Certus
← All services

ADHICS Privacy Alignment

Mapping and closing the privacy-specific gaps between your security posture and ADHICS requirements.

What it is

A focused alignment programme for healthcare and healthcare-adjacent entities, connecting the privacy obligations under PDPL with the technical and governance controls required by the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) standard.

Why it matters

ADHICS is a security standard, but a significant share of its control requirements — access governance, data classification, third-party management, incident handling — are privacy questions in disguise. Treating ADHICS purely as an IT security project misses the accountability and data-subject-rights obligations that sit alongside it.

What Certus does
  • Map ADHICS control requirements against your existing privacy and security controls to find true gaps, not duplicated effort.
  • Align data classification, access governance and third-party controls across both frameworks.
  • Build the evidence base auditors expect to see for both ADHICS certification and PDPL accountability.
  • Coordinate with your existing security team so privacy and security workstreams reinforce, not duplicate, each other.
What you receive
  • An ADHICS-to-PDPL control mapping, with clearly identified true gaps
  • A joint remediation roadmap sequenced for audit readiness
  • An evidence pack structured the way ADHICS auditors expect to review it
  • A briefing for your security and compliance teams on where the two frameworks intersect
Typical timeline

5–8 weeks, run alongside your existing ADHICS certification timeline.

Who this is for

Healthcare and insurance CISOs, Compliance leaders and DPOs preparing for ADHICS audit or renewal.

How this differs from a generic consultancy

We are not a general cyber consultancy applying a privacy label to ADHICS work. We start from the data subject's rights and work back to the control, which is what auditors are increasingly testing for.