DIFC Data Protection Law: Do You Need a DPO? (2026)

DIFC Data Protection Law: Do You Need a DPO? (2026)

DIFC Data Protection Law: Do You Need a DPO? (2026)

DIFC Data Protection Officer Requirements: The DPL 2020 Guide for DIFC Companies (2026)

Last updated: October 2026.

The short answer first. Companies in the Dubai International Financial Centre follow the DIFC Data Protection Law No. 5 of 2020 (DPL), not the UAE PDPL. Article 16 makes a data protection officer (DPO) mandatory for DIFC Bodies and for any controller or processor that carries out High Risk Processing Activities on a systematic or regular basis. The Commissioner of Data Protection expects virtually all regulated financial businesses and medical practices to carry out such processing, so in practice most DFSA-authorised firms need a DPO.

The DIFC is also stricter than ADGM about who the DPO can be. The DPO must live in the UAE, unless they are employed within your group and do a similar job for the group internationally. A controller that must appoint a DPO also files an annual assessment of its processing with the Commissioner, which neither ADGM nor the PDPL requires.

Firms that do not need a DPO still register with the Commissioner and renew every year, keep a record of processing (firms under 50 staff are exempt unless they carry out high-risk processing), answer access requests within 30 days and report breaches as soon as practicable. This guide covers when the requirement applies, who can hold the role, how the DIFC differs from ADGM and the PDPL, and what an outsourced DPO costs.

Your DPO of record in the UAE and Middle East
A named Data Protection Officer, backed by a delivery team that builds and runs your privacy programme. From $1,900 / mo

Your DPO of record in the UAE and Middle East
A named Data Protection Officer, backed by a delivery team that builds and runs your privacy programme. From $1,900 / mo

DIFC data protection at a glance

Topic

DIFC rule

Law

Data Protection Law, DIFC Law No. 5 of 2020, amended in 2022 and 2025, with the Data Protection Regulations

Regulator

Commissioner of Data Protection

Who it covers

Entities incorporated in the DIFC wherever they process, and anyone processing in the DIFC as part of stable arrangements (Article 6)

When a DPO is mandatory

DIFC Bodies, and controllers or processors carrying out High Risk Processing Activities on a systematic or regular basis (Article 16(2)); the Commissioner can also require one (Article 16(3))

Where the DPO can be based

In the UAE, unless a group employee performs a similar role for the group internationally (Article 16(7))

Annual assessment

Prepared by the DPO and filed with the Commissioner for every controller that must appoint one (Article 19)

Registration

Notification of processing operations on the DIFC Client Portal, renewed every year with the licence (Article 14(7))

Record of processing

Required, except for firms under 50 staff with no high-risk processing (Article 15, Regulation 2.2)

Data subject requests

Within one month, defined as 30 days, extendable by two further months (Article 33)

Breach notification

To the Commissioner as soon as practicable; to individuals as soon as practicable where the risk to them is high (Articles 41 and 42)

Fines

Up to USD 100,000 per listed contravention under Schedule 2, plus a general fine with no fixed cap (Article 62)

Court claims

Individuals can claim compensation in the DIFC Courts (Article 64A, added in July 2025)

Who the DIFC Data Protection Law applies to

Article 6 of the Data Protection Law sets two routes into scope. The first is incorporation: a controller or processor incorporated in the DIFC is covered wherever the processing happens, so a DIFC fund manager whose investor platform runs in an Irish cloud region is fully in scope. The second is location: anyone processing personal data in the DIFC as part of stable arrangements is covered, wherever it is incorporated. The text as amended in July 2025 expressly reaches sub-processors and transfers of data out of the DIFC.

The UAE PDPL (Federal Decree-Law No. 45 of 2021) does not apply in free zones with their own data protection law. A DIFC holding company with an operating subsidiary on the mainland therefore runs two regimes, and an ADGM affiliate adds a third. Our UAE PDPL compliance guide covers the onshore side, and our ADGM DPO guide covers Abu Dhabi's financial free zone.

When a DIFC company must appoint a DPO

Article 16(2) makes the appointment mandatory in two cases:

  1. You are a DIFC Body, such as the DFSA, the DIFC Authority or the DIFC Courts, other than courts acting in their judicial capacity.

  2. You are a controller or processor that carries out High Risk Processing Activities on a systematic or regular basis.

Under Article 16(3), the Commissioner can also order any other controller or processor to appoint one. The law does not define "systematic or regular". High-risk processing that forms part of normal business, such as onboarding every client or running a product on customer data, meets it in practice. A one-off project may not.

What counts as High Risk Processing Activities

Schedule 1 of the DPL defines High Risk Processing Activities as processing where at least one of four things applies:

  • (a) new or different technologies or methods are adopted, and they materially increase the risk to individuals' security or rights, or make it harder for individuals to exercise their rights;

  • (b) a considerable amount of personal data will be processed, including staff and contractor data, and the processing is likely to result in a high risk to individuals;

  • (c) the processing involves a systematic and extensive automated evaluation of people, including profiling, on which decisions with legal or similarly significant effects are based;

  • (d) a material amount of special categories of personal data will be processed.

The Commissioner's guidance on High Risk Processing Activities and DPO appointments turns these limbs into practical tests, and it reads more broadly than most firms expect.

On the second limb, the Commissioner sets no number but lists the kinds of entity that typically process a considerable amount of data: a controller with several hundred staff or several thousand customer records, any business that stores or analyses personal data for its customers or its group, outsourced HR, payroll and IT service providers, hosted subscription services, and aggregator or referral platforms. Holding companies, advisory firms with a small client base and small businesses that collect little customer data usually fall outside. In the Commissioner's view, taking card payments through a PCI DSS compliant solution does not amount to processing a considerable amount of data, however many transactions run through it.

The data itself decides whether the risk is high. The guidance treats names, email addresses and account identifiers as typically low-risk. Special category data, bank account and salary details, copies of passports and ID cards, location tracking data and data about third parties count as typically high-risk. The guidance then states that the Commissioner would expect virtually all medical practices and regulated financial businesses to be carrying out High Risk Processing Activities, along with many of the service providers that have access to their personal data.

The first limb catches technology choices. The guidance cites storing records on a blockchain instead of a traditional database, and using AI to automate decisions or run chat features, as examples of new methods. The limb applies only where the change also materially harms individuals' security or rights, for example by making erasure impossible.

Special categories in the DIFC cover racial or ethnic origin, communal origin, political affiliations or opinions, religious or philosophical beliefs, criminal record, trade-union membership, health and sex life, and genetic and biometric data used to identify a person. A fintech that matches selfies to identity documents processes biometric data. A health or insurance product processes health data as its core.

Applied to the companies we see in the DIFC, our reading is this:


Company

Likely position

Reason

DFSA-authorised bank, broker, asset manager or insurer

DPO likely required

The Commissioner expects virtually all regulated financial businesses to carry out high-risk processing, and client onboarding runs continuously

Health-tech, wellness or insurtech company

DPO likely required

Health data is processed as the product

SaaS, payments or IT services provider handling client data for DIFC firms

DPO likely required

The guidance names hosted services, outsourced business services and IT support among typical high-risk processors

AI or analytics startup that profiles people to make decisions about them

DPO likely required, plus Regulation 10

Profiling with significant effects; AI developers appear in the Commissioner's examples

Family office or advisory firm with a small client base

Usually not required

Few individuals, so the volume is not considerable, even where the financial data is sensitive

Holding company or SPV

Not required

The guidance treats holding companies as low volume unless they have many individual shareholders

Write the decision down either way, with the reasoning. The DIFC publishes a DPO appointment assessment tool on its data protection guidance pages, and a recorded decision is what the Commissioner will ask to see.

If you do not need a DPO

Article 16(4) still requires you to allocate responsibility for data protection compliance clearly inside the organisation, and to name the people responsible if the Commissioner asks. Every DIFC entity also registers with the Commissioner by filing a notification of its processing operations (Article 14(7)). New entities file it through the DIFC Client Portal as part of setting up, renew it with the commercial licence each year, and update it within 14 days of starting any new processing. The register is public, so a bank or investor running due diligence can check it.

The rest of the law applies whatever you decide about the DPO. You keep a record of processing activities unless you employ fewer than 50 people and carry out no high-risk processing (Regulation 2.2). You run a data protection impact assessment (DPIA) before any high-risk processing (Article 20), and consult the Commissioner if the risks remain particularly high after mitigation (Article 21). Processor contracts need the Article 24 terms, and transfers need an adequate destination or a safeguard (Articles 26 and 27). Data subjects need at least two ways to exercise their rights, one of them free on your website without creating an account (Article 40).

You can also appoint a DPO voluntarily under Article 16(1), and many firms do because banks and enterprise clients ask for a named privacy contact. A voluntary DPO must meet the same Article 17 requirements as a mandatory one. Give the person the independence and access the law describes, or use a different title.

What the DPO must be and do

Article 16(5) lets the role sit with a member of staff, an individual employed elsewhere in your group, or a third party under a service contract. A group can share one DPO if that person is easily accessible from each entity (Article 16(6)). The Commissioner's guidance adds that the DPO should ideally be an individual, and asks firms that want to appoint an organisation as DPO to consult the Commissioner's office first. If you outsource the role, the contract should name the person who holds it.

Then comes the residency rule. Article 16(7) requires the DPO to reside in the UAE unless they are employed within your group and perform a similar function for the group internationally. A London-based group privacy lead can therefore serve as DPO for a DIFC subsidiary. An outsourced DPO provider in London or Bangalore cannot.

Article 17 sets the DPO's competencies and status. The DPO needs knowledge of the law, must be able to act independently and on their own authority, reports directly to senior management, and needs sufficient resources and timely, unrestricted access to information. Article 17(3) adds a duty most regimes lack: the DPO must be transparent and cooperative with the Commissioner and notify the Commissioner of all relevant information within the organisation, other than material covered by legal privilege or a conflicting duty of non-disclosure.

Article 18 sets the tasks. The DPO monitors compliance with the DPL, any other privacy law that applies in the DIFC and the firm's own policies, including staff training and the related audits. The DPO also informs and advises the business and its staff, advises on DPIAs, cooperates with the Commissioner as the contact point, and acts on the Commissioner's findings and directions. Data subjects can contact the DPO directly about their data (Article 18(2)), and you must publish the DPO's contact details so that a third party can find them without disproportionate effort (Article 16(8)).

The annual assessment

Where a controller must appoint a DPO, Article 19 requires the DPO to carry out an annual assessment of the controller's processing activities and submit it to the Commissioner. The assessment also states whether the controller intends to carry out High Risk Processing Activities in the following period. The Commissioner publishes the format, content and deadline on the DIFC Client Portal (Regulation 4.1.1). A missed or incomplete assessment can be fined up to USD 25,000 under Schedule 2, and the Commissioner can direct the controller to complete it within a further period.

Who should not be your DPO

Article 18(1)(c) bars additional duties that create a conflict of interest or stop the DPO doing the job properly. The Commissioner's guidance asks to be read alongside UK and EU guidance, and that guidance treats senior roles that set the purposes of processing as conflicted: usually the CEO, COO and CFO, and the heads of marketing, HR and IT. The test is whether the person decides what personal data the business uses and why.

Article 17(4) lets the DPO hold other roles where they do not conflict. In DFSA-authorised firms the compliance officer often takes the DPO role as well, which works if that person has the time and the data protection knowledge. In our view, an external virtual CISO in Dubai also sits on the right side of the line: a security lead advises on and implements the controls that protect personal data, while decisions on what data to collect and why stay with management. Our Builder plan puts both roles with one named person for that reason.

AI systems: Regulation 10 and the Autonomous Systems Officer

Regulation 10 of the Data Protection Regulations, in force since September 2023, covers personal data processed through autonomous and semi-autonomous systems, which in practice means AI. Deployers and operators must give users clear notice when a system processes their data without human direction, including any effect on their rights to rectification, erasure or objection.

High-risk use carries more. Under Regulation 10.3.3, nobody may offer or operate a system commercially for High Risk Processing Activities unless the system meets the Commissioner's audit and certification requirements and processes data only for human-defined or human-approved purposes. The deployer or operator must also appoint an Autonomous Systems Officer (ASO) with the same or substantially similar competencies, status and tasks as a DPO. The Commissioner has published an accreditation and certification framework for these systems, and the Regulation 10 FAQs expect that the ASO may also be the DPO.

For an AI startup in the DIFC Innovation Hub, the high-risk assessment can therefore lead to two appointments: a DPO for the company and an ASO for the product.

DIFC vs ADGM vs UAE PDPL: DPO rules compared



DIFC

ADGM

UAE mainland

Law

Data Protection Law No. 5 of 2020

Data Protection Regulations 2021

Federal Decree-Law No. 45 of 2021 (PDPL)

Regulator

DIFC Commissioner of Data Protection

ADGM Commissioner of Data Protection

UAE Data Office

DPO mandatory

DIFC Bodies; High Risk Processing Activities on a systematic or regular basis

Public authorities; large-scale monitoring or large-scale special category data as a core activity

High-risk processing through new technology or data volume; systematic evaluation of sensitive data, including profiling; large-scale sensitive data (Article 10)

Where the DPO can be based

In the UAE, unless a group DPO performs a similar role internationally

Anywhere, if easily accessible

Inside or outside the UAE

Annual DPO assessment filed with the regulator

Yes (Article 19)

No

No

Breach notification to the regulator

As soon as practicable

Within 72 hours where feasible

Procedures deferred to the Executive Regulations, which are not yet issued

Maximum fine

USD 100,000 per listed contravention, plus a general fine with no fixed cap

USD 28 million

Set by Cabinet decision

The trigger is where the DIFC bites hardest. ADGM asks whether large-scale monitoring or special category data is your core activity. The DIFC asks whether you carry out high-risk processing regularly, and the Commissioner's guidance answers yes for most regulated firms. A DFSA-authorised broker may need a DPO in the DIFC while its FSRA-authorised sister company in ADGM does not.

For a group, the efficient answer is one privacy programme with the filings each regime requires. A single DPO can cover a DIFC entity and an ADGM entity, provided that person lives in the UAE.

Transfers out of the DIFC

The Commissioner's list of adequate jurisdictions includes ADGM, the UK, the EU and EEA, Switzerland, Singapore, Japan, the Republic of Korea, California, the Qatar Financial Centre and a short list of others. It does not include the UAE mainland, Saudi Arabia, India or the United States as a whole, and the Commissioner is reassessing the EU-US Data Privacy Framework. A transfer from a DIFC company to its own onshore subsidiary, or to a development team in India, needs an Article 27 safeguard, usually the DIFC standard contractual clauses, or one of the derogations. The Commissioner's Export Assessment tool on the same page walks through the options.

Breaches and data subject requests: the clocks that matter

Article 41 has no risk threshold of the kind GDPR and ADGM use. Any personal data breach that compromises a data subject's confidentiality, security or privacy goes to the Commissioner as soon as practicable in the circumstances. Regulation 8.1 asks for the report by email to the Commissioner's office or through the form on the DIFC website, without undue delay after you become aware. You can send the information in phases as it emerges, and every breach goes into an internal record of its facts, effects and the remedial action taken.

Where a breach is likely to result in a high risk to individuals, you also tell them as soon as practicable, and promptly where there is an immediate risk of damage (Article 42). A public communication can replace individual notices where contacting everyone would take disproportionate effort. Processors tell their controller without undue delay.

DFSA-authorised firms run a second clock. GEN 5.5.19 requires material cyber incidents to be reported to the DFSA within 72 hours, so a single ransomware attack can start the DFSA deadline and the Commissioner's "as soon as practicable" at the same moment. Our guide to the DFSA and FSRA cyber rules covers the DFSA side.

Data subject requests run on a 30-day clock. Article 33 gives you one month to respond, and the DPL defines a month as 30 days. If a request is particularly complex, or requests are numerous, you can extend by two further months by telling the requester within the first month and giving reasons. Article 33(9) also requires a register of every extension, fee and refusal of a manifestly unfounded or excessive request, and the Commissioner can inspect it.

Fines and court claims

Schedule 2 lists maximum fines for specific contraventions. Failing to appoint a required DPO carries up to USD 50,000, as does skipping a DPIA before high-risk processing or failing to report a breach under Article 41 or 42. Failing to register, keep a record of processing or file the annual assessment carries up to USD 25,000 each. Breaches of the main data subject rights, such as access and erasure, carry up to USD 100,000 each. Article 62(3) then lets the Commissioner add a general fine for any contravention, not limited to the Schedule 2 amounts, sized to the seriousness of the contravention and the risk of harm.

The DIFC Laws Amendment Law No. 1 of 2025, in force since 15 July 2025, added a private right of action. Under Article 64A, a data subject who suffers damage from a contravention can apply to the DIFC Courts for compensation, in addition to complaining to the Commissioner, and damage includes distress as well as financial loss.

In-house vs outsourced DPO: four options for DIFC firms

DIFC firms usually choose between four options, and each fits a different kind of firm.

Naming the compliance officer as DPO costs nothing extra and suits a firm with light processing and a compliance officer who has the time. It strains once the privacy work grows: the record of processing, DPIAs before launches, requests on a 30-day clock, vendor contracts and the annual assessment all compete with compliance monitoring and AML.

A group DPO abroad works in the DIFC only if that person is employed within your group and does a similar job for the group internationally. Subsidiaries of international banks and asset managers often use this route.

Law firms are the right call for a legal opinion on a novel question. They rarely keep a record of processing current or work through access requests each week, and billing that work by the hour gets expensive quickly.

An outsourced DPO, also called DPO as a service or a virtual DPO, is a named individual appointed under a service contract, as Article 16(5) permits, who runs the programme for a fixed monthly fee. In the DIFC that person must live in the UAE. It suits firms that carry out high-risk processing regularly but do not have enough privacy work for a full-time hire.

What an outsourced DPO does in the first 90 days

The sequence below is how we run a new DIFC engagement. Most of the build work lands in the first quarter.

  1. Weeks 1 to 2, scope and appointment. Run the high-risk assessment and record the decision. Appoint the DPO, publish the contact details, and check that the notification on the DIFC Client Portal matches what the business actually does.

  2. Weeks 2 to 5, data mapping. Interview the teams that handle personal data, map systems and data flows, and build the record of processing with a lawful basis for each activity.

  3. Weeks 4 to 8, notices, vendors and transfers. Rewrite the privacy notices for clients, staff and investors, set up at least two request channels, put Article 24 terms into processor contracts, and record each transfer outside the DIFC with its safeguard.

  4. Weeks 6 to 10, DPIAs and retention. Run DPIAs on the high-risk processing already in place and set retention periods for each category of data.

  5. Weeks 8 to 12, requests, incidents and training. Write the request procedure around the 30-day clock. Build the breach runbook with the Commissioner notification and, for DFSA firms, the 72-hour DFSA one, then test it in a tabletop exercise. Train staff and send the first report to senior management.

After that the role settles into a smaller recurring cycle: requests as they arrive, DPIAs before launches and new vendors, notification updates within 14 days of a change in processing, the licence renewal, and the annual assessment on the Commissioner's deadline. If you want the programme certified, ISO/IEC 27701:2025 can now be certified on its own, and these records make up most of its evidence.

What it costs

A full-time privacy hire in Dubai costs a senior package, for work that needs a few days a month once the programme is built. Below a few hundred staff, the numbers rarely justify it.

Dynova's prices are public. Our standalone named DPO of record costs USD 1,900 a month on a 12-month term and includes the record of processing, DPIAs, processor agreements, data subject requests, privacy notices, breach notification, liaison with the Commissioner and a quarterly privacy report. On the Builder plan, at USD 4,500 a month, the same DPO comes with eight hours a week of vCISO time for security strategy, hands-on control implementation and certification preparation, and one named person holds both roles. See the DPO service page for the full breakdown.

The DIFC's own notification fees are separate and small. Registration costs USD 1,250 for DFSA-authorised firms, USD 750 for other non-retail firms and USD 250 for retail, with annual renewals of USD 500, USD 250 and USD 100.

One cost rarely appears in quotes: your own people's time. Even with the DPO carrying the work, the people who own client data and IT will spend a few hours a week on interviews and decisions during the first quarter.

Frequently asked questions

Does the UAE PDPL apply to companies in the DIFC?

No. The PDPL (Federal Decree-Law No. 45 of 2021) excludes free zones that have their own data protection legislation, and the DIFC is one of them. DIFC entities follow the DIFC Data Protection Law No. 5 of 2020, and a group with an onshore subsidiary follows the PDPL for that subsidiary only.

Is a DPO mandatory in the DIFC?

For DIFC Bodies, and for any controller or processor that carries out High Risk Processing Activities on a systematic or regular basis. The Commissioner can also require any other firm to appoint one. Because the Commissioner expects virtually all regulated financial businesses to carry out high-risk processing, most DFSA-authorised firms should assume they need a DPO.

Does a DIFC DPO have to live in the UAE?

Yes, unless the DPO is employed within your group and performs a similar function for the group internationally. An outsourced provider therefore needs a UAE-resident person in the role.

Can we outsource the DPO role in the DIFC?

Yes. Article 16(5) allows a third party under a service contract. The Commissioner prefers the DPO to be an individual, so the contract should name the person who holds the role.

What is the DIFC annual assessment?

A yearly review of a controller's processing activities that its DPO carries out and submits to the Commissioner under Article 19, including whether the controller plans High Risk Processing Activities in the following period. Every controller that must appoint a DPO files one, on the format and deadline the Commissioner publishes on the DIFC Client Portal. A missed assessment can be fined up to USD 25,000.

How much does DIFC data protection registration cost?

USD 1,250 for DFSA-authorised firms, USD 750 for other non-retail firms and USD 250 for retail, then USD 500, USD 250 or USD 100 a year on renewal. Telling the Commissioner that you do not process personal data costs nothing.

What is the deadline for reporting a data breach in the DIFC?

As soon as practicable in the circumstances, for any breach that compromises a data subject's confidentiality, security or privacy. DFSA-authorised firms also report material cyber incidents to the DFSA within 72 hours under GEN 5.5.19.

How long do we have to answer a data subject access request in the DIFC?

One month, which the DPL defines as 30 days. You can extend by two further months for complex or numerous requests if you tell the requester within the first month and give reasons.

What are the fines under the DIFC Data Protection Law?

Schedule 2 sets maximum fines per contravention, from USD 25,000 to USD 100,000, and failing to appoint a required DPO carries up to USD 50,000. The Commissioner can add a general fine with no fixed cap under Article 62(3), and since July 2025 individuals can claim compensation in the DIFC Courts under Article 64A.

Can our compliance officer or vCISO also be our DPO?

In most cases, yes. Article 17(4) allows the DPO to hold other roles that do not create a conflict of interest. The conflict lies with people who decide what personal data the business processes and why, such as the CEO or the head of marketing. Neither a compliance officer nor an external vCISO makes those decisions.

Do AI products in the DIFC need anything extra?

Yes, if they process personal data. Regulation 10 requires clear notice to users, and a system used commercially for High Risk Processing Activities needs certification under the Commissioner's framework and an Autonomous Systems Officer with DPO-level competencies.

Working with Dynova in the DIFC

If you are setting up in the DIFC, or already licensed and unsure whether your processing counts as high risk, get in touch. We will tell you whether you need a DPO, what your notification, record of processing and breach plan are missing, and what the first 90 days should cover. Our DPOs are based in the UAE, as the DIFC requires, and we act as named DPO for regulated companies, including InsuranceMarket.ae alongside its in-house security team.

Related: ADGM Data Protection Regulations: Do You Need a DPO? · DFSA & FSRA Cybersecurity Requirements: A vCISO Guide · UAE PDPL Compliance: A vCISO and DPO Guide · UAE PDPL Executive Regulations: Status in 2026 · vCISO for Fintechs in the UAE

Written by

Founder of Dynova, vCISO and DPO (CISSP, CISM)

Founder of Dynova, vCISO and DPO for UAE companies. Formerly Head of Information Security and Privacy at Equiti. CISSP, CISM.

Guide

Experience

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant