uae-grc

Routes UAE compliance questions across mainland, DIFC, ADGM, and sector regimes.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: uae-grc
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/uae-grc/skills/uae-grc
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

UAE compliance obligations depend on where an organization sits — mainland, DIFC, ADGM, healthcare, or CBUAE-licensed finance — and answering with the wrong regime produces wrong advice. This Skill enforces jurisdiction-first routing before any obligation detail is given.

Core Features & Use Cases

  • Jurisdiction Routing: An intake gate and applicability matrix map organizations to the correct instruments (Federal PDPL, DIFC DP Law with 2025 amendment, ADGM DP Regulations, ICT Health Law, CBUAE rules, IA Regulation).
  • Gap Assessments & Breach Response: Produces requirement-by-requirement gap tables per applicable regime and identifies every breach-notification clock (ADGM 72-hour, DIFC as-soon-as-practicable, CBUAE parallel duties).
  • Market Entry & Cross-Mapping: Sequences UAE market-entry roadmaps and maps UAE requirements to ISO 27001:2022, NIST CSF 2.0, and SOC 2 TSC.
  • Use Case: A DIFC fintech asks about data transfers — the Skill applies the DIFC 2025 amendment's documented adequacy-assessment duty and private right of action, rather than citing the federal PDPL.

Quick Start

Ask the advisor to assess which UAE data protection and cybersecurity laws apply to your organization expanding into Dubai with health data processing.

Frequently Asked Questions about uae-grc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which UAE data protection law applies to my company?

UAE privacy law depends on jurisdiction: mainland entities fall under Federal Decree-Law 45/2021, DIFC entities under DP Law No. 5 of 2020 as amended in 2025, and ADGM entities under the ADGM DP Regulations 2021. Sector overlays like the ICT Health Law apply across all zones.

Is the UAE Federal PDPL currently being enforced?

The Federal PDPL has been in force since January 2, 2022, but its Executive Regulations remain unissued as of August 2026, so enforcement is effectively dormant. Organizations get a 6-month compliance grace period once the regulations are issued, and should build GDPR-style readiness now.

Can UAE health data be stored outside the UAE?

No — the ICT Health Law (Federal Law 2/2019) prohibits storing, processing, or transferring UAE health data outside the country unless an authorized exception applies, such as approved telemedicine. Violations carry fines of AED 500,000–700,000, and the rule applies across all zones including DIFC and ADGM.

What changed in the DIFC data protection law in 2025?

Amendment Law No. 1 of 2025, in force July 15, 2025, added a statutory private right of action, mandatory documented transfer-adequacy assessments, Commissioner power to withdraw adequacy decisions, and higher fine tiers up to USD 50,000 for certain failures.

Does CBUAE regulation apply to DIFC or ADGM financial firms?

CBUAE rules apply only to CBUAE-licensed financial institutions. Firms regulated solely by DFSA (DIFC) or FSRA (ADGM) answer to those regulators for prudential and conduct matters, and to their zone's data protection law for privacy.

What are the breach notification timelines in the UAE?

ADGM requires notification to the Commissioner within 72 hours, plus data-subject notice for high-risk breaches. DIFC requires notification as soon as practicable when a breach compromises confidentiality, security, or privacy. Federal PDPL notification duties exist on paper, with operational details pending the Executive Regulations.