Stay compliant across the GCC without slowing down your business

We are the experts in the KSA PDPL, the UAE PDPL, and the data protection laws of all GCC countries, without slowing down your business.

gcc-hero-img-1
solar_shield-check-bold

CERTIFIED

ISO 27001 Compliant

solar_shield-check-bold (1)

20+ Years

in GCC Compliance

Our Certifications

cert-1
cert-2
cert-3
cert-4
cert-5
gcc-stat-img

0+

KSA PDPL Projects

0+

GDPR Projects

0+

Other GCC Privacy Projects

Compliance is not a one-time thing. We don’t want you to always depend on consultants

We ask you to nominate someone as DPO. We take that person, train them, then deliver the program with them, mentoring and upskilling them so that they can take our roadmap and ensure continuous compliance.

Holistic Compliance Solutions

Records of Processing Activities

Records of Processing Activities

Records of Processing Activities are a legal requirement. A catalogue of your data, showing what you do and compliance risks. We conduct detailed interviews with your business units to understand what they do with personal data, do some discovery and then use the RoPA to manage your risks

Down Arrow
Staff Training

Staff Training

Hamburger Menu

We train and mentor your nominated DPO, using the compliance program as a learning tool. We also create all staff training and awareness messages.

International Data Transfers

International Data Transfers

Hamburger Menu

Sending data outside the country is complex – we help you navigate the legal difficulties and do your transfer risk assessments.

Framework, Strategy and Operating Model

Framework, Strategy and Operating Model

Hamburger Menu

These are not theoretical – we tailor these to your company set up and operations so you can manage future compliance.

Lawful Basis and Consent Management

Lawful Basis and Consent Management

Hamburger Menu

Identification of lawful bases and we dive into your consent statements and operations to give clients control of their choices.

Data Protection Policy

Data Protection Policy

Hamburger Menu

This underpins what you do, responsibilities and risk appetites. It underpins the legal obligations and corporate stance.

AI and Tech Development

AI and Tech Development

Hamburger Menu

We look at the data protection aspects of your AI or tech development to make sure that you are compliant with privacy laws.

Data Breaches

Data Breaches

Hamburger Menu

Handy toolkits for all staff to detailed guidance for your DPO and C-Suite, a complete manual to manage issues and learn lessons.

Privacy Notices and Cookies

Privacy Notices and Cookies

Hamburger Menu

We write your external and staff privacy policies in clear language to promote transparency and trust. We also manage your cookies.

Data Subject Rights

Data Subject Rights

Hamburger Menu

How to handle requests from customers and staff for copies of information, withdrawal of consent, corrections or other rights.

Marketing Policy

Marketing Policy

Hamburger Menu

Marketing, whether through emails, phone calls, social media or events is covered by the law. We help you comply and keep you effective.

Vendor Management

Vendor Management

Hamburger Menu

From tender invitations, shortlisting, due diligence, risk assessments and contracts. We make sure your vendors look after your data.

Privacy Impact Assessments

Privacy Impact Assessments

Hamburger Menu

Privacy impact assessment are mandatory under privacy laws. We assess your high risk processing and mitigate risks.

Down Arrow
SDAIA Self-Assessment

SDAIA Self-Assessment

We use the SDAIA/NDMO self assessments to help you understand your compliance and issue you with a report.

Down Arrow

Customized GCC program to match industry needs

gcc-ai-img

AI

gcc-commerce-img

Commerce

gcc-igital-img

Digital

gcc-eucation-img

Education

gcc-energy-img

Energy

gcc-government-img

Government

gcc-health-img

Health

gcc-justice-img

Justice

gcc-manufacture-img

Manufacture

gcc-non-profit-img

Non Profit

Subscribe to the smartest feed in your industry

Frequently Asked Questionsn

Find quick answers to common questions about our regional data protection services and methodology.

How long does a privacy program take?

Hamburger Menu

Our programs are usually 15-40 days – we can deliver as fast as you can work with us. With most clients, our projects take 1-3 months to deliver – we work at your pace.

What does compliance cost?

Hamburger Menu

Do you offer on-site consulting in Doha and Kuwait?

Hamburger Menu

Are your training programs HRDF reimbursable?

Hamburger Menu
cta_bg_mb

Protecting your data across the globe

We have 20 years’ experience in data protection and has led privacy programs globally, including some of the largest tech companies in KSA.

Book a Call

Book a Call
Saudi Arabia Saudi Arabia

The Personal Data Protection Law (issued pursuant to Royal Decree No. M/19 of 9/2/1443 H, as amended by Royal Decree No. M/148 dated 5/9/1444H) (“PDPL”)

Oman Oman

Royal Decree No. 6 of 2022 promulgating the law on the protection of personal data dated 9 February 2022

Bahrain Bahrain

Law No. 30 of 2018 with respect to Personal Data Protection (“PDPL”)

Kuwait Kuwait

Kuwait Law No. 20 of 2014, on Electronic Transactions (the “E-Commerce Law”) and Kuwait Law No. 63 of 2015, on Combating Cyber Crimes the (“Cybercrime Law”)

DIFC and ADGM DIFC and ADGM

DIFC Law No. 5 of 2020 on Data Protection Law (“DPL”)
 ADGM Data Protection Regulations 2021

United Arab Emirates United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data Protection (“PDPL”)

UK & European Union UK & European Union

UK & European GDPR

Qatar Qatar

Law No. (13) of 2016 Concerning Personal Data Protection (“the Data Protection Law”)

Whatsapp Webinar
Hamburger Menu
White Check

Thank You!

The Form has been submitted. We’ll reach to you as soon as possible.