The data privacy partner behind the GCC's most resilient organizations.
Certus Privacy Partners builds and runs the privacy operating model behind UAE PDPL and ADHICS compliance — not a binder of policies, but a function that works.
Trusted by CISOs, DPOs, General Counsel and Boards across healthcare, insurance, financial services and government-adjacent entities in the UAE.
We do not advise on privacy. We operate it.
Most firms hand you a policy and a PDF. Certus builds the workflows, owns the mechanics of data subject requests and DPIAs, and stays in the room until your privacy function runs itself — audit-ready, every day, not just before an assessment.
Operational, not theoretical
Every engagement produces a working process your team runs the next day — not a recommendation.
Specialist, not generalist
Privacy is our only discipline. We are not translating a cyber framework into privacy language.
Evidence-first
Everything we build is designed to survive scrutiny from a regulator, auditor or your own Board.
Embedded, not detached
We stay close enough to the work to know when a process is actually holding, not just documented.
A complete privacy operating model, delivered in parts or in full.
PDPL Readiness Assessment
A precise, evidence-based read on where you stand against UAE PDPL — and what closing the gap actually requires.
Explore→Data Subject Request (DSR) Management
The workflow, tooling and SLA discipline to handle access, correction and deletion requests without scrambling.
Explore→DPIA Design & Execution
A structured, defensible Data Protection Impact Assessment methodology built into how projects actually get approved.
Explore→Data Breach Reporting Readiness
The playbook, thresholds and rehearsed response that turn a breach from chaos into a controlled, timely process.
Explore→RoPA & Data Mapping
A living Record of Processing Activities that reflects what your systems actually do with personal data.
Explore→Vendor Privacy Reviews
Structured due diligence on the third parties who process your data on your behalf — before and during the relationship.
Explore→ADHICS Privacy Alignment
Mapping and closing the privacy-specific gaps between your security posture and ADHICS requirements.
Explore→Privacy Automation & Workflow Implementation
Turning DSR, consent, retention and vendor-review processes into workflows your systems run for you.
Explore→Managed Privacy Office Support
An embedded, fractional privacy function for organisations that need senior capability without a full-time hire.
Explore→A disciplined path from exposure to a privacy function that runs itself.
Discover
We map your data, processing activities, vendors and regulatory exposure against UAE PDPL and ADHICS — in weeks, not quarters.
Design
We design the specific workflows, RACI and governance model your organisation needs — sized to your risk, not a generic template.
Implement
We build the DSR, DPIA, breach-response and vendor-review mechanics directly into your existing tools and teams.
Operate
We stay embedded as your managed privacy office, or hand over a function your team can run and defend on its own.
Built differently, on purpose.
Pure privacy focus
Not a cyber consultancy with a privacy slide. Data privacy is the entire firm.
CISO-led
Led by practitioners who have owned security and privacy risk from inside regulated organisations.
Implementation-heavy
We measure ourselves on workflows shipped, not decks delivered.
GCC-ready
Built around UAE PDPL, ADHICS and the realities of operating across the Emirates and the wider GCC.
Audit-friendly
Every deliverable is built to withstand scrutiny from regulators, auditors and your own board.
Outcome-based
Engagements are scoped against measurable privacy outcomes, not billable hours.
Regulated sectors. Real operating context.
Healthcare
ADHICS-aligned privacy for hospitals, clinics and health-tech platforms handling the region's most sensitive data.
Learn more →Insurance
Privacy operating models for insurers managing health, financial and behavioural data across underwriting and claims.
Learn more →Financial Services
Privacy that stands alongside existing regulatory, AML and risk functions rather than duplicating them.
Learn more →Government-Adjacent Entities
Privacy programmes built for the scrutiny and public accountability government-linked organisations face.
Learn more →Large Enterprise
Multi-entity, multi-system privacy programmes that hold together across a complex organisation.
Learn more →Family Offices & High-Trust Sectors
Discreet, senior-led privacy advisory for organisations where discretion is the entire value proposition.
Learn more →What changes when privacy is operated, not just advised on.
Privacy thinking for people who have to act on it.
UAE PDPL, in plain English: what Federal Decree-Law No. 45 actually requires
A clear-eyed walkthrough of what the UAE's Personal Data Protection Law actually obliges organisations to do — beyond the headlines.
Why GCC privacy programmes fail differently than European ones
Regional data flows, multi-jurisdiction free zones and fast-scaling organisations create a distinct set of privacy failure modes across the GCC.
The 30-day clock: handling data subject requests without the scramble
What actually breaks when a real data subject request arrives — and the operational discipline that prevents it.
Your privacy exposure will not wait for the next audit cycle.
Talk to a Certus Privacy Partner and find out precisely where you stand under UAE PDPL and ADHICS — and what it takes to close the gap.