Defining the right scope is the single biggest determinant of UAE PDPL success. Too narrow and the certificate is meaningless; too broad and the programme stalls under its own weight.
ISO/IEC 27001 Certified
ISO/IEC 27701 Certified
ISO 9001 Certified
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Who the standard applies to
UAE-licensed entities under the relevant federal or emirate regulator
Service providers processing in-scope data for UAE entities
Branches of foreign entities operating in the UAE
Critical-infrastructure operators designated by the authority
Typical in-scope boundaries
Legal entities and business units in scope
Geographies and data residency boundaries
Cloud accounts, data centres and end-user computing estates
Third parties processing in-scope data on your behalf
Products, services or customer segments included
Scope dimensions
Icon grid titled "Scope dimensions" with 5 categories: Legal entities and business units in scope, Geographies and data residency boundaries, Cloud accounts, data centres and end-user computing estates, Third parties processing in-scope data on your behalf, Products, services or customer segments included.
01Legal entities and business units in scope
02Geographies and data residency boundaries
03Cloud accounts, data centres and end-user computing estates
04Third parties processing in-scope data on your behalf
05Products, services or customer segments included
Common scoping mistakes
Excluding shared services (HR, payroll, identity) that handle in-scope data.
Treating SaaS platforms as out-of-scope when they process production data.
Omitting DR, backup and recovery sites from the boundary.
Forgetting to include the security operations function itself.
Scoping pitfalls to avoid
Checklist titled "Scoping pitfalls to avoid" with 4 items, every item marked complete: Excluding shared services (HR, payroll, identity) that handle in-scope data.; Treating SaaS platforms as out-of-scope when they process production data.; Omitting DR, backup and recovery sites from the boundary.; Forgetting to include the security operations function itself..
✓Excluding shared services (HR, payroll, identity) that handle in-scope data.
✓Treating SaaS platforms as out-of-scope when they process production data.
✓Omitting DR, backup and recovery sites from the boundary.
✓Forgetting to include the security operations function itself.
How we run the scoping exercise
A two-week scoping sprint with your sponsor, IT, security, legal and audit produces a written scope statement, an asset and data-flow map, and a signed-off boundary diagram. This becomes the anchor for the entire UAE PDPL programme.