UAE Information Assurance Standards, Dubai ISR and federal Personal Data Protection Law compliance for organisations operating across the Emirates.
The UAE combines federal direction with emirate-specific regulation, and knowing which applies to you is the first question worth answering properly. Organisations frequently assume a single national regime and discover mid-programme that a second, emirate-level one also applies.
The UAE Information Assurance Standards — historically associated with NESA — define national controls for entities supporting critical information infrastructure across sectors including energy, banking, aviation, healthcare, ICT and transport. The standards cover both management and technical controls, and are prioritised so that a subset must be addressed first rather than the whole set at once. Responsibility for the standards has moved between federal bodies over recent years, so it is worth confirming the current supervising authority for your sector rather than relying on older guidance.
The Dubai Electronic Security Center issues the Information Security Regulation for Dubai government entities and their partners. If you operate in Dubai and supply a government entity, ISR is usually the regime that reaches you in practice, and it is assessed independently of the federal standards.
The UAE’s federal personal data protection law governs the processing of personal data, with obligations covering lawful basis, transparency to data subjects, security measures, and responses to data subject requests. Specialised regimes apply in the financial free zones — the DIFC and ADGM each have their own data protection legislation and regulators, which are separate from the federal law and generally more prescriptive.
This is where UAE compliance most often goes wrong. An organisation established in the DIFC or ADGM is subject to that zone’s data protection law and regulator, not the federal law. Advice written for mainland UAE does not transfer cleanly, and a privacy programme built against the wrong instrument can require substantial rework.
We establish which regime actually applies before designing the programme — including for groups that operate across mainland and free zone entities simultaneously, which is common and needs handling deliberately rather than by assumption.
Where you want tooling rather than spreadsheets, GRCLens runs ISO/IEC 27001, SOC 2, PCI DSS and other frameworks on one shared control model, and can be deployed on-premises or in a UAE-hosted environment where residency matters. Our Dubai presence means on-site delivery where an engagement needs it.
They apply to entities supporting critical information infrastructure and to government bodies, and reach private organisations both directly by sector and indirectly through contract. Sector matters more than ownership here.
Generally no — DIFC entities are subject to DIFC data protection legislation and its own commissioner. Groups operating across both mainland and free zone entities need to handle each under the right regime rather than applying one policy to everything.
Yes. The Dubai ISR is issued by DESC and applies to Dubai government entities and their partners. Some organisations are in scope for both ISR and the federal standards, which is manageable but needs mapping so the work is not done twice.
Yes. We have a Dubai presence and deliver workshops, assessments and board sessions on site alongside remote delivery.
Tell us where you are established and which authority is asking, and we will tell you which regime actually applies before any work begins. Get in touch.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.