligation, and Orvix is not a qualified security assessor.
Yes — access control, lifts and building management are frequently outside the security perimeter and inside the risk.
That is the question the assessment answers, and the time it takes to assemble the answer is usually the finding.
A fixed-scope assurance review of your AI estate — inventory, control mapping against the frameworks that apply to you, and a written evidence package your board and your regulator can read. Defined price, defined duration, no obligation beyond it.
The people who bring us in are usually the ones who saw it coming.