Skip to content

    The GCC practice · Dubai 25.20°N

    Governance, risk and compliance across the Gulf, led by a partner on the ground.

    Data protection, cybersecurity and AI regulation in the GCC have moved from emerging to enforced. We advise organisations in Saudi Arabia, the UAE, Qatar, Bahrain and Oman, and the European groups that operate there, from our Dubai office, with the same team that carries the European work.

    discuss a GCC engagement →

    § 01The regimes we cover

    Country by country.

    The rules differ in detail and converge in intent. We design one set of controls and document where each regime genuinely diverges.

    01

    Saudi Arabia

    Personal Data Protection Law (PDPL) and implementing regulations · NDMO data governance · NCA Essential Cybersecurity Controls · SAMA Cyber Security Framework · SDAIA AI Ethics Principles
    02

    UAE, federal

    Federal Decree-Law 45 of 2021 (PDPL) · Child Digital Safety Law · UAE Information Assurance Standards · UAE Charter for AI
    03

    UAE, DIFC

    DIFC Data Protection Law 2020 · Regulation 10 on autonomous and semi-autonomous systems · DFSA rules
    04

    UAE, ADGM

    ADGM Data Protection Regulations 2021 · FSRA rules
    05

    Qatar

    Personal Data Privacy Protection Law · National Information Assurance standard · QFC Data Protection Regulations
    06

    Bahrain

    Personal Data Protection Law · CBB rulebook requirements
    07

    Oman

    Personal Data Protection Law and executive regulations
    § 03Who leads it
    01
    Simon Leadbetter, Associate Partner, GCC, White Label Consultancy

    Associate Partner

    Simon Leadbetter

    Associate Partner, GCC

    Simon is a lawyer and digital trust, governance and transformation programme director with 20 years of GRC experience across the UK and the GCC, spanning data protection, AI governance and regulatory frameworks. Before joining WLC, he served six years as Director of Personal Data Protection at NEOM, where he led enterprise privacy governance and PDPL compliance and helped define NEOM's AI Ethics Council, after leading the development of a draft data protection law, regulation and operating model for a new Saudi regulator. He previously spent 20 years at Accenture across the UK and the UAE, including building its data privacy centre of excellence for GDPR. Simon holds the FIP, CIPP/E and CIPM certifications.

    Dubai office: +971 558 701 959, Dubai World Trade Center, Sheikh Zayed Road. Meet the full team.