banner-bg

Subscribe to our weekly newsletter on how to comply with GCC data protection laws

Subscribe

Subscribe

GCC Privacy Law Compliance, built with your team

Expert PDPL, GDPR and GCC data protection consultancy for KSA, the UAE and the wider GCC region. We train your nominated DPO or Privacy Manager as we deliver your compliance program, reducing regulatory risk while building an in-house capability that gives you a commercial edge. Your team owns compliance today, next year, and beyond.

hero-img-gcc

Our Certifications

gcc-homo-fip
gcc-home-cipp
gcc-home-cipm
gcc-home-aigp
gcc-home-iso
gcc-laning-img

0+

KSA PDPL Projects

0+

Other GCC Privacy Projects

0+

GDPR Projects

Compliance is a continuous process. We upskill your organization.

We don’t want you to rely on consultants forever – enabling your team is our core delivery method. You nominate a DPO or Privacy Lead and we train them and mentor them as we work through your privacy program. They then take our detailed roadmap and ensure your compliance is continuous.

The workflow of a typical project – these are the areas we cover

Records of Processing Activities (RoPA)

Records of Processing Activities (RoPA)

The RoPA is a legal requirement. We work with your business to understand what personal data you process and record this to create a register. This register is used to understand what the data is, what is done with it – and, importantly, what your regulatory risks are.

Down Arrow
All Staff and DPO training

All Staff and DPO training

Hamburger Menu

We train and mentor your nominated DPO, using the compliance program as a learning tool. We also create all staff training and awareness messages.

International Data Transfers

International Data Transfers

Hamburger Menu

Sending data outside the country is complex – we help you navigate the legal difficulties and do your transfer risk assessments.

Framework, Strategy and Operating Model

Framework, Strategy and Operating Model

Hamburger Menu

These are not theoretical – we tailor these to your company set up and operations so you can manage future compliance.

Lawful Basis and Consent Management

Lawful Basis and Consent Management

Hamburger Menu

Identification of lawful bases and we dive into your consent statements and operations to give clients control of their choices.

Data Protection Policy

Data Protection Policy

Hamburger Menu

This underpins what you do, responsibilities and risk appetites. It underpins the legal obligations and corporate stance.

AI and Tech Development

AI and Tech Development

Hamburger Menu

We look at the data protection aspects of your AI or tech development to make sure that you are compliant with privacy laws.

Data Breaches

Data Breaches

Hamburger Menu

Handy toolkits for all staff to detailed guidance for your DPO and C-Suite, a complete manual to manage issues and learn lessons.

Privacy Notices and Cookies

Privacy Notices and Cookies

Hamburger Menu

We write your external and staff privacy policies in clear language to promote transparency and trust. We also manage your cookies.

Data Subject Rights

Data Subject Rights

Hamburger Menu

How to handle requests from customers and staff for copies of information, withdrawal of consent, corrections or other rights.

Marketing Policy

Marketing Policy

Hamburger Menu

Marketing, whether through emails, phone calls, social media or events is covered by the law. We help you comply and keep you effective.

Vendor and Data Processor Onboarding

Vendor and Data Processor Onboarding

Hamburger Menu

From tender invitations, shortlisting, due diligence, risk assessments and contracts. We make sure your vendors look after your data.

Privacy Impact Assessments

Privacy Impact Assessments

Hamburger Menu

Privacy impact assessment are mandatory under privacy laws. We assess your high risk processing and mitigate risks.

Down Arrow
SDAIA/NDMO Compliance Assessment

SDAIA/NDMO Compliance Assessment

SDAIA and the NDMO have published a framework to assess compliance. We measure your compliance against this and give you a report.

Down Arrow
Roadmap

Roadmap

DPO and compliance diary and continuous compliance plan

Down Arrow

Become a Certified KSA Data Protection Officer

Lots of people offer courses. We offer courses with built in 6 months of mentorship so you are not abandoned at the end of classroom sessions – monthly 1-2-1 meetings to go through assignments that enable you to operationalize the PDPL.

1150+

DPOs trained

170+

Trainings led by trainers

We have worked in your industry before and understand your operations

gcc-ai-image

AI

gcc-image-1

Commerce

gcc-image-2

Digital

gcc-education-image

Education

gcc-energy-image

Energy

gcc-government-image

Government

gcc-health-image

Health

wmremove-transformed 2

Justice

gcc-manufature-image

Industry

gcc-non-profit-image

Non Profit

Subscribe to the smartest feed in your industry

Frequently Asked Questions

Find quick answers to common questions about our regional data protection services and methodology.

How long does a privacy program take?

Hamburger Menu

Our programs are usually 15-40 days long – we can deliver as fast as you can work with us. It typically takes 3 months to deliver a project but we work at your pace.

What does compliance cost?

Hamburger Menu

What services do you provide?

Hamburger Menu

Can you help us prove our compliance to potential customers?

Hamburger Menu

Can you help if we work across several countries?

Hamburger Menu

Who on your team do we work with?

Hamburger Menu

Do you work on site or remotely?

Hamburger Menu

Do you deliver in Arabic?

Hamburger Menu
cta_bg_mb

Protecting your data across the globe

We have 20 years' experience in data protection and have led privacy programs globally, including some of the largest tech companies in KSA.

Contact Us

Contact Us
Saudi Arabia Saudi Arabia

The Personal Data Protection Law (issued pursuant to Royal Decree No. M/19 of 9/2/1443 H, as amended by Royal Decree No. M/148 dated 5/9/1444H) (“PDPL”)

Oman Oman

Royal Decree No. 6 of 2022 promulgating the law on the protection of personal data dated 9 February 2022

Bahrain Bahrain

Law No. 30 of 2018 with respect to Personal Data Protection (“PDPL”)

Kuwait Kuwait

Kuwait Law No. 20 of 2014, on Electronic Transactions (the “E-Commerce Law”) and Kuwait Law No. 63 of 2015, on Combating Cyber Crimes the (“Cybercrime Law”)

DIFC and ADGM DIFC and ADGM

DIFC Law No. 5 of 2020 on Data Protection Law (“DPL”)
 ADGM Data Protection Regulations 2021

United Arab Emirates United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data Protection (“PDPL”)

UK & European Union UK & European Union

UK & European GDPR

Qatar Qatar

Law No. (13) of 2016 Concerning Personal Data Protection (“the Data Protection Law”)

Hamburger Menu
White Check

Thank You!

We will send you an invoice in the next two working days.