Certus
Privacy, operationalised — for the GCC

The data privacy partner behind the GCC's most resilient organizations.

Certus Privacy Partners builds and runs the privacy operating model behind UAE PDPL and ADHICS compliance — not a binder of policies, but a function that works.

Trusted by CISOs, DPOs, General Counsel and Boards across healthcare, insurance, financial services and government-adjacent entities in the UAE.

Why Certus

We do not advise on privacy. We operate it.

Most firms hand you a policy and a PDF. Certus builds the workflows, owns the mechanics of data subject requests and DPIAs, and stays in the room until your privacy function runs itself — audit-ready, every day, not just before an assessment.

Operational, not theoretical

Every engagement produces a working process your team runs the next day — not a recommendation.

Specialist, not generalist

Privacy is our only discipline. We are not translating a cyber framework into privacy language.

Evidence-first

Everything we build is designed to survive scrutiny from a regulator, auditor or your own Board.

Embedded, not detached

We stay close enough to the work to know when a process is actually holding, not just documented.

How we work

A disciplined path from exposure to a privacy function that runs itself.

01

Discover

We map your data, processing activities, vendors and regulatory exposure against UAE PDPL and ADHICS — in weeks, not quarters.

02

Design

We design the specific workflows, RACI and governance model your organisation needs — sized to your risk, not a generic template.

03

Implement

We build the DSR, DPIA, breach-response and vendor-review mechanics directly into your existing tools and teams.

04

Operate

We stay embedded as your managed privacy office, or hand over a function your team can run and defend on its own.

Why clients choose Certus

Built differently, on purpose.

Pure privacy focus

Not a cyber consultancy with a privacy slide. Data privacy is the entire firm.

CISO-led

Led by practitioners who have owned security and privacy risk from inside regulated organisations.

Implementation-heavy

We measure ourselves on workflows shipped, not decks delivered.

GCC-ready

Built around UAE PDPL, ADHICS and the realities of operating across the Emirates and the wider GCC.

Audit-friendly

Every deliverable is built to withstand scrutiny from regulators, auditors and your own board.

Outcome-based

Engagements are scoped against measurable privacy outcomes, not billable hours.

Outcomes

What changes when privacy is operated, not just advised on.

10x
Faster response to data subject requests
60%
Reduction in breach exposure windows
100%
Audit-ready evidence, on demand
1
Clear owner for every privacy obligation

Your privacy exposure will not wait for the next audit cycle.

Talk to a Certus Privacy Partner and find out precisely where you stand under UAE PDPL and ADHICS — and what it takes to close the gap.