What problem does it solve?
UAE compliance obligations depend on where an organization sits — mainland, DIFC, ADGM, healthcare, or CBUAE-licensed finance — and answering with the wrong regime produces wrong advice. This Skill enforces jurisdiction-first routing before any obligation detail is given.
Core Features & Use Cases
- Jurisdiction Routing: An intake gate and applicability matrix map organizations to the correct instruments (Federal PDPL, DIFC DP Law with 2025 amendment, ADGM DP Regulations, ICT Health Law, CBUAE rules, IA Regulation).
- Gap Assessments & Breach Response: Produces requirement-by-requirement gap tables per applicable regime and identifies every breach-notification clock (ADGM 72-hour, DIFC as-soon-as-practicable, CBUAE parallel duties).
- Market Entry & Cross-Mapping: Sequences UAE market-entry roadmaps and maps UAE requirements to ISO 27001:2022, NIST CSF 2.0, and SOC 2 TSC.
- Use Case: A DIFC fintech asks about data transfers — the Skill applies the DIFC 2025 amendment's documented adequacy-assessment duty and private right of action, rather than citing the federal PDPL.
Quick Start
Ask the advisor to assess which UAE data protection and cybersecurity laws apply to your organization expanding into Dubai with health data processing.