Privacy thinking for people who have to act on it.
No hype, no fear tactics — precise, practical thinking on UAE PDPL, ADHICS and the realities of running privacy across the GCC.
UAE PDPL, in plain English: what Federal Decree-Law No. 45 actually requires
A clear-eyed walkthrough of what the UAE's Personal Data Protection Law actually obliges organisations to do — beyond the headlines.
Why GCC privacy programmes fail differently than European ones
Regional data flows, multi-jurisdiction free zones and fast-scaling organisations create a distinct set of privacy failure modes across the GCC.
The 30-day clock: handling data subject requests without the scramble
What actually breaks when a real data subject request arrives — and the operational discipline that prevents it.
When a DPIA is actually required — and when it is theatre
Not every project needs a full Data Protection Impact Assessment. Knowing the difference is what makes a DPIA programme credible.
Breach notification under PDPL: the decisions that matter in the first 24 hours
Speed matters, but the first hours after a suspected breach are more about clear decision rights than raw speed.
Where privacy automation actually pays off (and where it doesn't)
Automation is not a privacy strategy on its own. Applied to the right processes, it is what makes a strategy survive contact with scale.